Privacy Policy
ThirdSIM · version 2 · effective 18 Sep 2026
ThirdSIM, a company registered in Bangladesh, operates ThirdSIM and is the controller of the personal data described here. Our postal address is our registered address, available on request from support. For anything about this policy, or to exercise a right in it, write to support@thirdsim.com.
This policy explains what we collect, why, how long we keep it, and what you can ask us to do with it. It is written to be read, not to be skimmed past.
What we collect
When you create an account Your name, email address and profile picture as given by Google or Apple when you sign in with them, or your email address if you sign in with a one-time code. A device record for each phone or browser you sign in from: a device name, platform, app version and the time it was last used.
When you verify a phone number The phone number and the fact that it is verified. We store a hash of the one-time code, never the code itself.
When you buy something The order, the plan, the amount, the currency, the payment method and the payment reference our gateway gives us. We never see or store your card number, your bKash or Nagad PIN, or your bank credentials. Those stay with the payment provider.
When you use an eSIM The eSIM’s ICCID, the plan attached to it, its status, and how much data it has used. Usage figures come from our wholesale provider. We do not see the websites you visit, the apps you use or the contents of your traffic — that is between you and the network you are attached to.
When you use a virtual number The number, the messages sent and received on it, call records (who called whom, when, for how long, and the price), and a link to a voicemail recording when a caller leaves one — the recording itself is held by the carrier, not by us. The text of SMS messages is encrypted at rest with AES-GCM, so a copy of the database alone does not reveal message contents.
When you contact support Your ticket, the messages in it, any files you attach, and a snapshot taken when you open it of the eSIM, order, number and device the ticket is about. We snapshot it so an agent does not have to ask you for it and so the thread still makes sense later.
When you use the site or the app Standard technical data: IP address, browser or device type, and the pages or screens you opened. See the Cookie Policy for what the website stores in your browser.
Why we use it, and on what basis
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account | To let you sign in and to keep your purchases together | Performance of our contract with you |
| Deliver eSIMs, numbers, calls and messages | It is the product | Performance of our contract |
| Take payment and keep wallet balances | To charge you and to show what you have | Performance of our contract |
| Send service email and push notifications (order ready, data running out, renewal failed, support reply) | So the product works | Performance of our contract |
| Answer support tickets | To help you | Performance of our contract |
| Detect fraud, abuse of virtual numbers, and duplicate accounts | To protect customers, carriers and us | Our legitimate interests |
| Keep accounting records and respond to lawful requests | Because we must | Legal obligation |
| Send offers and product news | Only if you have not switched it off in notification settings | Consent, withdrawable at any time |
You can switch off data warnings, expiry reminders, message and call alerts, support-reply notifications and offers individually in notification settings. Messages needed to run the service — a receipt, a failed renewal, a security notice — are always sent.
Who we share it with
We share the minimum needed, with:
- eSIM wholesale platforms, to provision and monitor your eSIM: the plan you bought and a reference to the order. Not your name or email.
- Telephony carriers, to allocate your number and to carry your calls and messages.
- Payment gateways, to take payment: the amount, the currency and a reference.
- Email and push delivery providers, to send you notifications.
- Hosting and infrastructure providers, who store the data on our behalf.
We do not sell personal data, and we do not share it for anyone else’s advertising.
Some of these providers are outside Bangladesh, so your data is transferred internationally. We use providers that commit to appropriate safeguards, and we share only what the provider needs for its part of the job.
We disclose data to a court, a regulator or law enforcement where we are legally required to, and we tell you when we are allowed to.
How long we keep it
These are the periods our systems actually enforce, not aspirations.
- Account and profile: while your account is open. Deleting it anonymises the profile (see Your rights).
- Orders, payments and accounting records: at least 6 years after the transaction, because tax and company law require it. This is why deleting your account does not delete your invoices.
- eSIM usage: detailed samples for 90 days, then daily totals only.
- Message contents: 90 days. The encrypted SMS bodies go with them.
- Call detail records (who called whom, when, how long, what it cost): about 13 months, because they are billing records.
- Support tickets and their attachments: kept with your account, so the history is there if you come back. Ask us and we will remove an attachment from a thread.
- Technical logs: vendor webhooks and provider call records for 90 days, application events for 30 days, the email delivery log for 90 days.
- Notification preferences: stored on your account until you change them.
Your rights
You can:
- See what we hold about you, and get a copy.
- Correct anything wrong — most of it you can edit yourself in the app.
- Delete your account. In the app: Account → Delete account (
DELETE /v1/mein our API). Deleting anonymises your profile — your name, email, phone number and profile picture are removed and every session is signed out. Orders and accounting records stay, without your identity attached, because we must keep them. We will refuse a deletion while you still hold wallet credit or an active phone number: spend or transfer the credit and release the number first, so you do not lose either by accident. - Object to processing based on our legitimate interests, and withdraw consent to marketing at any time.
- Ask for a portable copy of the data you gave us.
- Complain to us at support@thirdsim.com, and to your local data-protection authority if you are not satisfied.
We answer rights requests within 30 days. We may ask you to confirm your identity first, so we do not hand your data to someone else.
Children
The service is not for children. We do not knowingly collect data from anyone under 18. If you believe a child has an account, write to support@thirdsim.com and we will remove it.
Security
- Sign-in uses Google, Apple or a one-time email code; we never store a password for a customer account.
- SMS bodies are encrypted at rest with AES-GCM under a key held outside the database.
- Secrets and vendor credentials are encrypted with a key that exists only in the server environment, never in our code repository and never in the database in plain form.
- Access to production data is limited to staff who need it, and administrative actions are recorded in an audit log.
No system is perfectly secure. If a breach affects you, we will tell you and the relevant authority as quickly as we can.
Changes
This page always shows the version in force, with its version number and effective date. We keep every earlier version and will send you any of them if you write to support@thirdsim.com. If a change is significant, we will tell you in the app or by email before it takes effect.
