LEGAL
Privacy Policy
This policy explains what personal information QuickSIM collects, why we collect it, who we share it with, how long we keep it and the rights you have over it. It is written to follow UK data protection law (the UK GDPR and the Data Protection Act 2018) and the rules on cookies and electronic marketing in the Privacy and Electronic Communications Regulations. It should be read alongside our Terms and Conditions, which it forms part of.
1. Who we are
QuickSIM ("we", "us", "our") sells data-only eSIM plans through this website. For the purposes of the UK GDPR we are the data controller of the information described in this policy, which means we decide why it is collected and how it is used.
You can contact us about anything in this policy at support@quicksim.world, or through the live chat on this website. If your message is a request to use one of the rights in section 9, please say so, so that we handle it within the legal timescales.
2. The short version
- We collect what we need to create your account, take payment, deliver your eSIM and support you afterwards, nothing more.
- We do not sell, rent or trade your personal information, and we do not share it with advertisers or data brokers.
- We do not use advertising cookies, tracking pixels or third-party analytics. Your activity is not followed across other websites.
- Card details go straight to our payment provider, Stripe. We never see or store your full card number.
- The organisations that receive your details are the ones that help us run the service, including our payment provider, our eSIM supplier, our email provider and our hosting provider, plus the services that serve our typeface, our country flags and the country lookup, which see your IP address as the page loads.
- You can ask to see, correct, download or delete your information at any time. See section 9.
3. What we collect and why
Account details. Your first name, last name, email address, mobile number and address (both optional), and your password. Your password is stored as a one-way scrypt hash with a random salt. We can never read it, and neither can anyone who gets hold of our database.
Order and eSIM details. The plan you bought, what it cost, your order reference, the date, and the identifiers our supplier returns for your eSIM (the ICCID and SIM reference) plus its expiry date. This is what lets us show your order history on any device and help you if something goes wrong.
Payment information. Handled by Stripe. We receive a payment reference, the amount, whether it succeeded, and the email address you asked Stripe to send the receipt to. We never receive or store your full card number, expiry date or security code.
Email confirmation codes. Before your first payment we send a six-digit code to prove the address is yours and that we are not emailing eSIM credentials to a mistyped or someone else's inbox. The code is stored as a hash, expires after 15 minutes, and is deleted once it is used.
Support conversations. Whatever you type into the live chat, along with the name, email and phone number you give there. We keep them so we can pick up where we left off and so you can read the history.
Technical and usage information. Your IP address, the pages you visit on our site, the website that referred you, and your device and browser type. We use your IP address to work out an approximate city and country, which is what lets the shop open on the right country and currency, and we keep a short-lived anonymous visitor ID so the admin panel can show how many people are on the site at that moment. We use this to keep the site secure and working, to understand which pages are useful, and to spot abuse such as card testing. If you arrive from one of our adverts we also record which campaign the link came from — the campaign tags in the address bar and the site that sent you — so we can tell which adverts are worth running. That is all we read: we set no advertising cookies and use no tracking pixels, and we do not sell any of it.
Marketing preferences. Whether you have agreed to hear from us by email or SMS. We only send marketing where you have opted in, every marketing email we send will carry a working unsubscribe link, and you can change your mind at any time.
4. Our lawful bases for using your information
- Contract: to create your account, take payment, deliver and support your eSIM, and handle refunds.
- Legitimate interests: to keep the site, your account and our payments secure, to prevent fraud and misuse, and to understand how the shop is used so we can improve it. We balance our interests against your rights and expectations.
- Consent: marketing by email or SMS. You can withdraw it at any time.
- Legal obligation: keeping accounting records, and responding to lawful requests from authorities.
We do not collect special category information (such as health or ethnicity), we do not build advertising profiles, and we do not make automated decisions that have a legal or similarly significant effect on you. The country we suggest from your IP address is only a default for the shop; you can change it, and it never affects what anything costs.
5. Who we share it with
We share the minimum needed to run the shop:
- Stripe: to take the payment, screen it for fraud and send your receipt. Stripe handles card data under its own privacy policy.
- Our eSIM supplier (eSIM Access): the wholesale partner that creates your eSIM profile. They receive your email address, your order reference and the package you bought, so the profile can be issued and sent to you. They are outside the UK.
- Our email provider (Resend): to send your eSIM, verification and account emails.
- Our hosting provider (OVH): the servers the website and database run on, in a data centre in the European Union.
- Google Fonts: the typeface on this site is loaded from Google's font service, so your browser contacts Google and they see your IP address while it is delivered.
- Our country lookup provider (ipapi.co): when you first open the site we ask it which country your IP address appears to be in, so the shop opens on the right country and currency. That request shares your IP address with them.
- A public image CDN (flagcdn.com): the country flag images are served from there, which also means it sees your IP address. None of these three is used to profile you or to follow you to other websites; they exist to deliver a file or answer a lookup.
- The mobile networks your eSIM connects to: they see your eSIM identifier and your data usage as part of providing the connection. They cannot see the contents of your messages or browsing.
