Use this promo code for 10% off on all your orders! WELCOME10

Privacy Policy

Last updated: August 10, 2026

1. Introduction

This Privacy Policy explains how SimJuno ("SimJuno", "we", "us", or "our") collects, uses, shares, and protects personal data when you visit our website, create an account, or purchase and use our travel eSIM products and related services (together, the "Services").

We process personal data in accordance with applicable data protection laws, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").

We may update this Policy from time to time (see Section 14). Please read it carefully. If you do not agree with this Policy, please do not use the Services.

2. Who We Are and How to Contact Us

The controller responsible for the processing of your personal data described in this Policy is [LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("SimJuno").

For any questions about this Policy, or to exercise your privacy rights, you can contact us at [email protected].

3. Personal Data We Collect

Account information. When you create an account we collect your name, username, email address, and a password. Passwords are never stored in plain text; we store only a securely hashed version. You may optionally upload a profile picture, which is stored with our cloud storage provider.

Sign-in with Google or Apple. If you register or sign in using Google or Apple, we receive your name, email address, and profile picture from that provider, together with the technical tokens required to authenticate you. We never receive your Google or Apple password.

Security and session data. Each time you sign in we create a session record that includes your IP address and browser and device information (user agent). We use this to keep you signed in, to let you review and revoke your active sessions, and to protect your account. IP addresses are also used for rate limiting and abuse prevention. If you enable two-factor authentication, we store the secret and backup codes required to verify your codes.

Payment and transaction data. We keep records of your purchases, top-ups, account balance, refunds, redeemed coupons, and the payment method used, including amounts, timestamps, transaction identifiers, and related technical metadata returned by our payment processors. We do not collect or store full payment card numbers (see Section 6). If you pay with or are refunded in cryptocurrency, we process the relevant wallet addresses.

eSIM data. To provision and manage your eSIM we store technical identifiers such as the ICCID, IMSI, and EID, activation codes and QR codes, network settings (APN), plan validity dates, and the volume of data you have used. If a phone number (MSISDN) is assigned to your eSIM, we store that number as well.

Support data. When you contact our support team or open a ticket, we collect the content of your messages and any files you attach.

Affiliate and payout data. If you participate in our affiliate program, we store your referral activity, earnings, and the payout destination you provide, such as a bank account (IBAN) or a cryptocurrency wallet address.

Other data. We also store API keys you generate, your language preference, and interface settings.

4. How We Use Your Personal Data

We use your personal data to: (a) provide and operate the Services, including creating and managing your account, provisioning eSIMs, and displaying your data usage; (b) process payments, refunds, coupon redemptions, and affiliate payouts; (c) send transactional emails such as email verification, password reset, and password change confirmations; (d) respond to your support requests; (e) secure the Services, including authenticating you, managing sessions and two-factor authentication, rate limiting, and detecting and preventing fraud and abuse; (f) comply with legal obligations, such as tax and accounting requirements and lawful requests from authorities; and (g) maintain and improve the Services, including monitoring and fixing errors.

Where the GDPR applies, we rely on the following legal bases: performance of a contract (providing the Services you purchase); our legitimate interests (securing the Services, preventing fraud and abuse, and improving our products); compliance with legal obligations; and your consent, where required, which you may withdraw at any time.

We do not sell your personal data, and we do not use it for third-party advertising or for profiling that produces legal or similarly significant effects.

5. Cookies and Similar Technologies

We use only cookies that are necessary to operate the Services or that store your preferences. We do not use advertising cookies or third-party analytics cookies.

The cookies we set are: authentication and session cookies that keep you signed in; a temporary cookie used during two-factor authentication sign-in; a locale cookie that remembers your language; and interface preference cookies (for example, remembering whether a dashboard sidebar is open).

You can delete or block cookies through your browser settings, but parts of the Services — in particular signing in — will not work without the strictly necessary cookies.

6. Payment Processing

Card payments are processed by Stripe. Your card details are transmitted directly from your browser to Stripe and never pass through or are stored on our servers. To process card payments, we share your username and email address with Stripe to create a customer record, and we store the resulting Stripe customer reference and transaction metadata. Stripe processes your data in accordance with its own privacy policy, available at stripe.com/privacy.

