SAIMING's formal legal documents are being prepared. What is shown here is for reference only and is not current policy; the formal versions will be published here.
Privacy Policy
Revision Date: September 9, 2026
SAIMING INC. ("SAIMING," "we," "us," or "our") is a Wyoming corporation with its principal office at 30 N Gould St Ste R, Sheridan, WY 82801, USA. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit saiming.com and its subdomains (the "Website"), create or manage a SAIMING account through the Website, purchase or use Services associated with that account, participate in promotions, or otherwise interact with us through the Website. The SAIMING mobile application has a separate App Privacy Policy addressing App-specific permissions, SDKs, and mobile-device data.
For the purposes of the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and similar laws, SAIMING INC. is the controller of the personal information described in this Privacy Policy. Please read this Privacy Policy carefully. This Policy explains our practices; it is not a request for blanket consent. Where processing requires consent, we request it separately and provide a way to withdraw it.
1. Personal Information We Collect
The personal information we collect depends on how you interact with the Services. It falls into the following categories.
1.1 Information You Provide to Us
Account and identity information: name, email address, phone number, password, country of residence, preferred language, and profile details you choose to add.
Identity verification information: where required by law, regulators, or our connectivity partners for eSIM or phone-number activation in certain destinations, we may collect a copy of a government-issued identification document, your date of birth, nationality, address, and a selfie or other verification data. We collect only what the applicable requirement demands.
Purchase and payment information: details of the plans, Paid Balance top-ups, subscriptions, calls, messages, and other Services you purchase; billing information; transaction identifiers; and limited information about your payment method. Payments are currently processed by Stripe. Full payment-card numbers and card security codes are collected and processed by Stripe or another payment processor we designate; SAIMING generally receives tokenized payment information, payment status, card brand/type, limited card details such as the last four digits and expiry date, and risk or fraud signals.
Communications: the contents of emails, chat messages, support tickets, survey responses, reviews, and other communications you send us, together with associated metadata.
Referral and promotion information: referral codes you use or share, promotional codes you redeem, and the email address or identifier of any person you refer (which you must be authorized to share).
Marketing preferences: your choices about receiving marketing communications.
1.2 Information Collected Automatically When You Use the Services
Device and browser information: browser type and version, device type, operating system and version, language and time-zone settings, IP address, and identifiers needed for Website security, authentication, fraud prevention, checkout, and account management. If you purchase or manage an eSIM or connectivity Service through the Website, we may also process eSIM-related identifiers (such as EID, ICCID, IMSI, or IMEI) to the extent required to provision or support that Service.
Connectivity and usage data: the destinations in which you connect, the network operator used, session start and end times, data volume consumed, plan status, Wallet/Paid Balance status, and diagnostic information about connection quality. This information is generated by or through connectivity partners and is used to deliver, meter, secure, troubleshoot, and bill the Services.
Voice and messaging data: for SAIMING Numbers, we process call detail records and message metadata such as originating and destination numbers, date, time, duration, routing information, sender, recipient, delivery status, and related service events. We do not record ordinary call audio content unless a specific feature expressly provides recording and appropriate notice/consent is obtained. SMS/message content is processed and may be stored as reasonably necessary to transmit, synchronize, display, secure, troubleshoot, or comply with lawful requirements for the messaging service. See Section 6 for the SMS-content deletion and backup safeguards.
Location information: approximate location derived from your IP address and, when you use an eSIM or connectivity Service, from the mobile network through which the Service connects (for example, country or region). The Website does not use browser permissions to continuously track your precise location in the background.
Website log and analytics data: IP address, browser type, referring and exit pages, pages viewed, time spent, clicks, security events, error logs, and Website performance data.
Cookies and similar technologies: as described in Section 5 and in our Cookie Policy.
1.3 Information from Third Parties
Connectivity partners and network operators: provisioning status, network registration events, usage and metering records, and fraud or abuse signals.
Payment processors and fraud-prevention providers: payment confirmation, chargeback notices, and risk scores.
Identity verification providers: verification outcomes.
Marketing and analytics partners: campaign attribution and aggregated audience data.
Referrers: if another user refers you to SAIMING, we receive your contact identifier from them.
