1. Introduction
This Privacy Policy explains how Configo LTD d.b.a Pelesim ("Pelesim," "we," "us," or "our") collects, uses, shares, transfers, retains, and protects personal information when you use the Pelesim website, applications, customer portal, checkout, eSIM services, and support channels.
By using Pelesim, you acknowledge this policy. If you do not agree, do not use the service. This policy should be read together with our Terms of Service.
2. Information you provide
- Account information, including your email address, name, and authentication method.
- Billing details, including billing country, transaction references, payment status, and limited payment-method details.
- Order information, including destination, plan, price, currency, purchase time, refund status, and invoice details.
- Support information, including messages, attachments, device details, order references, and troubleshooting context.
- Preferences and communications choices that you submit through the service.
We do not store full payment card numbers. Card payments are processed by Stripe or another disclosed payment processor. App marketplace payments are processed by the applicable marketplace.
3. eSIM and service information
To deliver and manage a purchased plan, we may process:
- Provider, order, transaction, and eSIM identifiers, including an ICCID where supplied.
- Installation details such as QR-code URLs, activation codes, and SM-DP+ information.
- Plan status, activation time, expiry time, data allowance, used data, remaining data, and top-up history.
- Coverage, destination, supported network, operator, and fulfillment information.
This information may come from or be shared with the eSIM supplier responsible for fulfilling and operating the plan.
4. Information collected automatically
- IP address, approximate country, browser, device, operating system, app version, and language.
- Session, authentication, security, request, error, performance, and diagnostic logs.
- Pages viewed, navigation, referral source, campaign parameters, entry page, and conversion events.
- Cookies and similar technologies used for sessions, security, attribution, preferences, and analytics, described by category in section 12.
We may receive approximate location from network or CDN headers. We do not need precise GPS location to sell a plan through the website.
When you arrive through a campaign, affiliate, or referral link, the page request may contain information about the source of the visit. We may read that information without placing or reading a non-essential cookie or browser-storage item. If you start checkout or create an account, we may send relevant source information to our server and associate it with the checkout, order, or account so we can measure referral performance and reconcile partner commissions.
5. Information from third parties
We may receive information from:
- Stripe and other payment processors about payments, disputes, refunds, and fraud signals.
- Apple, Google, and other app marketplaces about purchases, receipts, refunds, and account authentication.
- Google or Apple when you choose their sign-in service.
- eSIM suppliers and mobile network partners about fulfillment, installation, activation, coverage, and usage.
- Analytics, hosting, security, email, support, and fraud-prevention providers.
6. Why we use personal information
- Create, authenticate, secure, and maintain your account.
- Process payments, apply taxes, issue invoices, and handle refunds or disputes.
- Fulfill eSIM orders, display installation details, refresh usage, and deliver top-ups.
- Send login codes, receipts, service notices, installation guidance, plan alerts, and support responses.
- Prevent fraud, chargeback abuse, scraping, unauthorized access, and other misuse.
- Attribute signups and purchases to campaign, affiliate, and referral sources and reconcile partner commissions.
- Measure acquisition and service performance, troubleshoot failures, and improve the customer experience.
- Comply with tax, accounting, consumer-protection, sanctions, court, and law-enforcement obligations.
7. Legal bases
Where GDPR, UK GDPR, or similar laws apply, we rely on one or more of the following:
- Contract, to create accounts, process orders, deliver plans, and provide support.
- Legitimate interests, to secure, measure, maintain, and improve the service and prevent fraud.
- Consent, when we ask for it and you choose to give it.
- Legal obligations, including tax, accounting, consumer, sanctions, and lawful-request requirements.
For server-side campaign, affiliate, and referral attribution connected to a signup or purchase, we may rely on legitimate interests in measuring the source of sales and administering partner arrangements. We limit this processing to the attribution needed for that purpose and do not use this fallback for cross-site behavioral profiling, personalized advertising, or retargeting. This basis for server-side attribution is separate from consent required for cookies and similar technologies placed on or read from your device.
8. How we share personal information
We may share only the information reasonably needed with:
- eSIM suppliers and network partners that fulfill, activate, operate, or support your plan.
- Payment processors, app marketplaces, invoicing providers, banks, and fraud-prevention services.
- Cloud hosting, content delivery, analytics, monitoring, email, authentication, and support providers.
- Professional advisers, insurers, auditors, and prospective transaction counterparties under appropriate safeguards.
- Courts, regulators, law enforcement, and other authorities when disclosure is legally required or necessary to protect rights and safety.
