Legal
Privacy Policy
This Privacy Policy describes how FlyoSIM collects, uses, stores, discloses, and safeguards personal data when users access our website, app, checkout flow, and support channels. It also explains available rights and contact paths for privacy concerns.
1. Scope of this Policy
This policy applies to data collected through FlyoSIM-owned digital services. It does not apply to independent third-party services that maintain separate privacy notices.
2. Processing Roles
FlyoSIM generally acts as data controller for account, service-operation, and support data. Payment providers, anti-fraud partners, and Merchant of Record providers may act as independent controllers or processors for billing and compliance data under their own legal obligations and contractual terms.
- FlyoSIM support contact: support@flyosim.com
- Payment-related processing includes anti-fraud and chargeback prevention controls.
- Where required by law, partner processing is governed by data-processing agreements or equivalent legal safeguards.
3. Data Categories We Collect
- FlyoSIM account and authentication data: email address, FlyoSIM user ID, account status, session metadata, and provider identifiers used for email, Google, or Sign in with Apple authentication. FlyoSIM requests only email scope from Apple.
- Provider-declared sign-in processing: Google's iOS sign-in component declares that it may process name, phone number, user ID, device ID, other usage data, other technical data, and coarse-location data. FlyoSIM does not request or store a Google profile name or phone number in its account record, but these categories may be processed by the sign-in provider or its SDK when you use Google sign-in.
- Device-integrity and security data: Apple App Attest key identifiers, public-key material, counters, environment and verification results; request and audit identifiers; IP/network metadata; and an IP-derived country when infrastructure makes it available. The app does not request GPS access.
- Order data: purchased plan, amount, timestamps, transaction and fulfillment references.
- Service and interaction data: eSIM activation/status, balance and expiry indicators, installation-detail access events, and troubleshooting traces. Access to protected installation details is audited for account and service security.
- Support data: inquiry messages, recent conversation context, issue-resolution history, human-handoff records, and limited order/status context needed to answer an authenticated request. The current iOS app does not provide a support attachment control.
- Technical and diagnostic data: device/app version context, sanitized request route, request ID, response status, duration, integrity failures, rate-limit/security events, and reliability or error records.
- Compliance data: risk signals, sanctions-screening flags, dispute/chargeback references, and verification outcomes where legally required.
4. Data We Typically Do Not Store
FlyoSIM does not intentionally store full payment card numbers or CVV values. Sensitive payment credentials are handled by licensed payment providers using tokenized or equivalent secure mechanisms.
5. Data Sources
- Directly from you during registration, checkout, and support communication.
- From Google and Apple when you choose their native sign-in services.
- Automatically from app/browser interactions and device, network, App Attest, hosting, logging, and security infrastructure.
- From payment and risk partners for transaction validation.
- From carrier, eSIM provisioning, network, and infrastructure partners to support service delivery.
- From fraud-prevention providers and publicly available sanctions/compliance sources where required.
6. Purposes and Legal Bases
We process personal data for the following purposes:
- Contractual necessity: account operations, order fulfillment, support delivery.
- Legitimate interests: fraud prevention, service hardening, abuse detection, quality improvements.
- Provider component purposes: Google's iOS sign-in component declares that its listed identifiers, usage data, and technical data may be processed for app functionality or analytics. FlyoSIM does not use these data for targeted advertising or cross-app tracking.
- Legal obligations: tax, accounting, sanctions compliance, dispute and claims management.
- Consent-based processing when required for optional marketing or similar features.
If local law requires a different legal basis framework, the equivalent lawful basis under that law applies.
7. Fraud Prevention and Security Monitoring
We may use automated and manual controls to identify suspicious behavior, including repeated failed authentication, unusual transaction patterns, and abuse indicators.
We do not use solely automated decision-making to produce legal or similarly significant effects without human review where required by applicable law.
8. Sharing and Disclosure
We share data only when operationally necessary or legally required, including with:
- Google and Apple for the native sign-in flow you choose. Apple also processes App Attest requests used to protect account and eSIM operations. These providers maintain their own privacy notices.
- Resend for login, password-reset, account-deletion verification, and redacted support email delivery.
- Render for production application hosting, database storage, request logging, operational monitoring, and provider-managed backups. The primary FlyoSIM production region is Singapore, while provider support and backup processing may occur elsewhere under the provider's terms.
- OpenAI when authenticated AI-assisted support is enabled. Before a request is sent, FlyoSIM screens and redacts sensitive input and limits context to the current message, bounded recent support history, prior support topics, and limited order/status summaries needed to respond. FlyoSIM sends Responses API requests with
store: false; that setting does not itself promise zero provider security or abuse- monitoring retention. Do not submit passwords, one-time codes, payment credentials, bank information, or eSIM activation secrets in support. - eSIMAccess and other approved carrier/provisioning suppliers for plan availability, fulfillment, status, and usage. Suppliers receive the package and opaque transaction information required to provide service and return provider order, eSIM, ICCID, activation, status, and usage records. FlyoSIM does not send the customer's account email to eSIMAccess as part of its current provisioning request.
