PRIVACY POLICY
Effective date: 01 July 2026
Last updated: 21 July 2026
1. INTRODUCTION
New Fin-Tech Information Technology Network Services CO. L.L.C, having its registered address at I RISE TOWER, Al Thanyah First, 22C-14, Dubai, United Arab Emirates (“NEWFINTECH”, “we”, “us” or “our”), operates the esim4trip.net website, user accounts and related eSIM services (collectively, the “Services”).
NEWFINTECH is responsible for determining how and why personal data covered by this Privacy Policy is processed.
This Privacy Policy explains what personal data we collect, why and on what basis we process it, with whom it may be shared, how international transfers are managed, how long personal data is retained, and what rights Users have in relation to their personal data.
We seek to minimise the collection of personal data. We do not intend to collect or store the content of internet traffic, browsing history, communications content or DNS query content transmitted through an eSIM.
This Privacy Policy should be read separately from our Terms of Service. It is a notice explaining our personal data processing practices and does not require the User to consent to every type of processing described below.
2. SCOPE
This Privacy Policy applies to personal data processed when a User:
– visits esim4trip.net;
– creates or uses an account;
– purchases, installs, activates or uses an eSIM or Data Plan;
– contacts customer support;
– subscribes to marketing communications; or
– otherwise interacts with NEWFINTECH or the Services.
Third-party mobile network operators, connectivity providers, payment providers and other service providers may process personal data under their own privacy policies where they act as independent controllers.
3. PERSONAL DATA WE COLLECT
Depending on how the User interacts with the Services, NEWFINTECH may process the following categories of personal data.
3.1 Account and identification data
This may include:
– email address;
– name, where provided or required;
– account identifier;
– country of residence;
– login and authentication information;
– age or confirmation that the User meets the minimum age requirement; and
– identity documents or verification results where verification is legally required or reasonably necessary for fraud prevention.
3.2 Order and transaction data
This may include:
– purchased eSIM and Data Plan;
– order number;
– price, currency, taxes and discounts;
– payment status;
– transaction date and time;
– refund and chargeback information;
– billing information; and
– limited payment information received from the payment provider, such as payment method, card type, token and last four digits.
NEWFINTECH does not normally receive or store complete payment card numbers or card security codes. These are processed by the relevant payment provider.
3.3 eSIM and service-usage data
This may include:
– eSIM identifier and order association;
– activation and installation status;
– activation date and time;
– Data Plan validity period;
– country and network of connection;
– total and remaining data allowance;
– aggregated data consumption;
– Top-Up information;
– service status and relevant network error codes.
We do not intend to collect the content of communications, websites visited, browsing history or DNS query content transmitted through the eSIM.
3.4 Device and technical data
This may include:
– IP address;
– device type and model;
– operating system and platform version;
– browser type and language;
– device settings relevant to eSIM compatibility;
– approximate location derived from IP address or connection country;
– session identifiers;
– login records;
– security and authentication logs; and
– website and application interaction data.
3.5 Support and correspondence data
When the User contacts us, we may process:
– email address and account information;
– support request and message content;
– order details;
– attachments and screenshots;
– technical device information;
– troubleshooting information; and
– dates, times and outcomes of support interactions.
Users should not send unnecessary sensitive personal data through customer support.
3.6 Diagnostic data
Where enabled or consented to when required, we may collect:
– crash reports;
– application or website errors;
– service performance information;
– diagnostic logs; and
– unsuccessful activation information.
Diagnostic data may be linked to a device, session, account or order where this is necessary to identify and resolve a technical problem. Where reasonably possible, diagnostic information will be aggregated, pseudonymised or anonymised.
3.7 Marketing and preference data
This may include:
– marketing consent or opt-out status;
– communication preferences;
– email delivery, opening and interaction information;
– responses to surveys or promotions; and
– advertising and cookie identifiers, where permitted.
