Privacy policy
Last updated 2026-08-08
What we hold about you, who else touches it, how long it stays, and what you can ask us to do with it.
Who is responsible for your data
SefereSIM is responsible for the personal data described here, as the controller. [OPERATOR: legal entity name and registered address, repeated here as the data controller]
Anything on this page that is unclear, or that you want acted on, goes to support@seferesim.com.
What we hold
- Your email address and your nameGiven at checkout. The email address is your account and where your eSIM is sent. The name goes on your receipt, and our sign-in provider will not finish an account without it.
- Your ordersWhich plan, for which country, when, what you paid, and whether the payment went through.
- eSIM identifiersThe identifiers of the profile issued for you, such as its ICCID and its activation details, so that it can be installed, looked up and supported.
- Usage figures from the network operatorHow much of the plan data has been used, and when we last checked. These come from the operator on a delay. They are a volume, not a record of what you did online.
- What you write to usYour support emails, and our replies.
- Ordinary web request dataRequests to this site reach Cloudflare, which logs them for a short period to keep the site up and to block abuse.
We never see your card number. Card details go straight to Stripe, and what comes back to us is the amount, the currency and whether the payment worked.
We do not hold what you browse while using the plan. That traffic runs over the local operator network and never passes through us.
Why we hold it
- To sell you a plan and deliver the eSIM, which is the contract between us.
- To show you your orders, and to help when something does not work.
- To keep the accounting and tax records we are required by law to keep.
- To see how the site is used, and to measure whether the adverts we pay for lead to sales. The advertising half of that happens only if you accept cookies.
Companies that handle it for us
Each of these processes data on our instructions, for the job named next to it. We do not sell personal data, and we do not pass it to anyone for their own marketing.
- ClerkAccounts and sign-in. Holds your email address, your name and the codes we send you.
- StripePayments. Receives your card details directly from your browser, and the amount of the order.
- esimaccessOur eSIM supplier. Issues the profile, reports its status and its usage, and receives what it needs to do that.
- CloudflareHosting for this site and our API, the bot check at checkout (Turnstile), and the email service that sends your eSIM and carries support@seferesim.com.
- OneSignalPush notifications for the iOS app. Involved only if you use the app and allow notifications there.
- PostHog, European regionProduct analytics, on European servers, reached through our own domain rather than a third-party host. Described in the next section.
Analytics, and what is stored in your browser
PostHog counts visits and the steps of the funnel: which page, which question, which plan. Until you accept cookies it runs in cookieless mode, which counts a visit without setting a cookie and without keeping an identifier on your device. Accepting cookies switches it to its ordinary mode, which does set a cookie and can join your visits together.
Four things are stored in your browser by us, and this is all of them:
- seferesim.attribution, in sessionStorageWritten on the first page you land on, before you have answered the cookie banner. It holds the campaign parameters from the link you arrived on (utm_source, utm_medium, utm_campaign), our own angle tag, and the language you landed in, so that a purchase can be credited to the advert that brought you. It lives in the browser tab and goes when you close it.
- seferesim.consent, in localStorageYour answer to the cookie banner, so we do not ask again. Declining adds nothing to this list: the other three are written by the site doing its job, not by advertising.
- seferesim.quiz.v1, in localStorageThe answers you give in the questions, so that a reload or a step back does not lose them. It stays on your device and is not sent to us as a profile.
- seferesim.checkout.v1, in sessionStorageWritten when you start paying for an order. It holds the order reference and the secrets Stripe needs to show you that same payment again, so that reloading the page resumes the payment you already started instead of creating a second one and charging you twice. It lives in the browser tab, stops being usable after thirty minutes, and is cleared the moment the order is paid for.
Beyond those four: signing in adds a session from Clerk, checkout loads Stripe for the card form and Cloudflare Turnstile for the bot check, and each of those sets what it needs to do its job. If you accept cookies, PostHog and the advertising tags below set theirs too.
Advertising, and only if you accept cookies
If you accept cookies, we load measurement tags from Meta, Google and X. Those three then learn that you visited, and, if you buy, that a purchase happened, with its value and the order reference.
On a purchase we also send Meta a one-way hashed copy of your email address (SHA-256), from our server, so that Meta can match the sale to an advert you were shown. Meta receives the hash, not the address itself.
If you decline, or never answer the banner, none of the three is loaded, nothing is sent to any of them, and no purchase is reported to Meta.
Meta, Google and X use what they receive under their own terms as well as ours. They are recipients of your data, not processors working only for us.
How long we keep it
- Order records are keptPurchases and payments stay on file for the legal and accounting periods we're required to keep them, even once the account is gone.
- Your accountDeleted when you delete it, from the iOS app or by writing to us. Deleting it does not switch off an eSIM you have already installed, and it does take away access to anything you bought and have not installed yet.
- eSIM identifiersKept with the order record for the same period, because they are how a payment is matched to what was delivered.
- Support emailKept while it is useful for supporting you and for the record of what was agreed, then deleted.
- Analytics eventsKept in our PostHog project for the retention window set on that project.
The exact periods belong on this page rather than in a sentence about periods. [OPERATOR: the retention periods, in years, confirmed with the accountant]
Your rights
You can ask us for a copy of what we hold, to correct it, to delete what we are not required to keep, to restrict what we do with it, and to object to the advertising measurement described above. Write to support@seferesim.com from the address on the account, and we will answer within the period the law allows us.
You can change your answer to the cookie banner whenever you like, with the "Cookie choice" link at the foot of the page. Going from accept to decline reloads the page, because reloading is the only thing that actually stops advertising tags that have already started. Clearing this site data in your browser also removes the stored answer, and the banner then asks again on your next visit.
If you think we have handled your data badly, you can complain to the data protection authority where you live.
KVKK notice for visitors in Türkiye
Visitors and customers in Türkiye are covered by KVKK, law 6698. The aydınlatma metni that law asks for is on the Turkish version of this page, at /tr/privacy, and it is in Turkish because that is the language it has to be readable in. It describes the same processing this page describes, under the headings the law names.
[OPERATOR: veri sorumlusu identity: the same legal entity as above, as it will appear on the Turkish page]
Changes to this page
When this page changes we change the date at the top. If we start doing something materially different with your data, we will say so plainly rather than quietly reword a paragraph.
Contact
support@seferesim.com. It reaches a person, not a queue.