Privacy Policy

Effective 19 August 2026

Tavi sells prepaid mobile data plans (eSIM profiles) for international travel, through the Tavi iOS app and through https://taviesim.com. This policy explains what we collect, why, who else sees it, and what you can make us do about it. It covers both the app and the website.

If anything here is unclear, email privacy@taviesim.com and we will answer.

The short version

We collect your email address, your orders, and the eSIMs those orders produced. We do not collect your name, your address, your location, your contacts, or your browsing.

We never see your card details — payment is handled entirely by our merchant of record. We do not use advertising or analytics SDKs, we do not track you across other companies' apps or websites, and we do not sell or share your personal information.

What we collect

Your email address. This is your account. You give it to us when you sign in or when you buy from the website. We use it to send your one-time sign-in code, to deliver your eSIM, and to contact you about an order.

Your orders. For each purchase we store the destination, the plan, the price, the time, and the order's status. We keep this because it is your receipt, because we need it to re-deliver an eSIM you have lost, and because tax law requires us to keep sales records.

Your eSIMs. For each eSIM we store the activation details needed to install it — the SM-DP+ address, the activation code, and the ICCID — plus the data allowance, the days remaining, and whether it is still active. Without these the app cannot show you the thing you bought.

A session token. When you sign in we issue a token so you do not have to sign in again on every launch. Only a hashed form of it is stored on our servers. The token itself lives in your device's Keychain and is sent only to our own API.

Ordinary server logs. Our hosting provider records requests to our API and website — IP address, timestamp, and URL — for security and reliability.

That is the complete list.

What we do not collect

No card numbers. See "Payment" below.

No location. The app never asks for location permission. A destination you tap is a shopping choice, not a position fix.

No contacts, photos, calendar, microphone, camera roll, or health data.

No advertising identifier (IDFA), and no App Tracking Transparency prompt, because we do not track you. We do not link your data to data from other companies for advertising or measurement.

No third-party analytics or advertising SDKs in the app. There is no Firebase, no AppsFlyer, no Meta SDK, no Google Analytics.

No data from children. Tavi is not directed at children under 13 (or the equivalent age in your country), and we do not knowingly collect their data. If you believe a child has given us data, email privacy@taviesim.com and we will delete it.

Payment

Checkout is operated by Polar (Polar Software Inc.), acting as our merchant of record. That means Polar — not Tavi — is the seller of record for the transaction, and Polar collects and processes your payment details on its own hosted page.

We never receive, see, or store your card number, CVV, or bank details. We receive only the fact that an order was paid, and the email address you used.

Polar's own privacy policy governs what it does with your payment data: https://polar.sh/legal/privacy

Who else processes your data

Polar — our merchant of record, takes the payment. Receives your email, the amount, and your card details, which never reach us.

eSIM Access — our wholesale carrier partner, issues the actual eSIM profile. Receives the plan ordered. Not your email, not your name.

Resend — sends our transactional email, meaning sign-in codes and eSIM delivery. Receives your email address and the message content.

Cloudflare — hosts our API, database, and website. Holds your stored account and order data, and request logs.

That is all of them. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

Where your data lives

Our database and API run on Cloudflare's global network. Your data may be processed in any country where Cloudflare operates, including outside your own. Where transfers out of the UK or EEA are involved, they rely on the standard contractual clauses in our providers' data processing terms.

How long we keep it

Sign-in codes: 10 minutes, then deleted.

Session tokens: 60 days, then expired.

eSIM records: for the life of the eSIM plus 12 months, so we can help if something goes wrong after your trip.

Order records: 7 years, because tax and accounting law requires it. This is the one category we cannot delete on request while that period runs.

Server logs: per our hosting provider's retention, typically short.

Your rights

Wherever you live, you can ask us to show you what we hold about you, correct anything wrong, delete your account and its data (subject to the order-record retention above), export your data in a portable form, or object to and restrict how we use it.

If you are in the UK or EEA, these are your rights under UK GDPR and GDPR. Our lawful bases are contract (delivering the eSIM you bought), legal obligation (keeping sales records), and legitimate interests (keeping the service secure and working).

If you are in California, you have the rights described under the CCPA and CPRA, including the right to know, delete, and correct, and the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined.

To exercise any of this, email privacy@taviesim.com. We will respond within 30 days. We will not charge you, and we will not treat you differently for asking.

If you are unhappy with our response and you are in the UK, you can complain to the Information Commissioner's Office (ico.org.uk). In the EEA, complain to your local supervisory authority.

Security

Sign-in is by one-time emailed code, so there is no password to leak. Session tokens are stored only as hashes on our servers. All traffic to our API and website is encrypted in transit using TLS. Access to production data is limited to the people who operate Tavi.

No system is perfect. If we ever suffer a breach affecting your data, we will tell you and the relevant regulator as the law requires.

Changes

If we change this policy we will update the effective date at the top, and for anything material we will tell you by email before it takes effect. The current version always lives at https://taviesim.com/privacy

Contact

privacy@taviesim.com for privacy questions and rights requests. support@taviesim.com for anything about an order or an eSIM. legal@taviesim.com for legal notices.

Website: https://taviesim.com