Privacy Policy

Privacy Policy

Service: 22SIM Connect

Website / App: connect.22sim.com and the 22SIM Connect mobile application

Effective Date: 25 May 2026

Last Updated: 25 May 2026

1. Introduction

This Privacy Policy ("Policy") explains how 22 Service FZ-LLC (referred to as "22SIM", "we", "us", or "our"), a company incorporated in the Meydan Free Zone, Dubai, United Arab Emirates, collects, uses, shares, stores, and protects personal data of individuals who use the 22SIM Connect service (the "Service"), including the website at connect.22sim.com and the 22SIM Connect mobile applications for iOS and Android.

22SIM Connect is a digital eSIM platform that allows users to discover, purchase, activate, and manage eSIM data plans for use locally and internationally.

By creating an account, downloading the application, purchasing a plan, or otherwise using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, please do not use the Service.

This Policy is issued in compliance with:

  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL");
  • Meydan Free Zone regulations;
  • The EU General Data Protection Regulation 2016/679 ("GDPR") and the UK GDPR, to the extent applicable to users in the European Economic Area, the United Kingdom, and Switzerland;
  • Other applicable data protection laws in the jurisdictions where we offer the Service.

2. Data Controller and Contact

The data controller responsible for your personal data is:

22 Service FZ-LLC

Meydan Free Zone, Dubai, United Arab Emirates

Email: [email protected]

Support: [email protected]

For any questions, requests, or complaints regarding this Policy or your personal data, please contact our Data Protection Officer at [email protected].

3. Definitions

  • Personal Data — any information relating to an identified or identifiable natural person.
  • Processing — any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
  • eSIM — an embedded SIM profile delivered electronically and installed on a compatible device.
  • ICCID — the unique identifier of a SIM/eSIM profile.
  • IMEI — the unique identifier of a mobile device.
  • MNO — a Mobile Network Operator providing the underlying connectivity for an eSIM plan.

4. Personal Data We Collect

We collect the following categories of personal data:

4.1 Account and Registration Data

  • Full name
  • Email address
  • Mobile phone number (if provided)
  • Password (stored in hashed, encrypted form)
  • Country of residence
  • Preferred language
  • Date of registration
  • Authentication tokens (including third-party login identifiers if you sign in via Apple, Google, or Facebook)

4.2 Identity and Verification Data

Where required by law, by the underlying MNO, or for fraud prevention:

  • Government-issued identification details (passport, national ID, Emirates ID number)
  • Date of birth
  • Nationality
  • Address
  • A photograph or selfie used for liveness verification (when applicable)

4.3 eSIM, Device, and Connectivity Data

  • ICCID, IMSI, and activation codes of the eSIM profile(s) assigned to you
  • IMEI / EID of the device on which the eSIM is installed (for compatibility and provisioning)
  • Device make, model, and operating system version
  • App version and language settings
  • Approximate location derived from network or IP address (used to display available plans for your country and to support roaming functionality)

4.4 Usage and Connectivity Data

  • Data consumption (megabytes used, remaining balance)
  • Country in which the eSIM is currently connected (derived from the serving MNO)
  • Plan activation and expiry dates
  • Top-up and renewal history
  • Speed/quality indicators reported by the device for diagnostics

We do not access, intercept, or read the content of your communications, browsing activity, or applications you use while connected through a 22SIM eSIM.

4.5 Transaction and Payment Data

  • Plan(s) purchased, price, and currency
  • Date and time of purchase
  • Order and invoice identifiers
  • Payment method type (e.g., credit card, Apple Pay, Google Pay, PayPal, Stripe, MyFatoorah)
  • The last four digits of the card and the card brand (we do not store full card numbers, CVV, or expiry dates — these are handled directly by our PCI-DSS-compliant payment processors)
  • Billing address (where required)
  • Refund and chargeback records

4.6 Customer Support and Communications Data

  • Messages, emails, chat transcripts, and call recordings (where applicable)
  • Attachments you submit to support (screenshots, photos, documents)
  • Feedback, ratings, and survey responses

4.7 Marketing and Preferences Data

  • Marketing opt-in/opt-out status by channel (email, push, SMS)
  • Promotional codes redeemed
  • Campaign and referral participation

4.8 Technical, Log, and Cookie Data

  • IP address
  • Device identifiers (advertising ID, app instance ID)
  • Browser type, time zone, and language
  • Pages visited, features used, and timestamps
  • Crash logs and diagnostic information
  • Cookies and similar technologies (see Section 12)

4.9 Information from Third Parties

We may receive personal data about you from:

  • Identity verification providers
  • Payment service providers
  • Fraud-prevention services
  • MNOs and eSIM platform partners
  • Authentication providers (Apple, Google, Facebook) when you choose to sign in via those services
  • Public sources, where lawful and necessary

We do not knowingly collect special categories of personal data (such as racial origin, religious beliefs, biometric data for identification purposes beyond verification, or health data) unless required for identity verification, where it is processed under strict safeguards.

