Privacy Policy

What personal data Carrier Wireless collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

Last updated

Starter template — not legal advice. This policy was supplied with the Carrier Wireless platform as a professionally drafted starting point. It is not legal advice and it has not been reviewed for your jurisdiction, your business model or your suppliers. Every value in [SQUARE BRACKETS] is a fact only you can supply. Have a qualified lawyer review and adapt this page before you trade.

Last updated: [DATE]

1. Who we are

This site is operated by [LEGAL ENTITY NAME] ("we", "us"), registered at [REGISTERED ADDRESS], company number [COMPANY REGISTRATION NUMBER]. We are the data controller for the personal data described in this policy. Contact us about privacy at [PRIVACY CONTACT EMAIL].

2. What we collect

  • Order information — your email address, the products you bought, the amount paid, and the country you gave for billing.
  • Account information, if you create an account — your name, email address and a hashed password. We never store your password itself.
  • Refill details, if you buy a mobile top-up — the destination phone number, which we need in order to perform the service.
  • Support correspondence — the messages you send us and our replies.
  • Technical data — IP address, browser type and pages visited, collected in server logs for security and troubleshooting.

We do not receive or store your card number, expiry date or security code. Those are entered on the payment provider's own systems.

3. Why we use it, and on what basis

PurposeLawful basis
Delivering the product you boughtPerformance of a contract
Sending order, delivery and refund emailsPerformance of a contract
Answering support requestsPerformance of a contract; legitimate interests
Preventing fraud and abuseLegitimate interests
Keeping accounting and tax recordsLegal obligation
Marketing email, where you have opted inConsent

Where we rely on consent you may withdraw it at any time, and every marketing email carries an unsubscribe link.

4. Who we share it with

We share the minimum necessary with the providers that make the service work: payment processors (Stripe, PayPal and our cryptocurrency processor), our email delivery provider, our hosting provider, and — for mobile refills — the carrier or distributor that applies the top-up. Each acts under contract and may only use the data to provide their service to us.

We may also disclose data where the law requires it, or to establish or defend legal claims. We do not sell personal data.

Some of these providers are located outside [YOUR JURISDICTION]. Where data is transferred internationally we rely on [TRANSFER MECHANISM — e.g. Standard Contractual Clauses].

5. How long we keep it

  • Order and transaction records: [RETENTION PERIOD — commonly 6 or 7 years], because tax law requires it.
  • Account data: until you ask us to delete the account.
  • Support correspondence: [RETENTION PERIOD].
  • Server logs: [RETENTION PERIOD — commonly 30 to 90 days].

6. Your rights

Depending on where you live you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent. Write to [PRIVACY CONTACT EMAIL] and we will respond within [RESPONSE PERIOD].

If you are unhappy with our response you may complain to [SUPERVISORY AUTHORITY].

7. Security

The site is served over TLS. Passwords are hashed with a modern algorithm and are never recoverable. Sensitive product data — eSIM activation codes, VPN credentials, refill PINs — is encrypted at rest, is excluded from application logs, and is only accessible to staff whose role requires it, with every access recorded in an audit trail.

No system is perfectly secure. If a breach affects your rights we will notify you and the relevant authority as the law requires.

8. Cookies

See our cookie policy for what we set and why.

9. Children

This service is not directed at children under [AGE] and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

10. Changes

We will post any change to this policy on this page and update the date at the top. Material changes will also be notified by email where we have your address.