Japan Plans How it works Networks FAQ Travel guides See plans

Legal document · Pinglo store

Privacy Policy

We collect the least data needed to deliver your eSIM and help you, and we never sell it. Here's what we collect, why, who sees it, and how to get a copy or have it deleted.

Version
1.6
Effective
4 October 2026
Reading time
About 8 min · summary in 1
Governing law
Personal Data Protection Law (KSA)
One-minute summary Your data rights

This is an English translation for convenience. The Arabic text is the governing version.

The one-minute summary

For guidance only — the full text below is what counts.

  • Four details are enoughName, email, mobile and your order. No ID, no address, no date of birth.
  • Your card never touches usYou pay on Techrar's, Tamara's or Tabby's page; we never see or store your card number.
  • No selling, no ad trackingWe don't sell your data or run advertising trackers. Visits are measured without cookies; browsing is recorded only if you agree.
  • Shared only as neededWith the eSIM, payment and email providers, to fulfil your order.
  • Your data, your callAsk for a copy, a correction or deletion in one message; we reply within 30 days at most.
  • The phone check knows littleIt sends only your phone model, nothing that identifies you.

Your data map

Everything we keep about you, in one table. Details in the clauses below.

DataWhy we need itWho else sees itHow long
Name & emailDeliver your QR code and invoice, contact you about your orderEmail provider, payment providerAs long as sales records must be kept by law
Mobile numberPayment confirmation, contact when needed, top-ups from the order pageTechrar, Tamara or Tabby, depending on how you payWith the order record
Order & invoiceFulfilment, refunds, tax obligationsPayment providerAs required by commercial and tax law
eSIM details & usageShow balance and validity, low-data and expiry alertseSIM providerWith the order record
Reports & messagesSolve your problem and replyEmail provider when we replyUp to 24 months after closing
Live chat (if you use it)Answer you right away and understand the context of your question; the first reply may come from an automated assistantConferbot, the provider of the chat tool and the automated assistantIn our Conferbot account; deleted on your request
Your review (if you write one)Publish your experience on the plan's page so others can learn from itEveryone: the display name you choose, the stars, your text, the cities, and your country and trip type if you pick them — never your e-mail or phoneAs long as it is published; deleted whenever you ask
Phone model (when checking)Tell whether your phone supports eSIM, keep the device list currentNo oneNot linked to you; kept as statistics
IP address (hashed)Stop repeated spam from one sourceNo oneWith the report only
Browsing statisticsSee where visitors drop off in the buying steps, to improve the sitePostHog (EU)Up to 12 months, cookieless, not linked to your name
Browsing recording (with consent)See what gets in a visitor's way, with everything typed hiddenPostHog (EU)30 days
Browser settingsRemember your cart, language, currency and phone check on your deviceNo one (stays in your browser)Until you clear it

1Who is responsible for your data

Pinglo is the controller of your data; here are its official details.

1.1 The business that owns pinglo-sim.com is the controller of your personal data under the Personal Data Protection Law and its Implementing Regulations. This policy covers the site, your order page and the messages we send you.

Business name
—
Unified number
—
City
—
National address
—
Data contact
[email protected]

2What we collect

What you type into our forms, and what's needed to run your eSIM. Nothing else.

2.1 When you buy: name, email, mobile number, the plans chosen, the amount, any discount code, and your site language.

2.2 After delivery: eSIM identifiers (such as the ICCID), its status, data usage and expiry, as reported by the eSIM provider.

2.3 When you pay: payment status, method (mada, card, Apple Pay, Tamara, Tabby…) and transaction reference. Card details are entered on the payment provider's page and never reach us.

2.4 When you contact us or file a report: what you write, the order number if you give it, and your phone model and general location (e.g. "in Japan") if you choose to share them.

2.5 When you check your phone: the phone model only. If we don't know the model yet, we record it with nothing that identifies you, to update the device list.

2.6 Technical: your IP address in a one-way hashed form to stop repeated spam, security-check signals processed by Cloudflare to tell people from bots, and anonymous browsing statistics (clause 8).

2.7 We don't collect sensitive data, ID numbers, home addresses or your precise location.

2.8 When you write a review: reviews can only be written from your order page (so each is tied to a real purchase) and include the stars, your text if any, the Japanese cities you pick, the display name you choose (by default your first name and last initial), and your country and trip type if you pick them. Each is checked before it goes live, then shown on the plan's page and possibly on the home page and in search results (such as Google's stars). Your e-mail, phone and order number are never published; we may post a public reply under it. You can edit it until it is published and ask us to delete it at any time.

3Why we use it, and on what basis

First to fulfil your order, then to meet legal duties, then to protect the site. Marketing only with consent.

  • Performing the contract: issuing and delivering the eSIM, top-ups, related alerts, reports and refunds.
  • Legal obligations: invoices, accounting and tax records, and requests from competent authorities.
  • Legitimate interest: preventing fraud and spam, protecting the site, and improving the service with statistics that identify no one.
  • Consent: marketing messages and offers; you can withdraw consent at any time.

3.1 If you start an order and don't finish paying, we may send you one reminder about your cart. If you'd rather not get it, tell us and we won't send it again.

3.2 We make no fully automated decisions about you with legal effect. Approval to pay in instalments or later is Tamara's or Tabby's decision under their own policies.

3.3 A few days after you use your eSIM in Japan we may send you one message asking about your trip (our legitimate interest in improving the service). We never send it twice for the same order; tell us if you don't want it. Publishing your review is based on your consent when you send it.

4Who we share it with

Service providers needed to deliver your eSIM, only as much as needed. Never sold.

