Privacy Policy
This policy explains the information Simpriest processes when you browse the site, request a quote, purchase an eSIM, contact support, or use the protected order-status page.
Controller
The controller is SIM Priest, a sole proprietorship operating the Simpriest brand from 15 York Street, Toronto, Ontario M5J 0B2, Canada. Privacy and legal inquiries may be sent to legal@simpriest.com; order support remains available at support@simpriest.com.
Information we process
- Contact and order information, including email address, destination, package, currency, payment status and order history.
- eSIM fulfilment information, including provider order number, ICCID, activation details and delivery status.
- Technical and security information such as IP address, request time, browser/device data, fraud signals and server logs.
- Sanitized mobile crash and error reports, including app version, operating system, error type and technical stack trace. Email addresses, access tokens, credentials and secret query values are removed on the device before transmission.
- Messages and attachments you choose to send support.
Payment information
Stripe processes card and payment-method details on its systems. Simpriest receives identifiers, status, amount, currency and limited billing information needed to operate and support the order; we do not store full card numbers.
Why we use information
We use information to provide quotes, take payment, provision and deliver eSIMs, show protected order status, prevent fraud and abuse, provide support, keep accounting records, troubleshoot failures, and comply with legal obligations. Where required, our legal bases include performing the purchase contract, legitimate interests in securing and improving the service, legal obligations, and consent.
First-party service measurement
We count destination views, plan selections, checkout starts, successful payments and eSIM deliveries by day, destination country and plan category. This aggregate dataset does not contain email addresses, IP addresses, account identifiers, advertising identifiers or device fingerprints, and we do not set an analytics cookie for it. We use it to understand where the purchase journey fails and retain the aggregate counts and short-lived duplicate-prevention records for up to 400 days.
Service providers and international transfers
We share only what is reasonably necessary with providers that help run the service, including Stripe for payment, eSIMAccess and relevant mobile operators for fulfilment, Resend when email delivery is enabled, and hosting/security providers such as Hetzner and Cloudflare. These companies may process information in other countries under their own terms and applicable transfer safeguards. We do not sell personal information.
Retention
Order, invoice, payment, refund and tax records may be retained for up to seven years after the relevant transaction where needed for Canadian accounting, tax, dispute and legal obligations. Purchase IP addresses are removed from ordinary completed-order records after 180 days unless an open fraud review, dispute, support matter or legal requirement needs them longer. Expired sessions are removed automatically; expired one-time authentication records are removed after seven days; recipient rate-limit records after 30 days; aggregate service-measurement records after 400 days; eSIM usage snapshots and lifecycle-delivery records after two years; and resolved operational-error records after one year. Support records are reviewed when a case closes. Approved deletion requests are automatically anonymised when their recorded retention date passes, unless a documented legal hold remains. Encrypted backups expire under the backup lifecycle and may retain deleted data until that cycle completes.
Security
We use encrypted transport, restricted server-side credentials, signed payment webhooks, access controls and protected order-status tokens. No internet service is risk-free; contact us immediately if you believe an order or activation code was exposed.
Your choices and rights
Depending on your location, you may request access, correction, deletion, restriction, portability or objection, or complain to a data-protection authority. Signed-in customers can download a structured data export, submit and track privacy requests, change a verified email, review active sessions and sign out every device. We may need to verify identity and retain records required by tax, accounting, fraud, dispute or other law. A documented legal hold or retention deadline pauses deletion; eligible records are anonymised when the hold ends.
Children and changes
The service is not directed to children under 16. We may update this policy and will change the effective date when we do.
Contact
Use the privacy request portal, email legal@simpriest.com for privacy or formal legal matters, or email support@simpriest.com for order support.