Privacy Policy
How Connectra eSIM collects, uses, and protects your personal data.
Last updated: September 18, 2024
Download as Word documentWho we are
When we say "ConnectraeSim", "we", "us", or "our" in this policy, we mean ConnectraEsim Corp. We operate the ConnectraEsim website and mobile app (together, the "Platform") and provide our Unlimited Travel eSIM plans and optional add-ons including Global Cruise Connectivity (together, the "Service").
This Privacy Policy explains what personal data we collect from you, why we collect it, how we use and share it, how long we keep it, and what rights you have over it. Please read it carefully. It applies every time you visit our Platform or use our Service.
This policy should be read alongside our Terms & Conditions and Acceptable Use Policy.
We take your privacy seriously. We do not sell your personal data to third parties.
What data we collect and why
We collect personal data in three ways: directly from you, automatically through your use of the Platform, and in limited cases from third parties. The table below sets out the categories of data we collect and why we need them.
| Category | What we collect | Why we collect it |
|---|---|---|
|
Account and identity data
|
Name
Email address
Phone number
Login credentials
Third-party login info (Google, Apple) if used
|
To create and manage your account
To verify your identity
To communicate with you about your plan and account
|
|
Purchase and billing data
|
Payment method details (processed by our payment provider)
Billing address / postcode
Transaction history
|
To process your payment and issue receipts
To calculate applicable taxes
To manage refunds and disputes
To detect and prevent fraud
|
|
Device and eSIM data
|
Device type, model, and OS
eSIM installation and activation status
Device IMEI / EID (where required for eSIM provisioning)
eSIM enable and disable events
|
To provision and manage your eSIM
To troubleshoot connectivity issues
To support you when you contact us
|
|
Usage and technical data
|
IP address
Browser type and version
Pages visited and time spent on Platform
App events (e.g. login, plan purchase, eSIM activation)
Crash and error reports
|
To keep the Platform secure and operational
To diagnose bugs and improve performance
To understand how customers use Maya
To prevent fraud and AUP violations
|
|
Network connectivity data
|
IMSI (International Mobile Subscriber Identity)
MSISDN (mobile number identifier)
IP addresses used to establish network connections
Data usage volumes per session
|
To route and deliver your mobile data
To enforce daily quota and fair-use policies
To calculate usage for billing and support purposes
This data is technical and processed by network operators only to the minimum extent necessary
|
|
Support and communications data
|
Content of emails, chat messages, and support tickets
Feedback and survey responses
Call recordings (where applicable)
|
To respond to your enquiries
To resolve issues with your plan
To improve our support quality
To maintain records of our interactions
|
|
Marketing preferences data
|
Email marketing consent and opt-out status
Push notification preferences
|
To send you relevant offers and news, only with your consent
To honour opt-outs promptly
|
Our legal basis for processing your data
We only process your personal data where we have a valid legal basis to do so. Depending on the purpose, we rely on one of the following:
| Legal basis | When we rely on it |
|---|---|
|
Contract performance
|
To provide you with the Service, including processing your purchase, provisioning your eSIM, and providing customer support.
|
|
Legitimate interests
|
To keep the Platform secure, prevent fraud, improve our Service, send transactional communications, and conduct internal analytics. We balance our interests against yours and will only process data where our legitimate interest is not overridden by your fundamental rights and freedoms.
|
|
Legal obligation
|
Where we are required to retain or share data to comply with applicable laws, tax obligations, or lawful requests from authorities.
|
|
Consent
|
For marketing emails and push notifications, and for non-essential cookies. You can withdraw consent at any time. This does not affect the lawfulness of processing already carried out.
|
How we collect your data
Directly from you: when you create an account, purchase a plan, contact support, complete a survey, or otherwise interact with us.
Automatically: when you use our Platform or app, through cookies, app analytics, and usage logs. See our Cookie Policy for more detail.
From third parties: if you create an account using a third-party login (e.g. Google or Apple), we receive basic profile data from that provider. If you access our Services via a partner or reseller, we may receive your details from them.
Who we share your data with
We do not sell your personal data. We share it only in the limited circumstances described below, and only to the extent necessary.
Network operators
To deliver your mobile data, we share the minimum necessary technical identifiers (IMSI, MSISDN, and connection IP addresses) with our roaming network partners. These partners can access only the technical data required to route connectivity. They cannot see your name, email address, or payment information. All communications with network partners use end-to-end encryption. We maintain strict data processing agreements with all network partners.