4. HOW WE COLLECT PERSONAL DATA
We may collect personal data:
– directly from the User;
– automatically through the website, account or Services;
– from payment processors;
– from Network Partners, eSIM providers, MVNOs, roaming providers and connectivity aggregators;
– from identity-verification and fraud-prevention providers;
– from analytics, advertising and technical service providers; and
– from competent authorities or other parties where permitted or required by law.
5. PURPOSES AND LEGAL GROUNDS FOR PROCESSING
NEWFINTECH processes personal data only where there is an appropriate legal ground under applicable law.
5.1 Providing the Services and performing the contract
We process personal data where necessary to:
– create and administer an account;
– process and confirm orders;
– deliver an eSIM;
– activate and administer a Data Plan;
– provide data usage and balance information;
– process Top-Ups;
– provide technical support;
– process refunds;
– communicate important service information; and
– enforce the Terms of Service.
This processing is necessary to enter into or perform the contract with the User.
5.2 Payments and financial administration
We process transaction and payment-related data to:
– process payments and refunds;
– issue receipts and invoices;
– reconcile transactions;
– maintain accounting records;
– investigate chargebacks; and
– comply with tax and financial obligations.
This processing is necessary to perform the contract and comply with applicable legal obligations.
5.3 Security, fraud prevention and misuse detection
We may process account, transaction, device and technical data to:
– authenticate Users;
– detect unauthorised account access;
– investigate suspected fraud or chargebacks;
– prevent misuse of the Services;
– protect NEWFINTECH, Users, Network Partners and third parties;
– establish, exercise or defend legal claims; and
– comply with sanctions or other applicable restrictions.
This processing is carried out where necessary to protect legal rights, comply with applicable law, perform the contract, or pursue legitimate interests recognised under applicable law.
5.4 Legal and regulatory compliance
We may process and disclose personal data where necessary to:
– comply with applicable laws and regulatory obligations;
– respond to lawful requests from courts, regulators and public authorities;
– maintain tax, accounting and transaction records;
– investigate complaints; and
– establish, exercise or defend legal claims.
5.5 Service analytics and improvement
We may process technical, usage and diagnostic data to:
– monitor service performance;
– identify technical failures;
– improve activation and support procedures;
– understand how the website and Services are used; and
– develop and improve our products.
Where required by law, non-essential analytics will be based on the User’s consent. Otherwise, this processing may be based on NEWFINTECH’s legitimate interests in maintaining and improving its Services, provided those interests do not override the User’s rights.
5.6 Marketing
We may use contact and preference data to send news, promotions and special offers where the User has given consent or where another applicable legal basis permits such communication.
Where consent is required, marketing consent will be requested separately and will not be a condition of purchasing an eSIM.
The User may unsubscribe at any time by using the unsubscribe link in a marketing message, changing available account preferences, or contacting NEWFINTECH.
Withdrawal from marketing does not prevent NEWFINTECH from sending order confirmations, security alerts, support messages or other necessary service communications.
6. AUTOMATED PROCESSING
NEWFINTECH and its service providers may use automated tools to detect payment fraud, suspicious transactions, chargebacks, unauthorised account access or misuse of the Services.
Automated processing may result in an order being held for review, additional verification being requested, or a transaction being temporarily declined.
Where required by applicable law, the User may request information about a significant automated decision, object to it or request human review by contacting NEWFINTECH.
7. SHARING OF PERSONAL DATA
NEWFINTECH does not sell personal data.
We may share personal data, only to the extent reasonably necessary for the relevant purpose, with the following categories of recipients:
7.1 Network and eSIM providers
This includes mobile network operators, MVNOs, roaming providers, eSIM providers and connectivity aggregators involved in delivering and administering an eSIM or Data Plan.
7.2 Payment providers
Payment processors, acquiring banks, card networks and fraud-prevention providers may process payment and transaction data to authorise payments, issue refunds and investigate fraud or chargebacks.
