Privacy Policy
Privacy Policy
Service: 22SIM Connect
Website / App: connect.22sim.com and the 22SIM Connect mobile application
Effective Date: 25 May 2026
Last Updated: 25 May 2026
1. Introduction
This Privacy Policy ("Policy") explains how 22 Service FZ-LLC (referred to as "22SIM", "we", "us", or "our"), a company incorporated in the Meydan Free Zone, Dubai, United Arab Emirates, collects, uses, shares, stores, and protects personal data of individuals who use the 22SIM Connect service (the "Service"), including the website at connect.22sim.com and the 22SIM Connect mobile applications for iOS and Android.
22SIM Connect is a digital eSIM platform that allows users to discover, purchase, activate, and manage eSIM data plans for use locally and internationally.
By creating an account, downloading the application, purchasing a plan, or otherwise using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, please do not use the Service.
This Policy is issued in compliance with:
- UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL");
- Meydan Free Zone regulations;
- The EU General Data Protection Regulation 2016/679 ("GDPR") and the UK GDPR, to the extent applicable to users in the European Economic Area, the United Kingdom, and Switzerland;
- Other applicable data protection laws in the jurisdictions where we offer the Service.
2. Data Controller and Contact
The data controller responsible for your personal data is:
22 Service FZ-LLC
Meydan Free Zone, Dubai, United Arab Emirates
Email: [email protected]
Support: [email protected]
For any questions, requests, or complaints regarding this Policy or your personal data, please contact our Data Protection Officer at [email protected].
3. Definitions
- Personal Data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
- eSIM — an embedded SIM profile delivered electronically and installed on a compatible device.
- ICCID — the unique identifier of a SIM/eSIM profile.
- IMEI — the unique identifier of a mobile device.
- MNO — a Mobile Network Operator providing the underlying connectivity for an eSIM plan.
4. Personal Data We Collect
We collect the following categories of personal data:
4.1 Account and Registration Data
- Full name
- Email address
- Mobile phone number (if provided)
- Password (stored in hashed, encrypted form)
- Country of residence
- Preferred language
- Date of registration
- Authentication tokens (including third-party login identifiers if you sign in via Apple, Google, or Facebook)
4.2 Identity and Verification Data
Where required by law, by the underlying MNO, or for fraud prevention:
- Government-issued identification details (passport, national ID, Emirates ID number)
- Date of birth
- Nationality
- Address
- A photograph or selfie used for liveness verification (when applicable)
4.3 eSIM, Device, and Connectivity Data
- ICCID, IMSI, and activation codes of the eSIM profile(s) assigned to you
- IMEI / EID of the device on which the eSIM is installed (for compatibility and provisioning)
- Device make, model, and operating system version
- App version and language settings
- Approximate location derived from network or IP address (used to display available plans for your country and to support roaming functionality)
4.4 Usage and Connectivity Data
- Data consumption (megabytes used, remaining balance)
- Country in which the eSIM is currently connected (derived from the serving MNO)
- Plan activation and expiry dates
- Top-up and renewal history
- Speed/quality indicators reported by the device for diagnostics
We do not access, intercept, or read the content of your communications, browsing activity, or applications you use while connected through a 22SIM eSIM.
4.5 Transaction and Payment Data
- Plan(s) purchased, price, and currency
- Date and time of purchase
- Order and invoice identifiers
- Payment method type (e.g., credit card, Apple Pay, Google Pay, PayPal, Stripe, MyFatoorah)
- The last four digits of the card and the card brand (we do not store full card numbers, CVV, or expiry dates — these are handled directly by our PCI-DSS-compliant payment processors)
- Billing address (where required)
- Refund and chargeback records
4.6 Customer Support and Communications Data
- Messages, emails, chat transcripts, and call recordings (where applicable)
- Attachments you submit to support (screenshots, photos, documents)
- Feedback, ratings, and survey responses
4.7 Marketing and Preferences Data
- Marketing opt-in/opt-out status by channel (email, push, SMS)
- Promotional codes redeemed
- Campaign and referral participation
4.8 Technical, Log, and Cookie Data
- IP address
- Device identifiers (advertising ID, app instance ID)
- Browser type, time zone, and language
- Pages visited, features used, and timestamps
- Crash logs and diagnostic information
- Cookies and similar technologies (see Section 12)
4.9 Information from Third Parties
We may receive personal data about you from:
- Identity verification providers
- Payment service providers
- Fraud-prevention services
- MNOs and eSIM platform partners
- Authentication providers (Apple, Google, Facebook) when you choose to sign in via those services
- Public sources, where lawful and necessary
We do not knowingly collect special categories of personal data (such as racial origin, religious beliefs, biometric data for identification purposes beyond verification, or health data) unless required for identity verification, where it is processed under strict safeguards.
