10% off with codeSUMMER10enjoy!

Home

Privacy policy

Last updated: July 2026

1. What we collect

To provide the service we store your email address and name (from signing in with Google), a phone number if you gave one at checkout, and your order details — destination, plan, amount and invoice. We also keep basic usage data for the eSIM you bought: when it was installed, when it first used data, and how much data it used each day. Card details never reach our servers — your browser sends them straight to our payment processor and we get back only a single-use token.

2. How we use it

To send your eSIM and activation details, to support you, to manage your order, and to remind you before your trip. If you allowed it, we also use Google's measurement tools — Analytics and Google Ads conversion measurement — to understand how the site is used and which ads bring customers. We don't sell personal data. For conversion attribution only, your email may be sent to Google as a one-way hash — never in plain text.

3. Who else sees it

SUMIT (payments and tax invoices — name, email, phone and amount), eSIM Go (our eSIM supplier — receives an internal order reference only, no name or email), Resend (sending our emails), Google (sign-in, and with your approval Analytics and Google Ads conversion measurement), Vercel and Neon (hosting and database), and Anthropic (the support assistant — receives your order details so it can answer, and only when you open a chat). We don't store support conversations.

4. How long we keep it

Invoices and payment records are kept for about seven years, as Israeli law requires. Phone numbers and technical error messages are deleted after 24 months; trip dates after six months; daily usage history after six months (the running total is kept); supplier system messages after 90 days; expired sign-in codes and sessions are deleted automatically. An expired plan's activation code stops being available.

5. Your rights

You can ask to see the data we hold about you, correct it, or have it deleted. In practice we erase every identifying detail — name, email, phone, preferred destinations and trip dates — and keep only the invoice line the law requires, with no name behind it. Contact us at team@wing.travel. Note that database backups roll for a few more days after a deletion, and the providers listed above retain data under their own policies.

6. Cookies

Essential cookies only by default: sign-in, language, currency and your theme choice. Google's measurement tools run in a restricted mode by default: no measurement cookies and no identifying data — basic anonymous signals only. Measurement cookies are set only after you approve. You can change your choice at any time by clearing this site's cookies in your browser.

7. Security

Traffic is encrypted, card details are never stored by us, and access to customer data is limited to our team and logged. That said, no method is completely secure, and we work to minimise risk.