Skip to main content
Halo eSIM
  • Destinations
  • How it works
  • Support
  • Field Notes

Non-GBP prices are estimates. Your final price is confirmed at checkout.

Non-GBP prices are estimates. Your final price is confirmed at checkout.

Back to Legal

Privacy Policy

Last updated: 27 July 2026

Introduction

Halo eSIM Ltd (“Halo”, “we”, “us”) is the data controller for the personal data we collect through haloesim.com. We are registered in England and Wales (company number 15176432) at 86-90 Paul Street, London, EC2A 4NE, United Kingdom, and registered with the UK Information Commissioner’s Office (ICO registration reference ZC112616).

This policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have. We have written it in plain English. If anything is unclear, email legal@haloesim.com and we will explain.

In this policy, “you” and “your” refer to any person who visits our website or buys an eSIM from us.

What data we collect

We collect as little personal data as possible to run the service. The categories are:

Account and order data. Email address, name (if you provide it), and billing country. You give us this at checkout so we can deliver your eSIM and send order-related messages.

Transaction data. Payment confirmation token from Stripe, order history, plan purchased, destination, and order total. Halo never sees your full card number, CVV, or expiry date. Stripe processes your card details directly.

Device and usage data. IP address, browser type, device type, pages visited, timestamps, and referrer. Our analytics run cookieless by default. On the pages where a cookie banner is shown, accepting analytics cookies additionally stores an identifier on your device and enables session recording. See our Cookie Policy for the detail.

Session recordings. Only where you have accepted analytics cookies. A recording is a replay of your visit: the pages you opened, where you clicked, what you scrolled past. Every form field is masked before the recording leaves your browser, so anything you type – your email address, your name – is not captured. Recording is switched off entirely on our checkout pages and on every page of your order portal, whether or not you have accepted analytics cookies. If you have not accepted analytics cookies, no recording is made at all.

eSIM activation metadata. Activation status and the destination country of first network attach. This is operational data returned by our wholesale provider. Halo does not see what you do on the network – we have no access to your browsing activity, messages, or any content data.

Marketing preferences. Your consent status, the timestamp of your consent, and how you gave it (for example, a checkbox at checkout or an email signup form).

Communications. Any emails you send to legal@haloesim.com and our responses, and the messages you exchange with the support chat assistant on our website, including any email address you give it when you open a chat.

Why we process your data (purposes and legal bases)

Purpose Data categories Legal basis
Fulfilling your order and delivering your eSIM Account/order data, transaction data, eSIM activation metadata Performance of a contract (Article 6(1)(b))
Sending transactional emails about your eSIM (delivery, activation, expiry, and a single post-trip invitation to review Halo eSIM) Account/order data Performance of a contract (Article 6(1)(b))
Customer support Account/order data, communications Performance of a contract (Article 6(1)(b))
Fraud prevention and security Transaction data, device and usage data Legitimate interests (Article 6(1)(f))
Service analytics and product improvement Device and usage data Legitimate interests (Article 6(1)(f))
Marketing communications Account/order data, marketing preferences Consent (Article 6(1)(a)), or UK soft opt-in under PECR Regulation 22(3) for existing customers of similar products
Legal compliance including tax and accounting records Account/order data, transaction data Legal obligation (Article 6(1)(c))

Marketing and consent

We treat marketing consent differently depending on where you are, because the rules differ.

UK customers. Under the Privacy and Electronic Communications Regulations 2003 (PECR), we may rely on the “soft opt-in”: if you have bought a similar product from us, we may send you marketing about similar products provided we gave you a clear opportunity to opt out at the point of purchase and we offer that opt-out in every subsequent message.

Australian customers. The Spam Act 2003 (Cth) requires express opt-in consent for all commercial electronic messages. If you are in Australia, we will only send you marketing emails if you have actively opted in. There is no soft opt-in for Australian customers.

How to withdraw consent. You can unsubscribe at any time by clicking the unsubscribe link in any marketing email, or by emailing legal@haloesim.com. Unsubscribing from marketing does not affect transactional emails about your order (for example, your QR code delivery email, activation confirmation, or post-trip review invitation).

Who we share data with

We use a small number of carefully selected processors to run the business. Each is bound by a data processing agreement.

  • Stripe (payment processing and card tokenisation; also receives your email address, IP address, browser user agent, and the consent record captured at checkout) – US and Ireland. Safeguards: Standard Contractual Clauses and the EU-US Data Privacy Framework.
  • Resend (email delivery via mail.haloesim.com; receives your email address and the content of the messages we send you, including your QR code and activation code) – US. Safeguards: Standard Contractual Clauses.
  • PostHog (product analytics) – hosted on PostHog’s EU Cloud. Cookieless by default; stores an identifier on your device and records your session only where you have accepted analytics cookies.
  • eSIM Access (wholesale eSIM provisioning; receives your order reference, the plan you bought, and the ICCID of the eSIM issued to you – not your email address, name, or billing country) – Hong Kong/China region. Safeguards: Standard Contractual Clauses with transfer impact assessment.
  • Anthropic (the AI model behind our support chat assistant; receives the messages you type into the chat, the assistant’s earlier replies in the same conversation, the help-centre content we retrieved for your question, and a random identifier for your browser. It does not receive your email address, your name or your order records unless you type them into the chat yourself) – United States.
  • Cloudflare (hosting, CDN and DDoS protection; also runs the databases that hold your order records, support chat transcripts and contact details, and the Workers AI service that converts your support chat question into a numeric vector so it can be matched against our help-centre index) – global edge network, with UK and EU data residency where available.