5. Purposes and Legal Bases for Processing
We process your personal data for the following purposes, relying on the legal bases indicated:
| # | Purpose | Legal Basis (GDPR) | Legal Basis (UAE PDPL) |
|---|---|---|---|
| 1 | Creating and managing your account | Performance of a contract | Necessary for performance of a contract |
| 2 | Provisioning, activating, and operating eSIM plans (including transmitting required identifiers to MNOs) | Performance of a contract | Necessary for performance of a contract |
| 3 | Processing payments, refunds, and invoicing | Performance of a contract; compliance with legal obligations | Performance of a contract; legal obligation |
| 4 | Verifying your identity where required by law or by an MNO | Compliance with legal obligations; legitimate interests | Legal obligation; legitimate interests |
| 5 | Providing customer support | Performance of a contract; legitimate interests | Performance of a contract |
| 6 | Detecting, preventing, and investigating fraud, abuse, and security incidents | Legitimate interests; compliance with legal obligations | Legitimate interests; legal obligation |
| 7 | Sending transactional notifications (purchase confirmations, expiry alerts, balance updates) | Performance of a contract | Performance of a contract |
| 8 | Sending marketing communications about our products and offers | Consent; legitimate interests (where permitted by law) | Consent |
| 9 | Improving and developing the Service, including analytics, A/B testing, and product research | Legitimate interests | Legitimate interests |
| 10 | Complying with applicable laws, regulations, and lawful requests from authorities | Compliance with legal obligations | Legal obligation |
| 11 | Establishing, exercising, or defending legal claims | Legitimate interests | Legitimate interests |
Where we rely on consent (for example, for certain marketing or for non-essential cookies), you may withdraw your consent at any time without affecting the lawfulness of processing performed before the withdrawal.
Where we rely on legitimate interests, we have carried out a balancing test to ensure that our interests are not overridden by your rights and freedoms. You may request information about that assessment by contacting [email protected].
6. Sharing of Personal Data
We do not sell your personal data. We share personal data only with the following categories of recipients and only to the extent necessary:
6.1 Mobile Network Operators and eSIM Platform Partners
To provision and operate the eSIM service, we share the technical identifiers required (such as ICCID, IMEI/EID, and where mandated by local regulation, KYC details) with our underlying MNOs and eSIM platform providers. These partners act as independent controllers for their own regulatory obligations and as processors for the technical service we resell.
6.2 Payment Service Providers
We share transaction data with PCI-DSS-compliant payment processors (which may include Stripe, PayPal, MyFatoorah, Apple Pay, and Google Pay) to process your payments, manage refunds, and prevent fraud. We never receive or store your full card details.
6.3 Identity Verification and Fraud-Prevention Providers
Where verification is required, we share the minimum data necessary with vetted identity-verification and anti-fraud vendors.
6.4 Cloud Infrastructure and IT Service Providers
We host the Service on cloud infrastructure (including DigitalOcean) and use supporting services for databases, queuing, monitoring, logging, error tracking, email delivery, push notifications, and customer support. These providers process personal data only on our documented instructions and under written data processing agreements.
6.5 Analytics and Marketing Providers
We use analytics tools (such as in-app analytics, crash reporting, and marketing attribution) to understand how the Service is used and to improve it. Where required, these tools operate only after you provide consent.
6.6 Professional Advisors
Where necessary, we may share personal data with our auditors, lawyers, accountants, and other professional advisors under duties of confidentiality.
6.7 Government, Regulators, and Law Enforcement
We may disclose personal data when required by applicable law, court order, regulatory request, or to protect the rights, property, or safety of 22SIM, our users, or others.
6.8 Corporate Transactions
In the event of a merger, acquisition, reorganisation, or sale of all or part of our business, personal data may be transferred to the acquiring entity, subject to appropriate confidentiality and data-protection commitments.
6.9 With Your Consent
We will share your personal data with other third parties only with your explicit consent or at your direction.
7. International Data Transfers
We are based in the United Arab Emirates. To provide a global service, your personal data may be transferred to, stored in, or processed in countries other than the one where you reside, including countries that may not provide the same level of data protection as your home jurisdiction.
When we transfer personal data internationally, we rely on appropriate safeguards, including:
- Adequacy decisions issued by the UAE Data Office, the European Commission, or the UK government, where available;
- Standard Contractual Clauses ("SCCs") or equivalent contractual safeguards;
- Your explicit consent, where lawful;
- Other safeguards permitted by applicable law.
You may request a copy of the safeguards in place by contacting [email protected].
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for legal, regulatory, accounting, or reporting requirements.
