PostFinance Travel eSIM Privacy Policy
Mindszi Technologies Ltd is the company behind this service. eSIM Copilot is our brand. We are registered in England and Wales, company number 15524190, at 128 City Road, London EC1V 2NX, United Kingdom.
Last updated: 29 September 2026
1. Who we are and what this policy covers
PostFinance Travel eSIM, powered by eSIM Copilot, is a travel eSIM service provided by Mindszi Technologies Ltd, trading as eSIM Copilot ("eSIM Copilot", "we", "us", "our").
This Policy describes the information we collect from you, or that you provide ("Personal Information"), on the PostFinance Travel eSIM website and through our WhatsApp service, together with any related products and services ("Services"). It also describes how we use, keep, protect and disclose that information, and the choices you have.
We are the controller of that Personal Information. We decide how and why it is used, and we are responsible for it under the Swiss Federal Act on Data Protection (FADP) and, because we are based in the UK, the UK GDPR and the Data Protection Act 2018.
The PostFinance name and brand are used with permission. PostFinance AG does not sell you the eSIM and is not the controller of the information described here. PostFinance handles the information it already holds about you under its own privacy policy.
We supply your mobile connection ourselves, working with partner mobile networks in the countries you visit.
This Policy does not apply to the practices of companies we do not own or control.
2. Information we collect
Collected automatically. When you open the website, our servers record information your browser or device sends. This includes your IP address, browser and device type and version, operating system, language preference, the page you came from, the pages you visit, time spent on them, what you search for, and access times and dates. We use this information to detect abuse and to understand how the Services are used.
Information you give us. You may browse the website without identifying yourself. To buy an eSIM you will be asked for:
- Account details, such as user name, user ID and password
- Contact details, such as your email address and phone number
- Basic personal details, such as name, country of residence and preferred language
- Payment details, which go directly to our payment provider (see section 4)
Information about your eSIM and connection. To deliver and support the service we hold your eSIM identifiers (EID and ICCID), the status of your eSIM, the plans you have bought, how much data you have used, and the countries and networks your eSIM connects to. In some cases we also hold your device make and model, in order to confirm compatibility and to assist with support requests. Most of this comes from the partner networks that carry your connection.
Support and chat. We keep your messages with our AI assistant and our support team, and any feedback you send us. If you contact us on WhatsApp, your messages also pass through WhatsApp.
We do not have access to the content of your internet traffic, such as the websites you visit or the messages you send. We do not collect your precise location through this service.
If you do not provide this information, we will not be able to supply you with an eSIM. If you are unsure which details are required, please contact us.
3. How we use your information
We use your Personal Information to:
- create and manage your account
- fulfil and manage your orders
- deliver your eSIM, activate it and show your data balance
- send service messages, such as order confirmations, activation steps, low balance and expiry alerts
- answer your questions and provide support
- improve our products and services
- protect against abuse, fraud and misuse
- meet our legal, tax and accounting obligations
- send marketing, where you have agreed to it
The legal bases below apply under the UK GDPR. Under Swiss law we process your information for the purposes set out in this Policy and no others.
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Selling, delivering and supporting your eSIM, and running your account | Performance of our contract with you |
| Fraud prevention, security and service improvement | Our legitimate interests in protecting and improving the service |
| Tax, accounting and responding to lawful requests | Legal obligation |
| Analytics cookies and marketing | Your consent |
Our AI assistant. Support chat is answered first by an AI assistant, which uses your messages and your order and eSIM details to answer you. You can ask for a person at any time and we will pass your request to our support team, which is available Monday to Friday during European business hours. Requests received outside those hours are handled on the next business day. The assistant runs on Amazon Bedrock, inside our private AWS account in the EU. The companies whose models we use do not receive your messages, and your messages are not used to train any model. Please do not include card numbers or passwords in chat messages.
