Skip to content
SimChao

Privacy Policy

How SimChao collects, uses, and protects your data. We collect the minimum needed to sell and provision your eSIM, never sell your personal data, and use trusted processors (Firebase, Stripe) under strict terms.

Effective date: 2026-07-20

1. Who we are

SimChao is a travel eSIM service operated by DaJuJu LLC, a limited liability company organized under the laws of Wyoming, WY, United States ("SimChao", "we", "us"). For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), we are the data controller of the personal data described in this policy.

Contact: support@simchao.app · Postal: 30 N Gould St Ste N, Sheridan, WY 82801 US

This policy covers the SimChao iOS app, the simchao.app website, and the services we provide through them. It explains what we collect, why, who we share it with, and the rights you have.

2. The short version

  • We collect the minimum needed to sell you an eSIM, install it, bill you, and support you.
  • We never sell your personal data, and we don't use it for third-party advertising.
  • Payment card data and identity documents are handled by Stripe — they never touch our servers.
  • You can delete your account and data yourself, in the app, at any time.

3. What we collect

3.1 Account data

When you sign up (with Apple, Google, or email) we receive and store:

  • email address (Sign in with Apple may provide a private relay address — that's fine, it works normally);
  • display name, if your sign-in provider shares one;
  • authentication identifiers (a Firebase user ID; Apple/Google account identifiers used for sign-in);
  • account metadata (creation date, sign-in method).

3.2 Order and payment data

  • what you bought (Plan, destination, price, currency, taxes), when, and the Order's status and history;
  • payment metadata from Stripe: payment method type, card brand and last four digits only, billing country, and Stripe transaction identifiers. We never receive or store your full card number — payment details go directly from your device to Stripe;
  • refund requests and their outcomes;
  • invoices/receipts and the transactional emails we sent you.

3.3 eSIM and usage data

  • technical eSIM identifiers (ICCID, activation code / SM-DP+ address) needed to deliver and manage your eSIM;
  • Plan status and data-consumption totals reported to us by our eSIM suppliers (how much of your allowance is used — not the content of your traffic, and not your browsing activity);
  • destination country of the Plans you buy (inherent in the product — we know you bought a Japan plan; we do not track your movements).

We do not have access to the content of your communications. Your internet traffic passes through the Network Operator, not through SimChao.

3.4 Identity verification (KYC) data

Some destinations legally require identity verification. Verification is performed by Stripe Identity: you submit your identity document and selfie directly to Stripe, under Stripe's privacy policy. We never receive or store your document or biometric data. We store only:

  • the verification outcome (verified / not verified);
  • a Stripe reference identifier;
  • the verification date and expiry.

3.5 Support data

When you contact support: your message, the contact details you use, and — if you use in-app support on an order — a technical snapshot attached to help us help you (order reference, eSIM ICCID, device model, iOS version, and relevant order state).

3.6 Rewards and referral data

If you participate in SimChao Rewards: your coin balance and ledger (earn and redemption events), your referral code, and the fact that an account was referred by yours (referral links between accounts are stored by pseudonymous account identifiers).

3.7 App analytics, diagnostics, and logs

  • Product analytics (PostHog). We use PostHog to understand how the app and site are used — events such as screens viewed, purchases completed, and feature usage, together with device type, app version, OS version, language, and coarse (country-level) location derived from IP. See Section 5 for how consent applies.
  • Crash reporting (Firebase Crashlytics). If the app crashes, we receive a crash report (stack trace, device model, OS version, app version) so we can fix it. Crash reports are not tied to your marketing profile.
  • Server logs. Our backend keeps operational logs (timestamps, request identifiers, IP addresses, user IDs, error details) for security, fraud prevention, and troubleshooting.

3.8 Cookies and similar technologies (website)

The website uses:

  • strictly necessary cookies/storage (sign-in session, security);
  • analytics cookies/storage (PostHog), only as described in Section 5.

We do not use third-party advertising cookies. Your browser can block or clear cookies; strictly necessary ones are required for sign-in to work.

4. Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR)
Selling, provisioning, and delivering your eSIM and Plans; managing your accountAccount, order, eSIM dataContract (Art. 6(1)(b))
Payment processing and refundsOrder and payment dataContract; legal obligation (bookkeeping, tax)
Identity verification for destinations that require itKYC outcome dataLegal obligation (Art. 6(1)(c)) of us and our suppliers; contract
Customer supportSupport data, order and eSIM dataContract; legitimate interest in resolving issues
Transactional email (order confirmation, eSIM delivery, refund notices)Account, order dataContract
Rewards programRewards dataContract (the program's terms)
Fraud prevention, abuse detection, and securityLogs, order data, account dataLegitimate interest (protecting the service and other users); legal obligation where applicable
Product analyticsAnalytics data (Section 3.7)Consent where required; legitimate interest for the limited pre-consent processing described in Section 5
Crash reporting and service diagnosticsCrash and log dataLegitimate interest (keeping the service working)
Legal compliance (tax, accounting, sanctions, lawful requests)As requiredLegal obligation

Where we rely on legitimate interest, we have balanced our interest against your rights and use the minimum data needed; you can object at any time (Section 9).