- Payment processors, acquiring partners, and Merchant of Record providers.
- Other approved monitoring, security, and analytics providers when their feature is enabled.
- Professional advisors, auditors, and authorized public authorities where required by law.
The FlyoSIM iOS app does not use personal data for cross-app tracking or targeted advertising, and FlyoSIM does not sell personal data to data brokers. Optional website analytics or marketing technologies remain controlled by the choices described in our Cookie Policy.
9. International Data Transfers
FlyoSIM and its partners may process data across multiple countries. We implement commercially reasonable legal and technical safeguards to protect personal data during cross-border transfer and processing.
Safeguards may include contractual transfer clauses, access controls, encryption, and vendor due diligence.
10. Retention and Deletion
You can initiate account deletion from the Profile area of the signed-in FlyoSIM app. After FlyoSIM accepts the confirmed request, account access is revoked and an asynchronous deletion process begins. A private receipt link lets you check whether the request is pending, processing, retrying, needs review, or is completed.
- Direct account identifiers, credentials, and provider tokens are deleted or anonymized when no longer needed.
- Financial, tax, refund, dispute, and fraud-prevention records that must remain are minimized, pseudonymized where appropriate, access-restricted, and retained only for the applicable legal or operational period.
- Security and deletion-integrity records may retain pseudonymous keyed fingerprints, private receipt and idempotency state, redacted audit events, App Attest key history, and limited order/payment/provider facts needed to prevent account recreation abuse, prove deletion handling, protect the service, or meet legal obligations. Pseudonymous records are not treated as anonymous merely because direct profile fields were removed.
- Active eSIM, order, payment, support, processor, security-log, and backup data follow their approved service, dispute, security, and expiry obligations; a partial processor failure is not reported as completed. Provider logs and backups may remain until their normal protected retention cycle expires and are not restored to active use except for authorized recovery.
- Carrier and eSIM supplier systems may retain service, network, regulatory, or dispute records under their own obligations. FlyoSIM deletes protected local activation material through its account-deletion workflow, but deletion does not cancel an active eSIM or guarantee immediate erasure from an independent supplier.
- Data is deleted, anonymized, or aggregated when its approved purpose and retention period end.
Read the direct account deletion instructions before confirming a request, especially if you have an active eSIM or unresolved refund.
11. Cookies and Similar Technologies
We and service providers may use cookies or similar technologies for login persistence, security controls, session continuity, performance measurement, and reliability improvements.
Browser controls may allow you to manage cookie preferences, but disabling some technologies may affect service functionality.
12. Security Safeguards
FlyoSIM applies layered safeguards including encrypted transport, access restrictions, service monitoring, incident response procedures, environment controls, protected local credential storage, and Apple App Attest verification for sensitive native-app operations. No online system can guarantee absolute security.
If a reportable data incident occurs, we will provide notifications as required by applicable law.
13. User Rights
Depending on your jurisdiction, you may have rights to:
- Access and receive a copy of your personal data.
- Correct inaccurate or incomplete data.
- Request deletion, restriction, or objection to specific processing.
- Request portability where legally applicable.
- Withdraw consent for consent-based processing.
Initiate complete account deletion in the signed-in FlyoSIM app under Profile and Delete account. For other privacy requests, contact support@flyosim.com. We may require identity verification before processing requests. Support can assist with deletion issues, but email is not the deletion initiation path.
Subject to law and request complexity, we aim to respond within 30 days, or another period allowed by applicable law.
14. Marketing Preferences
Transactional communications related to orders and account security may still be sent as required for service operation. Optional marketing communications can be unsubscribed via the provided controls.
15. Children and Minors
FlyoSIM Services require users to be at least 18 years old, or the legal age of majority in their jurisdiction, and able to enter a binding agreement. If data is submitted by or for a child improperly, contact support for review.
16. Policy Updates
We may revise this Privacy Policy to reflect legal, operational, or product changes. Updated versions are posted on this page with a revised "Last updated" date.
17. Related Legal Pages
Terms: https://www.flyosim.com/terms
Refund Policy: https://www.flyosim.com/refund-policy
Pricing: https://www.flyosim.com/pricing
18. Contact and Complaints
Privacy inquiries: support@flyosim.com
If local law provides authority-level complaint rights, you may contact the relevant supervisory authority in your jurisdiction.
This document is for transparency and platform compliance and is not legal advice.