PRIVACY POLICY

Last Updated: 2026-08-20

1. INTRODUCTION

NEW ACCESS LLC ("Company", "we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use the esimNB website, iOS or Android applications, customer support, and eSIM services (collectively, the "Services").

We process personal data in accordance with applicable privacy laws, including the General Data Protection Regulation (GDPR) where it applies. Where consent is required, we will request it separately; using the Services does not replace any consent required by law.

2. DATA CONTROLLER

NEW ACCESS LLC
30 N Gould St Ste R, Sheridan, WY 82801, United States
Email: hello@esimnb.com

We are the data controller responsible for your personal data processed in connection with our services.

3. INFORMATION WE COLLECT

3.1 Account, Authentication, and Support Information

  • Email address, internal user ID, account status, and account creation or update timestamps
  • Name and profile image when provided by Apple, Google, or by you
  • One-time verification codes and security/session records used to authenticate your account
  • Support messages and information you choose to provide, such as device model, screenshots, error messages, or a phone number used to contact us

3.2 Purchases, eSIMs, Wallet, and Referral Information

  • Order and transaction identifiers, destination or package, amount, currency, status, and refund data
  • eSIM identifiers and service data, including ICCID, installation or activation status, validity, and data-usage status
  • Wallet top-ups, balance, cashback, referral relationships, and related ledger records
  • Payment status and payment-processor customer or transaction identifiers. Stripe or Airwallex processes your payment credentials; we do not store full payment-card numbers or card security codes

3.3 Device, Notification, Usage, and Security Information

  • Push-notification token, platform, and language or locale after you grant notification permission
  • Browser or app version, device and operating-system information, IP-derived approximate region, referring page, pages or features used, and timestamps
  • Diagnostics, security events, and information needed to prevent fraud, abuse, or duplicate payments
  • Our payment and sign-in SDK providers may process device, interaction, or other technical data under their own privacy policies

3.4 Information We Do Not Intentionally Collect

We do not intentionally access your precise GPS location, contacts, photo library, health data, or advertising identifier. We do not sell personal data or use it to track you across apps or websites owned by other companies for advertising.

4. LEGAL BASIS FOR PROCESSING

Under GDPR, we process your personal data based on the following legal grounds:

  • Contract Performance: To provide our eSIM services and fulfill our contractual obligations
  • Legitimate Interest: To operate our business, provide customer support, and improve and secure our services, including fraud prevention and service analytics
  • Consent: For optional notifications, marketing communications, or non-essential cookies where consent is required
  • Legal Obligation: To comply with tax, accounting, consumer-protection, sanctions, law-enforcement, and other applicable requirements

5. HOW WE USE YOUR INFORMATION

5.1 Primary Uses

We use the information described above to:

  • Create, authenticate, secure, and manage your account
  • Process payments, deliver and manage eSIMs, maintain wallet or referral records, and handle refunds
  • Send verification codes, order confirmations, service messages, and notifications you have permitted
  • Respond to support requests and troubleshoot installation, activation, or connectivity issues
  • Operate, analyze, protect, and improve the Services and comply with legal obligations

5.2 Marketing Communications

  • We may send you promotional emails about our services
  • You can opt out of marketing emails at any time using the unsubscribe link
  • Opting out will not affect essential service communications

5.3 Customer Support

  • We record and store customer support communications (email, WhatsApp, contact forms)
  • This helps us provide better support and resolve issues effectively
  • Support records are used solely for customer service purposes

6. DATA SHARING AND THIRD PARTIES

6.1 No Sale or Advertising Tracking

We do not sell or rent your personal information. We do not share personal data for cross-context behavioral advertising. We disclose data only as described below, as directed by you, or as required by law.

6.2 Service Providers

We work with the following categories of service providers who may process your data:

  • Account providers: Apple and Google for sign-in and authentication
  • Payment processors: Stripe and Airwallex for payment processing and fraud prevention
  • eSIM suppliers and mobile networks: To provision, activate, support, and measure usage of the connectivity service you purchase
  • Infrastructure and communications: Cloudflare for hosting and security, Expo for push notification delivery, and Resend for transactional email
  • Analytics: Umami to understand website usage and service performance

These providers receive only information reasonably needed for their services and may independently process some information under their own privacy notices.

6.3 Legal Requirements

We may disclose your information if required by law, court order, or government request, or to protect our legal rights and interests.