7.3 Hosting and technology providers
We may use providers of website and cloud hosting, email delivery, account authentication, databases and storage, customer support systems, cybersecurity and monitoring, analytics and error reporting.
7.4 Professional advisers
Personal data may be shared with auditors, accountants, insurers, consultants and legal advisers where reasonably necessary.
7.5 Governmental and regulatory authorities
We may disclose personal data where required by law, court order, regulatory requirement or a legally valid request from a competent authority.
7.6 Corporate transactions
If NEWFINTECH is involved in a merger, acquisition, restructuring, financing or sale of assets, relevant personal data may be disclosed subject to appropriate confidentiality and data protection safeguards.
Service providers processing personal data on behalf of NEWFINTECH are required to process it only for authorised purposes and apply appropriate security and confidentiality measures.
8. INTERNATIONAL DATA TRANSFERS
NEWFINTECH operates from the United Arab Emirates. Some Network Partners and service providers may be located in other countries, and personal data may therefore be processed outside the UAE or the User’s country of residence.
Where personal data is transferred internationally, NEWFINTECH will use an applicable transfer mechanism, which may include:
– transfer to a jurisdiction recognised as providing an adequate level of protection;
– contractual obligations requiring the recipient to protect personal data;
– standard contractual clauses or equivalent safeguards;
– transfer necessary to perform the contract with the User;
– transfer necessary to provide a service requested by the User;
– explicit consent where required; or
– another mechanism permitted by applicable law.
Information about applicable safeguards may be requested using the contact details below, subject to legal and confidentiality restrictions.
9. PAYMENTS
Payments are processed through third-party payment providers. Complete payment card details are normally collected directly by the relevant payment provider and are not stored by NEWFINTECH.
Payment providers may process personal data under their own privacy policies and legal obligations, including payment security, anti-fraud, financial reporting and regulatory requirements.
The identity of the applicable payment provider should be displayed during checkout or otherwise made available to the User.
10. COOKIES AND SIMILAR TECHNOLOGIES
We use cookies and similar technologies for operating the website, maintaining user sessions, remembering preferences, securing accounts and payments, measuring website performance, analytics and, where enabled and permitted, advertising.
Strictly necessary cookies may be used without consent where permitted by law because they are required for the website or requested Services to function.
Analytics, advertising and other non-essential cookies will be used only after consent where applicable law requires it. The User may accept, reject or manage non-essential cookies through the cookie preference tool.
We may use services such as Google Analytics and advertising platforms where disclosed in the cookie preference tool. The tool should identify the providers, purposes and relevant cookie durations.
Disabling some cookies may affect website functionality. Withdrawal of cookie consent does not affect processing lawfully carried out before consent was withdrawn.
11. DATA RETENTION
NEWFINTECH retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing Services, complying with legal obligations, resolving disputes and preventing fraud.
Unless a longer period is required or permitted by law, we generally apply the following criteria:
– account data: while the account remains active and for a reasonable period after closure;
– order, payment, invoice and refund records: for the period required by applicable tax, accounting and commercial laws;
– eSIM activation and usage records: for the duration of the Service and a reasonable period needed for support, billing, fraud prevention and dispute resolution;
– support correspondence: for a reasonable period after the request is resolved;
– security and fraud-prevention records: for as long as reasonably necessary to investigate incidents, prevent repeated abuse and defend legal claims;
– marketing data: until consent is withdrawn, the User opts out, or the data is no longer required; and
– cookie and analytics data: according to the periods disclosed through the cookie preference tool.
When personal data is no longer required, it will be deleted, anonymised or securely isolated until deletion is possible.
Account deletion does not require NEWFINTECH to delete information that must be retained for legal, tax, accounting, fraud-prevention, dispute-resolution or regulatory purposes.
12. DATA SECURITY
NEWFINTECH applies appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, destruction or loss.