- Professional advisers and authorities: only where we are legally required to, for example a valid request from the police or HMRC, or to establish or defend a legal claim.
- A buyer, if the business is ever sold: customer information could transfer as part of the sale. You would be told, and this policy would keep applying until it was properly changed.
We do not sell, rent, trade or otherwise hand over your personal information to advertisers, data brokers, list builders or any other third party for their own marketing. The only recipients are the service providers listed above and the mobile networks that carry your data. If you ever see a QuickSIM email address being used by another company, it did not come from us; please tell us and we will look into it.
6. Sending information outside the UK
Some of the organisations above (in particular our payment provider and our eSIM supplier) process information outside the UK. Where that happens we rely on the safeguards UK law requires for the transfer, such as the UK International Data Transfer Agreement or Addendum, or the UK's adequacy regulations where the destination is approved. We keep a record of which safeguard covers which provider and can tell you if you ask.
7. How long we keep it
We keep personal information only while we need it. Our usual periods are:
- Account details: while your account is open, and for up to 24 months after your last purchase, then deleted.
- Order and transaction records: 6 years, because tax law requires us to keep accounting records that long.
- Support chats: 24 months, so you can refer back to advice we gave you.
- Email confirmation codes: deleted once used or after 15 minutes, whichever comes first. A short-lived counter is kept to stop the code emails being abused.
- Visitor and technical logs: retained for ongoing analytics and customer-support purposes. These records are not automatically removed based on a fixed visit-count limit.
- Marketing consent records: while you are on the list, plus 24 months, so we can prove what you agreed to.
- Server backups: kept for 14 days.
Not every one of these is deleted automatically, so if you would like something removed sooner, ask us and we will do it by hand.
8. Keeping your information safe
- The whole site runs over encrypted HTTPS connections.
- Passwords are stored as scrypt hashes with a random salt, never in plain text.
- Sign-in cookies are httpOnly, so scripts on the page (including anything injected by an attacker) cannot read your session token.
- Your account data sits in our own database on our own server, which is not reachable from the internet and is not exposed to the public web.
- Access is limited to the people who run QuickSIM and need it to answer your messages and manage orders, using a server key and a separate password-protected admin panel.
No system is perfect. If a breach ever occurred that was likely to put your rights at risk, we would tell you and report it to the Information Commissioner's Office within the timescales the law requires.
9. Your rights
Under the UK GDPR you have the right to ask us to do any of the following. It is free, and we normally answer within one month:
- Access: tell you what we hold about you and give you a copy.
- Rectification: correct anything that is wrong or incomplete.
- Erasure: delete information we no longer need to keep. You can ask us to close and delete your account.
- Restriction and objection: pause some of our processing, or object to it. You can object to marketing at any time, and we will always stop.
- Portability: give you the information you provided to us in a common, machine-readable format.
- Withdraw consent: for marketing, at any time.
To use any of these, email support@quicksim.world or message us on the live chat. We may need to confirm who you are first. There are a few things we must keep, such as tax records, or information needed to deal with a legal claim. If that applies, we will always explain why.
10. Cookies and other storage on your device
We keep this deliberately simple: no advertising cookies, no tracking pixels, no third-party analytics, and no cookie banner, because we only use storage that is essential to run the shop.
Our own cookie. fs_customer_session keeps you signed in. It is httpOnly, so scripts cannot read it, and it lasts 30 days or until you sign out. The admin panel has its own equivalent, only created if you sign in there.
Your browser's local storage. This stays on your device and the law treats it like a cookie, so we are telling you about it. We use it to remember the plan you were looking at, the country and currency you chose, your chat with us, a short-lived anonymous ID that tells us whether anyone is on the site, and a small copy of your own account details so the header can show your name instead of your email address.
Stripe's fraud-prevention cookies. When the card form loads, Stripe's script sets __stripe_mid and __stripe_sid on our domain. They help Stripe judge whether a payment looks genuine. We do not use them to track you anywhere else.
We rely on the exception in the Privacy and Electronic Communications Regulations that covers storage which is essential to provide a service you have asked for. If we ever add analytics or advertising, we will ask for your consent first and update this policy.
You can clear or block cookies and local storage whenever you like in your browser settings. Blocking our sign-in cookie means you will not stay signed in, and blocking Stripe's may make a card payment more likely to be declined by its fraud checks.
11. Children
Our plans are sold to adults. You must be 18 or over to buy one, or have a parent or guardian buy it for you. We do not knowingly collect information from children. If you believe a child has given us their details, contact us and we will delete them.
12. Changes to this policy
If we change how we use your information, we will update this page and change the date at the top. If the change is significant, we will email account holders to tell them. We will not start selling your information; if that ever changed, it would need your consent first, and we would ask.
13. Complaints and contact
If you are unhappy with how we have handled your information, please tell us first. Email support@quicksim.world or use the live chat and we will try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection, at ico.org.uk or on 0303 123 1113. Complaining to us costs you nothing and does not affect your right to go to the ICO or to court.
