Last updated · July 24, 2026
Privacy Policy
Effective from: July 24, 2026. This policy explains how Ankaflare LTD, trading as Esimplefly, handles your personal data under the UK GDPR and the EU GDPR.
1. Who we are
esimplefly.com ("esimplefly", "we", "us", "our") is operated by Ankaflare Ltd, a company registered in England and Wales under company number 17319673, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
Ankaflare Ltd is the data controller for the personal data described in this policy. This means we decide why and how your personal data is processed.
| info@ankaflare.com | |
| Postal address | Ankaflare Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom |
| Response time | Within one month of receiving a request (see section 11) |
We have not appointed a statutory Data Protection Officer, as we are not required to do so under Article 37 UK GDPR / EU GDPR. Privacy enquiries are handled by the contact above.
2. What this policy covers
This policy explains how we collect, use, share and protect personal data when you:
- visit esimplefly.com or any of our subdomains;
- create an account or place an order;
- purchase, activate or use an eSIM data plan bought through us;
- contact our customer support by email, WhatsApp or web form;
- receive marketing communications from us.
This policy does not cover the practices of third-party websites, mobile operators or app stores that you may reach through links from our site. Those organisations have their own privacy notices.
3. The personal data we collect
3.1 Data you give us
| Category | Examples |
|---|---|
| Account data | Name, email address, password (stored only as a cryptographic hash), preferred language and currency |
| Order data | Products purchased, order reference, purchase date, price, billing country |
| Billing data | Billing name, billing address and country, tax identifiers where required by law |
| Support data | The content of messages you send us by email, contact form or WhatsApp, and our replies |
| Marketing preferences | Whether you have consented to receive marketing emails, and any later withdrawal of that consent |
3.2 Data generated when you use our service
| Category | Examples |
|---|---|
| eSIM provisioning data | The eSIM profile issued to you, its ICCID, activation code / QR code, activation status and validity period |
| Device compatibility data | Where you use a compatibility check, the device model and eSIM identifier (EID) you provide or that your device reports |
| Connectivity metadata | Data allowance consumed, remaining balance, plan start and expiry dates, and the country or network region in which the plan was used |
| Technical data | IP address, browser type and version, operating system, device type, referring URL, and pages viewed |
| Cookie data | See section 9 |
3.3 Data we do not collect
We do not collect or store your full payment card number, card expiry date or security code. Card details are entered directly into a payment form operated by our payment processor and never reach our servers (see section 6).
We do not intentionally collect special category data (such as data revealing health, religious beliefs, or biometric data). Please do not include such information in support messages.
4. Why we use your data, and our legal basis
Under the UK GDPR and EU GDPR we must have a lawful basis for each processing activity. Ours are set out below.
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Contract (Art. 6(1)(b)) |
| Processing your order, issuing your eSIM profile and delivering activation details | Contract (Art. 6(1)(b)) |
| Providing customer support and handling complaints | Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) |
| Taking payment and processing refunds | Contract (Art. 6(1)(b)) |
| Keeping accounting, tax and VAT records | Legal obligation (Art. 6(1)(c)) |
| Preventing fraud and misuse, and securing our platform | Legitimate interests (Art. 6(1)(f)) |
| Screening orders against international sanctions and trade restrictions | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
| Sending service messages (order confirmations, activation instructions, expiry reminders) | Contract (Art. 6(1)(b)) |
| Sending marketing emails about offers and new plans | Consent (Art. 6(1)(a)), or legitimate interests for existing customers where permitted |
| Measuring site performance and understanding how our site is used | Consent where required; otherwise legitimate interests (Art. 6(1)(f)) |
| Establishing, exercising or defending legal claims | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interests do not override your rights and freedoms. You may request a summary of that assessment using the contact details in section 1.
5. Automated decisions
To comply with international sanctions and export-control rules, and to prevent fraud, our checkout applies automated screening rules. An order may be automatically declined — for example where the destination country of the plan is subject to sanctions, or where a transaction is flagged as high-risk by our payment processor.
This screening does not involve profiling based on your personal characteristics. If your order is declined and you believe this is incorrect, you may contact us to request human review, express your point of view and contest the outcome.
6. Payments
Payments are processed by Stripe Payments Europe, Ltd. and its affiliated entities ("Stripe"). When you pay, your card details are collected directly by Stripe through their secure payment interface.
Stripe acts as an independent controller in respect of the payment data it collects, including for fraud prevention and for meeting its own legal and regulatory obligations. Its processing is governed by Stripe's own privacy policy, available at stripe.com. We receive only the information we need to fulfil your order: whether the payment succeeded, the amount, the currency, the billing country, and a truncated card reference (card brand and last four digits).
