What happens to your data

A privacy policy you can actually read: what is collected when you buy an eSIM, where it is stored, what is encrypted, what is passed to the supplier — and what you can ask for at any time.

Last updated: 28 July 2026

Who operates SIMM.li

The SIMM.li site is operated by Adpro Communications. We sell eSIM data plans, and the information we collect is the information needed to sell you a plan, issue the eSIM and support you after the purchase.

This page explains, in plain language, what is collected, what happens to it, who it is shared with and what you can ask for. For any privacy question or request, message us onוואטסאפ: 058-476-6666 or in the site chat.

What information we collect

and what each piece of it actually does

Your eSIM details are stored encrypted

The details that make it possible to install the eSIM are the most sensitive thing we hold about you, which is why they are never kept here as plain text.

The ICCID, the QR code, the activation code, the SM-DP+ address, the LPA string, the phone number, the one-tap install links and the identity verification link are all stored encrypted in the database, with modern authenticated encryption (libsodium XChaCha20-Poly1305) and a version on every record, so that a key can be rotated without breaking existing data.

Even the ICCID itself is not stored as a readable number in a column you could search: lookups go through a keyed hash, so the raw number simply is not there.

And the details are disclosed only to the order's owner. The ownership check is enforced in the API itself and not only on screen — so this is not visual hiding but a real check on every request.

Payment and card details

Credit card details are not stored on our servers. Payment is handled by a payment processor, and all we keep is the order record — what was bought, when and for how much.

There is no trace of it in the system logs either: card numbers, CVV and expiry dates are masked before anything is written.

What is passed to the eSIM supplier

To issue an eSIM we go to the supplier that actually issues the profile, and we pass on only what is needed to issue it — no more.

The order reference we send to the supplier is deliberately built so that it holds no personal details. Its job is to prevent duplicate issuing, not to identify you.

What is sent to your e-mail

The order confirmation and the eSIM details are sent to the email address you gave at checkout. It is worth making sure it is correct before you pay — that is where the QR code and the installation instructions will be waiting for you.

In some cases the supplier sends the eSIM details straight to that address as a backup route. That is what the email address is passed to it for — and that is the only use made of it there.

System logs, redaction and automatic deletion

The system keeps two kinds of records: a log of requests to the supplier's API, and an event log of what happened on an order. Both are deleted automatically by a daily job. The default windows are 30 days for the API log and 180 days for the event log.

And more important than that: the masking happens before the write, not after it. Secrets and eSIM content are masked the moment the record is created, so they are never written to the log in the first place:

  • API keys, tokens and authorisation headers
  • Credit card details
  • QR code, activation code, LPA string and SM-DP+ address
  • The identity verification link
  • and personal fields such as name, email, phone and ICCID — partially masked

The result is simple: even someone with access to the logs will not find your installation details there.

Cookies

The site uses functional WordPress and WooCommerce cookies — the ones that hold your session, your cart and your sign-in state. Without them you simply cannot make a purchase or sign in to your account.

We do not currently run any analytics or marketing tracking of our own. If one is added in future, it will only run with consent.

Mailings and marketing

Your order details are not used for marketing without consent.

Order confirmations, eSIM details and service messages are not marketing email — they are part of the service you bought, and you need them in order to receive the eSIM. If consent to marketing is given, it can be withdrawn at any time and without explanation.

Your rights

Every request goes through one channel — WhatsApp: 058-476-6666

What we cannot delete, and you should know about it

Some records the law requires us to keep — mainly accounting and tax records for a transaction that has already taken place. A deletion request will not remove those, and that is not at our discretion.

Everything beyond that is deleted on request.

How long information is kept

Order records are kept for as long as they are needed to provide the service, to support you and to meet the obligations the law places on us.

System logs are deleted automatically within the windows described above. Information that is no longer needed is not kept for the sake of it.

How we protect your information

Encryption at rest

All the eSIM installation details are stored encrypted in the database, using authenticated encryption.

Redaction in the logs

Secrets, payment details and eSIM contents are masked before they are written to any record at all.

Access control

The eSIM details are disclosed only to the owner of the order, and the ownership check is enforced in the API and not only on screen.

An honest word about security

No system is completely immune, and nobody can promise otherwise. What can be promised is this: your sensitive information is encrypted, it never reaches the system logs, and it is never disclosed to anyone who is not the order's owner.

If you run into something that looks wrong to you — message us onוואטסאפ: 058-476-6666.

Changes to this policy

If we update this policy, the updated version will be published here, on this page, with the date of the last update shown alongside it.

A material change will be explained clearly and not buried between the lines. Continuing to use the site after publication refers to the policy as it appears on the page.

A question about your information?

View, correct, delete, export or withdraw consent — it all starts with one WhatsApp message, and we answer in Hebrew and English.