Privacy Policy
Last revised: March 2026
At Onetel, we take your privacy seriously and are committed to protecting your personal data. Below: the data we collect, the reasons we use it, and the rights you hold over that data.
1. Who You're Dealing With
Onetel runs the eSIM marketplace found at onetel.com.hk. Where we say "Onetel", "we", "us", or "our", we mean the entity that runs this platform. Questions go to [email protected].
2. Data We Collect
The information we collect falls into these types:
- Account data: the name, email address, and password you give us at registration.
- Order data: which eSIM plans you bought, transaction IDs, and purchase history.
- Device data: your device type and eSIM ICCID/EID, needed to provision the plan.
- Payment data: handled securely by Stripe — we do not store card numbers.
- Usage data: clicks, pages visited, session duration, and IP address (anonymised after 30 days).
- Communications: the emails and support tickets you send us.
3. What We Do With Your Data
Here is what we do with your data:
- Fill and deliver your eSIM orders
- Send QR codes, order confirmations, and account notifications
- Answer support requests
- Detect fraud and improve the platform
- Send marketing emails (consent required; unsubscribe anytime)
- Comply with the law
4. Our Legal Grounds for Processing (GDPR)
Where GDPR applies, we rely on these legal bases: contract performance (delivering your order), legitimate interests (analytics, fraud prevention), consent (marketing), and legal obligation (tax records).
5. Cookies
Cookies run session management, analytics (Google Analytics), and personalisation on this site. Read our Cookie Policy for the full breakdown and opt-out controls.
6. Data Sharing
Your personal data is never sold. We share it only with:
- eSIM providers (Zendit, for example) — to set up your plan
- Payment processor (Stripe) — to take payments
- Analytics (Google Analytics) — usage data, anonymised
- Support tools — to handle support tickets
- Legal authorities — when the law demands it
7. Data Retention
Close your account and the account data goes within 30 days. Order records stay for 7 years, because tax and legal rules require it. Marketing consent records are held until you withdraw that consent.
8. Your Rights
Your location decides which rights apply. Those rights may include: getting a copy of your data, correcting it, or having it deleted; objecting to processing; asking for data portability; withdrawing consent at any time. Send requests to [email protected].
9. Security
Passwords are hashed, traffic uses industry-standard encryption (TLS 1.3), and we run regular security audits. Payment data is handled exclusively by PCI-DSS compliant processors.
10. Updates to This Policy
This policy can change from time to time. When a change is material, we tell you by email or with a banner on the site. Carry on using the service afterwards and you accept the change.
11. Contact
Got a question on this policy? Email [email protected].