Privacy Policy
Account-free by design. We collect only the details needed to take payment, deliver your eSIM and support you.
Last updated 11 July 2026. Data controller: Safira Khan Marketing LTD (support@simzora.com).
The short version.
We are account-free and collect as little as possible. We ask for your email, name and city to deliver and support your order; phone, country and postal code are optional. We never see or store your card details.
What we collect & why.
(a) Checkout details, including email, name, city and optional contact details, to deliver and support your eSIM; (b) order details, country, plan, amount, order ID and timestamps; (c) payment confirmation from our processor, never the card number; and (d) your advertising preference. We also process your IP address transiently to route requests and prevent abuse.
Who we share it with (sub-processors), and the minimum each gets.
- Stripe (card payments), your email and the amount, to take the charge.
- NOWPayments (crypto payments), the amount and order ID; no email.
- eSIM Access (our eSIM supplier), only a package code and order reference; no buyer personal data at all.
- Resend (email delivery), your email and the order email content.
- Vercel (hosting + analytics), request logs and cookieless, aggregate traffic/performance metrics that don't identify you.
- Google Ads and Meta, only if you actively opt in to advertising measurement. They receive ad measurement events, including purchase value, currency and an order reference.
Cookies.
We use essential storage for the store and cookieless analytics. UK and EEA visitors receive an explicit choice before advertising cookies are used; Google Ads uses consent mode with a denied default, while Meta advertising tags wait for consent. Visitors elsewhere can open or change advertising preferences at any time. See our Cookie Policy.
Where it's stored & for how long.
Orders are stored encrypted with our hosting provider and kept for about 200 days (aligned to eSIM validity), then removed. Sub-processors may process data outside your country under their own safeguards.
Your rights (GDPR / UK GDPR / CCPA).
You can access, correct, delete, port, or object to the processing of your data. To delete it yourself, use My eSIMs → “Delete my data”, which erases your email from our records and clears your device. Or email support@simzora.com and we'll action it (including asking Stripe/NOWPayments to erase the email they hold for the charge). We don't sell your data.
Legal basis for processing.
Under the UK GDPR and EU GDPR we rely on: performance of a contract to take your payment and deliver the eSIM you bought; legitimate interests to keep the service secure and prevent fraud and abuse; and your explicit consent before loading Google Ads or Meta advertising measurement. Cookieless aggregate analytics does not rely on tracking consent.
How we keep it safe.
Traffic to and from the site is encrypted in transit (HTTPS), order records are stored encrypted with our hosting provider, and access is limited to what is needed to run the store. We never see or store full card numbers, and we do not ask you to create a password unless you choose to open an optional account, in which case passwords are stored only as a salted, hashed value that even we cannot read.
International transfers.
Some of our sub-processors (Stripe, NOWPayments, eSIM Access, Resend and Vercel) may process data outside your home country. Where they do, they operate under their own recognised safeguards, such as standard contractual clauses, to protect your data to an equivalent standard.
Children.
The service isn't directed at anyone under 18, and we don't knowingly collect their data.
Changes & contact.
We'll post updates here with a new date. Questions or requests: support@simzora.com.
This notice reflects how Safira Khan Marketing LTD handles your data across Simzora. For any privacy request or question, contact support@simzora.com.