eSIMplefly

Last updated · July 24, 2026

Privacy Policy

Effective from: July 24, 2026. This policy explains how Ankaflare LTD, trading as Esimplefly, handles your personal data under the UK GDPR and the EU GDPR.

1. Who we are

esimplefly.com ("esimplefly", "we", "us", "our") is operated by Ankaflare Ltd, a company registered in England and Wales under company number 17319673, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

Ankaflare Ltd is the data controller for the personal data described in this policy. This means we decide why and how your personal data is processed.

How to contact us about privacy
Emailinfo@ankaflare.com
Postal addressAnkaflare Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Response timeWithin one month of receiving a request (see section 11)

We have not appointed a statutory Data Protection Officer, as we are not required to do so under Article 37 UK GDPR / EU GDPR. Privacy enquiries are handled by the contact above.

2. What this policy covers

This policy explains how we collect, use, share and protect personal data when you:

  • visit esimplefly.com or any of our subdomains;
  • create an account or place an order;
  • purchase, activate or use an eSIM data plan bought through us;
  • contact our customer support by email, WhatsApp or web form;
  • receive marketing communications from us.

This policy does not cover the practices of third-party websites, mobile operators or app stores that you may reach through links from our site. Those organisations have their own privacy notices.

3. The personal data we collect

3.1 Data you give us

CategoryExamples
Account dataName, email address, password (stored only as a cryptographic hash), preferred language and currency
Order dataProducts purchased, order reference, purchase date, price, billing country
Billing dataBilling name, billing address and country, tax identifiers where required by law
Support dataThe content of messages you send us by email, contact form or WhatsApp, and our replies
Marketing preferencesWhether you have consented to receive marketing emails, and any later withdrawal of that consent

3.2 Data generated when you use our service

CategoryExamples
eSIM provisioning dataThe eSIM profile issued to you, its ICCID, activation code / QR code, activation status and validity period
Device compatibility dataWhere you use a compatibility check, the device model and eSIM identifier (EID) you provide or that your device reports
Connectivity metadataData allowance consumed, remaining balance, plan start and expiry dates, and the country or network region in which the plan was used
Technical dataIP address, browser type and version, operating system, device type, referring URL, and pages viewed
Cookie dataSee section 9

3.3 Data we do not collect

We do not collect or store your full payment card number, card expiry date or security code. Card details are entered directly into a payment form operated by our payment processor and never reach our servers (see section 6).

We do not intentionally collect special category data (such as data revealing health, religious beliefs, or biometric data). Please do not include such information in support messages.

4. Why we use your data, and our legal basis

Under the UK GDPR and EU GDPR we must have a lawful basis for each processing activity. Ours are set out below.

PurposeLegal basis
Creating and managing your accountContract (Art. 6(1)(b))
Processing your order, issuing your eSIM profile and delivering activation detailsContract (Art. 6(1)(b))
Providing customer support and handling complaintsContract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
Taking payment and processing refundsContract (Art. 6(1)(b))
Keeping accounting, tax and VAT recordsLegal obligation (Art. 6(1)(c))
Preventing fraud and misuse, and securing our platformLegitimate interests (Art. 6(1)(f))
Screening orders against international sanctions and trade restrictionsLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))
Sending service messages (order confirmations, activation instructions, expiry reminders)Contract (Art. 6(1)(b))
Sending marketing emails about offers and new plansConsent (Art. 6(1)(a)), or legitimate interests for existing customers where permitted
Measuring site performance and understanding how our site is usedConsent where required; otherwise legitimate interests (Art. 6(1)(f))
Establishing, exercising or defending legal claimsLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interests do not override your rights and freedoms. You may request a summary of that assessment using the contact details in section 1.

5. Automated decisions

To comply with international sanctions and export-control rules, and to prevent fraud, our checkout applies automated screening rules. An order may be automatically declined — for example where the destination country of the plan is subject to sanctions, or where a transaction is flagged as high-risk by our payment processor.

This screening does not involve profiling based on your personal characteristics. If your order is declined and you believe this is incorrect, you may contact us to request human review, express your point of view and contest the outcome.

6. Payments

Payments are processed by Stripe Payments Europe, Ltd. and its affiliated entities ("Stripe"). When you pay, your card details are collected directly by Stripe through their secure payment interface.

Stripe acts as an independent controller in respect of the payment data it collects, including for fraud prevention and for meeting its own legal and regulatory obligations. Its processing is governed by Stripe's own privacy policy, available at stripe.com. We receive only the information we need to fulfil your order: whether the payment succeeded, the amount, the currency, the billing country, and a truncated card reference (card brand and last four digits).

