Draft for review — this document has not been reviewed by a lawyer and is not yet in effect.
1. Who we are
Esender LLC (“Esender”, “we”, “us” or “our”) is a limited liability company registered in [State of registration], United States, with its registered address at [Registered address]. We make Esender Chat and Esender eSIM, and we are developing Esender VPN and Esender Wallet. All four apps use a single Esender account.
For the purposes of data protection laws such as the EU and UK General Data Protection Regulation (GDPR), Esender LLC is the controller of the personal information described in this policy, unless we say otherwise. [EU/UK representative, if required — to be confirmed.]
2. Scope of this policy
This policy applies when you:
- create or use an Esender account;
- use Esender Chat, Esender eSIM, or — once they are available — Esender VPN or Esender Wallet (together, the “Services”);
- visit esender.com, esim.esender.com or this website; or
- contact us, join an early-access list or subscribe to product news.
Some Services may have additional privacy notices that explain product-specific details. Where they do, those notices form part of this policy. Esender VPN and Esender Wallet are not yet available; we will update this policy before either launches.
3. Information we collect
We collect information you give us, information created when you use the Services, and a limited amount of information from third parties such as payment processors.
Your Esender account
- Account details — such as your name, email address, [phone number, if used for sign-up — to be confirmed] and password or other sign-in credentials.
- Profile information — such as a display name and profile photo that you choose to add.
- Support and communications — messages you send us, the contents of support requests, and your communication preferences.
Esender Chat
- Content you send — text messages, voice notes, photos, files, stories and call signalling needed to deliver your messages and calls to the people you choose. [Describe how message content is stored, for how long, and whether it is encrypted — to be confirmed by engineering before publication.]
- Contacts — if you allow access, phone numbers or identifiers from your address book so you can find people you know on Esender Chat. [Confirm whether contact data is uploaded, hashed or processed on-device.]
- Groups and communities — the groups and communities you create or join, their names, members and your role in them.
- Usage and technical information — such as app version, device type, operating system, language, crash reports and push-notification tokens needed to deliver notifications.
- Reports — if you or another user reports a conversation or account, the information included in that report.
Esender eSIM
- Purchase information — the destination and plan you buy, the price, date and order reference.
- Payment information — payments are processed by our payment processors. We receive confirmation of payment and limited details such as the payment method type and [last four digits / card country — to be confirmed]. [Confirm that Esender does not receive or store full card numbers.]
- eSIM and device information — technical identifiers needed to provision and manage your eSIM, such as the eSIM profile identifier and [device EID — to be confirmed], and your device model to check compatibility.
- Data usage and connection information — the amount of data used on your plan, plan status and, from our network partners, limited technical connection records such as the network and country you connect in. [Confirm exact records received from network partners, and whether any browsing content or destinations are visible to Esender.]
Esender VPN (when available)
Esender VPN is in development. Before it launches we will describe here exactly what information the service processes, including any connection records. [VPN logging practices to be defined and confirmed before launch.]
Esender Wallet (when available)
Esender Wallet is in development. Financial services are regulated, and when Wallet launches we or our regulated partners may need to collect additional information — for example to verify your identity, meet anti-money-laundering obligations and process transactions. We will update this policy with full details before launch. [Wallet data practices and partner roles to be confirmed.]
Website and early access
- Forms — when you use a contact, newsletter or early-access form, the information you enter (such as your name, email address, company and message).
- Technical information — such as your IP address, browser type and the pages you visit, collected by our hosting provider and the services described in Cookies and similar technologies.
4. How we use information
We use personal information to:
- Provide the Services — create and secure your account, deliver messages and calls, provision and support eSIM plans, and show your plans and usage in the app.
- Process payments — take payment for plans, prevent fraudulent transactions and handle refunds.
- Support you — respond to requests, troubleshoot problems and send service messages such as purchase confirmations and security alerts.
- Keep Esender safe — detect, investigate and prevent spam, abuse, fraud, security incidents and violations of our terms.
- Improve the Services — understand how features perform, fix bugs and plan new features, using aggregated or de-identified information wherever practical.
- Communicate with you — send product news or early-access updates when you have asked for them. You can unsubscribe at any time.
- Meet legal obligations — keep records required by tax, accounting and telecommunications laws, and respond to lawful requests.
We do not sell your personal information, and we do not show ads inside your conversations. [Confirm no targeted advertising or data brokerage across all Services.]
5. Legal bases and consent
If you are in the European Economic Area, the United Kingdom or another place with similar laws, we rely on the following legal bases:
- Contract — to provide the Services you sign up for, including delivering messages and provisioning eSIM plans.