We do not ask you to provide information about racial or ethnic origin, political opinions, religious beliefs, health or sexual orientation. Some data described above, including government identifiers and message content, may be sensitive personal information under applicable law. We apply the relevant safeguards and restrictions. Where identity verification involves biometric identification or other special-category data, processing requires an applicable legal basis and any additional consent or safeguard required by law.
2. How We Collect Personal Information
We collect personal information (a) directly from you, when you register, make a purchase, verify your identity, contact support, participate in a promotion, or otherwise communicate with us through the Website; (b) automatically, through your browser or device, the Website, our servers, cookies and similar web technologies, and, where you use connectivity Services associated with your account, the networks of our connectivity partners; and (c) from the third parties described in Section 1.3.
3. How We Use Personal Information
We use personal information for the following purposes and, where the GDPR or UK GDPR applies, on the legal bases indicated.
| Purpose | Examples | Legal Basis (GDPR/UK GDPR) |
|---|---|---|
| Providing the Services | Creating and managing your account; provisioning, activating, and managing eSIM profiles; delivering data connectivity, calls, and messages; metering usage; maintaining your Wallet, Paid Balance, and Promotional Credit ledger | Performance of a contract |
| Processing payments | Charging your payment method; processing top-ups, subscriptions, and auto-reload; issuing receipts | Performance of a contract; legal obligation (tax and accounting) |
| Identity verification | Verifying your identity where required for activation in certain destinations | Legal obligation; performance of a contract |
| Customer support | Responding to your inquiries, troubleshooting connectivity problems, handling complaints | Performance of a contract; legitimate interests |
| Security and fraud prevention | Detecting and preventing fraud, abuse, unauthorized access, spam, and violations of our Terms; protecting our network and partners | Legitimate interests; legal obligation |
| Service communications | Sending purchase confirmations, activation instructions, low-balance and expiry alerts, security notices, and changes to our terms | Performance of a contract; legitimate interests |
| Marketing | Sending newsletters, offers, and promotions by email or SMS where permitted; measuring campaign performance | Consent (where required); legitimate interests |
| Promotions and referrals | Administering referral rewards, promotional codes, and campaigns; preventing abuse | Performance of a contract; legitimate interests |
| Analytics and improvement | Understanding how the Services are used; developing new features, plans, and destinations; testing and improving performance and reliability | Consent where required for device storage/access or optional analytics; otherwise legitimate interests only where an applicable exemption and balancing assessment support it. ATT permission is separate. |
| Personalization | Recommending plans based on your destinations and usage; remembering your preferences | Legitimate interests; consent |
| Legal compliance | Complying with telecommunications, tax, sanctions, and consumer-protection laws; responding to lawful requests from authorities; establishing and defending legal claims | Legal obligation; legitimate interests |
| Business transactions | Evaluating or carrying out a merger, acquisition, financing, or sale of assets | Legitimate interests |
We may also aggregate or de-identify personal information so that it can no longer reasonably be used to identify you. We may use and disclose de-identified information for any purpose, including analytics, network planning, product development, security, and service improvement, and we commit to maintaining it in de-identified form and not attempting to re-identify it, except as permitted by law to test the effectiveness of our de-identification.
4. How We Disclose Personal Information
We disclose personal information to the following categories of recipients, in each case only to the extent necessary for the purposes described above.
Connectivity partners and mobile network operators: the wholesale connectivity providers and local network operators whose networks deliver your eSIM connectivity, calls, and messages. They receive device identifiers, eSIM identifiers, usage records, and, where required, identity information for activation and lawful-interception compliance in the relevant country.
Service providers and processors: companies that perform services on our behalf, including cloud hosting, connectivity and eSIM provisioning, voice and messaging infrastructure, payment processing (currently including Stripe), identity verification where required, customer support, email/SMS/push delivery, security and fraud prevention, analytics or diagnostics, and marketing or attribution services where enabled and lawfully permitted. Their processing is subject to contractual, technical, and legal restrictions appropriate to the service they provide.
Professional advisers: lawyers, accountants, auditors, and insurers, where necessary for the services they provide to us.
Legal and regulatory recipients: courts, law-enforcement agencies, regulators, and other authorities where we believe disclosure is required by law, regulation, subpoena, or legal process; to protect the rights, property, or safety of SAIMING, our users, or others; or to enforce our Terms.
Business transferees: an actual or prospective buyer, investor, successor, or assignee in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business.
With your consent or at your direction: for example, when you ask us to share information with a third party.
