Legal

Privacy Policy

What Eazi eSIM (operated by Simplify Connect, "we", "us") collects about you, why, where it goes, and what you can do about it. SIM registration laws mean we handle more identity data than a typical web shop — this page is specific about it.

We are the data controller for everything described here, and we process personal data under the EU General Data Protection Regulation (and the UK GDPR for customers in the United Kingdom). South Africa's POPIA applies in addition to the SIM-registration leg of your purchase, because that is where the network operator is. Where the two differ, we apply whichever gives you more.

Last updated 25 August 2026

1. What we collect

Account. Your email address (sign-in is by magic link), an optional password, and your billing currency preference.

Identity (KYC), where the law requires it. Some networks legally require SIM registration — in South Africa, the RICA Act. For those purchases we collect your first name and surname, passport number and expiry date, nationality, country of residence and address. We do not ask for a scan or photo of your passport: the operator's registration only accepts these typed fields, so an image would serve no purpose. Images captured before August 2026, when we still asked for one, are being erased.

Phone numbers. The numbers (MSISDNs) of eSIMs we issue you and of any of your own SIMs you link, including the one-time SMS verification used to prove a linked SIM is yours.

Orders and payments. What you bought, when, for how much, and its delivery status. Card details go directly to Stripe — we never see or store them.

Technical. A session cookie to keep you signed in and a CSRF token to protect forms. We run no advertising or analytics trackers, and our pages load nothing from a third party — typefaces and scripts are served from our own servers, so no other company sees your IP address when you visit.

2. Why we collect it, and our lawful basis

To deliver what you bought — provisioning your eSIM, activating bundles, applying top-ups, and showing your balance (performance of a contract).

Because the law requires it — identity details are collected solely to register your SIM with the network operator where legislation such as RICA demands it (legal obligation). We do not use KYC data for marketing, profiling, or anything else.

To keep the service safe — SMS possession checks stop strangers claiming your number; send limits stop abuse; error monitoring tells us when something breaks (legitimate interest).

3. Where your data goes

We share data only with the processors needed to run the service:

  • The mobile network operator (for example Vodacom or MTN) — your KYC details, where registration is legally required, and your number for provisioning, balance, and SMS.
  • Stripe — payment processing. Stripe receives your email and payment details under its own privacy policy.
  • SparkPost — delivers our emails (sign-in links, receipts, order updates) to your address.
  • Hosting and storage — the application and its database run on Fly.io (Amsterdam region). Identity documents captured before August 2026 sit in access-controlled object storage (Tigris) until the retention sweep erases them; we store no new ones.
  • Error monitoring (Sentry) — receives technical crash reports so we can fix faults. We do not send it your identity documents or passport details.

We do not sell personal data, and we run no advertising.

4. How long we keep it

Identity (KYC) details — five years after your SIM's last activity, mirroring the record-keeping period the South African operator is held to under RICA. A nightly job erases them automatically once that period is up; nothing is kept "just in case". Passport images captured before August 2026 are erased on the same schedule.

Account and order records — while your account exists, and afterwards for as long as tax and accounting law requires the invoice to exist. After an account deletion these rows have no name attached to them.

SMS verification codes — stored only as hashes, and expire within ten minutes.

5. Your rights

Under the GDPR you have the right to access your data, to receive it in a portable form, to have it corrected, to have it erased, to restrict or object to processing, and not to be subject to automated decision-making (we do none). Two of these you can exercise yourself, immediately, without asking us:

  • Get a copy of your data — "Download my data" on your account page returns everything we hold about you as a JSON file.
  • Erase your account — "Delete my account" on the same page erases your passport details, any identity document, your eSIM nicknames and your verified numbers, and signs you out. Order and payment rows survive with no name attached, because tax law requires the invoice to exist; that is the only thing we keep, and we keep it in a form that no longer identifies you.

For correction, restriction, objection, or anything else, write to [contact email — pending] from the address on your account. We answer within one month.

If you think we have got this wrong, you can complain to your local data protection authority — in the EU, the supervisory authority where you live or work; in the UK, the Information Commissioner's Office; in South Africa, the Information Regulator. We would rather you told us first.

6. Sending data outside the EEA

The service itself runs in the EU (Fly.io, Amsterdam). Buying a local prepaid eSIM does, however, mean sending your registration details to the operator in the destination country — South Africa today — because that is the whole point of a local SIM. South Africa has no EU adequacy decision, so those transfers rely on Standard Contractual Clauses with the operator's gateway, and we send only the fields the registration needs.

Stripe and SparkPost may also process data outside the EEA under their own Standard Contractual Clauses.

7. Security

All traffic is encrypted in transit (TLS, with HSTS). Sign-in links and verification codes are single-use and short-lived, and codes are stored hashed. Card data never touches our systems at all. The strongest control on identity documents is that we no longer hold them: we stopped collecting passport images in August 2026, and the ones we already had are being erased.

8. Changes

If this policy changes materially, we will update this page and the date at the top. The terms of service cover the rest of our relationship.