Skip to content

Your privacy matters.

A plain-language draft of the information a live Simpli service may handle.

Draft pending legal review. This is working copy, not a final policy. TODO: Confirm the business identity, service practices, providers, timelines, applicable law, and consumer rights before accepting real orders.

Who operates the service

The supplied draft identifies Simpli as the service at simpli.pk, but does not provide the operating legal entity or registered address. TODO: Add and verify the data controller’s legal name and address. The draft lists privacy@simpli.pk for privacy questions; confirm that this inbox is monitored before launch.

Information a live service may collect

Depending on how the live service is built, information may include your name, email, billing country or postcode, support messages and attachments, marketing choices, orders, selected destination and plan, price and date, eSIM/order identifiers, installation and activation status, usage, device details you provide, and technical details such as IP address, browser, device, language, approximate location, pages viewed, and timestamps. The proposed service does not read your calls, texts, or browsing history.

What this prototype actually does

This static demo does not send entered checkout details to a server, take payment, issue an eSIM, send email, run analytics, or use tracking cookies. It stores only a mock order number, plan ID, and demo flag in session storage for the current tab. Do not enter real personal or payment information.

How the live service may use information

The supplied draft proposes using information to deliver orders and setup details, process payments and refunds, answer support requests, send service notices, protect the service and investigate fraud, improve the service, send permitted marketing, and meet legal obligations. The proposed legal bases and actual practices must be confirmed for the countries served. The draft says Simpli will not sell personal data or use automated decisions with legal effects.

Who may receive information

The draft names the eSIM supplier (currently identified there as eSIM Access) and network partners, payment processors, hosting and email services, support tools, analytics or advertising services where permitted, professional advisers, authorities where legally required, and a successor in a business transfer. TODO: Verify each provider, data shared, contracts, and the accurate supplier name before launch.

International transfers and retention

The draft proposes suitable safeguards for international transfers where required. It also proposes retention periods for order records, support history, analytics, and security logs, but those periods remain placeholders. TODO: Confirm transfer mechanisms, retention periods, deletion practices, and applicable legal requirements.

Your choices and rights

Depending on applicable law, people may be able to request access, correction, deletion, restriction, portability, or object to certain processing; withdraw consent; opt out of marketing; or complain to a regulator. The source draft mentions GDPR/UK GDPR and California rights, but the countries served and exact processes are not yet confirmed. TODO: Confirm which rights apply, identity checks, response timelines, and the process for requests.

Cookies, security, children, and links

The supplied draft proposes essential cookies and optional analytics or marketing cookies, security measures, and safeguards for sensitive eSIM QR codes. Those are proposed live-service practices, not features of this prototype. It also proposes an age restriction and a process for data relating to children; the applicable age needs confirmation. External sites linked from Simpli have their own privacy practices. TODO: Confirm cookie consent, Global Privacy Control handling, security controls, age rules, breach processes, and third-party links.

Updates and contact

The live policy should show its effective date and explain how material changes will be communicated. TODO: Confirm the operating entity and address, privacy@simpli.pk contact, and whether a representative or data protection officer is required.


Questions? Get help