We do not sell your personal data to anyone. We do not share your data for third-party marketing purposes. We may disclose data if required by law, court order, or to protect our legal rights.

International transfers

Halo is a UK company. Our primary processing occurs in the UK and EEA.

Where personal data is transferred to the United States (Stripe, Resend), we rely on Standard Contractual Clauses approved under UK GDPR and, where applicable, the EU-US Data Privacy Framework.

Analytics data is sent to PostHog’s EU Cloud, hosted in the European Union.

Support chat messages are sent to Anthropic’s API in the United States. This transfer is covered by Anthropic’s Data Processing Addendum, incorporated into its commercial terms, which applies the EU Standard Contractual Clauses as adapted for the UK by the International Data Transfer Addendum.

Where personal data is transferred to Hong Kong (eSIM Access), we have assessed the transfer under Standard Contractual Clauses with a transfer impact assessment.

You can ask us for more details about any specific transfer by emailing legal@haloesim.com.

How long we keep your data

Data category Retention period Reason
Order records 7 years after last order UK tax and accounting obligations
Financial records 7 years Statutory retention
Email marketing list Until consent is withdrawn Ongoing consent
Analytics data 24 months rolling Product improvement
Support correspondence 3 years after last contact Resolve follow-up queries and demonstrate service quality

When data is no longer needed, we delete or irreversibly anonymise it.

Your rights (UK GDPR)

Under UK GDPR, you have the following rights:

  • Access. You can ask us for a copy of the personal data we hold about you.
  • Rectification. You can ask us to correct inaccurate or incomplete data.
  • Erasure. You can ask us to delete your data where it is no longer needed for the purpose it was collected (“right to be forgotten”).
  • Restriction. You can ask us to restrict processing in certain circumstances, for example while we verify the accuracy of your data.
  • Portability. You can ask us to provide your data in a structured, machine-readable format so you can transfer it to another service.
  • Objection. You can object to processing based on legitimate interests. We will stop unless we have compelling grounds that override your interests.
  • Withdrawal of consent. Where we rely on your consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
  • Automated decision-making. You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Halo does not currently make such decisions.

How to exercise your rights. Email legal@haloesim.com with your request. We will respond within one month. If your request is complex, we may extend this by up to two further months, but we will tell you within the first month.

Right to complain. If you are unhappy with how we have handled your data, you have the right to complain to the UK Information Commissioner’s Office at ico.org.uk or by calling 0303 123 1113. We would appreciate the chance to address your concern first.

Australian customer rights (Privacy Act 1988)

If you are in Australia, you also have rights under the Privacy Act 1988 (Cth):

  • Access (APP 12). You can request access to the personal information we hold about you.
  • Correction (APP 13). You can ask us to correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.

To exercise these rights, email legal@haloesim.com.

If you are not satisfied with our response, you have the right to complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Security

We take the security of your personal data seriously:

  • All data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest where supported by our infrastructure.
  • Our website and API are served through Cloudflare, which provides enterprise-grade infrastructure security, DDoS protection, and edge network security.
  • Card payment data is handled entirely by Stripe, which is PCI-DSS Level 1 certified. Halo never sees or stores your card number.
  • We use access controls and audit logs to limit and monitor access to personal data.
  • We maintain an incident response process to detect, investigate, and report data breaches.

Children

Halo’s service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided personal data to us, please contact legal@haloesim.com and we will delete it.

Changes to this policy

We may update this policy from time to time. Material changes will be notified by email (to opted-in subscribers) or by a notice on our website. The current version and effective date are always shown at the bottom of this page.

Contact

If you have any questions about this policy or your personal data, contact us at:

legal@haloesim.com

Halo eSIM Ltd, 86-90 Paul Street, London, EC2A 4NE, United Kingdom

Version 1.3.0

Effective: 28 July 2026

Last reviewed: 27 July 2026

Halo eSIM

Data? Nata Problem.

Destinations

  • USA
  • Japan
  • Australia
  • Europe
  • View all

Getting started

  • What is an eSIM
  • Device compatibility
  • How it works
  • Installation guide
  • Field Notes

Support

  • Manage my eSIM
  • Troubleshooting
  • Contact us
  • FAQ
Secured by Stripe
VisaMastercardAmerican ExpressApple PayGoogle PayKlarnaRevolut Pay

Halo eSIM Ltd. UK Company No. 15176432. Registered in England and Wales. 86-90 Paul Street, London, EC2A 4NE.

LegalPrivacyAccessibilityAbout
Ask Hal

Hal is an AI assistant and can get things wrong. Check anything important, and see how we use chats.

By chatting, you agree to our Privacy Policy and Terms.

We use cookies

Essential cookies keep the site running. Analytics help us make it better. Nothing is sold on. Cookie policy

Choose your cookies

Essential Always on

Checkout, security, your basket. Can't be switched off.

Analytics

Which pages get used, so we fix the ones that don't.

Marketing

Lets us show Halo ads to people who'd use one.