7. Who we share your data with

We do not sell your personal data, and we do not share it with third parties for their own marketing purposes. We share personal data with the following categories of recipient:

RecipientPurposeRole
eSIM connectivity providersTo provision your eSIM profile and to activate, manage and support your data planProcessor or independent controller
Mobile network operatorsProviding the underlying network connectivity in the country where you use the planIndependent controller
Payment processorTaking payment, processing refunds, and preventing payment fraudIndependent controller
Cloud hosting and database providersHosting our website, application and customer databaseProcessor
Email and messaging providersSending transactional and, where applicable, marketing messagesProcessor
Analytics providersMeasuring website performance and usageProcessor
Accounting and tax advisersBookkeeping, statutory accounts and tax filingsProcessor or independent controller
Professional advisers and authoritiesWhere required by law, court order, or to establish or defend legal claimsIndependent controller

Where a recipient acts as our processor, we have a written contract in place under Article 28 UK GDPR / EU GDPR requiring them to process personal data only on our instructions and to keep it secure. If our business is sold or reorganised, personal data may be transferred to the acquiring entity, subject to this policy continuing to apply.

8. International transfers

We are established in the United Kingdom. Some of our service providers are located outside the UK and the European Economic Area, including in the United States and in other countries where our connectivity partners operate.

Where we transfer personal data outside the UK or the EEA, we rely on one or more of the following safeguards:

  • an adequacy decision by the UK Government or the European Commission covering the destination country;
  • the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the transfer is subject to UK GDPR;
  • the UK International Data Transfer Agreement;
  • the derogations in Article 49 — in particular, where a transfer is necessary for the performance of your contract with us. This applies when you buy a plan for use in a country outside the UK/EEA: your eSIM must be provisioned on a network in that country, which necessarily involves transferring the data required for provisioning.

You may request a copy of the safeguards we rely on using the contact details in section 1.

9. Cookies and similar technologies

We use cookies and similar technologies to operate our site, remember your preferences, and understand how the site is used.

Strictly necessary cookies are required for the site to function — for example to keep you signed in, hold your basket, and protect against fraudulent requests. These do not require your consent.

Analytics and marketing cookies are used only where you have given consent through our cookie banner. You may withdraw or change your consent at any time via our cookie settings, or by clearing cookies in your browser.

Full details of the cookies we set, their purpose and their duration are in our Cookie Policy.

10. How long we keep your data

DataRetention period
Account dataFor as long as your account is active, then 24 months after your last activity, unless you ask us to delete it sooner
Order and eSIM provisioning records7 years from the end of the financial year in which the transaction took place, to meet UK accounting and tax obligations
Invoices and accounting records7 years from the end of the relevant accounting period
Customer support correspondence24 months from the date the matter is closed
Connectivity metadata12 months from plan expiry
Marketing consent recordsFor as long as you remain subscribed, plus 3 years after withdrawal, as evidence that consent was properly obtained and withdrawn
Website analytics data14 months, in aggregated or pseudonymised form where possible
Records relating to a legal claim or disputeUntil the claim is resolved and the applicable limitation period has expired

When a retention period ends, we delete the data or irreversibly anonymise it so that it can no longer be linked to you.

11. Your rights

Under the UK GDPR and EU GDPR you have the following rights. They are not absolute and some apply only in certain circumstances.

  • Access — obtain confirmation of whether we process your data, and a copy of it (Art. 15).
  • Rectification — have inaccurate data corrected and incomplete data completed (Art. 16).
  • Erasure — ask us to delete your data where there is no ongoing lawful reason for us to keep it (Art. 17). We may need to retain order and accounting records to meet legal obligations.
  • Restriction — ask us to limit our processing while an issue is investigated (Art. 18).
  • Portability — receive the data you provided to us in a structured, commonly used, machine-readable format (Art. 20).
  • Objection — object to processing based on legitimate interests (Art. 21(1)). You may object to direct marketing at any time, without giving a reason (Art. 21(2)), and we will stop.
  • Withdraw consent — where processing is based on consent, withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.
  • Human review of automated decisions — see section 5 (Art. 22).

How to exercise your rights: email us at info@ankaflare.com. We will respond within one month. That period may be extended by up to two further months for complex or numerous requests; if so, we will tell you within the first month and explain why. We do not charge a fee unless a request is manifestly unfounded or excessive. We may ask you for information to verify your identity before acting on a request.

Complaints. If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority — in the United Kingdom the Information Commissioner's Office (ICO, ico.org.uk); in the European Economic Area, the data protection authority in the country where you live, work, or where the alleged infringement took place.

12. Security

We apply technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS) and at rest; hashed password storage; row-level access controls on our database; role-based access limited to staff who need it; and logging of administrative access.

No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and will inform you directly where the risk to you is high.

13. Children

Our service is not directed at children. We do not knowingly collect personal data from anyone under the age of 16 (or the lower age set by national law in your country, where applicable). If you believe a child has provided us with personal data, please contact us and we will delete it.

14. Changes to this policy

We may update this policy to reflect changes in our service, our providers, or the law. The date at the top shows when it was last revised. Where a change materially affects how we use your data, we will notify you by email or through a prominent notice on the site before the change takes effect.

15. Contact

Ankaflare Ltd — Company number 17319673 (England and Wales).
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
Email: info@ankaflare.com

Ankaflare LTD — Registered in England and Wales. Trading as "Esimplefly".
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