Automated decisions. Payments are screened for fraud by Stripe, using Stripe Radar, and may be declined automatically. If your payment is declined, you may contact us to request human review of the decision and to submit any information you consider relevant. We do not otherwise take decisions about you based solely on automated processing that produce legal effects concerning you or otherwise significantly affect you.
We will not use your Personal Information for a new purpose that is not compatible with those above without telling you first.
4. Payment processing
You can pay by credit or debit card, Apple Pay or Google Pay. TWINT may also be available. Your payment details go directly to our payment provider, Stripe, which processes payments on our behalf. We do not receive or store your full card number. We receive limited details such as card type and the last four digits, and the reference for your transaction.
Stripe is certified to PCI DSS Level 1, the standard set by the PCI Security Standards Council. Payment details are exchanged over an encrypted connection.
Stripe may collect information from you directly to process your payment, such as your email address, billing address and card details. Its use of that information is governed by its own privacy policy, which we suggest you read.
We share payment data with Stripe only as far as needed to take payments, make refunds, and deal with complaints and queries about them.
5. Who we share your information with
We share your Personal Information only with the organisations below, and each receives only the data it needs for its role. They act on our instructions and may not use that data for their own purposes. Stripe and the mobile networks also act for their own legal duties, such as fraud prevention and telecoms law, under their own privacy policies.
| Who | Their role | What they receive | Region |
|---|---|---|---|
| Partner mobile networks | Carry your connection in the countries you visit | Network identifiers for your eSIM, such as the IMSI, and records of your connection and data use. They do not receive your name, contact details or payment details | The countries you visit |
| PostFinance | Named and designated staff use our reseller portal | Account and order records for this service | Switzerland |
| AWS | Hosts the platform | Personal Information held in the platform, stored in encrypted databases and encrypted storage. AWS does not access it | EU |
| AWS (Amazon Bedrock) | Runs our AI assistant, inside our private AWS account | Your chat messages, with the order and eSIM details needed to answer them. The companies whose models we use do not receive your messages | EU |
| Auth0 | Manages account login | Your login email address and authentication data | EU |
| Stripe | Processes payments | Your payment details, email address and billing country | UK and EU |
| SendGrid | Sends our emails | Your name, email address and the content of those emails | EU |
| Twilio | Sends SMS and WhatsApp messages | Your phone number and the content of those messages | UK and EU |
| Datadog | Collects technical logs | Log data, which can include identifiers such as your IP address and user ID | EU |
| PostHog | Product analytics | Usage events with device and browser data and an analytics identifier | EU |
| Google Analytics | Website analytics | Usage events with device and browser data and an analytics identifier | EU and US |
We also disclose Personal Information where the law requires it, for example to comply with a court order or a request from a regulator or the police, and where we believe in good faith that disclosure is needed to protect our rights, your safety or the safety of others, or to investigate fraud.
If our business is sold, merged or restructured, your account and Personal Information will be among the assets transferred, under confidentiality.
We will never sell your Personal Information.
6. Transfer of information
Your Personal Information is stored at rest in the EU. It is also accessed and processed in the countries below.
| Country or region | Why | Safeguard |
|---|---|---|
| United Kingdom | Our team, which administers and supports the service | Switzerland recognises the UK as providing adequate protection |
| European Union and EEA | Hosting, connectivity, login, analytics and email | Switzerland and the UK recognise these countries as providing adequate protection |
| United States | Payment processing and website analytics | The Swiss-US Data Privacy Framework and its UK Extension where the provider is certified, otherwise standard contractual clauses recognised by the FDPIC, and the UK International Data Transfer Addendum |
| The countries you visit | Local networks carry your connection there | Necessary to perform our contract with you (Article 17 FADP, Article 49 UK GDPR) |
You can ask us for a copy of the safeguards we use, using the details in section 10.
7. Storage, retention and managing your information
Storage. We store Personal Information on secure servers run by our hosting providers. Access is limited to authorised staff and protected by industry-standard controls.
Managing your information. You can delete certain details from the settings page of your account, or ask us to delete your account.
