Privacy Policy
What personal data Carrier Wireless collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
Last updated
Starter template — not legal advice. This policy was supplied with the Carrier Wireless platform as a professionally drafted starting point. It is not legal advice and it has not been reviewed for your jurisdiction, your business model or your suppliers. Every value in [SQUARE BRACKETS] is a fact only you can supply. Have a qualified lawyer review and adapt this page before you trade.
Last updated: [DATE]
1. Who we are
This site is operated by [LEGAL ENTITY NAME] ("we", "us"), registered at [REGISTERED ADDRESS], company number [COMPANY REGISTRATION NUMBER]. We are the data controller for the personal data described in this policy. Contact us about privacy at [PRIVACY CONTACT EMAIL].
2. What we collect
- Order information — your email address, the products you bought, the amount paid, and the country you gave for billing.
- Account information, if you create an account — your name, email address and a hashed password. We never store your password itself.
- Refill details, if you buy a mobile top-up — the destination phone number, which we need in order to perform the service.
- Support correspondence — the messages you send us and our replies.
- Technical data — IP address, browser type and pages visited, collected in server logs for security and troubleshooting.
We do not receive or store your card number, expiry date or security code. Those are entered on the payment provider's own systems.
3. Why we use it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Delivering the product you bought | Performance of a contract |
| Sending order, delivery and refund emails | Performance of a contract |
| Answering support requests | Performance of a contract; legitimate interests |
| Preventing fraud and abuse | Legitimate interests |
| Keeping accounting and tax records | Legal obligation |
| Marketing email, where you have opted in | Consent |
Where we rely on consent you may withdraw it at any time, and every marketing email carries an unsubscribe link.
4. Who we share it with
We share the minimum necessary with the providers that make the service work: payment processors (Stripe, PayPal and our cryptocurrency processor), our email delivery provider, our hosting provider, and — for mobile refills — the carrier or distributor that applies the top-up. Each acts under contract and may only use the data to provide their service to us.
We may also disclose data where the law requires it, or to establish or defend legal claims. We do not sell personal data.
Some of these providers are located outside [YOUR JURISDICTION]. Where data is transferred internationally we rely on [TRANSFER MECHANISM — e.g. Standard Contractual Clauses].
5. How long we keep it
- Order and transaction records: [RETENTION PERIOD — commonly 6 or 7 years], because tax law requires it.
- Account data: until you ask us to delete the account.
- Support correspondence: [RETENTION PERIOD].
- Server logs: [RETENTION PERIOD — commonly 30 to 90 days].
6. Your rights
Depending on where you live you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent. Write to [PRIVACY CONTACT EMAIL] and we will respond within [RESPONSE PERIOD].
If you are unhappy with our response you may complain to [SUPERVISORY AUTHORITY].
7. Security
The site is served over TLS. Passwords are hashed with a modern algorithm and are never recoverable. Sensitive product data — eSIM activation codes, VPN credentials, refill PINs — is encrypted at rest, is excluded from application logs, and is only accessible to staff whose role requires it, with every access recorded in an audit trail.
No system is perfectly secure. If a breach affects your rights we will notify you and the relevant authority as the law requires.
8. Cookies
See our cookie policy for what we set and why.
9. Children
This service is not directed at children under [AGE] and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes
We will post any change to this policy on this page and update the date at the top. Material changes will also be notified by email where we have your address.