We do not sell personal information for money. If advertising, analytics, or attribution technologies enabled on the Website constitute a "sale," "sharing," or "targeted advertising" under an applicable U.S. state privacy law, we provide the opt-out mechanisms required by that law; see Section 10 and saiming.com/privacy-choices.
5. Cookies and Tracking Technologies
We and our service providers use cookies, pixels, local storage, tags, scripts, and similar web technologies on the Website to operate and secure the Website, remember preferences, analyze traffic (Google Analytics), and, where lawfully permitted and, where required, with your consent, measure our advertising campaigns (Google Ads and Meta Pixel). Detailed information about these technologies and available choices is provided in our Cookie Policy. Where applicable law requires us to recognize an opt-out preference signal such as Global Privacy Control (GPC), we treat a valid signal as an opt-out request for the browser or device from which the signal is sent to the extent required by law.
6. Data Retention
Retention depends on whether a category of information was actually generated or collected and on its purpose, not on whether you paid. Account deletion does not mean that every record is immediately physically erased. Information without a continuing lawful purpose is to be deleted; only the minimum information needed for an identified legal, lawful contractual, security, transaction or marketing-suppression purpose may remain, for the applicable period. A contract does not override applicable privacy or erasure rights. The periods below are our retention policy; exceptions must be limited to the relevant records, purpose and necessary period.
Account and profile information: retained as needed to operate your active account. On account deletion, information without a continuing lawful purpose is to be deleted. Any remaining record must be minimized and subject to the relevant category and period below; retaining a limited record does not justify retaining the whole account or rebuilding your profile.
Ordinary transaction ledger records: the standard period is one (1) year from each relevant transaction or billing event. This is not the period for all financial or compliance records. Tax records are retained for the applicable assessment and recordkeeping periods, measured from the legally relevant filing or accounting event. Subscription authorizations and consent evidence are retained separately for the period required by applicable law; for California agreements subject to the relevant automatic-renewal requirements, at least three years or one year after termination, whichever is longer. Records subject to a dispute or legal hold remain restricted for the necessary claim or hold period and are reviewed for deletion when it ends. These categories do not justify retention of an entire deleted profile.
Call detail records, SMS metadata and connectivity records: six (6) months, subject to deletion when no continuing lawful purpose remains and any specifically justified retention requirement. SMS metadata describes a message, such as sender, recipient and timestamp, and is distinct from its content. The deletion policy requires erasure of SMS content from the main and upstream systems following message or account deletion unless a continuing lawful purpose requires limited retention. Any exception must identify its purpose, restricted access and necessary period.
Identity-verification documents and selfies: if never submitted, no submitted document or selfie is held. Verification-session metadata, failed results or security records may nevertheless exist. Retention depends on the actual SIM or number verification process, applicable law and necessary lawful provider obligations, not on payment or account closure. Documents, selfies, verification results and session logs require separate retention criteria; no fixed one-year KYC period is asserted. A selfie used for unique biometric identification requires a separate applicable legal basis and safeguards. Records without a continuing lawful purpose must be deleted.
Support communications: a one (1) year retention period applies where a support interaction actually occurs. If there is no interaction, there is no support record. Account deletion does not by itself eliminate a record still necessary for its documented support or dispute purpose; any exception must be limited to its lawful purpose and necessary period.
Marketing data: direct-marketing use ends when you unsubscribe or withdraw the relevant consent. After account deletion, any minimal email-related identifier retained for marketing suppression is solely to honor your opt-out and prevent marketing to an address that has refused it. It must not be used for login, rebuilding an account or profile, analytics, advertising targeting or renewed marketing. A suppression record is separate from the deleted account and from transaction, tax and compliance records. It is retained only for as long as necessary to honor the refusal, with periodic review; routine cleanup must not remove the protection against renewed marketing.
Security logs: twelve (12) months from the relevant security event or log creation. A specific investigation or legal requirement may justify retaining only the necessary records for its documented period.
Google Analytics data: where actually collected, the retention policy is fourteen (14) months from collection. This period does not authorize collection without any required consent or other applicable basis.
The backup policy requires overwrite within ninety (90) days. Pending overwrite, deleted data in isolated backups must be unavailable for ordinary use and restricted to necessary recovery operations. Before restored systems reopen, deletion and suppression controls must be reapplied so that deleted information does not return to operational use and closed accounts, cancelled subscriptions or disabled Auto-Reload do not reactivate. Online removal, restricted backup retention and final physical erasure are distinct stages.