Indicative retention periods:
| Category | Retention Period |
|---|---|
| Account data | While your account is active; deleted within 90 days of account closure, unless a longer period is required by law |
| Transaction and invoicing records | At least 5 years from the transaction, in line with UAE tax and accounting laws |
| KYC and identity verification records | As long as required by applicable regulation (typically 5 years after the end of the customer relationship) |
| Customer support records | Up to 36 months from the last interaction |
| Marketing data | Until you unsubscribe or withdraw consent, then deleted within 30 days |
| Technical logs | Typically 30 to 180 days |
| Backups | Up to 90 days from the relevant date |
When personal data is no longer required, we securely delete or anonymise it.
9. Security
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These measures include:
- Encryption of data in transit (TLS) and at rest where appropriate;
- Strong password hashing and salted credential storage;
- Role-based access controls and least-privilege principles;
- Multi-factor authentication for administrative access;
- Regular security testing, code review, and dependency scanning;
- Network firewalls, intrusion detection, and bot protection (including Cloudflare WAF);
- Logging, monitoring, and alerting;
- Vendor due diligence and contractual safeguards;
- Employee confidentiality obligations and training.
Despite our efforts, no security measure is perfect. We cannot guarantee absolute security and ask that you also play your part by protecting your account credentials and keeping your device updated.
If a personal data breach affecting your data occurs, we will notify the relevant authorities and, where required, you, within the timeframes set by applicable law.
10. Your Rights
Subject to applicable law, you have the following rights regarding your personal data:
- Access — to obtain confirmation that we process your data and a copy of it.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure ("right to be forgotten") — to request deletion of your data in certain circumstances.
- Restriction of processing — to request that we limit how we use your data in certain circumstances.
- Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time.
- Portability — to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Withdraw consent — where processing is based on consent.
- Not to be subject to a solely automated decision that produces legal or similarly significant effects.
- Lodge a complaint with a competent supervisory authority (for UAE residents, the UAE Data Office; for EU/EEA residents, the data protection authority of your country; for UK residents, the Information Commissioner's Office).
To exercise any of these rights, contact us at [email protected] or [email protected]. We will respond within the timeframes required by applicable law (generally within 30 days, with the possibility of extension where the request is complex).
We may need to verify your identity before responding. We do not charge a fee for exercising your rights, except where the request is manifestly unfounded or excessive.
11. Children
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us at [email protected] and we will take steps to delete that information.
12. Cookies and Similar Technologies
The 22SIM Connect website uses cookies and similar technologies (such as local storage and SDKs in the mobile app) to:
- Keep you signed in and remember your preferences (essential);
- Measure and analyse the performance of the Service (analytics);
- Detect and prevent fraud and security incidents (security);
- Deliver and measure marketing campaigns (marketing — only with your consent where required).
You can manage your cookie preferences through our cookie consent banner on the website and through your device settings for the mobile app. Disabling certain cookies may affect the functionality of the Service.
For a detailed list of cookies and SDKs we use, see our Cookie Notice at connect.22sim.com/cookies.
13. Third-Party Links and Services
The Service may contain links to third-party websites, apps, or services that we do not operate. We are not responsible for the privacy practices of those third parties. We recommend that you review their privacy policies before providing them with any personal data.
14. Push Notifications
If you enable push notifications, we may send you transactional alerts (e.g., plan expiry, low data balance, payment receipts) and, with your consent, promotional messages. You can disable notifications at any time in your device settings.
15. Automated Decision-Making
We may use automated processes for limited purposes such as fraud detection, payment risk scoring, and personalising the Service. These processes do not produce decisions that have a legal or similarly significant effect on you without human review. Where they do, we will inform you and provide the safeguards required by applicable law, including the right to obtain human intervention, express your point of view, and contest the decision.
16. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by email, in-app message, or a prominent notice on the Service before the changes take effect. The "Last Updated" date at the top of this Policy indicates when it was most recently revised.
We encourage you to review this Policy periodically.
17. Governing Law and Jurisdiction
This Policy is governed by the laws of the United Arab Emirates, without regard to its conflict-of-laws principles. Any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts of the Dubai International Financial Centre (DIFC) or the courts of Dubai, as applicable, except where mandatory provisions of your local law provide otherwise.
Nothing in this Policy limits or excludes any rights you may have under mandatory provisions of the laws of your country of residence.
18. Contact
If you have any questions about this Policy or how we handle your personal data, please contact us:
22 Service FZ-LLC
Meydan Free Zone, Dubai, United Arab Emirates
Privacy: [email protected]
Data Protection Officer: [email protected]
Customer Support: [email protected]
Website: connect.22sim.com
© 2026 22 Service FZ-LLC. All rights reserved.