7. Who we share your data with
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes. We share personal data with the following categories of recipient:
| Recipient | Purpose | Role |
|---|---|---|
| eSIM connectivity providers | To provision your eSIM profile and to activate, manage and support your data plan | Processor or independent controller |
| Mobile network operators | Providing the underlying network connectivity in the country where you use the plan | Independent controller |
| Payment processor | Taking payment, processing refunds, and preventing payment fraud | Independent controller |
| Cloud hosting and database providers | Hosting our website, application and customer database | Processor |
| Email and messaging providers | Sending transactional and, where applicable, marketing messages | Processor |
| Analytics providers | Measuring website performance and usage | Processor |
| Accounting and tax advisers | Bookkeeping, statutory accounts and tax filings | Processor or independent controller |
| Professional advisers and authorities | Where required by law, court order, or to establish or defend legal claims | Independent controller |
Where a recipient acts as our processor, we have a written contract in place under Article 28 UK GDPR / EU GDPR requiring them to process personal data only on our instructions and to keep it secure. If our business is sold or reorganised, personal data may be transferred to the acquiring entity, subject to this policy continuing to apply.
8. International transfers
We are established in the United Kingdom. Some of our service providers are located outside the UK and the European Economic Area, including in the United States and in other countries where our connectivity partners operate.
Where we transfer personal data outside the UK or the EEA, we rely on one or more of the following safeguards:
- an adequacy decision by the UK Government or the European Commission covering the destination country;
- the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the transfer is subject to UK GDPR;
- the UK International Data Transfer Agreement;
- the derogations in Article 49 — in particular, where a transfer is necessary for the performance of your contract with us. This applies when you buy a plan for use in a country outside the UK/EEA: your eSIM must be provisioned on a network in that country, which necessarily involves transferring the data required for provisioning.
You may request a copy of the safeguards we rely on using the contact details in section 1.
9. Cookies and similar technologies
We use cookies and similar technologies to operate our site, remember your preferences, and understand how the site is used.
Strictly necessary cookies are required for the site to function — for example to keep you signed in, hold your basket, and protect against fraudulent requests. These do not require your consent.
Analytics and marketing cookies are used only where you have given consent through our cookie banner. You may withdraw or change your consent at any time via our cookie settings, or by clearing cookies in your browser.
Full details of the cookies we set, their purpose and their duration are in our Cookie Policy.
10. How long we keep your data
| Data | Retention period |
|---|---|
| Account data | For as long as your account is active, then 24 months after your last activity, unless you ask us to delete it sooner |
| Order and eSIM provisioning records | 7 years from the end of the financial year in which the transaction took place, to meet UK accounting and tax obligations |
| Invoices and accounting records | 7 years from the end of the relevant accounting period |
| Customer support correspondence | 24 months from the date the matter is closed |
| Connectivity metadata | 12 months from plan expiry |
| Marketing consent records | For as long as you remain subscribed, plus 3 years after withdrawal, as evidence that consent was properly obtained and withdrawn |
| Website analytics data | 14 months, in aggregated or pseudonymised form where possible |
| Records relating to a legal claim or dispute | Until the claim is resolved and the applicable limitation period has expired |
When a retention period ends, we delete the data or irreversibly anonymise it so that it can no longer be linked to you.
11. Your rights
Under the UK GDPR and EU GDPR you have the following rights. They are not absolute and some apply only in certain circumstances.
- Access — obtain confirmation of whether we process your data, and a copy of it (Art. 15).
- Rectification — have inaccurate data corrected and incomplete data completed (Art. 16).
- Erasure — ask us to delete your data where there is no ongoing lawful reason for us to keep it (Art. 17). We may need to retain order and accounting records to meet legal obligations.
- Restriction — ask us to limit our processing while an issue is investigated (Art. 18).
- Portability — receive the data you provided to us in a structured, commonly used, machine-readable format (Art. 20).
- Objection — object to processing based on legitimate interests (Art. 21(1)). You may object to direct marketing at any time, without giving a reason (Art. 21(2)), and we will stop.
- Withdraw consent — where processing is based on consent, withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.
- Human review of automated decisions — see section 5 (Art. 22).
How to exercise your rights: email us at info@ankaflare.com. We will respond within one month. That period may be extended by up to two further months for complex or numerous requests; if so, we will tell you within the first month and explain why. We do not charge a fee unless a request is manifestly unfounded or excessive. We may ask you for information to verify your identity before acting on a request.
Complaints. If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority — in the United Kingdom the Information Commissioner's Office (ICO, ico.org.uk); in the European Economic Area, the data protection authority in the country where you live, work, or where the alleged infringement took place.
12. Security
We apply technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS) and at rest; hashed password storage; row-level access controls on our database; role-based access limited to staff who need it; and logging of administrative access.
No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and will inform you directly where the risk to you is high.
13. Children
Our service is not directed at children. We do not knowingly collect personal data from anyone under the age of 16 (or the lower age set by national law in your country, where applicable). If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Changes to this policy
We may update this policy to reflect changes in our service, our providers, or the law. The date at the top shows when it was last revised. Where a change materially affects how we use your data, we will notify you by email or through a prominent notice on the site before the change takes effect.
15. Contact
Ankaflare Ltd — Company number 17319673 (England and Wales).
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
Email: info@ankaflare.com
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