We do not sell personal information for money.
9. International data transfers
Pelesim serves travelers globally and uses providers in multiple countries. Personal information may therefore be processed outside your country. International transfers are subject to applicable law and the safeguards available under our service-provider agreements.
10. Data retention and account deletion
We retain personal information for as long as needed to provide the service, maintain security, resolve disputes, enforce agreements, and meet legal, tax, accounting, and fraud-prevention obligations. Retention varies by record type and jurisdiction.
When you delete your account, access is disabled and the account is marked as deleted. Account, order, eSIM, invoice, payment-reference, security, and compliance records may remain linked to an internal account identifier where retention is necessary. Provider-side records may also remain subject to the provider's legal and operational requirements.
11. Your rights and choices
Depending on your location, you may have rights to:
- Access, correct, or receive a copy of your personal information.
- Request deletion, restriction, or objection to certain processing.
- Withdraw consent where processing is based on consent.
- Opt out of marketing communications.
- Complain to your local data-protection authority.
We may verify your identity and may retain information where an exception or legal obligation applies. Submit a request through our support form or email [email protected].
12. Cookies and analytics
Pelesim uses cookies and similar technologies, including local storage and session storage, for account sessions, security, privacy choices, limited preferences, visitor attribution, analytics, and advertising measurement. The categories below describe their purposes and typical retention. A technology may be removed earlier if you clear it, withdraw consent, or the relevant purpose ends.
Strictly necessary. These are required to operate the service and are used regardless of consent, because without them accounts, checkout, and your own privacy choice cannot work. They may include secure session cookies, a marker that helps identify an active session, and a cookie that remembers your privacy choice. They do not contain your account password or payment-card details.
Other browser storage. We may use local storage and session storage for limited operational and measurement purposes, such as remembering a billing-country choice or approximate country, coordinating account state between open tabs, temporarily carrying limited event information through navigation, and preventing duplicate conversion measurement. This storage is not used for the request-based attribution path described below. It does not contain passwords or payment-card details. Measurement-related storage follows the consent rules below. Session storage normally ends with the browser page session; local storage remains until it is cleared, overwritten, or no longer needed.
Analytics. Set only with your consent where consent is required. Analytics technologies help us understand which pages are used and where visitors drop out. Some privacy-focused analytics are designed to work without cookies or cross-site identifiers.
Advertising and attribution. Set only with your consent where consent is required. These technologies may record the campaign, source, referring site, entry page, or ad click that brought you here so we can measure advertising and referral performance. Advertising attribution may be retained for up to 90 days and first-party referral attribution for up to 6 months.
Request-based attribution without device storage. Separately from these technologies, we may read campaign and referral information already present in the request and hold it temporarily in page memory. When you start checkout or create an account, relevant source information may be transmitted to our server and retained with the related checkout, order, or account. This path does not create a device identifier or profile. Temporary checkout context is retained only as long as needed to complete the payment flow; completed order and account records follow the retention rules in section 10.
Your choice. If you are in the European Economic Area, the United Kingdom, or Switzerland, analytics and advertising technologies are blocked until you accept them, and we ask through a banner on your first visit. Elsewhere they are set by default and you can block them in your browser. Choosing Reject stops consent-gated technologies from being used for those purposes. To change your mind later, clear cookies and site data for this site in your browser and the choice will be offered again. Blocking strictly necessary cookies or storage may prevent account or checkout features from working.
Where consent applies, we record and communicate your choice to relevant measurement and advertising providers so they respect it. Rejecting does not affect your ability to browse, buy, or use an eSIM. Rejecting or withdrawing consent does not by itself erase a server-side attribution record already associated with a signup or purchase. You may still exercise applicable access, deletion, restriction, or objection rights under section 11.
13. Children
Pelesim is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided personal information, contact us so we can review and remove it where required.
14. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including encrypted transport, access controls, authentication controls, logging, and service-provider security measures. No online service is completely secure, so we cannot guarantee absolute security.
15. Third-party links and services
Pelesim may link to third-party websites, app marketplaces, mobile networks, or payment pages. Their privacy practices are governed by their own policies, and we are not responsible for services we do not control.
16. Changes to this policy
We may update this policy to reflect service, provider, legal, or security changes. The revised date will appear at the top of the page. Where required by law, we will provide additional notice.
17. Contact
Data controller: Configo LTD d.b.a Pelesim. Address: 16 Helkikei HaOr, Beersheba, Israel. Email: [email protected]. You can also contact us through our support form.