Travel eSIM

Data protection statement

Data Processing Agreement

PostFinance Travel eSIM Privacy Policy

Mindszi Technologies Ltd is the company behind this service. eSIM Copilot is our brand. We are registered in England and Wales, company number 15524190, at 128 City Road, London EC1V 2NX, United Kingdom.

Last updated: 29 September 2026

1. Who we are and what this policy covers

PostFinance Travel eSIM, powered by eSIM Copilot, is a travel eSIM service provided by Mindszi Technologies Ltd, trading as eSIM Copilot ("eSIM Copilot", "we", "us", "our").

This Policy describes the information we collect from you, or that you provide ("Personal Information"), on the PostFinance Travel eSIM website and through our WhatsApp service, together with any related products and services ("Services"). It also describes how we use, keep, protect and disclose that information, and the choices you have.

We are the controller of that Personal Information. We decide how and why it is used, and we are responsible for it under the Swiss Federal Act on Data Protection (FADP) and, because we are based in the UK, the UK GDPR and the Data Protection Act 2018.

The PostFinance name and brand are used with permission. PostFinance AG does not sell you the eSIM and is not the controller of the information described here. PostFinance handles the information it already holds about you under its own privacy policy.

We supply your mobile connection ourselves, working with partner mobile networks in the countries you visit.

This Policy does not apply to the practices of companies we do not own or control.

2. Information we collect

Collected automatically. When you open the website, our servers record information your browser or device sends. This includes your IP address, browser and device type and version, operating system, language preference, the page you came from, the pages you visit, time spent on them, what you search for, and access times and dates. We use this information to detect abuse and to understand how the Services are used.

Information you give us. You may browse the website without identifying yourself. To buy an eSIM you will be asked for:

  • Account details, such as user name, user ID and password
  • Contact details, such as your email address and phone number
  • Basic personal details, such as name, country of residence and preferred language
  • Payment details, which go directly to our payment provider (see section 4)

Information about your eSIM and connection. To deliver and support the service we hold your eSIM identifiers (EID and ICCID), the status of your eSIM, the plans you have bought, how much data you have used, and the countries and networks your eSIM connects to. In some cases we also hold your device make and model, in order to confirm compatibility and to assist with support requests. Most of this comes from the partner networks that carry your connection.

Support and chat. We keep your messages with our AI assistant and our support team, and any feedback you send us. If you contact us on WhatsApp, your messages also pass through WhatsApp.

We do not have access to the content of your internet traffic, such as the websites you visit or the messages you send. We do not collect your precise location through this service.

If you do not provide this information, we will not be able to supply you with an eSIM. If you are unsure which details are required, please contact us.

3. How we use your information

We use your Personal Information to:

  • create and manage your account
  • fulfil and manage your orders
  • deliver your eSIM, activate it and show your data balance
  • send service messages, such as order confirmations, activation steps, low balance and expiry alerts
  • answer your questions and provide support
  • improve our products and services
  • protect against abuse, fraud and misuse
  • meet our legal, tax and accounting obligations
  • send marketing, where you have agreed to it

The legal bases below apply under the UK GDPR. Under Swiss law we process your information for the purposes set out in this Policy and no others.

PurposeLegal basis (UK GDPR)
Selling, delivering and supporting your eSIM, and running your accountPerformance of our contract with you
Fraud prevention, security and service improvementOur legitimate interests in protecting and improving the service
Tax, accounting and responding to lawful requestsLegal obligation
Analytics cookies and marketingYour consent

Our AI assistant. Support chat is answered first by an AI assistant, which uses your messages and your order and eSIM details to answer you. You can ask for a person at any time and we will pass your request to our support team, which is available Monday to Friday during European business hours. Requests received outside those hours are handled on the next business day. The assistant runs on Amazon Bedrock, inside our private AWS account in the EU. The companies whose models we use do not receive your messages, and your messages are not used to train any model. Please do not include card numbers or passwords in chat messages.