- Legitimate interests — to keep the Services secure, prevent fraud and abuse, and improve our products, where these interests are not overridden by your rights.
- Consent — for optional features such as contact access, marketing emails and non-essential cookies. You can withdraw consent at any time without affecting processing that happened before.
- Legal obligation — where the law requires us to process or keep information.
Device permissions such as contacts, microphone, camera and notifications are always under your control in your phone's settings.
6. How we share information
We share personal information only as described below:
- Other users — Esender Chat shares your messages, profile information and stories with the people and groups you choose.
- Payment processors — to take and refund payments, including card and Apple Pay transactions. They process your payment details under their own terms and privacy policies.
- eSIM network partners — mobile network operators and eSIM platform providers that provision your eSIM and carry your data connection. They receive the technical information needed to activate and run your plan.
- Service providers — companies that host our infrastructure, send email and push notifications, provide customer support tools, and help us detect fraud and crashes. They may use personal information only to provide services to us.
- Legal and safety — where we believe in good faith that disclosure is required by law or legal process, or is necessary to protect the rights, property or safety of Esender, our users or the public.
- Business transfers — if Esender is involved in a merger, acquisition or sale of assets, personal information may be transferred as part of that transaction, subject to this policy.
[Maintain an internal list of service providers and sub-processors; consider publishing it.]
7. International transfers
Esender is based in the United States, and our service providers and network partners operate in many countries — which is necessary to provide travel data in the places you visit. Your information may therefore be processed outside the country where you live. When we transfer personal information out of the EEA, the UK or Switzerland, we use safeguards recognised by those laws, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. [Confirm transfer mechanisms.]
8. How long we keep information
We keep personal information for as long as we need it for the purposes described in this policy:
- Account information — while your account is open, and for [period] after you close it to handle any final requests or disputes.
- Chat content — [retention of messages, media and backups to be confirmed].
- eSIM purchase and billing records — for [period], as required by tax and accounting laws.
- Support requests — for [period] after the request is resolved.
- Website and early-access form submissions — until you unsubscribe or ask us to delete them.
When we no longer need information, we delete or de-identify it.
9. Security
We use administrative, technical and physical measures designed to protect personal information against loss, misuse and unauthorised access, and we limit access to staff and service providers who need it. [Describe specific safeguards once confirmed.] No system is completely secure, so please protect your account by using a strong, unique password and keeping your phone's software up to date. If you find a security issue, please report it through our security page.
10. Your rights and choices
Wherever you live, you can:
- update profile and account details in the apps;
- change device permissions in your phone's settings;
- unsubscribe from marketing emails using the link in each email; and
- ask us to access, correct or delete your personal information, or to close your account, by contacting us.
We will verify your request before acting on it, usually by confirming it from the email address on your account. Some information may need to be kept after a deletion request — for example, billing records we are legally required to keep.
EEA and UK residents
Under the GDPR and UK GDPR you have the right to access, correct, delete and receive a portable copy of your personal information; to restrict or object to certain processing, including processing based on legitimate interests; and to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority, such as the supervisory authority in your EU country or the UK Information Commissioner's Office. We would appreciate the chance to address your concern first.
California residents
If you live in California, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), gives you the right to know what personal information we collect, use and disclose; to request deletion and correction; to opt out of the “sale” or “sharing” of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioural advertising. [Confirm and add the CCPA categories disclosure table.] You may use an authorised agent to make a request on your behalf.
Other US states
Residents of other US states with consumer privacy laws may have similar rights, including the right to appeal a decision about their request. Contact us to exercise them.
11. Children
The Services are not directed to children under [13 / 16 — minimum age to be confirmed per country], and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
12. Cookies and similar technologies
Cookies are small files stored by your browser. Similar technologies include local storage and software development kits (SDKs) inside apps.
- Strictly necessary — used to make the website and apps work, for example to keep you signed in or remember your settings. These cannot be switched off.
- Web fonts — this website loads fonts from a third-party font service, which receives your IP address and browser information when a page loads.
- Analytics — [confirm whether the website or apps use analytics tools; if so, name the category and give an opt-out].
We do not use advertising cookies on this website. [Confirm before publication.] You can block or delete cookies in your browser settings; some features may not work without strictly necessary cookies. Where the law requires consent for non-essential cookies, we will ask for it first.
13. Changes to this policy
We may update this policy as our Services change — for example, before Esender VPN or Esender Wallet launches. We will change the “Last updated” date above and, for material changes, notify you in the apps or by email before they take effect.
14. Contact us
For privacy questions or to exercise your rights, contact:
Esender LLC
[Registered address]
Contact: support request form (choose "Privacy or data request")
You can also use our contact form.