5. Analytics and consent — exactly how it works

We aim to be precise here, because analytics is where most privacy policies get vague:

  • When you first use the app or site, we show a consent choice for analytics.
  • If you decline, product-analytics events are not collected for you.
  • If you accept, we collect the analytics events described in Section 3.7, associated with your user ID, so we can understand real user journeys.
  • Before you have answered the consent prompt, and only if you are signed in, we associate your session with your account identifier (an internal user ID — not your name or email) and record the minimal events needed for security, fraud prevention, and measuring that core service flows work (e.g. that a purchase you made completed). We do this on the basis of our legitimate interest in operating and securing a paid service, because a purchase flow cannot be safely operated blind. This pre-consent processing is limited to service-integrity purposes; it is not used for marketing, is not shared with advertisers, and is deleted on the same schedule as other analytics data.
  • You can change your analytics choice at any time in the app or site settings; withdrawing consent stops future collection.

Analytics data is processed for us by PostHog Inc. on servers in the United States and is subject to our data-processing agreement with them.

6. Who we share data with

We share personal data only with the processors and recipients needed to run the service. We never sell personal data and never share it for third-party advertising.

RecipientRoleWhat they get
Google LLC (Firebase / Google Cloud)Authentication, database, hosting, crash reportingAccount data, order/eSIM records, crash reports. Data is hosted on Google Cloud in the United States (us-central1)
Stripe, Inc.Payment processing; identity verificationPayment details (directly from you); identity documents (directly from you); order amounts and references
eSIM suppliers (eSIM Go Ltd; eSIM Access / our other aggregator partners)Provisioning the eSIM and Plans; usage reportingTechnical order details needed to provision (Plan, destination). They do not receive your name, email, or payment details from us.
Resend, Inc.Transactional email deliveryYour email address and the content of transactional emails (order confirmations, eSIM installation details)
PostHog Inc.Product analyticsAnalytics data per Section 5
Network OperatorsCarrying your mobile trafficYour device's technical identifiers as inherent to mobile service; governed by their own policies in the destination country
AuthoritiesLegal complianceOnly where legally required (valid legal process, tax, sanctions)
A future acquirerCorporate transactionsIf we merge, are acquired, or sell assets, data may transfer as part of the transaction; this policy continues to apply until changed with notice

All processors act under data-processing agreements consistent with GDPR Article 28.

7. International transfers

We are a U.S. company and our primary data storage is in the United States (Google Cloud, us-central1). If you are in the EU/EEA, UK, or Switzerland, your data is transferred to the U.S. and other countries. Where GDPR applies, transfers rely on:

  • the EU–U.S. Data Privacy Framework (and UK Extension / Swiss–U.S. DPF) for certified recipients; and/or
  • the European Commission's Standard Contractual Clauses with supplementary measures.

You can request a copy of the relevant safeguards via privacy@simchao.app.

8. How long we keep data

DataRetention
Account dataUntil you delete your account
Orders, payments, invoices7 years after the transaction, as required by tax/accounting law, then deleted — retained even after account deletion, in minimized form
eSIM technical dataLife of the eSIM + 12 months, then deleted
KYC outcomeUntil expiry of the verification + 12 months, or account deletion, whichever is sooner — subject to legal retention duties
Support tickets24 months after resolution
Analytics data12 months, then deleted or irreversibly aggregated
Crash reports90 days in identifiable form
Server logs30–90 days, longer only for security investigations
Rewards ledgerUntil account deletion (kept with order records where redemptions affected billing)

When you delete your account, we erase your personal data except the minimum we must keep to satisfy legal obligations (e.g. tax records of completed purchases) or to resolve active disputes; that residual data is kept only for those purposes and deleted when they lapse.

9. Your rights

9.1 Everyone

  • Access, correction, deletion. You can view your data in the app, correct your account details, and delete your account (Account → Delete account) — deletion is immediate and self-serve, no support ticket needed.
  • You can email privacy@simchao.app to exercise any right in this section.

9.2 If you are in the EU/EEA, UK, or Switzerland (GDPR)

You have the right to: access your data; rectify it; erase it; restrict processing; object to processing based on legitimate interest (including the pre-consent analytics in Section 5); data portability; and to withdraw consent at any time (without affecting prior processing). We respond within one month. You also have the right to lodge a complaint with your local supervisory authority. We do not use your data for automated decision-making producing legal effects.

9.3 If you are a California resident (CCPA/CPRA)

You have the right to know what personal information we collect, use, and disclose; to delete it; to correct it; and to non-discrimination for exercising your rights. We do not sell or "share" (for cross-context behavioral advertising) personal information, so there is nothing to opt out of under "Do Not Sell or Share." We do not use or disclose sensitive personal information beyond what is necessary to provide the service. Authorized agents may submit requests on your behalf to privacy@simchao.app; we will verify the request via your account email.

9.4 Other jurisdictions

Local law may give you similar rights (e.g. other U.S. state privacy laws, Canada's PIPEDA, Australia's Privacy Act). Email privacy@simchao.app and we will honor applicable rights.

10. Security

  • All traffic is encrypted in transit (TLS); data is encrypted at rest on Google Cloud.
  • Clients never access the database directly — all access goes through our backend with per-user authentication; database rules deny all direct client access as defense in depth.
  • Payment credentials and identity documents never reach our infrastructure (they go device → Stripe).
  • Access to production data is restricted to those who operate the service, and secrets are stored in a managed secret vault.
  • No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as required by law (including GDPR's 72-hour authority notification).

11. Children

The Service is for adults (18+) and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact privacy@simchao.app and we will delete it.

12. Changes to this policy

We may update this policy. For material changes we will notify you in the app and/or by email before the changes take effect, and update the effective date above. Earlier versions are available on request.

13. Contact

DaJuJu LLC (operating as SimChao) 30 N Gould St Ste N, Sheridan, WY 82801 US privacy@simchao.app · support@simchao.app · https://esim.simchao.app

If we have appointed an EU or UK representative under GDPR Article 27, their contact details will be listed here.