Automated decisions. Payments are screened for fraud by Stripe, using Stripe Radar, and may be declined automatically. If your payment is declined, you may contact us to request human review of the decision and to submit any information you consider relevant. We do not otherwise take decisions about you based solely on automated processing that produce legal effects concerning you or otherwise significantly affect you.

We will not use your Personal Information for a new purpose that is not compatible with those above without telling you first.

4. Payment processing

You can pay by credit or debit card, Apple Pay or Google Pay. TWINT may also be available. Your payment details go directly to our payment provider, Stripe, which processes payments on our behalf. We do not receive or store your full card number. We receive limited details such as card type and the last four digits, and the reference for your transaction.

Stripe is certified to PCI DSS Level 1, the standard set by the PCI Security Standards Council. Payment details are exchanged over an encrypted connection.

Stripe may collect information from you directly to process your payment, such as your email address, billing address and card details. Its use of that information is governed by its own privacy policy, which we suggest you read.

We share payment data with Stripe only as far as needed to take payments, make refunds, and deal with complaints and queries about them.

5. Who we share your information with

We share your Personal Information only with the organisations below, and each receives only the data it needs for its role. They act on our instructions and may not use that data for their own purposes. Stripe and the mobile networks also act for their own legal duties, such as fraud prevention and telecoms law, under their own privacy policies.

WhoTheir roleWhat they receiveRegion
Partner mobile networksCarry your connection in the countries you visitNetwork identifiers for your eSIM, such as the IMSI, and records of your connection and data use. They do not receive your name, contact details or payment detailsThe countries you visit
PostFinanceNamed and designated staff use our reseller portalAccount and order records for this serviceSwitzerland
AWSHosts the platformPersonal Information held in the platform, stored in encrypted databases and encrypted storage. AWS does not access itEU
AWS (Amazon Bedrock)Runs our AI assistant, inside our private AWS accountYour chat messages, with the order and eSIM details needed to answer them. The companies whose models we use do not receive your messagesEU
Auth0Manages account loginYour login email address and authentication dataEU
StripeProcesses paymentsYour payment details, email address and billing countryUK and EU
SendGridSends our emailsYour name, email address and the content of those emailsEU
TwilioSends SMS and WhatsApp messagesYour phone number and the content of those messagesUK and EU
DatadogCollects technical logsLog data, which can include identifiers such as your IP address and user IDEU
PostHogProduct analyticsUsage events with device and browser data and an analytics identifierEU
Google AnalyticsWebsite analyticsUsage events with device and browser data and an analytics identifierEU and US

We also disclose Personal Information where the law requires it, for example to comply with a court order or a request from a regulator or the police, and where we believe in good faith that disclosure is needed to protect our rights, your safety or the safety of others, or to investigate fraud.

If our business is sold, merged or restructured, your account and Personal Information will be among the assets transferred, under confidentiality.

We will never sell your Personal Information.

6. Transfer of information

Your Personal Information is stored at rest in the EU. It is also accessed and processed in the countries below.

Country or regionWhySafeguard
United KingdomOur team, which administers and supports the serviceSwitzerland recognises the UK as providing adequate protection
European Union and EEAHosting, connectivity, login, analytics and emailSwitzerland and the UK recognise these countries as providing adequate protection
United StatesPayment processing and website analyticsThe Swiss-US Data Privacy Framework and its UK Extension where the provider is certified, otherwise standard contractual clauses recognised by the FDPIC, and the UK International Data Transfer Addendum
The countries you visitLocal networks carry your connection thereNecessary to perform our contract with you (Article 17 FADP, Article 49 UK GDPR)

You can ask us for a copy of the safeguards we use, using the details in section 10.

7. Storage, retention and managing your information

Storage. We store Personal Information on secure servers run by our hosting providers. Access is limited to authorised staff and protected by industry-standard controls.

Managing your information. You can delete certain details from the settings page of your account, or ask us to delete your account.