Retention. We keep Personal Information only as long as we need it for the purposes set out in this Policy, and for as long as applicable law requires, for example for tax and accounting records. After that we delete it, or anonymise it so it no longer identifies you. You can ask us to delete your account and its data sooner.
8. Cookies, analytics and messages
Cookies. We use cookies and similar technologies on the website.
- Essential cookies log you in, keep your basket, take payment securely and help prevent fraud, including Stripe's fraud prevention cookies. They are always on.
- Analytics cookies show us how the Services are used. We set them only if you accept them, and you can change your choice at any time in the cookie settings.
You can also set your browser to refuse cookies. Parts of the Services may not function correctly if you do so. We do not use advertising cookies.
Analytics. We use PostHog and Google Analytics to produce reports on how often the Services are visited, which pages are used and for how long. We use these reports to improve the Services.
Email marketing. We only send marketing about PostFinance Travel eSIM if you have agreed to it. Every marketing email carries an unsubscribe link, and you can also opt out in your account settings or by contacting us. You will still receive service emails about your orders and your eSIM.
Marketing by PostFinance. At checkout you can choose to let us pass your name and email address to PostFinance so that it can send you marketing. This is optional and applies only if you select it. PostFinance is then responsible for that data under its own privacy statement. You may withdraw your consent at any time.
Do Not Track. Browsers send Do Not Track signals in different ways and there is no agreed standard, so the Services are not set up to respond to them. We limit how we collect and use your information as described in this Policy.
9. Your rights
If you are in Switzerland. Under the FADP you have the right to:
- ask whether we process information about you and receive a copy of it
- have inaccurate information corrected
- have information deleted, or its processing restricted, where the conditions in the law are met
- object to the processing of your information
- receive information you gave us in a common electronic format, or have it sent to another provider
- ask for a person to review a decision taken solely by automated means (see section 3)
If you are in the EU, the EEA or the UK. Under the GDPR and the UK GDPR you have the rights above, and you may also withdraw your consent at any time where we rely on it. Withdrawal does not affect processing carried out before you withdrew.
How to exercise your rights. Contact us using the details in section 10. We may ask you to verify your identity, or the authority of anyone making a request for you, before we respond. Please provide sufficient detail for us to identify and process the request. We aim to respond within 30 days.
Complaints. Please contact us first so that we can resolve the matter. You can also contact:
- in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch
- in the UK, the Information Commissioner's Office (ICO): ico.org.uk
- in the EU or EEA, your local data protection authority
10. Security, children, changes and contact
Information security. We apply commercially reasonable, industry-recognised measures to protect your information, including encryption in transit and at rest, access controls limiting who can reach personal data, regular security assessments, and physical security at our data centre providers. No system can be guaranteed secure. If you believe that your interaction with us is no longer secure, please notify us immediately using the details below.
Data breach. If we learn that Personal Information has been exposed, we will investigate, report and cooperate with the authorities as required. We will notify the FDPIC and the ICO where the law requires, and we will inform you where the breach is likely to result in a high risk to you.
Children. The Services are for people aged 18 and over. We do not knowingly collect information from children. If you believe that a child has provided us with information, please contact us and we will delete it.
Links to other sites. The Services link to sites we do not control, including PostFinance's own sites. We are not responsible for their privacy practices, so please read their privacy notices.
Changes to this policy. We may change this Policy at any time. We will post the new version with a new date and, where the change is material, notify you by email before it takes effect.
Contact us.
| Controller | Mindszi Technologies Ltd, trading as eSIM Copilot, 128 City Road, London EC1V 2NX, United Kingdom |
| Company number | 15524190 |
| Privacy questions and data requests | privacy@mindszi.com |
| Data Protection Officer | Michael Moorfield |
| Customer support | Chat on the PostFinance Travel eSIM website, WhatsApp, or hello@esimcopilot.com |
We will seek to resolve any complaint or dispute, and to give effect to your rights, as promptly as possible and within the time limits set by data protection law.