Payment processors
We use authorised third-party payment processors to handle your payment. Your card details are transmitted securely to our payment provider and are not stored on ConnectraeSim systems. Our payment processor is contractually bound to process your data only for payment purposes.
Service providers
We engage trusted third-party providers to help us operate the Platform and deliver the Service. These include hosting and infrastructure providers, customer support tools, analytics providers, and email delivery services. All providers are contractually required to protect your data and use it only for the specific purpose for which it is shared.
Legal and regulatory authorities
We may disclose your data to law enforcement agencies, courts, regulators, or other public authorities where required to do so by law, court order, or valid legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a government request. Where legally permitted and practically feasible, we will make reasonable efforts to notify you of such requests unless prohibited by law or court order.
Business transfers
If ConnectraeSim is involved in a merger, acquisition, or sale of all or part of its assets, your data may be transferred to the acquiring or successor entity as part of that transaction. We will use reasonable efforts to notify you via email or prominent notice on our Platform before your data is transferred and becomes subject to a different privacy policy, except where such notification is prohibited by law or impractical due to the nature of the transaction.
International data transfers
ConnectraeSim is a global service, and your data may be stored and processed in countries other than your own, including countries that may not provide the same level of data protection as your home country.
Where personal information is transferred or accessed outside Canada, ConnectraeSim will ensure that such transfers are conducted in accordance with applicable Canadian privacy legislation, including PIPEDA where applicable. Appropriate contractual, technical, and organizational safeguards will be implemented to maintain a level of protection comparable to that required under Canadian privacy law. The organization will remain accountable for personal information transferred to third-party service providers and will assess applicable privacy, security, and jurisdictional risks associated with international processing.
Cookies
We use cookies and similar technologies on our website and app to make them work, to understand how they are used, and with your consent, to personalise your experience and serve relevant marketing.
Essential cookies are always active, as they are required for the Platform to function. For all other cookies, we ask for your consent. You can manage your cookie preferences at any time via the cookie settings on our website.
How long we keep your data
We keep your personal data for only as long as we need it for the purpose it was collected, or as required by law. Our key retention periods are:
| Data type | Retention period |
|---|---|
|
Account and transaction data
|
For the duration of your account, plus 7 years after closure (to comply with financial and tax obligations).
|
|
Support communications
|
3 years from the date of the last interaction.
|
|
Network connection logs
|
6 months from the date of connection.
|
|
Payment records
|
7 years, in accordance with financial record-keeping requirements.
|
|
Marketing consent records
|
Until you withdraw consent, plus 3 years thereafter for record-keeping purposes.
|
|
Fraud or abuse-related records
|
Indefinitely, where we have a legitimate interest in preventing recurrence or where required by law.
|
When data is no longer required, we securely delete or anonymise it.
How we protect your data
We apply industry-standard technical and organisational measures to protect your personal data against unauthorised access, loss, disclosure, or alteration. These include:
- Encryption of data in transit (HTTPS/TLS) and at rest.
- Strict access controls. Only staff with a genuine need can access personal data.
- Regular security testing and audits.
- Data minimisation. We collect and retain only what is necessary.
- Contractual data protection obligations with all third-party processors.
No method of electronic transmission or storage is completely secure. While we implement industry-standard security measures to protect your data, we cannot guarantee absolute security, and you acknowledge that you provide your data at your own risk. You are responsible for maintaining the confidentiality of your account credentials. If you become aware of any security concern related to your ConnectraeSim account, please contact us immediately at support@connectraesim.com
Children's privacy
Our Services are not directed to children under the age of 13, and we do not knowingly collect personal data from anyone under 13. If you are under 18, please ensure you have a parent or guardian's permission before using ConnectraeSim.
If we become aware that we have inadvertently collected personal data from a child under 13, we will delete it promptly. Please contact us at support@connectraesim.com if you believe this has occurred.
