Privacy Policy

Effective date: 19 September 2026

This policy explains what personal data Xpress-eSIM collects when you use our website (xpressesim.com) or our mobile app, why we collect it, who we share it with, how long we keep it and the rights you have over it. It is written to meet the Nigeria Data Protection Act 2023 (NDPA).

1. Who we are

Xpress-eSIM ("we", "us") is the data controller for the personal data described here. For anything about your data, email support@xpressesim.com with "Privacy" in the subject line.

2. What we collect

Account details you give us:: first and last name, username, email address, mobile number with country code, country, and, if you complete your profile, city, state, postcode and address. Your password is stored only as a one-way hash; we cannot read it.

Orders and payments:: the plans you buy, amounts, currency, payment method, transaction references and payment status. Card details are entered on Flutterwave's checkout and crypto payments are made through NOWPayments; we never receive or store your full card number or card security code. For crypto payments we may record the wallet address and amount involved in the transaction.

Your eSIMs:: the eSIM identifiers our supplier issues for your order (such as the ICCID, serial number and any phone number attached to the plan), the installation QR code, expiry date and status, so you can install, top up and check your eSIM from your dashboard.

Sign-in records:: each time you log in we record your IP address, an approximate location derived from it (city, country and coordinates), your browser and operating system. We use these to secure your account and spot suspicious sign-ins.

Support and messages:: your name, email and whatever you write to us through the contact form, support tickets or the virtual-numbers waitlist, with any attachments you add.

Referrals:: if you joined through another customer's referral link, we record who referred you so any referral reward can be credited.

Mobile app:: if you use the app, a device token that lets us send notifications to that device.

Cookies:: see section 7.

We do not ask for identity documents, and we do not collect sensitive personal data such as health, religious or biometric data.

3. Why we use it, and our legal basis

  • To provide the service you ordered: (performance of a contract): creating your account, taking payment, ordering your eSIM from our supplier, delivering it to your dashboard and email, top-ups, refunds and support.
  • To keep accounts and payments secure: (legitimate interests): sign-in records, fraud and abuse checks, and investigating failed or disputed payments.
  • To meet legal obligations: (legal obligation): keeping transaction records for tax and accounting, and responding to lawful requests from authorities.
  • To send service messages: (performance of a contract): order confirmations, eSIM delivery, password resets and support replies. These are not marketing.
  • To send news or offers: (consent): only if you have agreed, and you can withdraw that consent at any time.

We do not sell your personal data, and we do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

4. Who we share it with

  • eSIM suppliers: the network partners that issue your eSIM (currently Airalo) receive the order details needed to issue and manage it.
  • Payment processors: Flutterwave (card payments) and NOWPayments (crypto payments) process your payment under their own privacy policies.
  • Hosting and email: our hosting provider stores the website and database, and our email delivery provider sends service emails on our behalf.
  • Authorities: where the law requires it, for example a valid court order or a request from a regulator.
  • A buyer of the business: if Xpress-eSIM is sold or merged, your data would pass to the new owner under the same protections.

Service providers may only use your data to provide their service to us, under written terms that require them to keep it secure.

5. Transfers outside Nigeria

Some of these providers process data outside Nigeria. When your data leaves Nigeria we rely on the transfer bases permitted by the NDPA, such as the transfer being necessary to perform your contract with us (for example, ordering an eSIM from a supplier abroad) or appropriate safeguards in our agreements with the recipient.

6. How we protect it

The site is served over HTTPS, passwords are hashed, card data never reaches our servers, and access to customer data is limited to staff who need it. If a personal data breach is likely to put your rights at risk, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it and tell you without undue delay.

7. Cookies

We use cookies that the site needs to work: a session cookie that keeps you signed in, a security cookie that protects forms against cross-site request forgery, and a cookie that remembers your cookie-banner choice. We do not currently use advertising cookies or third-party analytics. If we add them, we will update this policy and ask for your consent first where the law requires it.

8. How long we keep it

  • Account details: while your account is open. When you ask us to delete your account, we delete or anonymise it, except records we must keep by law.
  • Orders, payments and eSIM records: for as long as Nigerian tax and accounting law requires us to keep transaction records.
  • Sign-in records: 12 months.
  • Support tickets and waitlist requests: 24 months after the last message.

9. Your rights

Under the NDPA you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct data that is wrong or incomplete (you can also edit most account details in your profile);
  • delete your data, or restrict how we use it;
  • send your data to you or to another company in a commonly used format;
  • stop using your data for a purpose based on our legitimate interests, or for marketing;
  • withdraw any consent you have given, without affecting what we did before.

Email support@xpressesim.com from the address on your account. We may ask you to confirm your identity, and we will reply within 30 days. If you are unhappy with our answer, you can complain to the Nigeria Data Protection Commission (ndpc.gov.ng).

10. Children

Our service is for people aged 18 or over, or younger users with a parent or guardian's consent, as set out in our Terms of Service. We do not knowingly collect data from children without that consent; if you believe we have, contact us and we will delete it.

11. Changes to this policy

We will post any changes on this page and update the effective date. If a change materially affects how we use your data, we will tell you by email or in your dashboard before it takes effect.