7. Security
We implement administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These include encryption of data in transit and at rest, access controls and least-privilege principles, network segmentation, logging and monitoring, vendor due diligence, and staff training. Payment card data is handled by PCI DSS-compliant payment processors. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for using a secure device and network.
8. Children's Privacy
The Services are intended for adults and are not directed to children under eighteen (18). We do not knowingly permit a person under 18 to register for a SAIMING account or knowingly collect personal information from a child for the purpose of providing the Services. If you believe a minor has provided us with personal information in violation of this Policy, contact cs@saiming.com and we will take appropriate steps, which may include deletion, subject to applicable legal obligations.
9. International Data Transfers
SAIMING INC. is the U.S. service operator and data controller. Our primary data storage is in the United States. Providing international connectivity also requires processing by service providers and network operators in the countries where their services are delivered. The safeguards and rights below apply to relevant transfers; they do not create another SAIMING contracting entity.
A transfer requiring legal safeguards must not proceed until an applicable mechanism and any required assessment and supplementary measures are in place. Depending on the actual transfer, these may include approved contractual clauses, an applicable adequacy decision or another lawful mechanism. Contact cs@saiming.com for information about the safeguards applicable to your data. These requirements do not establish another SAIMING contracting company.
10. Additional Information for U.S. Residents
This Section supplements the rest of this Privacy Policy for residents of California and other U.S. states that grant comprehensive consumer privacy rights. The specific rights and our obligations vary by state and may depend on statutory applicability thresholds. We will apply the rights required by the law that applies to your request.
10.1 Categories of Personal Information
In the preceding twelve (12) months the categories relevant to the processing described in this Policy include the following categories of personal information as defined by the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"): identifiers (such as name, email, phone number, IP address, device and eSIM identifiers); customer records (such as billing address and payment token); commercial information (purchase history and wallet activity); internet or network activity (Website browsing and connectivity logs); geolocation data (approximate location); audio, electronic, or similar information (support call recordings where notified, message metadata); professional information (if you provide it in communications); inferences drawn from the above (such as plan recommendations); and, only where legally required for verification, sensitive personal information, where processed (government identification numbers, account access credentials, message content where classified as sensitive, and biometric identifiers used for unique identification). The sources, purposes, and recipients for each category are described in Sections 1 through 4. This category description does not mean each category is collected from every user.
10.2 Sale, Sharing, and Targeted Advertising
We do not sell personal information for money. Depending on the technologies actually enabled on the Website, certain analytics, advertising, or marketing activities may be considered a "sale," "sharing," or "targeted advertising" under some U.S. state privacy laws even when no money is exchanged for personal information. Where those laws apply, you may opt out through the applicable Privacy Choices or cookie controls, by using a recognized opt-out preference signal such as Global Privacy Control where required, or by contacting us. We do not knowingly sell or share personal information of individuals under sixteen (16) years of age.
We use sensitive personal information only for the purposes permitted by the CCPA, such as providing the Services and complying with law, and we do not use it to infer characteristics about you.
10.3 Your Rights
Subject to applicable law, you have the right to: (a) know and access the personal information we have collected about you, including the categories and specific pieces, sources, purposes, and recipients; (b) request deletion of your personal information; (c) request correction of inaccurate personal information; (d) opt out of the sale or sharing of personal information and of targeted advertising; (e) limit the use of sensitive personal information; (f) receive a portable copy of your personal information; and (g) not be discriminated against for exercising your rights. We will not deny you goods or services, charge different prices, or provide a different level of quality because you exercised your rights.
10.4 How to Exercise Your Rights
You may exercise applicable privacy rights through saiming.com/privacy-choices, saiming.com/account-deletion, available Website privacy controls, or by emailing cs@saiming.com with the subject line "Privacy Request." We may verify your identity by matching information you provide with our records and may ask you to confirm the request through the email address or other credential associated with your account. Authorized-agent requests will be handled as required by applicable law. We will respond within the time required by the law that applies to your request, and where a state law provides an appeal right, our response will explain how to appeal. We do not require account creation or identity verification for a sale, sharing or targeted-advertising opt-out unless applicable law permits it; verification of access or deletion requests is proportionate to the request. Requests are handled by SAIMING customer support. Identity checks use the account email or matching account records and are limited to what is necessary for the request. To appeal a decision where an appeal right applies, email cs@saiming.com with the subject Privacy Appeal and your request reference. We explain the outcome and available regulator complaint route.
