Lettuce Connect

Privacy Policy

LettuceConnect Pty Ltd (“Lettuce Connect”, “we”, “us”) is the data controller for personal information collected through this site. We handle it in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Last updated: 31 August 2026

1. What we collect

We collect what we need to sell you an eSIM and support it: your name and email address; order and eSIM details, including the plan, destination, and activation status; data-usage figures reported by the network partner for your eSIM; payment confirmation from our processor (we never see or store your full card number); and technical data such as your IP address, device and browser type, and cookies used to keep you signed in, remember your cart, and measure site performance.

2. How we use it

We use your information to process orders and provision eSIMs, show you your usage and enable one-tap top-ups, send transactional email (order confirmations, QR codes, and usage alerts), provide customer support, detect and prevent fraud and abuse, meet legal and tax obligations, and improve the service. We rely on your consent for any non-essential analytics or marketing, which you can withdraw at any time.

3. Sharing and third parties

We do not sell your personal information. We share it only with the sub-processors needed to run the service:

  • Stripe — payment processing.
  • Our eSIM provider — to provision your eSIM and retrieve usage data.
  • Resend — to deliver transactional email.
  • Our hosting and error-monitoring providers — to operate and support the site.

Some of these providers process data outside Australia. We also disclose information where required by law or to protect our rights.

4. Retention

We keep account and order records for as long as your account is active and for up to seven years afterwards to meet Australian tax and consumer-law requirements. Activation codes are encrypted at rest and deleted once an eSIM is activated. Aggregated, de-identified statistics may be kept indefinitely.

5. Security

We protect your information with encryption in transit, encryption of sensitive fields at rest, access controls, and audit logging. No system is perfectly secure, but we will notify you and the OAIC of an eligible data breach as required by law.

6. Your rights

You can ask us to access or correct the personal information we hold about you, delete it where we are not required to keep it, or export your order history. You can opt out of non-essential analytics and marketing at any time. To make a request or raise a privacy concern, contact us using the details below; if you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (OAIC).

7. Changes and contact

We may update this policy from time to time; the current version is the one published here, dated above. For any privacy request or question, email [email protected].

See also our Terms of Service.