Who we are
This policy is issued by SAIMING INC., which operates the SAIMING website and sells travel eSIM data plans. Where this policy says “we”, “us” or “our”, it means that company. We are the controller of the personal data described here — that is, we decide why and how it is used.
You can reach us on WhatsApp or by phone using the details at the bottom of this page. If you want to raise something specifically about privacy, say so in your first message and it will be routed accordingly.
What this policy covers
It covers personal data we handle when you browse this website, create an account, buy a plan, use an eSIM we supplied, or contact our support team.
What it does not cover
- Our payment provider’s own handling of your card details. Payment happens on their hosted page, under their privacy policy, and card numbers never reach our systems.
- Our network supplier’s own processing as a mobile operator, including anything they are required to log by telecoms regulation in the countries you roam in.
- The local mobile networks your eSIM connects to while you travel. They see the same traffic metadata any roaming subscriber generates, and we do not control that.
- Third-party websites and apps you reach from ours.
What we collect
Grouped by why it exists rather than by how it is stored, because that is the question people are actually asking.
- Account details
- Your email address, your password in hashed form, and any name you choose to give us. If you verify your email or reset a password we store the fact and time that happened.
- Orders and payments
- What you bought, when, the amount in Hong Kong dollars, the payment status, and a reference from our payment provider. We store the last four digits and card brand only — never the full card number, and never the security code.
- eSIM technical identifiers
- The ICCID of the SIM profile we issue you, the associated activation details, and — where our supplier reports it — the EID or IMEI of the device the profile was installed on. These identifiers are how we and our supplier can tell one customer’s eSIM from another’s; without them we could not provision, diagnose or support anything.
- Usage records
- How much data a plan has consumed and when the reading was taken, as reported to us periodically by our supplier. We do not receive, and do not want, the content of your traffic — no websites visited, no messages, no DNS logs.
- Support conversations
- Messages you send us, including anything you choose to put in them such as screenshots, order numbers and device models.
- Device and log data
- IP address, browser and operating system, the pages you requested and when. Our servers record this to run the site and to detect abuse.
- Preferences
- Your chosen language and light or dark theme, stored in cookies on your own device. See the cookie policy for the exact list.
Where it comes from
- From you directly, when you register, order or write to us.
- From your device automatically, when it requests pages from our servers.
- From our network supplier, when a plan is provisioned and when usage is reported.
- From our payment provider, when a payment succeeds, fails or is disputed.
Why we use it, and on what basis
Where data protection law requires a legal basis, ours are these. Where it does not, the purposes below still describe everything we do with your data.
- To perform our contract with you
- Creating your account, taking payment, provisioning the eSIM with our supplier, delivering the activation details, showing you your usage, and handling refunds. We cannot do any of this without the data above.
- Our legitimate interests
- Keeping the service secure, preventing fraud and abuse, diagnosing faults, understanding which parts of the site are failing people, and keeping records of what we did and why. We only rely on this where it does not override your own rights.
- Legal obligations
- Tax and accounting records, responding to lawful requests, and anything our network supplier is required by telecoms regulation to be able to produce.
- Your consent
- Only where we ask for it explicitly — for example if we ever send marketing email. You can withdraw it at any time and it will not affect anything we did beforehand.
What we do not do
International transfers
Selling connectivity in nearly two hundred destinations means personal data crosses borders by design. Our network supplier operates internationally, and our infrastructure and support providers may be located outside your own country.
Where the law requires a specific safeguard for such a transfer — standard contractual clauses, an adequacy decision, or an equivalent mechanism — we are responsible for putting it in place with each provider. The exact mechanism in place for each provider is one of the blanks listed at the top of this page, and it must be completed and verified before launch.
How long we keep it
The periods below are our intended defaults. They still need to be confirmed against the record-keeping obligations that apply to us, which is one of the open items at the top of this page.
- Account data
- For as long as your account exists, and for a short wind-down period after you delete it.
- Order and payment records
- For as long as tax and accounting law requires us to keep them, which is longer than the life of the plan and is not something we can shorten on request.
- eSIM identifiers and usage records
- For the life of the plan plus a period afterwards, so that we can investigate disputes and chargebacks about a plan that has already expired.
- Support conversations
- For a limited period after the issue is closed, so that a repeat problem has context.
- Server logs
- For a short period, then deleted or aggregated so they no longer identify anyone.
When a retention period ends we delete the data or irreversibly anonymise it. Anonymised, aggregated figures — how many plans were sold in a month, for example — are not personal data and we may keep them indefinitely.
Your rights
Depending on where you live, you may have some or all of the following rights. We will honour them wherever we reasonably can, whether or not the law in your country compels us to.
- Ask what personal data we hold about you, and get a copy.
- Have inaccurate data corrected.
- Ask us to delete data, where we do not have an overriding obligation to keep it.
- Ask us to restrict how we use it while a dispute is resolved.
- Receive the data you gave us in a portable, machine-readable format.
- Object to processing we base on our legitimate interests.
- Withdraw consent you previously gave, at any time.
- Complain to your data protection regulator. We would much rather you came to us first, but it is your right either way.
To exercise any of these, contact us and tell us which right you are using. We will verify who you are before acting — usually by confirming control of the account email — and reply within the period the applicable law sets, or promptly if none applies.
Deleting your account
How we protect it
- Traffic between your browser and our servers is encrypted in transit.
- Passwords are stored hashed, never in a form we could read.
- Session tokens are held in cookies that JavaScript cannot read, which limits the damage a cross-site scripting flaw could do.
- Full card numbers never touch our systems; the payment form belongs to our payment provider.
- Access to production data is limited to the people who need it to operate the service.
No system is perfectly secure, and we are not going to pretend otherwise. If a breach affects your personal data and the law requires us to notify you, we will — directly, and without burying it.
Children
This service is not intended for children, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, tell us and we will delete it. The minimum age to hold an account is set in the terms and conditions.
Automated decisions
We do not make decisions with a legal or similarly significant effect on you by automated means alone. Automated checks may flag an order as suspicious, but a person decides what happens next.
Changes to this policy
When we change this policy we will update the date at the top. If a change materially affects how we use your data, we will tell you directly rather than rely on you noticing a new date.