Privacy Policy
Este documento está redactado en inglés y todavía no se ha publicado en tu idioma. El texto en inglés de abajo es el que se aplica.
This policy explains what personal data eSIM Now Limited ("we", "us") collects when you use esim.now (the "Site") and the eSIM service, why we collect it, who sees it, and what you can ask us to do with it. We have tried to write it so that it can actually be read.
Contenido
- Who this covers and who is responsible
- The rules we follow
- What we collect
- Why we use it
- Legal bases (where a law requires one)
- Who we share it with
- Where the data goes
- How long we keep it
- How we protect it
- Cookies and browser storage
- Your rights
- Children
- Other websites
- Changes to this policy
- Governing law
- Contact us
1. Who this covers and who is responsible
eSIM Now Limited decides how and why personal data is processed on the Site, and is the party responsible for it under the Personal Data (Privacy) Ordinance of Hong Kong (Cap. 486, the "PDPO"). This policy applies to the Site, to the emails we send, and to support conversations, whether you buy as a guest or hold an account.
It does not cover the mobile operators whose networks your eSIM uses once installed, or the payment providers whose pages you pay on; section 6 says what we share with them, and their own policies say what they do with it.
2. The rules we follow
We handle personal data according to the six Data Protection Principles of the PDPO: collect it fairly and only for a stated purpose; keep it accurate and no longer than needed; use it only for that purpose or one directly related; keep it secure; be open about how we handle it; and let you see and correct it.
If you are in the European Economic Area, the United Kingdom or another place with its own data protection law, we also apply the rules of that law where they go further, as sections 5 and 11 describe.
3. What we collect
- Contact and account data. The email address you type at checkout or sign-in; a name, if you give one; the one-time codes we send to that address; a password hash, if you set a password; and, if you sign in with Google, the email and name Google returns.
- Order and payment data. What you bought, when, for how much, and the order number. From the payment processor we receive whether the payment succeeded, the method used (for example "Visa ending 4242" or "PayPal"), and a transaction reference. We never receive or store your full card number.
- eSIM data. From the network partner: the profile's identifiers (such as the ICCID), whether it has been downloaded and installed, its activation state, and how much data it has used. We need this to show your order status and to help when something does not work.
- Technical data. IP address, browser and device type, language, the pages you open on the Site and the times. Server logs keep this for security and debugging.
- Support data. What you write to us, the screenshots you send, and our replies.
- Referral data. If you arrive through a referral link, the referral code and a click identifier, stored in a cookie (see the Cookie Policy) so the discount and the commission can be applied to your order. If you join the referral program, the code you chose, your referral earnings and the payout details you give us.
- Wallet data. Top-ups, balances and transactions on your wallet.
We collect this from you directly, automatically as you use the Site, and from the partners named above. We do not buy data about you from anyone.
4. Why we use it
- To sell and deliver the eSIM: take the order, take the payment, have the profile issued, email you the QR code, and show you the order page.
- To support you: answer your messages, diagnose an eSIM that is not connecting, and process refunds.
- To run accounts, the wallet and the referral program: sign you in, keep balances right, apply discounts and pay commissions.
- To keep the Site safe: detect fraud, duplicate payments, abuse of promotions and attacks on the Site.
- To improve the Site: understand which pages and plans people use, mostly from aggregated data.
- To meet legal duties: keep accounting records, answer lawful requests from authorities, and handle disputes.
- To tell you about the service, with your permission: we email you about your order without asking; we only send offers or news if you have opted in, and every such email has an unsubscribe link.
5. Legal bases (where a law requires one)
Under the PDPO, we collect data for the purposes above and use it only for those purposes or ones directly related to them. Where the GDPR or the UK GDPR applies to you, our bases are: performing our contract with you (the order and the account); our legitimate interests in running, securing and improving the Site, balanced against your rights; legal obligations (tax and accounting records); and your consent, for marketing emails and non-essential cookies, which you can withdraw at any time.
7. Where the data goes
The Site is operated from Hong Kong, and our providers and network partners run systems in other countries — including the destination your eSIM is for. Where data leaves the place it was collected, we rely on contracts with the recipient that require an equivalent standard of protection (for EEA and UK data, the standard contractual clauses), and we keep what is transferred to the minimum the service needs.
8. How long we keep it
- Orders, payments and refunds: seven years after the order, because accounting and tax law require it.
- eSIM data: for the life of the plan and up to twelve months after, so that we can help with a late problem or a dispute.
- Account data: until you close the account, after which it is deleted or anonymised within 30 days, except what the line above requires us to keep.
- Support conversations: two years after the last message.
- Server logs: up to 90 days.
- Referral cookie: 30 days from the click.
Data we no longer need is deleted or anonymised; anonymised statistics may be kept indefinitely.
9. How we protect it
Data is encrypted in transit and at rest; access is limited to the people and systems that need it, and is logged; passwords are stored as one-way hashes; sign-in codes expire in minutes; payment details never touch our servers; and the Site is backed up. No system is perfectly secure, and we will tell you and, where required, the regulator, if a breach affects your data.
11. Your rights
Under the PDPO you can:
- Ask what we hold about you and get a copy of it.
- Have it corrected if it is wrong or incomplete.
- Withdraw consent for anything you agreed to, such as marketing emails — use the link in the email, or write to us.
- Opt out of direct marketing at any time, and we will not send it.
If the GDPR or UK GDPR applies to you, you can also ask us to delete your data, to restrict or object to how we use it, and to give you a copy in a portable format; and you can complain to the data protection authority where you live. Everyone can complain to the Office of the Privacy Commissioner for Personal Data in Hong Kong.
To exercise a right, email supper@eSIM.Now from the address on the account or order. We may ask you to confirm you are that person, and we answer within 40 days as the PDPO requires — usually much sooner. Where a law requires us to keep something (an order record, for instance), we will explain what we cannot delete and why.
12. Children
The Site is meant for adults. We do not knowingly collect data from anyone under 16, and we do not design any part of the Site for children. If you believe a child has given us data, write to us and we will delete it.
13. Other websites
The Site links to payment providers, to our network partners' instructions, and occasionally to other sites. Each of them has its own privacy policy, which governs what they do; this policy stops at the edge of the Site.
14. Changes to this policy
When we change this policy we update the date at the top and publish the new version on the Site. A change that affects how we use data already collected will be announced on the Site, and where the law requires it, we will ask for your consent again.
15. Governing law
This policy and any dispute about how we handle personal data are governed by the laws of the Hong Kong Special Administrative Region, and the courts of Hong Kong have jurisdiction — without taking away any protection that the data protection law where you live gives you and that cannot be waived.
16. Contact us
Questions, requests and complaints about personal data go to eSIM Now Limited at supper@eSIM.Now. Please put "Privacy" in the subject so it reaches the right person quickly.
¿Dudas sobre este documento? Escribe a supper@eSIM.Now.