5. Purposes and Legal Bases for Processing

We process your personal data for the following purposes, relying on the legal bases indicated:

# Purpose Legal Basis (GDPR) Legal Basis (UAE PDPL)
1Creating and managing your accountPerformance of a contractNecessary for performance of a contract
2Provisioning, activating, and operating eSIM plans (including transmitting required identifiers to MNOs)Performance of a contractNecessary for performance of a contract
3Processing payments, refunds, and invoicingPerformance of a contract; compliance with legal obligationsPerformance of a contract; legal obligation
4Verifying your identity where required by law or by an MNOCompliance with legal obligations; legitimate interestsLegal obligation; legitimate interests
5Providing customer supportPerformance of a contract; legitimate interestsPerformance of a contract
6Detecting, preventing, and investigating fraud, abuse, and security incidentsLegitimate interests; compliance with legal obligationsLegitimate interests; legal obligation
7Sending transactional notifications (purchase confirmations, expiry alerts, balance updates)Performance of a contractPerformance of a contract
8Sending marketing communications about our products and offersConsent; legitimate interests (where permitted by law)Consent
9Improving and developing the Service, including analytics, A/B testing, and product researchLegitimate interestsLegitimate interests
10Complying with applicable laws, regulations, and lawful requests from authoritiesCompliance with legal obligationsLegal obligation
11Establishing, exercising, or defending legal claimsLegitimate interestsLegitimate interests

Where we rely on consent (for example, for certain marketing or for non-essential cookies), you may withdraw your consent at any time without affecting the lawfulness of processing performed before the withdrawal.

Where we rely on legitimate interests, we have carried out a balancing test to ensure that our interests are not overridden by your rights and freedoms. You may request information about that assessment by contacting [email protected].

6. Sharing of Personal Data

We do not sell your personal data. We share personal data only with the following categories of recipients and only to the extent necessary:

6.1 Mobile Network Operators and eSIM Platform Partners

To provision and operate the eSIM service, we share the technical identifiers required (such as ICCID, IMEI/EID, and where mandated by local regulation, KYC details) with our underlying MNOs and eSIM platform providers. These partners act as independent controllers for their own regulatory obligations and as processors for the technical service we resell.

6.2 Payment Service Providers

We share transaction data with PCI-DSS-compliant payment processors (which may include Stripe, PayPal, MyFatoorah, Apple Pay, and Google Pay) to process your payments, manage refunds, and prevent fraud. We never receive or store your full card details.

6.3 Identity Verification and Fraud-Prevention Providers

Where verification is required, we share the minimum data necessary with vetted identity-verification and anti-fraud vendors.

6.4 Cloud Infrastructure and IT Service Providers

We host the Service on cloud infrastructure (including DigitalOcean) and use supporting services for databases, queuing, monitoring, logging, error tracking, email delivery, push notifications, and customer support. These providers process personal data only on our documented instructions and under written data processing agreements.

6.5 Analytics and Marketing Providers

We use analytics tools (such as in-app analytics, crash reporting, and marketing attribution) to understand how the Service is used and to improve it. Where required, these tools operate only after you provide consent.

6.6 Professional Advisors

Where necessary, we may share personal data with our auditors, lawyers, accountants, and other professional advisors under duties of confidentiality.

6.7 Government, Regulators, and Law Enforcement

We may disclose personal data when required by applicable law, court order, regulatory request, or to protect the rights, property, or safety of 22SIM, our users, or others.

6.8 Corporate Transactions

In the event of a merger, acquisition, reorganisation, or sale of all or part of our business, personal data may be transferred to the acquiring entity, subject to appropriate confidentiality and data-protection commitments.

6.9 With Your Consent

We will share your personal data with other third parties only with your explicit consent or at your direction.

7. International Data Transfers

We are based in the United Arab Emirates. To provide a global service, your personal data may be transferred to, stored in, or processed in countries other than the one where you reside, including countries that may not provide the same level of data protection as your home jurisdiction.

When we transfer personal data internationally, we rely on appropriate safeguards, including:

  • Adequacy decisions issued by the UAE Data Office, the European Commission, or the UK government, where available;
  • Standard Contractual Clauses ("SCCs") or equivalent contractual safeguards;
  • Your explicit consent, where lawful;
  • Other safeguards permitted by applicable law.

You may request a copy of the safeguards in place by contacting [email protected].

