1. Who we are
This Privacy Policy explains how Individual Entrepreneur Eduard Papiian (“we”, “us”, or “our”) collects and uses personal data when you use Simchao at https://simchao.com. For privacy requests, email support@simchao.com.
2. Personal data we collect
We collect the following categories of data, depending on how you use Simchao:
- Identity and contact data: email address, first name, last name, phone number, and country you provide at checkout or in your account profile.
- Account and authentication data: magic-link tokens, session information, and related security metadata such as IP address and user-agent when a login link is used.
- Order and payment references: products purchased, amounts, order status, and payment provider transaction IDs. Card numbers are processed by Monobank and are not stored by Simchao.
- eSIM and service data: technical identifiers and status needed to provision and support your plan (for example ICCID, activation details, usage or expiry information provided by our connectivity partner).
- Device and site data: information stored locally in your browser for cart and promo code state, and standard server logs needed to operate and secure the Service.
- Website measurement data: pages viewed, language, referring site, campaign tags, coarse device information, page performance timings, and errors. This is anonymous by design — see section 11.
- Support chat data: the text of messages you send to and receive from the on-site “Chat with Simchao” assistant, a browser session identifier used to keep the conversation continuous, the page you started from, language, and any rating you give a reply. Messages may include details you type voluntarily (for example a destination name or device model). Sequences that look like payment card numbers are masked before storage.
- Support communications: messages you send to our support email and related correspondence.
3. How we collect data
- Directly from you when you check out, create or use an account, update profile settings, use the support chat, or contact support.
- Automatically when you use the site (sessions, security logs, local cart storage, and the chat session cookie).
- From service providers involved in payment and eSIM provisioning (for example payment confirmation from Monobank and provisioning status from our eSIM partner).
- From our language-model provider when the support chat generates a reply (message text is sent to produce the answer; see section 6).
4. Why we use personal data
We use personal data to:
- Process orders, take payment, deliver eSIMs, and provide top-ups.
- Create and maintain your account, authenticate magic-link logins, and show order and eSIM history.
- Send transactional emails (receipts, delivery details, login links, and service notices).
- Provide customer support — including answering questions through the on-site assistant grounded in our published help articles and catalog — and investigate delivery or connectivity issues.
- Review support chat transcripts so we can improve help content, fix catalog gaps, and operate the assistant safely.
- Prevent fraud, abuse, and security incidents, and keep audit records of important account and order events.
- Comply with legal, tax, and accounting obligations.
- Improve reliability and user experience of the Service (for example fixing failed provisioning).
5. Legal bases (EEA/UK and similar)
Where data-protection laws require a legal basis, we typically rely on: performance of a contract (providing the eSIM you bought); legitimate interests (securing the Service, preventing fraud, improving operations, answering support requests); legal obligation (tax and accounting); and consent where we ask for it (for example optional marketing, if offered).
7. International transfers
We and our providers may process data in countries other than where you live. When we transfer personal data internationally, we take steps appropriate under applicable law (such as contractual safeguards with providers) to protect it.
8. Retention
We keep personal data only as long as needed for the purposes above. Order, payment, and eSIM records are typically retained for the life of the account relationship and for a further period required for accounting, dispute resolution, and legal compliance. Magic-link tokens expire quickly (minutes) after issuance. Cart data in your browser remains until you clear it or complete checkout.
Support chat transcripts are retained for up to 180 days from the last message in each conversation, then removed automatically. If you later sign in or create an account in the same browser session, earlier guest chats from that session may be linked to your account so we can honour support and deletion requests. You can ask us to delete identifiable chat history by emailing support.
When data is no longer needed, we delete or anonymize it, subject to legal retention requirements.
9. Security
We use administrative and technical measures appropriate to the nature of the data we hold, including encrypted transport (HTTPS), authenticated admin access, and payment handling via Monobank so card data is not stored on our servers. No method of transmission or storage is completely secure; please use a secure email account for magic-link login.
11. Website measurement
We measure how the website is used so we can fix what is broken and improve what is not working. This measurement is first-party and cookieless by default: it stores nothing on your device and it does not collect personal data.
When you open a page we record the page address, your language, the referring website, any campaign tag in the link you followed, and coarse device information such as browser, operating system and device type. Your IP address and browser user-agent are used only in the moment of the request to generate a one-way, irreversible identifier that lets us count visits without knowing who you are. That identifier is regenerated daily and cannot be linked back to your IP address or across days.
We also record technical measurements — page loading speed and JavaScript errors — so we can detect performance and reliability problems.
If you accept optional analytics, we additionally store a random identifier in your browser so returning visits can be recognised, and we may load Google Analytics. Neither happens unless you agree, and you can withdraw agreement at any time by clearing cookies for this site, which also deletes the stored identifier.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. You may also have the right to lodge a complaint with a supervisory authority.
To exercise privacy rights, email support@simchao.com. We may need to verify your identity (for example via the email on your account) before fulfilling a request. Some data must be kept for legal or transactional reasons even after a deletion request.
13. Children
The Service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
14. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date will change when we publish a revision. If changes are material, we may also provide an additional notice (for example by email or a site banner).
15. Contact
Privacy questions and requests: support@simchao.com. Controller: Individual Entrepreneur Eduard Papiian. See also our Terms of Service and Refund Policy.

