隐私政策
最后更新:2026年3月
1. 我们是谁
TripoSIM由BroadNet Technologies LLC运营,总部位于美国新泽西州。本隐私政策说明当您使用我们的网站(triposim.com)和服务时,我们如何收集、使用、存储和保护您的个人信息。
TripoSIM is operated by BroadNet Technologies LLC, a company registered in Dubai, United Arab Emirates ("TripoSIM", "we", "us", or "our"). This Privacy Policy explains in detail what information we collect, why we collect it, how we use and share it, how long we keep it, how we protect it, and the rights and choices you have. It applies to our website (triposim.com), our mobile applications, and all related services (together, the "Services"). By using the Services you agree to the practices described here.
Information We Collect
We collect the following categories of information, and only what we need to provide and improve the Services:
- Account information — your name, email address, and (optionally) phone number, plus a securely hashed password, created when you register.
- Order and transaction information — the eSIM plans you purchase, order history, destination and validity, and the ICCID of the eSIM profile issued to you.
- Payment information — payments are processed by our PCI-DSS-compliant payment processor (Stripe), which receives your card details directly. We never see or store your full card number; we retain only a payment reference, the amount, currency, and status.
- Device and technical information — IP address, browser type, operating system, device model, language, and, for our mobile apps, push-notification tokens and a device identifier used to deliver notifications.
- Usage and analytics information — pages viewed, features used, referring source, and interactions, collected (only with your cookie consent) to understand and improve the Services.
- Location information — collected only with your explicit permission (for optional features such as the WiFi map); if you decline, the Services work normally without it.
- Communications and support — the contents of messages you send us (email, chat, support tickets) so we can respond and keep a record of the request.
How We Use Your Information
We use the information above for the following purposes:
- To provide the Services — create your account, process your order, provision your eSIM, deliver the QR code, and provide customer support.
- To process payments and prevent fraud, and to keep records required for tax, accounting, and legal compliance.
- To operate, secure, and improve the Services, diagnose problems, and develop new features.
- To communicate with you about your orders, account, and service updates, and — only if you opt in — marketing messages you can unsubscribe from at any time.
- To measure our own marketing (for example, website conversions and advertising performance) where you have given cookie consent.
- To comply with legal obligations and enforce our terms.
Legal Bases for Processing
Where the GDPR or similar laws apply, we rely on these legal bases: performance of our contract with you (to deliver the Services you buy); your consent (for optional cookies, location, and marketing, which you can withdraw at any time); our legitimate interests (to secure and improve the Services and prevent fraud, balanced against your rights); and compliance with legal obligations (such as tax and record-keeping).
How We Share Information
We do not sell your personal information. We share it only as needed to run the Services:
- Connectivity partners — to activate your eSIM we share the minimum data required (your plan selection and the eSIM ICCID) with the network partner that fulfils your order.
- Service providers — payment processing, cloud hosting, email and SMS delivery, push notifications, analytics, and security, each acting on our instructions under contract.
- Legal and safety — where required by law, court order, or to protect the rights, safety, and security of our users, the public, or TripoSIM.
- Business transfers — if TripoSIM is involved in a merger, acquisition, or asset sale, information may be transferred, subject to this Policy.
Data Retention
We keep personal information only as long as necessary for the purposes above. Account information is kept while your account is active. Order and payment records are retained for up to 7 years to meet tax and accounting obligations, after which they are deleted or anonymized. Analytics data is retained on a rolling basis. When you delete your account, we remove your personal information as described in the Account Deletion section below, except where longer retention is required by law.
How We Protect Your Data
We use industry-standard safeguards to protect your information, including encryption in transit (HTTPS/TLS), hashed passwords, access controls that limit who can see personal data, network firewalls, and monitoring. No method of transmission or storage is completely secure, but we work continuously to protect your information and to notify you and the authorities of any breach as required by law.
Your Privacy Rights and Choices
Depending on where you live, you may have the right to: access the personal information we hold about you; correct inaccurate information; delete your information; receive a copy in a portable format; object to or restrict certain processing; and withdraw consent at any time (without affecting processing already carried out). You also have the right to lodge a complaint with your local data-protection authority.
To exercise any of these rights, email [email protected] or use Settings → Delete Account in the app or website. We will respond within the time required by applicable law. You can opt out of marketing at any time via the unsubscribe link, and you can manage cookies through our cookie banner.
International Data Transfers
TripoSIM operates globally, and your information may be processed in countries other than your own, including the United Arab Emirates and countries where our service providers operate. Where we transfer personal data across borders, we use appropriate safeguards (such as standard contractual clauses) to ensure it remains protected in line with this Policy.