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for legal, regulatory, accounting, or reporting requirements.

Indicative retention periods:

Category Retention Period
Account dataWhile your account is active; deleted within 90 days of account closure, unless a longer period is required by law
Transaction and invoicing recordsAt least 5 years from the transaction, in line with UAE tax and accounting laws
KYC and identity verification recordsAs long as required by applicable regulation (typically 5 years after the end of the customer relationship)
Customer support recordsUp to 36 months from the last interaction
Marketing dataUntil you unsubscribe or withdraw consent, then deleted within 30 days
Technical logsTypically 30 to 180 days
BackupsUp to 90 days from the relevant date

When personal data is no longer required, we securely delete or anonymise it.

9. Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These measures include:

  • Encryption of data in transit (TLS) and at rest where appropriate;
  • Strong password hashing and salted credential storage;
  • Role-based access controls and least-privilege principles;
  • Multi-factor authentication for administrative access;
  • Regular security testing, code review, and dependency scanning;
  • Network firewalls, intrusion detection, and bot protection (including Cloudflare WAF);
  • Logging, monitoring, and alerting;
  • Vendor due diligence and contractual safeguards;
  • Employee confidentiality obligations and training.

Despite our efforts, no security measure is perfect. We cannot guarantee absolute security and ask that you also play your part by protecting your account credentials and keeping your device updated.

If a personal data breach affecting your data occurs, we will notify the relevant authorities and, where required, you, within the timeframes set by applicable law.

10. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Access — to obtain confirmation that we process your data and a copy of it.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure ("right to be forgotten") — to request deletion of your data in certain circumstances.
  • Restriction of processing — to request that we limit how we use your data in certain circumstances.
  • Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time.
  • Portability — to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.
  • Withdraw consent — where processing is based on consent.
  • Not to be subject to a solely automated decision that produces legal or similarly significant effects.
  • Lodge a complaint with a competent supervisory authority (for UAE residents, the UAE Data Office; for EU/EEA residents, the data protection authority of your country; for UK residents, the Information Commissioner's Office).

To exercise any of these rights, contact us at [email protected] or [email protected]. We will respond within the timeframes required by applicable law (generally within 30 days, with the possibility of extension where the request is complex).

We may need to verify your identity before responding. We do not charge a fee for exercising your rights, except where the request is manifestly unfounded or excessive.

11. Children

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us at [email protected] and we will take steps to delete that information.

12. Cookies and Similar Technologies

The 22SIM Connect website uses cookies and similar technologies (such as local storage and SDKs in the mobile app) to:

  • Keep you signed in and remember your preferences (essential);
  • Measure and analyse the performance of the Service (analytics);
  • Detect and prevent fraud and security incidents (security);
  • Deliver and measure marketing campaigns (marketing — only with your consent where required).

You can manage your cookie preferences through our cookie consent banner on the website and through your device settings for the mobile app. Disabling certain cookies may affect the functionality of the Service.

For a detailed list of cookies and SDKs we use, see our Cookie Notice at connect.22sim.com/cookies.

13. Third-Party Links and Services

The Service may contain links to third-party websites, apps, or services that we do not operate. We are not responsible for the privacy practices of those third parties. We recommend that you review their privacy policies before providing them with any personal data.

14. Push Notifications

If you enable push notifications, we may send you transactional alerts (e.g., plan expiry, low data balance, payment receipts) and, with your consent, promotional messages. You can disable notifications at any time in your device settings.

15. Automated Decision-Making

We may use automated processes for limited purposes such as fraud detection, payment risk scoring, and personalising the Service. These processes do not produce decisions that have a legal or similarly significant effect on you without human review. Where they do, we will inform you and provide the safeguards required by applicable law, including the right to obtain human intervention, express your point of view, and contest the decision.

16. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by email, in-app message, or a prominent notice on the Service before the changes take effect. The "Last Updated" date at the top of this Policy indicates when it was most recently revised.

We encourage you to review this Policy periodically.

17. Governing Law and Jurisdiction

This Policy is governed by the laws of the United Arab Emirates, without regard to its conflict-of-laws principles. Any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts of the Dubai International Financial Centre (DIFC) or the courts of Dubai, as applicable, except where mandatory provisions of your local law provide otherwise.

Nothing in this Policy limits or excludes any rights you may have under mandatory provisions of the laws of your country of residence.

18. Contact

If you have any questions about this Policy or how we handle your personal data, please contact us:

22 Service FZ-LLC

Meydan Free Zone, Dubai, United Arab Emirates

Privacy: [email protected]

Data Protection Officer: [email protected]

Customer Support: [email protected]

Website: connect.22sim.com

© 2026 22 Service FZ-LLC. All rights reserved.