Depending on the nature and risk of the processing, these measures may include:
– encryption in transit and, where appropriate, at rest;
– access controls and authentication;
– logging and security monitoring;
– network and infrastructure protection;
– personnel confidentiality requirements;
– backups and recovery measures;
– vendor and access reviews; and
– incident response procedures.
Only authorised personnel and service providers with a legitimate need may access personal data.
No method of transmission or storage can guarantee absolute security. Users are responsible for protecting their account credentials and should promptly notify NEWFINTECH of suspected unauthorised access.
Where required by applicable law, NEWFINTECH will notify the competent authority and affected Users of a personal data breach.
13. USER RIGHTS
Subject to applicable law and relevant exceptions, the User may have the right to:
– obtain information about the personal data being processed;
– request access to personal data;
– request correction or completion of inaccurate data;
– request deletion of personal data;
– request restriction or cessation of processing;
– object to direct marketing;
– object to certain automated processing or request human review;
– receive or transfer personal data in a structured and machine-readable format where applicable;
– withdraw consent where processing is based on consent;
– receive information about recipients and international transfer safeguards; and
– submit a complaint to a competent data protection authority.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn. It also does not prevent processing based on a contract, legal obligation or another applicable legal ground.
NEWFINTECH may request reasonable information to verify the identity and authority of a person making a request. A request may be refused or restricted where permitted by law, including where it would adversely affect another person’s rights, interfere with an investigation or conflict with a legal retention obligation.
14. ADDITIONAL INFORMATION FOR USERS IN THE EEA AND UNITED KINGDOM
Where the GDPR or UK GDPR applies, NEWFINTECH processes personal data on one or more of the following legal bases:
– performance of a contract or taking steps requested before entering into a contract;
– compliance with a legal obligation;
– NEWFINTECH’s or a third party’s legitimate interests, where those interests do not override the User’s rights and freedoms;
– consent, where required;
– establishment, exercise or defence of legal claims; or
– another ground permitted by applicable law.
Users in the EEA or United Kingdom may also have the right to object to processing based on legitimate interests and to lodge a complaint with the data protection authority in their country of residence, employment or the place of the alleged infringement.
Where required, international transfers from the EEA or United Kingdom will be protected through adequacy decisions, approved standard contractual clauses or another permitted transfer mechanism.
15. CHILDREN’S PRIVACY
The Services are intended only for Users aged 18 or older. NEWFINTECH does not knowingly offer accounts to or collect personal data directly from children.
If we become aware that personal data has been collected from a child contrary to this requirement, we will take reasonable steps to delete it, unless retention is required by law.
16. THIRD-PARTY LINKS
The website may contain links to websites, applications or services operated by third parties.
NEWFINTECH is not responsible for the privacy practices of independent third parties. Users should review the relevant third party’s privacy policy before providing personal data.
17. CHANGES TO THIS PRIVACY POLICY
NEWFINTECH may update this Privacy Policy to reflect changes in the Services, processing practices or applicable law.
Material changes will be communicated through the website, User account, email or another appropriate channel before they take effect where required by law.
The effective date and last-updated date will be shown at the beginning of this Privacy Policy. Changes will not retroactively authorise materially different processing where new consent or another legal ground is required.
Continued use of the Services does not constitute consent to processing for which applicable law requires separate consent.
18. CONTACT INFORMATION
NEWFINTECH is the controller responsible for the processing described in this Privacy Policy.
Company: New Fin-Tech Information Technology Network Services CO. L.L.C
Registered address: I RISE TOWER, Al Thanyah First, 22C-14, Dubai, United Arab Emirates
Privacy email: privacyesim@esim4trip.net
Website: https://esim4trip.net
Users may contact NEWFINTECH to exercise their rights, ask questions or submit a privacy complaint.
If the User believes that personal data has been processed in violation of applicable law, the User may also submit a complaint to the competent data protection authority, subject to the procedures available in the relevant jurisdiction.