Privacy Policy
Last updated: August 1, 2026
1. Controller and scope
VALA TECH 2026 LLC, 2232 Dell Range Blvd, Suite 303 1440, Cheyenne, WY 82009, United States, operates Shqiponja eSIM and https://shqiponjaesim.com. This Policy covers our website, customer support, orders, eSIM delivery, and the Shqiponja eSIM ChatGPT integration described below.
2. Personal data we process
- Account, contact, and order information, such as name, email address, phone number, selected package, order and payment-status references, and customer communications.
- eSIM fulfilment information needed to deliver and support a purchase, which may include the package, activation information, and identifiers supplied by our eSIM provider.
- Payment information processed by Stripe or another payment provider. We do not collect or store full payment-card numbers in our application.
- Incoming and outgoing support and transactional-email records, including email addresses, message content, delivery status, support-ticket references, and request or correlation identifiers where generated by the service.
- SMS, verification, and notification data, such as phone number, message content or status, and provider message identifiers when SMS or verification is enabled.
- OAuth sign-in information from Google, Microsoft, Facebook, or Apple when you choose that sign-in method, such as the provider account identifier, verified email address, and profile information made available by that provider.
- Technical and security information, such as IP address, browser or device user agent, request and correlation identifiers, database audit records, and records generated for security, fraud prevention, reliability, and troubleshooting.
- Cookie, local-storage, analytics, and advertising-preference information as described in our Cookie Policy.
- Messages and information you choose to provide to customer support, including information in emails, forms, or chat interactions.
3. ChatGPT and the Shqiponja eSIM MCP server
When you use Shqiponja eSIM through ChatGPT, ChatGPT may send our Model Context Protocol (MCP) server your destination, country code, data or package preference, minimum or maximum days, maximum price, and result limit. You must enter only a destination, country, region, or package preference. Do not enter your name, email address, phone number, payment details, order information, or other personal data.
The MCP server queries only the Shqiponja eSIM public catalog API. It returns only public package information and a public catalog package ID. It does not create an order, collect payment details, perform checkout, activate an eSIM, create a user profile, or provision through Airalo. Its public output excludes provider pricing, provider identifiers, purchase links, tokens, and technical debug data.
The MCP source code does not write tool inputs or tool outputs to a database or file. It applies an in-memory security rate limit using a one-way, process-local address fingerprint rather than a stored raw IP address. Infrastructure and security logs may still be processed by the hosting provider according to its actual configuration; the source code does not define their retention period. OpenAI is a recipient and platform for the tool request and response that you make through ChatGPT.
4. Why we use data
We use personal data to provide and support eSIM services; process and document orders and payments; deliver activation information; respond to support requests; prevent fraud and abuse; secure, maintain, and improve our services; measure performance where you consent; and meet legal obligations. Depending on the context, our legal bases are performance of a contract, compliance with legal obligations, legitimate interests in security and service operation, and consent for non-essential cookies and marketing technologies.
5. Recipients and service providers
We disclose data only as needed for the purposes above, including to:
- OpenAI, when you choose to use the ChatGPT integration.
- Railway and other hosting, database, infrastructure, security, and error-monitoring providers used to operate our services. Their logs may process technical and security information.
- Stripe for payment processing and payment-related fraud prevention.
- Airalo for eSIM catalogue and fulfilment services where required for an order.
- Brevo and SMTP email providers for transactional, support, and newsletter email, including the delivery of email inbox/outbox communications.
- Twilio for SMS, telephone, delivery-status, and verification services where enabled.
- Google Analytics and Meta Pixel in accordance with your non-essential-cookie consent. Where Meta Conversions API is enabled, Meta may also receive event data and technical data such as IP address and user agent, together with hashed contact identifiers where supplied for event matching.
- Google, Microsoft, Facebook, and Apple when you choose to sign in through their OAuth services.
- Trustpilot if the Trustpilot BCC setting is enabled for an eligible transaction; in that case the transactional email is copied to the configured Trustpilot address.
- Professional advisers, regulators, law enforcement, or other parties where required by law or necessary to protect rights, safety, and security.
We do not sell personal data.
6. Retention
We retain personal data only for as long as needed for the purposes described here, including customer service, accounting, legal, fraud-prevention, and security needs. The application source code does not currently implement an automated retention or deletion schedule for all records. The MCP source code retains neither tool inputs nor outputs in a database or file. Infrastructure-log retention is controlled by the relevant hosting or security provider and is not defined in source code. Before this draft is published, VALA TECH 2026 LLC will adopt and publish verified retention periods and deletion procedures for each record category, including orders, payment records, eSIM activation data, email inbox/outbox records, SMS records, audit logs, analytics, provider records, and backups.
7. International transfers and security
Our providers may process data in the United States and other countries. We use reasonable technical and organisational safeguards designed to protect personal data, but no internet transmission or storage system is completely secure.
8. Your choices and rights
Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, object to or restrict certain processing, and withdraw cookie consent. You can decline non-essential cookies through our banner; see the Cookie Policy for current controls. To make a privacy request, contact info@shqiponjaesim.com. We may need to verify your identity before acting on a request.
The current account-deletion feature anonymises the account while retaining order records. It does not automatically delete or anonymise every order, payment, eSIM fulfilment or activation record, email inbox/outbox record, audit record, or provider record. Requests concerning those records are assessed under applicable law and the retention decisions described above.
9. Children and changes
Our services are not directed to children under 18, and we do not knowingly collect personal data from them. We may update this Policy when our practices or legal requirements change. The current version will be posted on this page.