1Who we are
This policy explains how Switas Tech Inc. ("Spidot", "we", "us"), 490 Post Street, Ste 500 PMB 2288, San Francisco, CA 94102, USA, handles personal data when you visit spidot.com, buy or use a Spidot eSIM, sign in, contact us, or enquire about our business services.
We are the controller of this personal data under the EU and UK General Data Protection Regulation (GDPR) and the "business" under California law. We have not appointed a data protection officer; for any privacy question, contact us at support@spidot.com.
When a company buys eSIMs for its travellers under our Business terms, we may process traveller data on that company's behalf as its processor, under our Data processing addendum. In that case the company's own privacy notice also applies.
2The data we collect
| Category | Examples | Source |
|---|---|---|
| Contact details | Email address; your name if you sign in with Google or give it to us | You; Google (if you sign in with Google) |
| Order details | Plan, destination, price, currency, order reference, payment status, receipts, top-ups | You; our systems |
| Payment details | Payment method type, last four digits and card country, fraud-check results. We never receive your full card number | Stripe |
| eSIM details | ICCID (eSIM identifier), activation code, data usage, remaining data, line status | Our wholesale eSIM supplier; our systems |
| Location (approximate) | The country your IP address points to, used for currency, sales restrictions and fraud prevention. We do not collect GPS location | Your device |
| Device and usage data | IP address, browser and device type, pages viewed, referring site, the device model you check for compatibility | Your device; cookies and similar technologies |
| Consent choices | Your cookie and privacy choices, Global Privacy Control signal | Your device |
| Support messages | What you write to us, your order reference, our replies | You |
| Business enquiries | Name, work email, company, expected number of travellers, message | You |
We do not ask for sensitive personal data such as health information, and we do not need your phone number, home address or date of birth to sell you an eSIM. Please do not send us sensitive data in support messages.
3How we use your data and our legal bases
Under the GDPR we must have a legal basis for each use of personal data. This table shows what we use data for and why we may do so.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Take payment, deliver your eSIM and top-ups, send the QR code and receipt | Contact, order, payment, eSIM details | Performance of our contract with you |
| Show your eSIMs, usage and receipts when you sign in | Contact, order, eSIM details | Performance of contract |
| Answer support requests and handle refunds | Contact, order, eSIM details, support messages | Performance of contract; legitimate interests in helping customers |
| Prevent fraud and misuse; apply sales restrictions (including not selling in Türkiye) | Payment, location, device data | Legitimate interests in protecting our business and customers; legal obligation |
| Keep accounting and tax records | Order and payment details | Legal obligation |
| Keep the Site secure and working | Device and usage data | Legitimate interests |
| Measure and improve the Site with analytics | Device and usage data | Consent (where required, for example in the EEA, UK and Switzerland) |
| Show and measure our advertising | Device and usage data, consent choices | Consent |
| Reply to business enquiries and manage partner and business customer relationships | Business enquiry details | Legitimate interests in developing our business; steps before a contract |
| Send service messages, such as low-data alerts, where offered | Contact, eSIM details | Performance of contract |
| Establish, exercise or defend legal claims | Any relevant data | Legitimate interests |
We do not send marketing emails without your consent where consent is required. Every marketing email will include a way to unsubscribe. We do not make decisions that have legal or similarly significant effects on you based solely on automated processing; automated fraud checks by Stripe may flag a payment for review, and you can ask us to review any declined order at support@spidot.com.
4Cookies and analytics
We use cookies that are strictly necessary for the Site, sign-in and payments. With your consent where required, we also use Google Analytics 4 to understand how the Site is used and Google advertising tags to measure our ads. We use Google Consent Mode, so Google tags adjust their behaviour to your choices. You can change your choices at any time through the "Cookie settings" link in the footer.
Full details, including each cookie and how long it lasts, are in our Cookie policy.
5Who we share it with
We share personal data only with the service providers we need to run Spidot, and only what they need:
| Provider | What they do | Location |
|---|---|---|
| Stripe | Payment processing and fraud prevention. Stripe is also an independent controller for some data, under its own privacy policy | USA and other countries |
| Vercel | Website hosting and delivery | USA and global edge network |
| Hostinger | Database hosting | Germany (EU) |
| MailerSend | Sending transactional emails (eSIM delivery, receipts, sign-in links) | EU and USA |
| Sign in with Google, Google Tag Manager, Google Analytics 4, and Google Ads measurement and remarketing (only with consent) | USA and other countries | |
| Meta Platforms | Advertising measurement via the Meta pixel and the Conversions API: page, product and checkout events with hashed email and country, IP address, browser user agent and Meta cookie identifiers (only with marketing consent) | USA and other countries |
| Our wholesale eSIM supplier | Issues and manages the eSIM lines. It receives only line identifiers (ICCID) and order reference notes, not your name or email address | Outside the EEA |
| Mobile network operators | Carry your data traffic when you use the eSIM. They see technical data about the connection, as for any mobile service | The countries you travel to |
We may also disclose personal data to professional advisers (such as lawyers and accountants), to authorities when the law requires it or to protect rights and safety, and to a buyer or successor if our business is sold or reorganised, in which case this policy continues to protect your data.
If you were given your eSIM by your employer, travel agency or another business, we share with that business the order and usage information it needs to manage the eSIMs it bought.