Retention. We keep Personal Information only as long as we need it for the purposes set out in this Policy, and for as long as applicable law requires, for example for tax and accounting records. After that we delete it, or anonymise it so it no longer identifies you. You can ask us to delete your account and its data sooner.

8. Cookies, analytics and messages

Cookies. We use cookies and similar technologies on the website.

  • Essential cookies log you in, keep your basket, take payment securely and help prevent fraud, including Stripe's fraud prevention cookies. They are always on.
  • Analytics cookies show us how the Services are used. We set them only if you accept them, and you can change your choice at any time in the cookie settings.

You can also set your browser to refuse cookies. Parts of the Services may not function correctly if you do so. We do not use advertising cookies.

Analytics. We use PostHog and Google Analytics to produce reports on how often the Services are visited, which pages are used and for how long. We use these reports to improve the Services.

Email marketing. We only send marketing about PostFinance Travel eSIM if you have agreed to it. Every marketing email carries an unsubscribe link, and you can also opt out in your account settings or by contacting us. You will still receive service emails about your orders and your eSIM.

Marketing by PostFinance. At checkout you can choose to let us pass your name and email address to PostFinance so that it can send you marketing. This is optional and applies only if you select it. PostFinance is then responsible for that data under its own privacy statement. You may withdraw your consent at any time.

Do Not Track. Browsers send Do Not Track signals in different ways and there is no agreed standard, so the Services are not set up to respond to them. We limit how we collect and use your information as described in this Policy.

9. Your rights

If you are in Switzerland. Under the FADP you have the right to:

  • ask whether we process information about you and receive a copy of it
  • have inaccurate information corrected
  • have information deleted, or its processing restricted, where the conditions in the law are met
  • object to the processing of your information
  • receive information you gave us in a common electronic format, or have it sent to another provider
  • ask for a person to review a decision taken solely by automated means (see section 3)

If you are in the EU, the EEA or the UK. Under the GDPR and the UK GDPR you have the rights above, and you may also withdraw your consent at any time where we rely on it. Withdrawal does not affect processing carried out before you withdrew.

How to exercise your rights. Contact us using the details in section 10. We may ask you to verify your identity, or the authority of anyone making a request for you, before we respond. Please provide sufficient detail for us to identify and process the request. We aim to respond within 30 days.

Complaints. Please contact us first so that we can resolve the matter. You can also contact:

  • in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch
  • in the UK, the Information Commissioner's Office (ICO): ico.org.uk
  • in the EU or EEA, your local data protection authority

10. Security, children, changes and contact

Information security. We apply commercially reasonable, industry-recognised measures to protect your information, including encryption in transit and at rest, access controls limiting who can reach personal data, regular security assessments, and physical security at our data centre providers. No system can be guaranteed secure. If you believe that your interaction with us is no longer secure, please notify us immediately using the details below.

Data breach. If we learn that Personal Information has been exposed, we will investigate, report and cooperate with the authorities as required. We will notify the FDPIC and the ICO where the law requires, and we will inform you where the breach is likely to result in a high risk to you.

Children. The Services are for people aged 18 and over. We do not knowingly collect information from children. If you believe that a child has provided us with information, please contact us and we will delete it.

Links to other sites. The Services link to sites we do not control, including PostFinance's own sites. We are not responsible for their privacy practices, so please read their privacy notices.

Changes to this policy. We may change this Policy at any time. We will post the new version with a new date and, where the change is material, notify you by email before it takes effect.

Contact us.

ControllerMindszi Technologies Ltd, trading as eSIM Copilot, 128 City Road, London EC1V 2NX, United Kingdom
Company number15524190
Privacy questions and data requestsprivacy@mindszi.com
Data Protection OfficerMichael Moorfield
Customer supportChat on the PostFinance Travel eSIM website, WhatsApp, or hello@esimcopilot.com

We will seek to resolve any complaint or dispute, and to give effect to your rights, as promptly as possible and within the time limits set by data protection law.