LinkSIM Privacy Policy
Who we are
LinkSIM operates the travel connectivity marketplace described in this policy. Privacy requests: privacy@linksims.com or Support inside the LinkSIM app. For California residents, the same channels serve as your CCPA contact.
Categories of personal data
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Email, optional phone, account ID, device identifiers used for sessions | Yes |
| Customer records | Name (if provided), language, currency, notification preferences | Yes |
| Commercial information | Orders, plans purchased, refunds, receipts, promotional redemptions | Yes |
| Payment metadata | Stripe customer and payment method summaries (brand, last four, expiry). We never store full card numbers (PAN) or CVV | Yes |
| Telecom / product data | eSIM metadata (masked ICCID/MSISDN), status, usage summaries, network status, SMS content where the product supports SMS | Yes |
| Internet / device activity | IP address, user agent, trusted devices, login events, app crash diagnostics (when enabled) | Yes |
| Support content | Tickets, live chat messages, attachments you upload | Yes |
| Inferences / advertising profiles | Cross-context behavioral advertising profiles | No |
| Sensitive government IDs | Passport, national ID, SSN | No |
Purposes of processing
- Create and secure your account, verify email, manage sessions and trusted devices
- Calculate prices, take payment via Stripe, issue receipts, and prevent fraud
- Provision and manage eSIM / SIM Links, installation help, usage, top-ups, and SMS where offered
- Provide customer support (chat and tickets) and operational notifications
- Honor consents: marketing email/push, product analytics, optional web cookies
- Meet tax, accounting, telecom, and other legal obligations
- Improve reliability and diagnose crashes (privacy-conscious monitoring; no card secrets or full ICCIDs in logs)
Lawful bases (GDPR)
| Processing | Lawful basis |
|---|---|
| Account, checkout, provisioning, installation help, support for an order | Contract performance |
| Fraud prevention, security alerts, abuse detection, service integrity | Legitimate interests |
| Marketing email/push, product analytics, optional cookies | Consent (withdraw anytime in Privacy and data) |
| Tax, accounting, telecom retention where required | Legal obligation |
Retention
| Data | Typical retention |
|---|---|
| Active account profile and consents | While the account remains open |
| Orders, payment metadata, receipts | Account life plus periods required for tax/accounting (often up to 7 years where law requires) |
| eSIM metadata and usage summaries | While the Link is active, then limited operational history; purged or anonymized on account deletion subject to legal holds |
| Support tickets and chat | While needed to resolve issues, then closed or anonymized on purge |
| Data export packages | About 7 days after ready, then deleted |
| Account deletion grace period | Soft-delete window (configurable, default days in env), then hard purge job |
| Security / audit logs | Limited operational window; secrets never logged |
| Cookie preference choice (browser) | Until you clear site data or change preferences |
Exact calendar periods can vary by jurisdiction and legal hold. After deletion completes, you cannot sign in. Confirmation emails cover export readiness and deletion lifecycle events.
Sharing and processors
We share personal data only with processors and partners needed to run the service:
- Stripe - payment processing (card data handled by Stripe)
- Connectivity provider (Omax Telecom Bappy) - plan availability and Link provisioning (server-side only; client never receives provider secrets)
- Email and push delivery - transactional and consented marketing messages
- Hosting, database, Redis, and monitoring - infrastructure under contract
- Crash and error monitoring (for example Sentry) - when enabled, with scrubbing for secrets
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising. International transfers use appropriate safeguards (for example standard contractual clauses) where required.
Do Not Sell or Share (CCPA / CPRA)
Under the California Consumer Privacy Act (as amended by the CPRA) and similar laws:
- LinkSIM does not sell personal information.
- LinkSIM does not share personal information for cross-context behavioral advertising.
- You can still set Do not sell or share my personal information in the app under Account → Privacy and data. The preference is stored on your account and honored server-side.
- California residents may request to know, access, correct, delete, or receive a portable copy of personal information, and may use an authorized agent where the law allows. We will not discriminate against you for exercising these rights.
Your rights (GDPR / CCPA and similar)
In the LinkSIM app under Account → Privacy and data you can:
- Request my data - portable ZIP/JSON export of profile, orders, eSIM metadata, payment method summaries (no PAN), tickets, devices, preferences, and consents. Status: pending / ready / expired. Secure short-lived download link; email and in-app notice when packaged.
- Do not sell or share - CCPA-style toggle persisted server-side.
- Manage consents - marketing email, marketing push, analytics.
- Delete account - password or biometric reauth, warnings for active eSIMs and open orders, soft-delete with grace period, then hard purge (sessions revoked, Stripe methods detached, PII anonymized or deleted, open chats closed or anonymized where required).
You may also object to certain processing, restrict processing, or withdraw consent where processing is based on consent. EU/UK residents may lodge a complaint with a supervisory authority. Admins can fulfill or review export and deletion requests in Privacy operations.
Cookies
Admin (admin.linksims.com) and docs (docs.linksims.com) use necessary cookies
for security, load balancing, and remembering this preference. Optional analytics and marketing
cookies stay off until you enable them in Cookie preferences on those sites.
The mobile app does not use browser cookies for core features. In-app analytics and marketing push require consent managed under Privacy and data.
Security
We use TLS in transit, access controls, encryption for sensitive fields and export packages, hashed credentials (Argon2id), short-lived signed download URLs, and audit logging without secrets. No security program is perfect; report suspected issues through Support or privacy@linksims.com.
Children
LinkSIM is not directed to children under 16 (or the higher age required in your country). We do not knowingly collect personal data from children. Contact us if you believe a child provided data so we can delete it.
Contact
Privacy and CCPA requests: privacy@linksims.com or Support in the LinkSIM app (Account → Support).
Hosted policy URL for stores and partners: https://linksims.com/privacy.html