Data Processing Agreement

Last updated September 2026

This page summarizes how oneSIM processes data on your behalf through the widget integration, and is designed to sit alongside a signed Data Processing Agreement (DPA) for your account. If you need a countersigned DPA for your own compliance records, ask for one through the contact form below — we'll send a version naming both parties.

Roles

For data your travelers give through the widget, you (the tour operator) are the controller: you decide to offer the widget and collect the booking reference it's tied to. oneSIM acts as a processor, handling that data only to issue and support the eSIM, and as an independent controller for the account data of your own dashboard login.

What data this covers

The widget is built to need as little data as possible. For each eSIM issued through your widget, we process: your booking reference, the destination and data amount requested, the trip dates if given, the order and eSIM status, and — for card payments — a Stripe payment reference (never the card number itself). We don't ask the widget for the traveler's name, email or phone number, and we don't record their IP address on these requests.

Why we process it

Solely to provision the eSIM through our network provider, show the QR code, and produce your monthly invoice or statement. We don't use this data for marketing, and we don't sell it.

Sub-processors

We use a small, fixed set of sub-processors: our mobile data network provider (to provision the eSIM), Stripe (for card payments only), and our infrastructure/hosting provider. We'll tell you before adding a new sub-processor that would handle this data.

International transfers

Our sub-processors may process data outside your country. Where that involves a transfer out of the EU/EEA, we rely on the safeguards those providers offer (such as Standard Contractual Clauses) and expect the same from any new sub-processor we add.

Security

Access to the dashboard and API is protected by login credentials and a per-account secret token; API requests are rate-limited, and we don't store card details on our own systems — Stripe handles those directly. We log requests and errors for reliability, with the IP-logging exclusion described above for widget traffic.

Retention and deletion

Order and eSIM records are kept for as long as your account is active, plus any period required for accounting or tax purposes. If your account closes, tell us through the contact form and we'll agree a deletion or export timeline with you.

Your obligations

You're responsible for having a lawful basis to collect and pass through the booking reference and trip details your widget sends us, and for your own privacy notice to travelers covering that.

Get a signed copy

For a DPA naming your company specifically, contact us and we'll send one to countersign alongside your pilot or service agreement.