Privacy Policy
Last updated: 11 August 2026
GoPocket is a trade name of Milioti LLC, a Wyoming limited liability company, 1309 Coffeen Avenue, Suite 1200, Sheridan, Wyoming 82801, United States. This Privacy Policy explains what data the GoPocket eSIM app ("the App") processes, why, and what rights you have. Contact: info@gopocket.shop.
1. Data we collect
| Data | Why | Where it lives |
|---|---|---|
| Email address (at checkout) | Order record and related service communication | Our order database |
| Selected destination and data plan (GB) | To place your order and show your plan | Our order database and our eSIM provider |
| Order details (plan, amount, order ID) | Order history and billing | Our order database and payment provider |
| ICCID and eSIM reference of your installed eSIM | Only to manage the service: data usage, top-up, and to associate an eSIM with your order | Our backend and our eSIM provider |
| Data usage of your active eSIM | To show you how much data you have used | Our backend and our eSIM provider |
| Crash and diagnostic data (error messages, platform, app build, timestamp) | Stability, debugging and quality of the Service — collected by our own telemetry, not linked to your identity, never used for advertising or profiling | Our backend (telemetry, retained 90 days — see section 6) |
| IP address (connection metadata) | Security, abuse prevention and diagnostics (incl. rate limiting) | Our server logs (telemetry), retained 90 days — see section 6 |
We collect the minimum necessary to provide the Service.
2. Data we do NOT collect
- Device identifiers: no IMEI, hardware SIM serial, Android ID, IDFV, or advertising identifiers.
- Location: no GPS or device location permissions.
- Contacts, photos, camera, or microphone.
- User accounts or passwords — checkout is guest-only.
- Advertising IDs and cross-app tracking: no IDFA, Google Advertising ID, or any advertising/tracking SDK. We do not sell, advertise against, or profile your data, and we never correlate app data across other companies' apps.
- Third-party analytics: we do not use third-party analytics SDKs. We do collect minimal first-party crash and diagnostic data via our own telemetry (see section 1) solely to keep the Service stable; this data is not linked to your identity and is not used for advertising or profiling.
- Push notification tokens.
- Payment card data: card details are entered and processed solely by our payment provider (currently Stripe); we never receive or store them.
3. How we use data
We use data only to:
- provide and operate the Service (place orders, deliver eSIMs, show usage, support top-up);
- communicate about orders when needed;
- comply with legal obligations and protect our rights;
- improve and secure the Service (including preventing abuse and diagnosing crashes with the telemetry described in section 1).
We never sell your data.
4. Who we share data with
We share the minimum data necessary with two types of third parties:
- Payment provider (currently Stripe) — receives order amount and a reference for the transaction. Your email address is never sent to the payment provider. Payment cards are processed by the provider under its own terms and security requirements (including PCI-DSS for card processing).
- eSIM provider (currently eSIM Access) — receives the destination, plan, and, for service management, the ICCID of your eSIM, to operate the telecommunications service you purchased.
We do not share data with any other third party.
5. Where data is stored and security
- On your device: the App stores your eSIMs and a pending-order reference locally on your device. Your order access token is stored in the device's secure storage (iOS Keychain / Android Keystore). Local eSIM data can be removed by uninstalling the App.
- On our backend: order records are stored in a database operated by us. Order access tokens are stored only as hashes.
- With our providers: your order and eSIM data are processed by our eSIM provider; payment data is processed by the payment provider.
Transmission to and from our backend is encrypted in transit (HTTPS). Access to our systems is restricted to personnel who need it.
We collect only connection metadata (an IP address) in our server and telemetry logs for security, abuse prevention and diagnostics, and we retain it for 90 days (section 6). We do not log the content of your requests.
6. Retention
We keep personal data only as long as needed for the purposes above or as required by law:
| Category | Retention |
|---|---|
| General enquiries | 12 months |
| Business enquiries | 24 months |
| Support requests | 24 months |
| Privacy requests | 5 years |
| Technical / security / diagnostic logs (telemetry, incl. connection metadata) | 90 days (automatic) |
| Order records (incl. email, plan, amount, order ID, ICCID reference) | Retained for business, accounting, refund, chargeback and support purposes. The exact period is a business/legal decision currently being finalised; we delete order data earlier on your request. |
| Legal / accounting documents | as required by applicable law |
Telemetry and connection-metadata logs are automatically deleted after 90 days (server-side rotation). Order records are not automatically deleted; if you ask us to delete your order data (section 7), we will remove or anonymise it, subject to any legal or accounting obligations that require us to keep a record.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal data, and to object to or restrict certain processing. If you are in the EEA or the UK, the GDPR gives you these rights. To exercise any right, email info@gopocket.shop — we will respond within the timeframe required by law. You may also lodge a complaint with your local data protection authority.
Because the App has no user accounts, there is no in-app self-service deletion: deletion of your data is handled on request via info@gopocket.shop. Uninstalling the App removes the local data it stores on your device.
8. Children
The App is not directed to children under 13 (or the minimum age under local law). We do not knowingly collect data from children.
9. International transfers
Your data may be transferred to and processed in the United States and in the jurisdictions where our providers operate, subject to appropriate safeguards.
10. Changes to this policy
We may update this policy. The "last updated" date below will be revised, and material changes will be highlighted. Continued use after changes constitutes acceptance.
11. Contact
info@gopocket.shop — GoPocket is a trade name of Milioti LLC, a Wyoming limited liability company, 1309 Coffeen Avenue, Suite 1200, Sheridan, Wyoming 82801, United States.