ProviderRoleWhat it receives
TechrarCard, mada and Apple Pay paymentsMobile, amount, plans
TamaraInstalment payments, when you choose themName, email, mobile, the order, and your purchase history with us for its assessment
TabbyPay-later / instalment payments, when you choose themName, email, mobile, the order, and your purchase history with us for its assessment
eSIM AccessIssuing and running the eSIM on Japanese networksOrder reference and plan only — not your name or email
Brevo & ResendSending email (QR code, invoice, replies)Name, email, message content
ConferbotLive chat and its automated assistant (its replies are written by an OpenAI AI model through Conferbot), only if you open the help windowWhat you write in the chat, IP address and browser type, language, the page you opened it from, cart contents, and the short order number
CloudflareHosting, database and protectionEverything passing through the site, encrypted in transit
PostHogMeasuring the buying steps; recording browsing for those who agreePages visited and purchase events, without your name or email, with secret codes removed from links

4.1 These providers may use the data only to provide their service and must protect it. We may disclose data where a law or a competent authority requires it.

4.2 If you contact us on WhatsApp or Instagram, that conversation is also subject to the platform's own policy.

5Transfers outside Saudi Arabia

Some providers process data outside the Kingdom, with the safeguards the law requires.

5.1 Because the service runs in Japan and relies on international providers (eSIMs, email, hosting), some of your data may be processed outside Saudi Arabia.

5.2 We limit transfers to the minimum the service needs and rely on providers with appropriate protection standards, as set by the Personal Data Protection Law and the regulation on transferring data outside the Kingdom.

6How long we keep it

As long as there's a purpose or the law requires, then deleted or made non-identifying.

6.1 Order and invoice records are kept for as long as Saudi commercial and tax law requires.

6.2 Reports and messages are kept up to 24 months after closing, then deleted unless tied to an open order or dispute.

6.3 Orders that were never paid are deleted or anonymised within 12 months.

6.4 Browser data (cart, language, currency, phone check) stays on your device until you clear it.

6.5 Reviews stay published while the plan is sold or until you ask us to delete them; hidden ones are deleted on request.

7How we protect it

Encrypted connections, a protected admin panel, and as few people as possible with access.

7.1 All connections to the site are encrypted (HTTPS). The admin panel sits behind Cloudflare Access identity checks, only authorised people can enter, and every action there is logged.

7.2 Your order page link carries a secret code of its own. Don't share it — anyone holding it can see your eSIM's QR code.

7.3 If a breach affects your data, we notify the competent authority and you as the law requires, with the steps we've taken.

8Cookies and browser storage

No advertising trackers. Visits measured without cookies; browsing recorded only with your consent.

8.1 We use your browser's local storage for your cart, language, currency, phone-check result, discount code and reading settings. None of it reaches us unless you place an order.

8.2 Cloudflare's security check (Turnstile) uses technical signals to tell people from bots on the payment and contact forms. Tamara and Tabby may show their promotional widgets on plan, cart and checkout pages under their own policies.

8.3 Visit measurement: we use PostHog to see how visitors move through the buying pages. It runs without cookies or browser storage and counts visitors with an anonymous fingerprint computed on PostHog's servers. We never send your name, email or number, and strip secret codes from links before sending.

8.4 Browsing recording: starts only if you tap “OK” in the small bar, covers page activity only, and hides everything you type. Your order page is never recorded, because it shows your eSIM's QR code. You can change your mind at any time: .

8.5 Live chat: the Conferbot tool is not loaded on any page until you open the help window. It then stores local storage (and possibly cookies) in your browser, needed to keep the conversation going between pages, and we pass it what helps us serve you: language, page, cart contents and the short order number. We never pass it your order page's secret link or the QR code. You may be answered in the chat by “Pinglo Assistant”, an automated AI assistant run by Conferbot, whose replies are written by an OpenAI model: your messages are processed automatically to write a reply from the information published on our website and the Pinglo guide. It can be wrong, so what our website pages and the Terms & Conditions say prevails. The assistant has no access to your orders and makes no decision about your order or a refund; our team reviews those. Do not write card numbers, passwords or one-time codes in the chat.

8.6 You can clear this data in your browser settings at any time; the site then behaves like a first visit.

9Your data rights

Ask for a copy, a correction or deletion, or withdraw consent. We reply within 30 days at most.

9.1 The Personal Data Protection Law gives you:

  • The right to be informed of what we collect and why — this policy.
  • The right of access to a copy of your data in a clear format.
  • The right to correction of anything inaccurate, such as a mistyped email.
  • The right to destruction of your data once its purpose ends, except what the law requires us to keep, such as invoices.
  • The right to withdraw consent to marketing at any time.

9.2 How to ask: write to [email protected] or use the contact form from the email you ordered with. We may ask for your order number to verify it's you. It's free.

9.3 Complaints: if our answer doesn't satisfy you, you can complain to the Saudi Data & AI Authority (SDAIA), which enforces the law.

10Minors

The site is meant for people aged 18 and over.

10.1 We don't knowingly collect data from anyone under 18 without a guardian's supervision. If you learn a minor has sent us their data, tell us and we'll delete it.

11Changes to this policy

Version and date are shown at the top, and we tell you about any material change.

11.1 We may update this policy when our services or the law change. We update the version and effective date at the top, and email you before a material change to how we use your data takes effect.

11.2 Read this policy together with the Terms & Conditions. The Arabic text governs in case of any difference with this translation.

12Contact us

Any question about your data? We'll answer.

12.1 To ask about this policy or exercise your rights: [email protected], or use Message us.

Your privacy is part of the service. If you still have a question about your data, ask us before you buy.