Cookies and Similar Technologies
We use strictly necessary cookies to run the site (for example, to keep you logged in and secure), and — only after you accept our cookie banner — analytics and advertising cookies to measure and improve the Services. Advertising and analytics storage default to "denied" under Google Consent Mode v2 and are enabled only after you accept. You can change or withdraw your choice at any time, and declining optional cookies does not affect your ability to buy or use an eSIM.
2. 我们收集的信息
我们收集以下类型的信息:
- 账户信息:创建账户时的姓名、电子邮件地址和密码。
- 支付信息:由Stripe安全处理。我们不存储完整卡号 — 仅保留最后四位、卡品牌和有效期供您参考。
- 使用数据:eSIM数据消耗和状态,用于显示您的控制面板和监控服务质量。
- 技术数据:IP地址、浏览器类型、设备信息和访问页面,用于安全和分析。
- 通信:您发送给客服团队的消息。
移动应用数据
当您使用 TripoSIM 移动应用(Android 或 iOS)时,我们还可能收集以下数据:
- 推送通知令牌(Android 使用 FCM,iOS 使用 APNs)——仅用于发送来电提醒和服务通知。令牌存储在我们的服务器上,您退出登录时将被删除。
- SIP/VoIP 凭证——由服务器端为 HomeLink 呼叫转移功能生成。安全存储在设备上(Android SharedPreferences,iOS Keychain)及我们的服务器上。绝不与第三方共享。
- 手机通讯录(仅限 HomeLink 功能)——如果您启用 HomeLink 并授予权限,我们会将您的联系人姓名和电话号码(规范化为 E.164 格式)同步到我们的服务器。这些数据仅用于将来电路由至正确的用户。联系人同步完全可选,可随时在【设置】中关闭。当您停用该功能或删除账户时,联系人将从我们的服务器上删除。
- 设备标识符——设备型号、操作系统版本以及制造商分配的设备 ID,用于推送通知和调试。
HomeLink(VoIP 呼叫转移)
HomeLink 允许您通过数据连接在 TripoSIM 应用上接收打到您家庭电话号码的来电。激活 HomeLink 后:
- 我们为您分配一个虚拟 DID 电话号码并存储您的 SIP 注册凭证。
- 通话详细记录(主叫号码、通话时长、时间戳)将被记录,用于您的通话记录和计费目的。
- 语音通话通过加密的 SIP/UDP 协议传输。音频实时处理,不会被录制或存储。
- 如果您启用联系人同步,主叫姓名将在我们的路由服务器上本地匹配,以便及时接听来电。
TripoSIM Shield 与家长控制
Shield 提供 DNS 级广告拦截和内容过滤。家长控制在此基础上增加儿童安全过滤功能(儿童安全模式 / 青少年友好模式)。
- DNS 查询通过我们的安全 DNS 代理服务器(shield.triposim.com)路由,该服务器将请求转发至上游过滤提供商(CleanBrowsing)。我们不记录个人 DNS 查询或浏览历史。
- 家长控制设置(过滤级别、PIN 哈希值)存储在我们的数据库中,并与您的用户账户关联。
- PIN 以 bcrypt 哈希形式存储,不可逆向还原。我们无法恢复您的 PIN。
- 不收集、存储或与任何第三方共享任何浏览活动数据。
位置数据
我们仅在您明确同意的情况下收集位置数据:
- WiFi 地图功能——如果您授予位置权限并接受 Cookie,我们将使用您的坐标显示附近的 WiFi 热点。位置数据将发送到我们的服务器和 Google Places API 用于热点查询。
- 基于 IP 的地理定位——仅当您接受 Cookie 同意后,我们可能使用您的 IP 地址检测您所在的国家,用于货币显示和紧急号码查询。此功能使用 ipapi.co 服务。
- 如果您拒绝 Cookie 或拒绝位置权限,将不会收集任何位置数据。应用无需位置访问即可正常运行。
第三方服务
我们使用以下可能处理您数据的第三方服务:
- Stripe(stripe.com)——支付处理。Stripe 直接接收您的支付卡信息。我们从不查看或存储完整的卡号。
- Google Analytics——网站分析,仅在您接受 Cookie 同意后加载。以匿名方式追踪页面浏览量和用户行为。
- Firebase Cloud Messaging——为 Android 设备推送通知。
- Apple Push Notification service(APNs)——为 iOS 设备推送通知。
- CleanBrowsing——为 Shield 和家长控制提供上游 DNS 过滤。DNS 查询被转发,但不由我们的代理记录。
- Cloudflare Turnstile——登录和注册时的 CAPTCHA 验证,防止自动化攻击。
- eSIM 供应商——我们与履行您 eSIM 订单的供应商共享您的套餐选择和 ICCID。供应商选择通过我们的路由引擎自动完成。
Google API Services & Advertising Data
TripoSIM uses Google advertising and measurement services to run and measure our own marketing. As required by the Google API Services User Data Policy, this section explains how we handle data in connection with Google services and APIs.
