Privacy policy
What we collect, what we never collect, who else sees it and how to get it deleted.
The short version
We collect what it takes to sell you an eSIM and deliver it: your WhatsApp number, your email, your name, what you ordered, and a payment reference from Razorpay. We log your IP address and browser to catch card fraud.
We never ask for your passport, any government ID, or your location. We do not track you around the internet, we do not sell or share your data, and we run no advertising.
Your order goes to our wholesale eSIM supplier so the profile can be issued. Payments go through Razorpay, WhatsApp messages through Flowgento and email through ZeptoMail. Nobody else. Data sits in Mumbai, India.
We keep order records for 8 years because tax law requires it. Ask us to delete your contact details and we will, subject to that. Write to privacy@airzippy.com and you will hear back within 30 days.
1. What we collect
- WhatsApp number — to deliver the eSIM QR and to sign you in with a one-time code.
- Email address — the second delivery channel and the sign-in alternative.
- Name — to address you on the order and in messages. You can leave it blank.
- Order records — which plan, when, how much, which destination, the eSIM assigned to it, and delivery status.
- Razorpay transaction reference — an identifier for the payment. We never receive or store your card number, CVV or UPI PIN; those go straight to Razorpay.
- IP address and user agent — recorded with order and login attempts, for fraud prevention and rate limiting.
2. What we never collect
- No passport or visa details. An eSIM does not need them.
- No government identity documents of any kind.
- No location data. We do not ask the browser for it, and we do not receive location from the mobile network.
- No advertising or cross-site tracking identifiers. There are no third-party analytics, advertising pixels or social widgets on this site.
We also do not see the contents of your internet traffic on the eSIM. That runs over the local carrier's network, not through us.
3. Why we process it
To take your order, issue and deliver the eSIM, let you sign in and re-download your QR, answer support questions, meet Indian tax and accounting obligations, and stop fraudulent payments. That is the whole list.
4. Who it is shared with
- Our wholesale eSIM supplier — receives the order detail needed to issue a profile. Not your full customer record.
- Razorpay — payment processing. Regulated in India; they hold the card data, not us.
- Flowgento — WhatsApp message delivery, so it handles your number and the message content.
- ZeptoMail — transactional email delivery, so it handles your email address and the message content.
Nobody else. We do not sell personal data, we do not share it with advertising networks or data brokers, and we do not pass it to anyone for their own marketing. We will disclose data if compelled by a lawful order from a competent authority, and we will tell you unless we are legally prevented from doing so.
5. Where it is stored
In Mumbai, India, on managed database infrastructure. Backups stay in the same region.
6. How long we keep it
Order records: 8 years. Indian tax law requires books and records to be retained, and an invoice we cannot produce is a problem for both of us.
Contact details: deleted on request, subject to that retention duty. In practice we can remove your name, email and WhatsApp number from your account and unlink them, while the underlying financial record of the sale is kept in the accounts for the statutory period.
Authentication artefacts — one-time codes, session tokens, password reset links — are short-lived and purged automatically.
7. Cookies
We set strictly necessary cookies only: the httpOnly session cookies that keep you signed in after you enter a one-time code. We also use your browser's local storage to remember display preferences such as your chosen currency and language.
There are no analytics, advertising or profiling cookies. That is why you do not see a consent wall on this site — under the ePrivacy rules, strictly necessary cookies do not require consent, and we have nothing else to ask you about.
8. Your rights in India — Digital Personal Data Protection Act, 2023
eMarinersApp is the Data Fiduciary. You are the Data Principal, and you have the right to:
- obtain confirmation of what we process about you and a summary of it;
- have inaccurate or incomplete data corrected, updated or completed;
- have your data erased where it is no longer needed for the purpose it was collected for, subject to the statutory retention above;
- nominate another person to exercise these rights if you die or become incapacitated;
- have a grievance redressed through our grievance procedure, and to escalate to the Data Protection Board of India if we do not resolve it.
9. Your rights in the EU and UK — GDPR
Where the EU or UK GDPR applies to you, eMarinersApp is the controller.
Lawful basis. Processing to take, deliver and support your order is performance of a contract (Article 6(1)(b)). Fraud prevention and rate limiting rest on our legitimate interests (Article 6(1)(f)) in not being defrauded — balanced against you, which is why the logging is limited to IP and user agent and is not used to profile you.
International transfers. Your data is stored in India, which does not have an EU adequacy decision. Transfers are made under the European Commission's Standard Contractual Clauses, with equivalent UK provisions where the UK GDPR applies.
You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your national supervisory authority (in the UK, the Information Commissioner's Office).
10. Your rights in the United States — CCPA / CPRA
If you are a California resident: you have the right to know what personal information we collect and why, to request deletion, to request correction, and not to be discriminated against for exercising those rights.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA as amended by the CPRA. There is therefore no "Do Not Sell or Share My Personal Information" mechanism to offer you — there is nothing to opt out of.
11. How to exercise any of this
Email privacy@airzippy.com from the address on the account, or message the WhatsApp number the order was delivered to, so we can tell it is you. We respond within 30 days. There is no charge.
Who you are dealing with
- Trading name
- eMarinersApp, a sole proprietorship
- Brand
- AirZippy
- Proprietor
- Rajesh Kumar
- Registered address
- Shakti Nagar 1st Lane, Berhampur, Odisha 760001, India
- GSTIN
- 21CIJPP8904K1ZY
- Grievance Officer
- Rajesh Kumar · grievance@airzippy.com
- Privacy
- privacy@airzippy.com
As a sole proprietorship, eMarinersApp has no Corporate Identity Number. The GSTIN above is the registration you can verify on the GST portal.