Legal
Privacy Policy
What we collect, why, who we share it with, and how long we keep it.
Last Updated: August 24, 2026
Terms of Service
Privacy Policy
Refund Policy
Cookie Policy
Acceptable Use
Mobile App Terms
Who We Share Data With
Accessibility
Affiliate Terms
Legal Overview
1. What We Collect#
What you give us directly
• Name and email address, to create your account and send your eSIM QR code.
• Billing country and address where the payment requires it.
• Payment details, handled entirely by Stripe. We never see or store your full card number.
• Support messages, including anything you send us by email or on WhatsApp, so we can help and keep a record of what was agreed.
What we collect automatically
• Device and browser type, so we can spot when something breaks on a particular device.
• IP address and approximate location, used for fraud checks and to show the right currency.
• Usage data, such as pages visited and session length.
• eSIM technical data from the network: the ICCID, connection status, and how much data has been used, so we can show your remaining balance and help when a plan misbehaves.
2. Why We Use It, and Our Legal Basis#
Under the GDPR and similar laws we have to tell you not just what we do, but the legal basis for each purpose. Here it is.
• Providing the service (creating your account, provisioning the eSIM, sending the QR code, showing usage, handling refunds and wallet balance). Basis: performance of our contract with you.
• Customer support, including WhatsApp and email conversations. Basis: performance of our contract, and our legitimate interest in running a support service that works.
• Fraud prevention and security, including card testing checks and sanctions screening. Basis: our legitimate interest in protecting the business and other customers, and legal obligation where sanctions law applies.
• Accounting, tax and invoicing. Basis: legal obligation.
• Analytics and improving the site. Basis: your consent, given through the cookie banner. Refusing costs you nothing.
• Marketing emails, if you ask for them. Basis: your consent, withdrawable at any time from the unsubscribe link in every message.
Transactional emails such as your order confirmation and QR code are part of the service, not marketing, so they are sent on the contract basis and cannot be unsubscribed from while you have an active plan.
We do not sell your personal data, we do not rent it, and we do not use it to target you with advertising on other platforms.
4. Where Your Data Goes#
MegaEsim is operated from the United Arab Emirates, and some of the companies above are in the United States, Hong Kong and the European Union. That means your data may be transferred outside your own country.
The UAE does not have an adequacy decision from the European Commission. So where we transfer personal data of people in the EU, EEA or UK out of those areas, we rely on the Standard Contractual Clauses approved by the European Commission, together with the UK Addendum where UK data is involved, and we assess whether the destination offers appropriate protection in practice.
You can ask us for details of the safeguards that apply to your data at support@megaesim.com.
5. How Long We Keep It#
We do not keep things forever. These are the actual periods.
• Order and invoice records — 7 years from the transaction, because tax and accounting law requires it.
• Account details (name, email, login) — for as long as your account is open, then deleted within 30 days of you closing it, apart from the order records above.
• eSIM technical records (ICCID, usage, status) — 24 months after the plan expires, so we can answer questions and handle refund disputes.
• Support conversations, including WhatsApp — 24 months from the last message.
• Website analytics — 14 months, then deleted automatically.
• Marketing consent records — until you withdraw consent, plus 2 years so we can show when and how consent was given.
• Fraud and sanctions screening logs — 5 years, because we may need to show we carried out the check.
6. Your Rights#
Wherever you live, you can ask us to:
• Give you a copy of the personal data we hold about you.
• Correct anything that is wrong.
• Delete your data, subject to records we must keep by law.
• Restrict or object to how we use it, including any use based on legitimate interests.
• Port your data to another provider in a machine readable format.
• Withdraw consent at any time, for marketing or analytics, without affecting what we did before you withdrew it.
Email support@megaesim.com and we will respond within 30 days. We do not charge for this and we will not make it difficult.
If you are in the EU, EEA or UK you also have the right to complain to your national data protection authority. If you are in the UK that is the Information Commissioner's Office. You are welcome to come to us first, but you do not have to.
7. Deleting Your Account and Your Data#
You can delete your account and the personal data attached to it at any time. There are three ways, and all of them work:
• In the mobile app: Profile, then Delete Account.
• On the website: your account settings.
• By email: write to support@megaesim.com and we will do it for you.
Deletion removes your name, email, login, saved preferences and support history. We keep order and invoice records for the 7 years that tax law requires, and those records are not used for anything else. Any unused wallet credit is dealt with as described in our Terms before the account closes, so please use it or ask us about it first.
8. The MegaEsim Mobile App#
The iOS and Android apps ask for these permissions, and you can change your mind at any time in your device settings:
• Camera — only to scan an eSIM QR code during setup. We never open the camera at any other time and we never store photos or video.
• Push notifications — order confirmations, eSIM delivery, and reminders such as low data or an expiring plan. Turn them off in device settings whenever you like.
The app does not track you across other apps or websites, does not use advertising identifiers, and does not sell data to anyone. Account deletion is available inside the app itself, as described above.
9. Cookies and Tracking#
We use a small number of cookies. Essential ones keep you logged in and protect the checkout, and they cannot be switched off because the site will not work without them. Analytics cookies are only set after you accept them in the cookie banner, and you can change your choice at any time using Cookie Settings in the footer.
We honour the Global Privacy Control signal. If your browser sends GPC, we treat it as an opt out of analytics and of any sharing of personal information, automatically and without you having to do anything else.
We do not run advertising or behavioural tracking cookies on this website. Our full Cookie Policy lists every cookie we set, what it does and how long it lasts.
10. How We Protect Your Data#
The site runs over HTTPS everywhere. Passwords are stored hashed, never in readable form. Card details never touch our servers, because Stripe handles them directly. Access to customer data inside the company is limited to the people who need it to do their job.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach happens that puts your rights at risk, we will report it to the relevant supervisory authority within 72 hours of becoming aware of it, and we will tell you directly and without delay where the risk to you is high.
11. Children#
MegaEsim is not for children. You must be at least 18 to hold an account, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to support@megaesim.com and we will delete it.
12. Changes to This Policy#
We update this policy when what we do changes. The date at the top always shows the current version. If a change materially affects how we use your data, we email registered customers rather than quietly editing the page.
Questions about this page?
A person reads every email. We reply within 24 hours, and we will explain anything here in plain language if it is not clear.
support@megaesim.com
Soha Trading LLC-FZ, Meydan Grandstand, 6th Floor, Al Meydan Road,
Nad Al Sheba, Dubai, United Arab Emirates