- Measurement & advertising tags: With your cookie consent, we load Google’s tag (gtag.js) to measure website conversions and build remarketing audiences. Under Google Consent Mode v2, advertising and analytics storage default to "denied" and are enabled only after you accept cookies. If you decline, no Google advertising or analytics cookies are set.
- Google Ads API (our own account only): We operate an internal, server-side integration that manages TripoSIM’s own Google Ads advertising account using our own authorized credentials. This integration accesses only our own advertising account. It does NOT access, collect, store, or share any personal data from the Google accounts of our website visitors or customers.
- Limited Use: TripoSIM’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google API data, do not use it for personalized advertising, and do not allow humans to read it except where permitted by that policy or with your explicit consent.
- Data retention: aggregate advertising performance data (such as campaign clicks and conversions for our own account) may be cached on our servers for reporting. It contains no personal data about our visitors.
For questions about our use of Google services, contact [email protected].
3. 我们如何使用您的信息
- 提供、维护和改进我们的服务
- 处理您的订单和交付eSIM配置文件
- 发送订单确认、使用提醒和客服回复
- 检测和防止欺诈和未授权访问
- 遵守法律义务
4. 信息共享
我们不出售您的个人信息。我们仅与以下方共享数据:
- eSIM供应商:为了配置和管理您的eSIM(仅ICCID和套餐详情)。
- 支付处理商:Stripe,用于安全处理您的付款。
- 法律机关:法律要求时或为保护我们的权利。
5. 数据安全
我们采用行业标准的安全措施,包括SSL/TLS加密、密码哈希(bcrypt)和安全服务器基础设施。但没有任何电子传输方法是100%安全的,我们无法保证绝对安全。
6. 数据保留
账户信息在账户活跃期间保留。订单和交易记录保留最多7年,用于法律和会计目的。您可以随时请求删除您的账户和个人数据。
7. 您的权利
您有权:
- 访问我们持有的关于您的个人数据
- 请求更正不准确的数据
- 请求删除您的个人数据
- 撤回营销通讯的同意
- 请求以可移植格式获取数据副本
如需行使这些权利,请联系 [email protected].
8. GDPR和国际用户
如果您位于欧洲经济区(EEA)、英国或其他有数据保护法律的司法管辖区,您根据《通用数据保护条例》(GDPR)或同等法规享有额外权利。这些包括访问权、纠正权、删除权、限制处理权、数据可移植权和反对权。
如有GDPR相关咨询或行使您的权利,请联系我们的数据保护官 [email protected].
9. Cookie
我们使用必要的Cookie来维护您的登录会话和偏好设置。我们可能使用分析Cookie(Google Analytics)了解访问者如何与我们的网站互动。继续使用我们的网站即表示您同意使用必要的Cookie。您可以通过浏览器控制Cookie设置。如需完整详情,请查看浏览器设置中的Cookie偏好。
账户删除
您可以随时在 TripoSIM 应用或网站的【设置】→【删除账户】中删除您的账户。删除账户后:
- 您的个人信息(姓名、电子邮件、电话)将被永久删除。
- 您的 SIP 凭证、推送令牌和联系人同步数据将被移除。
- 您的 HomeLink 号码将被释放,呼叫转移将停止。
- 订单和支付记录将依法保留 7 年,但会进行匿名化处理。
- 活跃的 eSIM 档案可能继续有效至到期,但将与您的账户解除关联。
账户删除不可撤销。删除确认前,您将通过电子邮件收到验证码。
儿童隐私
TripoSIM 不面向 13 岁以下儿童。我们不会故意收集 13 岁以下儿童的个人信息。家长控制功能旨在帮助家长管理子女的网络访问——无需儿童创建账户或提供个人信息。如果您认为某位儿童向我们提供了个人数据,请联系我们申请删除。
10. 本政策变更
我们可能不时更新本隐私政策。我们将通过电子邮件通知注册用户重大变更。