Skip to content

Draft for review. This page isn’t final and doesn’t yet form part of any agreement.

Privacy policy

Last updated 8 October 2026

CyberBakery Pty Ltd ("Landfall", "we") collects as little about you as we can to sell you an eSIM and support it. This policy explains what we collect, why, who we share it with, and your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

What we collect

  • Your email address, to send your eSIM, receipts and support replies, and to let you sign in.
  • Order details: what you bought, when, the price and currency, and the eSIM’s identifiers (such as its ICCID) and data usage.
  • Payment details: Stripe processes your card. We receive only the card brand, the last four digits, and Stripe’s fraud assessment, never the full number.
  • Technical details: your IP address and the country it’s in, your browser or app version, and a security check result, used to prevent fraud and work out the tax on your order.
  • What you tell us when you contact support.

We don’t collect your name, postal address, phone number or location history, and we don’t use advertising trackers.

Why we use it

  • To issue, deliver and support your eSIM and any top-ups.
  • To take payment, calculate tax and keep the records the law requires.
  • To prevent fraud and misuse, including checking some orders before we issue them.
  • To tell you about your data usage and your plan expiring.
  • To fix problems and improve the service.

We don’t sell your personal information, and we don’t send marketing email.

Who we share it with

We share information only with the service providers that help us run Landfall, only what each needs, and under contracts that require them to protect it. Some are overseas:

  • Stripe: payments and fraud screening (Australia, United States)
  • Our eSIM supplier (eSIM Access): issuing eSIMs and data plans (location to be confirmed)
  • Mailgun: sending order emails (United States)
  • Cloudflare: security, bot checks and network delivery (worldwide)
  • Vercel: hosting the website (United States, worldwide edge)
  • Fly.io: hosting our systems (Australia (Sydney))
  • Neon: our database (Australia (Sydney))
  • Upstash: short-lived data such as rate limits (Australia (Sydney))
  • Sentry: error reports, with personal details removed (United States)
  • Google Firebase: app notifications, if you use our app (United States)

We may also disclose information when the law requires it, for example to a court or a law enforcement agency with lawful authority.

How we protect it

Install details for your eSIM are encrypted in our database and never written to logs. Our systems remove email addresses, card details and eSIM identifiers from error reports and logs. Only staff who need it can see order details, and they sign in through Cloudflare Access.

How long we keep it

We keep order and payment records for 7 years, because Australian tax law requires it. Support messages are kept for 2 years. Security logs are kept for 90 days.

Your rights

You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete what we don’t need to keep. Email privacy@landfallesim.com; we reply within 30 days. If you live in the EU or UK, you also have rights under the GDPR, including to object to processing and to complain to your local data protection authority.

Cookies and storage

We don’t use advertising or analytics cookies. Your browser stores your chosen currency and theme, and, for the current tab only, your order link and sign-in. Cloudflare may set a cookie as part of its security check.

Complaints

If you’re unhappy with how we’ve handled your information, email privacy@landfallesim.com and we’ll respond within 30 days. If you’re still not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes

We’ll update this page if what we collect or who we share it with changes. See also our terms of service.

Questions? Contact us.

Privacy policy · landfall