6International transfers
Switas Tech Inc. is based in the United States, and some of our service providers are in the US and other countries. When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country that does not have an adequacy decision, we use the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss amendments where needed, or rely on a provider's certification under the EU-US Data Privacy Framework and its UK and Swiss extensions. You can ask us for a copy of the relevant safeguards at support@spidot.com.
7How long we keep it
| Data | How long |
|---|---|
| Orders, receipts, payment and tax records | 7 years after the order, to meet tax and accounting rules |
| eSIM details and usage | As long as the eSIM is active, then with the order record |
| Sign-in session | 30 days, or until you sign out |
| Support messages | 3 years after the conversation ends |
| Business enquiries (leads) | 2 years after the last contact, unless you become a customer |
| Analytics and advertising data | As set out in the Cookie policy (Google Analytics data retention: 14 months) |
| Consent records | For as long as the choice applies, plus the period needed to prove it |
We may keep data longer if the law requires it or we need it to deal with a dispute. When we no longer need data, we delete or anonymise it.
8How we protect it
We use encryption in transit (HTTPS), access controls, least-privilege access for staff and providers, and separation of payment data (handled by Stripe). No system is completely secure; if a breach affects your data and the law requires it, we will tell you and the relevant authorities.
9Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy;
- correct data that is wrong or incomplete;
- delete your data, unless we must keep it (for example, tax records);
- restrict or object to some uses, including any use based on legitimate interests and all direct marketing;
- port data you gave us to another provider in a machine-readable format;
- withdraw consent at any time, for example through "Cookie settings", without affecting earlier use;
- opt out of the sale or sharing of personal data and of targeted advertising;
- complain to a data protection authority.
To use a right, email support@spidot.com from the email address you used with us, or use our contact form. We may need to verify your identity before acting. We reply within one month (GDPR) or 45 days (US state laws), and can extend this where the law allows. We do not charge a fee unless a request is manifestly unfounded or excessive. An authorised agent may make a request for you with your signed permission.
10EEA, UK and Switzerland
The legal bases above apply under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection. You can complain to the supervisory authority where you live or work, or where you think a breach happened; in the UK, that is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to deal with your concern first.
In the EEA, the UK and Switzerland, analytics and advertising cookies stay off until you choose to allow them.
EU and UK representative under Article 27 GDPR / UK GDPR: [TO CONFIRM]. Until one is named here, contact us directly at support@spidot.com.
11California and other US states
This section applies to residents of California (under the CCPA as amended by the CPRA) and of other US states with comprehensive privacy laws, such as Colorado, Connecticut, Virginia, Utah, Texas and Oregon.
What we collect and disclose
In the past 12 months we have collected these categories of personal information, from the sources and for the purposes described above: identifiers (email, name, IP address, ICCID); commercial information (orders and top-ups); internet or network activity (pages viewed, interactions with ads); approximate geolocation (country from IP); and professional information (business enquiries). We disclose them for business purposes to the service providers listed above. We do not collect sensitive personal information for inferring characteristics about you.
"Sale" and "sharing"
We do not sell personal information for money. However, when you allow marketing cookies, Google and Meta advertising tags on the Site, and our server-side Meta Conversions API events, collect identifiers and internet activity for cross-context behavioural advertising. Under California law this may count as "sharing", and under some other state laws as a "sale" or "targeted advertising". We do not knowingly sell or share the personal information of anyone under 16.
Your privacy choices. You can opt out of sale, sharing and targeted advertising at any time with the "Your privacy choices" / "Cookie settings" link in the footer, by turning off marketing cookies. We also treat a Global Privacy Control (GPC) signal from your browser as a valid opt-out for that browser.
Your rights
You have the rights listed in section 9, including to know, access, correct and delete your personal information, and to opt out. If we deny your request, you may appeal by replying to our decision; if we deny your appeal, you can contact your state attorney general. We will not discriminate against you for using your rights, for example by charging a different price or giving you a worse service.
We keep each category of personal information for the periods in section 7.
12Canada
We handle personal information of people in Canada in line with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws. Your information may be stored and processed outside Canada, including in the United States and the EU, where it may be accessible to courts and authorities under local law. You can access and correct your information and withdraw consent by contacting us at support@spidot.com, and you may complain to the Office of the Privacy Commissioner of Canada.
13Brazil
If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) gives you the rights to confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary data, portability, information about sharing, and to withdraw consent. The legal bases we rely on correspond to those in section 3 (contract, legal obligation, legitimate interests and consent). International transfers rely on standard contractual clauses or other mechanisms the LGPD allows. Contact us at support@spidot.com; you may also complain to the Autoridade Nacional de Proteção de Dados (ANPD).
14Australia
If you are in Australia, we handle your personal information in line with the Privacy Act 1988 and the Australian Privacy Principles. Your information may be disclosed to the overseas providers listed in section 5, mainly in the United States and the EU. You can ask for access or correction at support@spidot.com. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
15Children
Spidot is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, contact us at support@spidot.com and we will delete it.
16Changes to this policy
We may update this policy as our Service or the law changes. We show the date of the latest version at the top of this page. If we make significant changes, we will tell you by email or on the Site before they take effect where the law requires it.
17Contact us
To exercise your rights or ask about this policy, contact Switas Tech Inc., the controller of your personal data.
- Email: support@spidot.com
- Post: Switas Tech Inc., 490 Post Street, Ste 500 PMB 2288, San Francisco, CA 94102, USA
- Contact form: spidot.com/legal/contact
Questions about this page?Contact us