7. DATA STORAGE AND SECURITY

7.1 Data Location

  • Your personal data is primarily stored on infrastructure located in the United States
  • Service providers and mobile-network partners may process data in other countries where they operate

7.2 Security Measures

We implement industry-standard security measures including:

  • Encrypted data transmission (SSL/TLS)
  • Secure server infrastructure
  • Access controls and authentication
  • Regular security monitoring and updates
  • Staff training on data protection

7.3 Data Retention

  • Verification codes and session records are retained until they expire or are no longer needed for authentication and security
  • Account, order, eSIM, wallet, referral, and push-token records are retained while your account is active and then deleted or de-identified when no longer needed, subject to the exceptions below
  • Support and security records are retained for as long as reasonably necessary to resolve requests, prevent abuse, and establish or defend legal claims
  • After account deletion, limited transaction, tax, fraud-prevention, or dispute records may be retained for the period required or permitted by applicable law. Our processors may also retain records under their legal obligations

8. YOUR RIGHTS UNDER GDPR

As a data subject, you have the following rights:

8.1 Right of Access

  • You can request information about what personal data we hold about you
  • Contact us to request a copy of your personal data

8.2 Right to Rectification

  • You can request correction of inaccurate or incomplete personal data
  • Contact our support team to update your information

8.3 Right to Erasure (Right to be Forgotten)

  • In the mobile app, open Profile > Delete My Account and confirm the request. You may also contact us using the details below
  • Deletion removes your account, active sessions, push-token association, wallet and referral records, and related service records from our active systems, except information we must or are permitted to retain by law
  • Deleting your account may permanently remove access to unused eSIMs, order history, and wallet balance. Download or use any needed service information before deleting your account

8.4 Right to Restrict Processing

  • You can request that we limit how we use your personal data
  • This may affect our ability to provide services to you

8.5 Right to Data Portability

  • You can request a copy of your data in a machine-readable format
  • This applies to data processed based on consent or contract

8.6 Right to Object

  • You can object to processing based on legitimate interest
  • You can opt out of marketing communications at any time

8.7 Right to Withdraw Consent

  • Where processing is based on consent, you can withdraw it at any time
  • This will not affect the lawfulness of previous processing

9. COOKIES AND TRACKING

9.1 Cookies Policy

  • We use cookies or similar storage needed for authentication, security, language preferences, checkout, and website operation
  • Our service providers may use similar technologies for payment, sign-in, fraud prevention, and analytics
  • We do not use these technologies for cross-context behavioral advertising

9.2 Your Cookie Choices

  • You can control cookies through your browser settings
  • Disabling cookies may affect website functionality
  • You can disable mobile push notifications at any time in your device settings

10. CHILDREN'S PRIVACY

  • Our services are not directed to children under 16 years of age
  • We do not knowingly collect personal information from children under 16
  • If we become aware of such collection, we will delete the information immediately

11. INTERNATIONAL DATA TRANSFERS

  • Your data is primarily stored and processed in the United States and may be processed in countries where our suppliers or network partners operate
  • Where required, international transfers are supported by appropriate safeguards, such as contractual protections or legally recognized transfer mechanisms

12. DATA BREACH NOTIFICATION

  • In the event of a data breach affecting your personal data, we will:
  • Notify relevant authorities within applicable legal deadlines, including 72 hours where required by GDPR
  • Inform affected users if the breach poses a high risk to their rights and freedoms
  • Take immediate steps to contain and remedy the breach

13. CONTACT US AND COMPLAINTS

13.1 Data Protection Contact

For privacy-related questions or to exercise your rights:

Email: hello@esimnb.com
Subject Line: Privacy/Data Protection Inquiry

13.2 Response Time

  • We will respond within the period required by applicable law, generally within 30 days under GDPR
  • Where legally permitted, complex requests may take longer and we will inform you of any extension

13.3 Complaints

  • You have the right to lodge a complaint with a data protection supervisory authority
  • If you are located in the EEA or UK, you may contact your local data protection authority

14. CHANGES TO THIS PRIVACY POLICY

  • We may update this Privacy Policy from time to time
  • Where required, material changes will be notified in the Services or by email
  • The "Last Updated" date at the top indicates when changes were made
  • We will request consent again if a change requires new consent under applicable law

15. THIRD-PARTY LINKS

  • Our website and apps may contain links to third-party websites or services
  • This Privacy Policy does not apply to external sites
  • We are not responsible for the privacy practices of third-party websites
  • We encourage you to read their privacy policies

16. BUSINESS TRANSFERS

  • In the event of a merger, acquisition, or sale of our business
  • Your personal data may be transferred to the new entity
  • You will be notified of any such transfer and your rights regarding your data

Important Note: This Privacy Policy is designed to be transparent about our data practices. We are committed to protecting your privacy and handling your personal data responsibly and in compliance with applicable laws.

apple paygoogle pay