10.5 Notice of Financial Incentive
Our referral campaign offers each eligible participant US$10 in Promotional Credit, usable for at most 50% of an eligible charge and expiring after 90 days. Participation is voluntary; it uses account, referral-attribution and qualifying transaction information to administer the reward and prevent abuse. It does not require consent to advertising tracking. You may leave the program by contacting cs@saiming.com without closing your service account. Where a financial-incentive notice is legally required, the campaign notice supplied before enrollment explains the applicable data categories and valuation method; participation is subject to that notice.
10.6 Customer Proprietary Network Information
To the extent our voice services are subject to U.S. Federal Communications Commission rules on Customer Proprietary Network Information ("CPNI"), we use your CPNI (such as call records and services purchased) only to provide, bill, and support the services you subscribe to, and we will not use it to market unrelated services without your approval.
11. Additional Information for Individuals in the EEA, the United Kingdom, and Switzerland
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the following additional information applies.
11.1 Legal Bases
We process your personal information on the legal bases described in Section 3. Where we rely on legitimate interests, we have assessed that those interests (operating, securing, and improving the Services; preventing fraud; marketing our services) are not overridden by your interests or fundamental rights. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
11.2 Your Rights
You have the right to: (a) access your personal information and receive information about how we process it; (b) rectify inaccurate or incomplete personal information; (c) erase your personal information in certain circumstances; (d) restrict processing in certain circumstances; (e) receive your personal information in a structured, commonly used, machine-readable format and transmit it to another controller (data portability); (f) object to processing based on legitimate interests, and to object at any time to processing for direct marketing; (g) withdraw consent; and (h) not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except as permitted by law. You may exercise these rights by contacting cs@saiming.com. We will respond within one (1) month, which may be extended by two (2) further months for complex requests. You also have the right to lodge a complaint with your local supervisory authority; in the UK, this is the Information Commissioner's Office (ico.org.uk).
11.3 Automated Decision-Making
We use automated fraud-detection systems that may decline a transaction or temporarily restrict an account. If an automated decision significantly affects you, you may request human review by contacting us.
12. Additional Information for Other Jurisdictions
If you are located in a jurisdiction with data-protection laws granting rights similar to those described above (for example, Canada, Brazil, Australia, Singapore, Japan, South Korea, or Hong Kong), you may exercise those rights by contacting us at cs@saiming.com. We will honor requests in accordance with the applicable law.
13. Your Choices
Account information: you can review and update account information through the Website/account controls made available to you or by contacting us.
Marketing emails: click "unsubscribe" in any marketing email or contact us. You will continue to receive service-related communications.
Cookies: manage through our cookie consent banner and your browser settings, as described in our Cookie Policy.
Account deletion: you can initiate an account-deletion request at saiming.com/account-deletion or by contacting cs@saiming.com. We may require reasonable authentication to prevent unauthorized deletion. Deletion may result in loss of access to plans, SAIMING Numbers, Paid Balance, and Promotional Credit and does not itself create a refund right. Records that must be retained for legal, tax, telecommunications, fraud-prevention, chargeback, security, or dispute purposes may be retained for the applicable period. After we verify your identity and you confirm account deletion, SAIMING stops future renewals and Auto-Reload charges that SAIMING manages through Stripe before completing deletion. Amounts already paid remain subject to our Refund Policy and applicable law. We confirm the billing cancellation and account-closure outcome and explain any information that remains, including the SMS-content deletion and backup safeguards in Privacy Policy Section 6. We also stop queued and retry attempts that would create future charges.
14. Third-Party Websites and Services
The Services may contain links to third-party websites and services that we do not operate. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to read the privacy policies of any third-party website or service you visit.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The Revision Date identifies this version of the Privacy Policy. The applicable Effective Date will be stated when the approved Privacy Policy is published or presented to you. If we make material changes, we will provide notice on the Website, through the account interface where appropriate, or by email as required by applicable law.
16. Contact Us
Contact: SAIMING INC., Attn: Privacy, 30 N Gould St Ste R, Sheridan, WY 82801, USA · cs@saiming.com

