A plain-language draft of the information a live Simpli service may handle.
Draft pending legal review. This is working copy, not a final policy. TODO: Confirm the business identity, service practices, providers, timelines, applicable law, and consumer rights before accepting real orders.
The supplied draft identifies Simpli as the service at simpli.pk, but does not provide the operating legal entity or registered address. TODO: Add and verify the data controller’s legal name and address. The draft lists privacy@simpli.pk for privacy questions; confirm that this inbox is monitored before launch.
Depending on how the live service is built, information may include your name, email, billing country or postcode, support messages and attachments, marketing choices, orders, selected destination and plan, price and date, eSIM/order identifiers, installation and activation status, usage, device details you provide, and technical details such as IP address, browser, device, language, approximate location, pages viewed, and timestamps. The proposed service does not read your calls, texts, or browsing history.
This static demo does not send entered checkout details to a server, take payment, issue an eSIM, send email, run analytics, or use tracking cookies. It stores only a mock order number, plan ID, and demo flag in session storage for the current tab. Do not enter real personal or payment information.
The supplied draft proposes using information to deliver orders and setup details, process payments and refunds, answer support requests, send service notices, protect the service and investigate fraud, improve the service, send permitted marketing, and meet legal obligations. The proposed legal bases and actual practices must be confirmed for the countries served. The draft says Simpli will not sell personal data or use automated decisions with legal effects.
The draft names the eSIM supplier (currently identified there as eSIM Access) and network partners, payment processors, hosting and email services, support tools, analytics or advertising services where permitted, professional advisers, authorities where legally required, and a successor in a business transfer. TODO: Verify each provider, data shared, contracts, and the accurate supplier name before launch.
The draft proposes suitable safeguards for international transfers where required. It also proposes retention periods for order records, support history, analytics, and security logs, but those periods remain placeholders. TODO: Confirm transfer mechanisms, retention periods, deletion practices, and applicable legal requirements.
Depending on applicable law, people may be able to request access, correction, deletion, restriction, portability, or object to certain processing; withdraw consent; opt out of marketing; or complain to a regulator. The source draft mentions GDPR/UK GDPR and California rights, but the countries served and exact processes are not yet confirmed. TODO: Confirm which rights apply, identity checks, response timelines, and the process for requests.
The supplied draft proposes essential cookies and optional analytics or marketing cookies, security measures, and safeguards for sensitive eSIM QR codes. Those are proposed live-service practices, not features of this prototype. It also proposes an age restriction and a process for data relating to children; the applicable age needs confirmation. External sites linked from Simpli have their own privacy practices. TODO: Confirm cookie consent, Global Privacy Control handling, security controls, age rules, breach processes, and third-party links.
The live policy should show its effective date and explain how material changes will be communicated. TODO: Confirm the operating entity and address, privacy@simpli.pk contact, and whether a representative or data protection officer is required.