Privacy Policy
This policy describes the data Global eSIM ("the app", "we") collects, how we use it, and your choices. Global eSIM is operated by ZhiEra LLC, a company registered in Delaware, USA.
Data we collect
- Account — email address, password (hashed), display name and username, and an encryption public key if you use encrypted chat.
- Purchases — order metadata and payment-method type. Full card numbers are collected directly by Stripe; we never see or store them.
- Approximate location — our servers infer your country/city from your IP address to recommend local plans. The app does not use GPS or request location permission.
- Device & usage — push token, device name, app version, locale/theme, and in-app product-interaction analytics. No advertising SDKs, no cross-app tracking.
- Chat media — if you use the optional in-app chat, messages, photos and voice recordings are end-to-end encrypted on your device; our servers store only ciphertext. Camera, microphone and photo library are accessed only when you actively use them.
- eSIM data — activation code, ICCID, APN and real-time usage, from our upstream connectivity partner.
- Security and compliance — account activity, transaction history, payment references, IP-derived country, device information, risk indicators, verification status and review audit records. If a compliance review requires identity verification, support will direct you to a secure provider-hosted page. Depending on the provider and jurisdiction, that provider may collect your legal name, date of birth, government-issued identity document, selfie or liveness result. Do not send identity documents through email or chat.
- Diagnostics — standard crash and performance reports.
What we do not collect
We do not collect precise/GPS location, your contacts, advertising identifiers, or browsing behavior on other apps and websites. We do not ask you to send raw identity-document images through email or chat.
How we use it
To deliver and operate the eSIM service, process payments, send transactional email, recommend relevant plans, provide support, protect accounts, detect fraud and abuse, and meet applicable anti-money-laundering and sanctions-screening obligations. We do not sell, rent or trade your data.
Sharing
We share the minimum necessary with Stripe (card payments), our upstream eSIM partner (provisioning), Twilio (optional virtual numbers), Apple APNs (push notifications), and a secure identity-verification provider when verification is required. The verification page identifies the provider before you submit data.
Compliance reviews
If risk controls require verification, we may temporarily prevent purchases, top-ups and transfers and hide eSIM or number cards while the review is open. Existing balances, settled payments and refunds remain recorded. Cards are hidden rather than deleted and reappear after the account is cleared.
We retain the provider reference, verification result and review audit record as needed for security, dispute handling and legal compliance. Any raw identity data held by the verification provider is governed by the provider notice shown before submission.
Your rights
You can access, correct, export or delete your data. Account deletion is available directly in the app (Account tab). Encrypted chat messages are erased when you delete your account. EU/UK and California privacy rights apply.
Security
TLS for all traffic, hashed passwords, end-to-end encrypted chat with device-held keys, and field-level encryption for sensitive server-side data.
Children
Global eSIM is not directed at children under 13 and we do not knowingly collect their data.
Contact
Questions: business@zhiera.com