Your rights
Depending on where you are located, you may have the following rights over your personal data:
| Right | What it means |
|---|---|
|
Access
|
Request a copy of the personal data we hold about you.
|
|
Correction
|
Ask us to correct inaccurate or incomplete data.
|
|
Erasure
|
Ask us to delete your data where we no longer have a valid reason to keep it.
|
|
Restriction
|
Ask us to pause processing your data in certain circumstances.
|
|
Portability
|
Request a machine-readable copy of data you have provided to us.
|
|
Object
|
Object to processing based on legitimate interests, including direct marketing (absolute right).
|
|
Withdraw consent
|
Withdraw any consent you have given at any time. This does not affect processing already carried out.
|
|
Complaint
|
Lodge a complaint with your local data protection authority if you believe we have mishandled your data.
|
To exercise any of these rights, you can use the account settings in the ConnectraeSim app, or contact us at support@connectraesim.com.We will respond within 30 days. In some cases, we may need to verify your identity before fulfilling a request. We may request additional information reasonably necessary to verify your identity and the authenticity of the request. If we cannot verify your identity with the degree of certainty required, we may deny the request and will explain the basis for the denial.
Region-Specific Information
Canada and Provincial Privacy Requirements
ConnectraeSim recognizes that privacy and information-management requirements in Canada may vary depending on the jurisdiction, type of organization, nature of the information, and manner in which personal information is collected, stored, accessed, used, or disclosed.
For projects involving Canadian organizations, ConnectraeSim will design and implement solutions in accordance with the privacy and security requirements applicable to the specific jurisdiction and client environment. Our approach will include consideration of federal, provincial, territorial, and sector-specific privacy legislation, as applicable.
Federal Requirements
Where applicable, ConnectraeSim will comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and its applicable privacy principles. PIPEDA establishes requirements governing the collection, use, disclosure, safeguarding, retention, and accountability of personal information in commercial activities and can apply to personal information transferred across provincial or international borders.
Provincial and Territorial Requirements
ConnectraeSim recognizes that certain provinces have substantially similar private-sector privacy legislation. In particular, Alberta, British Columbia, and Quebec have provincial private-sector privacy legislation that may apply instead of PIPEDA for activities occurring within those provinces, while PIPEDA may continue to apply in circumstances involving interprovincial or international transfers or federally regulated organizations.
Where applicable, ConnectraeSim will consider requirements under:
- Alberta: Personal Information Protection Act (PIPA)
- British Columbia: Personal Information Protection Act (PIPA)
- Quebec: Act respecting the protection of personal information in the private sector
- Ontario: Applicable provincial privacy legislation, including sector-specific requirements and public-sector requirements where applicable
- Other provinces and territories: Applicable provincial or territorial privacy, access-to-information, and sector-specific legislation.
Ontario and Municipal Projects
For projects involving Ontario municipalities and other public-sector institutions, ConnectraeSim will take into consideration the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA) and other applicable Ontario legislation, regulations, policies, directives, and contractual requirements.
MFIPPA establishes requirements governing the collection, use, disclosure, retention, and protection of personal information held by municipal institutions.
Where required by the client or applicable legislation, ConnectraeSim will support appropriate privacy and security assessments, documentation, access controls, audit requirements, data-retention requirements, breach-management procedures, and other privacy safeguards.
Data Residency and International Transfers
ConnectraeSim will identify where client and personal information is hosted, processed, accessed, or transferred. Where information is processed outside Canada, we will assess the applicable privacy, security, contractual, and jurisdictional requirements and implement appropriate safeguards.
International or cross-border processing will be managed in accordance with applicable Canadian privacy legislation and the specific requirements established by the client. Where required, appropriate contractual controls, security safeguards, access restrictions, encryption, and service-provider obligations will be implemented.
Other jurisdictions
ConnectraeSim serves customers globally. If you are located in a jurisdiction with specific data protection requirements, such as Brazil (LGPD), United States (CCPA), Australia (Privacy Act), or the Kingdom of Saudi Arabia (PDPL), the mandatory privacy laws of your country may apply to your use of our Services in addition to this Policy. If you have jurisdiction-specific questions, please contact us at support@connectraesim.com.
Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you via email or a notice on the Platform at least 14 days before the change takes effect.
Your continued use of our Services after the effective date of an updated Policy constitutes your acceptance of the changes.
Contact us
If you have any questions about this Privacy Policy, want to exercise your rights, or have a concern about how we handle your data, please get in touch:
- Email: support@connectraesim.com
- Website: connectraesim.com
We aim to respond to all privacy enquiries within 30 days.
Ready To Go
Install an eSIM now and get online in 5 minutes, or reserve your data plan for any future date. We'll activate it automatically.