Cryptocurrency payments are processed by Cryptomus and NowPayments. For these payments we share the order identifier and the amount with the processor. Please note that transactions on public blockchains are inherently public and outside our control. If we issue a refund in cryptocurrency, we process the wallet address you provide for that purpose.

We retain transaction records for accounting, tax, and fraud prevention purposes as required by applicable law.

7. eSIM Provisioning and Connectivity Data

Our eSIMs are provisioned through a third-party eSIM connectivity provider. When you purchase an eSIM or a top-up, we share with this provider only the order details required to fulfil it: an internal transaction reference and the selected data package. We do not share your name or email address with the connectivity provider.

In return, the provider sends us the technical data needed to deliver and manage your eSIM, including the ICCID, activation code and QR code, network settings, plan status, and data usage figures.

When you use your eSIM, your mobile traffic is carried by the connectivity provider and its partner mobile network operators in the countries you visit. These operators process communications metadata — such as device identifiers, approximate location derived from the network connection, and usage volumes — under their own legal obligations. We receive only aggregate usage figures (for example, the amount of data consumed). We do not receive or store the content of your communications or your browsing history.

8. How We Share Personal Data

We share personal data with service providers that process it on our behalf and under our instructions: payment processors (Stripe, Cryptomus, NowPayments); our eSIM connectivity provider; Amazon Web Services, which delivers our transactional emails; Cloudflare, which stores uploaded files such as profile pictures and support attachments and serves our content; and our hosting and infrastructure providers. Each provider receives only the data necessary for its function and is contractually required to protect it.

We may also disclose personal data: to comply with a legal obligation, court order, or enforceable governmental request; to establish, exercise, or defend legal claims; to protect the rights, property, or safety of SimJuno, our users, or the public; in connection with a merger, acquisition, or sale of assets, in which case we will notify you before your personal data becomes subject to a different privacy policy; and otherwise with your consent or at your direction.

We do not sell or rent personal data, and we do not share it for cross-context behavioral advertising.

9. International Data Transfers

Some of the service providers listed above process data outside your country of residence, including outside the European Economic Area and the United Kingdom. Where personal data is transferred to a country that has not been found to provide an adequate level of data protection, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent mechanisms. You may contact us for more information about the safeguards applied to a specific transfer.

10. Data Retention

We keep your personal data for as long as your account is active and as needed to provide the Services. Session records are kept until they expire or you revoke them. Support tickets are kept for as long as necessary to handle your request and any follow-ups.

Transaction and payment records are retained after account closure for as long as required by applicable tax, accounting, and anti-fraud laws.

When you delete your account, we delete or anonymize your personal data, except for the records we are legally required to retain. You can delete your account from your account settings or by contacting us at [email protected].

11. Security

We take appropriate technical and organizational measures to protect your personal data, including encryption of data in transit (TLS), password hashing, access controls that restrict which staff can access personal data, and optional two-factor authentication for your account.

No method of transmission or storage is completely secure. If we become aware of a personal data breach that affects you, we will notify you and the competent authorities where required by law.

12. Your Privacy Rights

If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar laws, you have the right to: access the personal data we hold about you; have inaccurate data corrected; have your data erased; restrict or object to certain processing; receive your data in a portable format; and withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local data protection supervisory authority.

If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request deletion and correction of your personal information; and not to be discriminated against for exercising your rights. We do not sell personal information or share it for cross-context behavioral advertising, so no opt-out is required.

To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before acting on your request, and we will respond within the timeframe required by applicable law.

13. Children's Privacy

The Services are not directed at children under the age of 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it.

14. Changes to This Policy

We may update this Policy from time to time, for example to reflect changes in the Services or in applicable law. We will post the updated Policy on this page and revise the "Last updated" date above. If a change materially affects how we process your personal data, we will notify you by email or through the Services before it takes effect.

15. Contact Us

If you have questions about this Policy or about how we handle your personal data, contact us at [email protected].

SimJuno

Secure, effective and private eSIMs across the globe