Privacy policy
This policy describes the personal data we collect, why we collect it and the rights available to you.
Last updated: 27 July 2026
1. Data controller
The data controller for personal data is SimGoFly, the publisher of the website https://simgofly.com.
2. Data collected
We collect the following data in the course of providing our services:
- Identification data: name, email address provided when creating an account or placing an order.
- Order data: purchase history, plan references, eSIM status.
- Payment data: payments are processed by AgentaOS. SimGoFly does not store any card data.
- Technical data: IP address, browser type, operating system, pages visited (via analytics tools).
- Compatibility data: device model and operating system provided when checking compatibility.
3. Purposes of processing
Your data is processed for the following purposes:
- Processing and fulfilling Plan orders.
- Providing customer service and managing support requests.
- Sending notifications related to your orders (confirmation, activation, expiry).
- Improving our services and analysing browsing statistics.
- Complying with our legal and regulatory obligations.
4. Legal basis for processing
The processing of your data is based on:
- Performance of the sales contract (Article 6(1)(b) of the GDPR).
- Our legitimate interest in improving our services (Article 6(1)(f) of the GDPR).
- Your consent, where applicable, for analytics cookies (Article 6(1)(a) of the GDPR).
- Our legal obligations (Article 6(1)(c) of the GDPR).
5. Data sharing
Your data may be shared with the following categories of recipients:
- eSIMerge: the technical provider of the Plans, for the fulfilment of orders.
- AgentaOS: the payment provider, for secure transaction processing.
- Hosting provider: secure storage of data on servers located within the European Union.
- Competent authorities: where required by law.
6. Retention periods
Your data is retained for the duration necessary for the purposes for which it is processed:
- Account data: for the duration of the business relationship and three (3) years after the last active contact.
- Order data: for five (5) years after purchase, in accordance with accounting obligations.
- Browsing data: a maximum of thirteen (13) months.
7. Your rights
In accordance with the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: obtain a copy of your personal data.
- Right to rectification: correct inaccurate data.
- Right to erasure: request the deletion of your data.
- Right to restriction: request restriction of processing.
- Right to data portability: receive your data in a structured format.
- Right to object: object to processing on legitimate grounds.
- Right to withdraw your consent at any time.
8. Cookies
We use a limited number of cookies, solely for operational and analytical purposes. For more details, please see our Cookie Policy.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction.
10. Contact
For any questions about the protection of your personal data or to exercise your rights, please contact us via the Contact page on the Site.