Privacy Policy
Last updated: 6 July 2026
Doft eSIM ("Doft eSIM", "we", "us") sells prepaid travel eSIM data plans through the Doft eSIM apps and esim.doft.com. This Privacy Policy explains what we collect, why, and what we never do with your data. By using Doft eSIM you agree to this policy.
Information we collect
We collect only what is needed to sell and deliver your eSIM:
- Contact details — your email address, used to deliver your eSIM QR code, receipts and service notices.
- Order details — the destination, plan, price, and payment status of your purchases.
- eSIM provisioning data — technical identifiers required to issue and manage your eSIM, such as the ICCID, activation code and plan usage totals (how much data remains).
- Basic diagnostics — app version, device model and crash reports, in anonymized and aggregated form, used to keep the app stable.
- Support messages — if you contact us, we keep the conversation so we can help you.
What we never collect
We are not your network operator's surveillance arm. We do not log or inspect the content of your internet traffic, the websites you visit, or the apps you use through the eSIM. We do not sell personal data to anyone. Mobile connectivity is provided by licensed local carriers via our connectivity partners, subject to the laws of the country you visit.
Payments
Card payments on our website and in the app are processed by Stripe, a PCI-DSS Level 1 certified payment provider. Your card number never touches our servers — we receive only a payment confirmation, the amount, and a payment reference. Purchases made through the Apple App Store or Google Play are processed by Apple or Google under their own terms.
eSIM provisioning
eSIM profiles and mobile data are provisioned through our wholesale connectivity partner eSIM Go Limited and its partner mobile networks. To issue your eSIM we share with them only what is technically required: the plan you bought and the eSIM identifiers. They do not receive your name or payment details from us.
How we use information
We use the data above to: deliver and activate your eSIM, show your remaining data, process payments and refunds, prevent fraud and abuse, comply with legal obligations, fix bugs, and answer your support requests. We may send you service emails about your order; marketing emails are optional and every one has an unsubscribe link.
Sharing
We share personal data only with the service providers who make the product work — payment processing (Stripe, Apple, Google), eSIM provisioning (eSIM Go and partner carriers), email delivery, and cloud hosting (Amazon Web Services) — and only the minimum each needs. We may disclose information where strictly required by law.
Data retention
Order and invoice records are kept for as long as accounting and tax law require. eSIM technical identifiers are kept while your eSIM or plan is active and for a reasonable period afterwards for support and fraud prevention. Diagnostics are aggregated. You can ask us to delete your personal data at any time (see Your rights).
Security
All traffic between the app, our website and our servers is encrypted with TLS. Access to production data is limited and logged. No method of storage is 100% secure, but we design for the minimum data we can hold.
Children
Doft eSIM is not directed at children under 16, and we do not knowingly collect their data.
International transfers
We operate globally: our infrastructure runs in the cloud and connectivity is delivered by carriers in the country you visit. Where data crosses borders we protect it in line with this policy and applicable data-protection law.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to certain processing. Email support+esim@doft.com and we will act on your request.
Changes and contact
We may update this policy; the "Last updated" date above will change, and significant changes will be announced in the app or by email.
Questions? Contact support+esim@doft.com.