PRIVACY POLICY
PRIVACY POLICY
Last Updated: July 15, 2026
IRON UNITED PTE. LTD. ("Company", "we", "us", or "our") is committed to protecting the privacy of our users ("User", "you"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website, mobile application, and use our SIMTOSS services (collectively, the "Services").
This Privacy Policy has been prepared in accordance with the Singapore Personal Data Protection Act 2012 ("PDPA") and, where applicable, the General Data Protection Regulation ("GDPR").
1. Collection of Personal Data
We collect personal data that you voluntarily provide to us when you register for an account, purchase data plans, or interact with our support team. The categories of personal data we collect include:
Account & Profile Data: Email address, password, name, nickname, and account creation date.
Transaction & Billing Data: Payment details (processed securely via global payment gateways such as Stripe or PayPal), billing address, and transaction history.
Technical Device Data (for eSIM/USIM delivery): Device model, EID, IMEI, and operating system information required to provision and activate the eSIM.
Verification Data (for Verified Members): Professional or corporate email address, and official credentials/documents to verify your eligibility for exclusive industry tariffs.
Alliance Service Data (for Airport Transfers): Passenger name, contact number, flight details, pickup/drop-off locations, and luggage specifications.
Automatically Collected Data: IP address, browser type, operating system, access times, pages viewed, and device identifiers collected via cookies and tracking technologies.
2. Purposes for Processing Personal Data
We process your personal data for the following purposes based on contractual necessity, legal obligations, or our legitimate business interests:
Service Provision: To process your transactions, provision and activate eSIM data plans, deliver physical USIM cards, and manage your account.
Identity Verification & Anti-Fraud: To implement the 'One Person, One Account' policy, prevent promotional abuse, and ensure compliance with age restrictions (14 years or older).
Alliance Service Intermediary: To forward your booking information to local transport Partners for fulfilling airport transfer reservations.
Customer Support: To investigate and resolve technical connectivity issues, process cancellations, and handle refund requests while you are abroad.
Marketing & Promotions (Subject to Consent): To send you updates, promotional offers, and newsletters. You may opt-out of marketing communications at any time.
3. Disclosure and Transfer of Personal Data
To provide our global Services, we may share your personal data with third-party service providers and corporate affiliates under strict confidentiality agreements:
Cross-Border Telecommunication Partners: We transfer technical identifiers (EID/IMEI) to overseas mobile network operators and roaming infrastructure providers to activate your data plan at your destination.
Local Transport Operators: For Alliance Services (Airport Transfers), your contact details, flight data, and pickup locations are shared with the specific local chauffeur or transport company executing the transit.
Payment Gateways: Credit card and payment authentication details are transmitted directly to PCI-DSS compliant global payment processors.
Legal Compliance: We may disclose your data if required to do so by Singapore law or in response to valid requests by public authorities (e.g., a court or government agency).
4. Retention of Personal Data
We will only retain your personal data for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Account Information: Retained for the duration of your active membership. Upon account deletion, data is destroyed, except where unique identity hashes (DI/device signatures) are held for up to 6 months to prevent registration fraud and bonus abuse.
Financial Transactions: Retained for a minimum of 5 to 7 years in compliance with Singapore tax regulations and international accounting standards.
5. Your Rights Under PDPA and GDPR
Depending on your jurisdiction, you have certain rights regarding your personal data. Under the Singapore PDPA and GDPR, these include the right to:
Access: Request a copy of the personal data we hold about you and information about how it has been used or disclosed.
Correction: Request the correction or update of inaccurate or incomplete personal data.
Withdrawal of Consent: Withdraw your consent to the collection, use, or disclosure of your personal data at any time (e.g., marketing opt-out).
Erasure ("Right to be Forgotten" - GDPR applicable): Request the deletion of your personal data under certain conditions, subject to our statutory retention obligations.
Data Portability: Request the transfer of your data to another service provider in a structured, commonly used format.
To exercise any of these rights, please contact our Data Protection Officer at the email address provided in Section 7.
6. Cookies and Tracking Technologies
We use cookies, web beacons, and similar tracking technologies to enhance your browsing experience, analyze platform traffic, and deliver personalized content. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Services.
7. Data Protection Officer (DPO)
If you have any questions, concerns, or complaints regarding this Privacy Policy or our data handling practices, please contact our Data Protection Officer at:
IRON UNITED PTE. LTD.
Attn: Data Protection Officer
Email: info@simtoss.com
Address: 77 High Street, #10-12B, High Street Plaza, Singapore 179433