LEGAL
Privacy Policy
Version 1.0 — Effective Date: 3 August 2026
1. Introduction
Mugen Links LLC (“we,” “us,” or “our”) is committed to
protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect
your personal information when you purchase and use MugenSIM eSIM services through
mugensim.com (“Site”).
This Policy applies to all customers worldwide, including those in the
European Economic Area (EEA) and the United Kingdom. Where you are located in the EEA or UK,
your rights are additionally governed by the General Data Protection Regulation (GDPR) (EU)
2016/679 and applicable local data protection laws.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
For the purposes of applicable data protection law, including the GDPR, the data controller responsible for your personal data is:
Mugen Links LLC, Tsukiji MS Building 4F, 4-10-16, Tsukiji, Chuo-ku, Tokyo, 104-0045, Japan. Contact: www.mugenlinks.com.
Our mobile network operator partner (“Operator”) acts as a data processor in respect of technical network provisioning data (see Section 4). The Operator may also process certain data as an independent data controller under Japanese telecommunications law, subject to their own privacy policy.
Shopify Inc. acts as a data processor in respect of payment and order processing data, subject to Shopify’s own Data Processing Agreement and Privacy Policy.
3. Personal Data We Collect
We collect and process the following categories of personal data:
3.1 Data You Provide Directly
-
Email address (for eSIM QR code delivery and order communications);
-
Credit card payment information (card number, expiration date, security code, name on card): processed directly by Shopify Payments via its PCI-DSS compliant infrastructure; Mugen Links does not store card details;
-
Order details (plan selected, purchase amount, date of purchase).
-
First name and last name (collected at checkout for billing purposes);
-
Billing address (street address, city, postal code, and country/region), collected for payment verification and fraud prevention;
-
Express payment wallet data (where you choose to pay via Google Pay, Apple Pay, or other digital wallets): your payment credentials are processed directly by the respective walletprovider (Google LLC, Apple Inc., or other) and are not stored by Mugen Links. Each walletprovider’s own privacy policy applies to that processing.
3.2 Technical Data Collected During eSIM Provisioning
The following technical data is collected automatically by the Operator during eSIM provisioning
and activation. This data is processed to deliver the Service and is held by the Operator as data
processor:
-
Profile activation code;
-
Activation code expiration date;
-
Profile download date and time;
-
Profile download status and result;
-
Device IMEI (International Mobile Equipment Identity) upon initial SIM insertion;
-
Terminal IMEI at initial network access;
-
Date and time of initial SIM insertion;
-
First access date;
-
PIN unlock code (technical identifier);
-
Line service termination date;
-
Service availability status;
-
Country code for use;
-
Daily data usage logs (volume in KB, by date).
Device IMEI constitutes personal data under applicable data protection law. It is collected solely for the technical purpose of eSIM provisioning, network authentication, and service delivery.
3.3 Data Collected Automatically via the Site
-
IP address and approximate geographic location;
-
Browser type and device information;
-
Pages visited and time spent on the Site;
-
Referral source.
This data is collected through Shopify’s standard analytics and is used for Site operation, security,
and service improvement.
4. Legal Basis for Processing (GDPR)
For customers in the EEA and UK, we process your personal data on the following legal bases:
Performance of a contract (Article 6(1)(b) GDPR): Processing your email address, order data, and technical provisioning data is necessary to deliver the eSIM service you havepurchased.
Legal obligation (Article 6(1)(c) GDPR): We may process certain data to comply with Japanese tax law (JCT obligations) and applicable telecommunications regulations.
Legitimate interests (Article 6(1)(f) GDPR): We process limited technical and usage data to detect fraud, ensure network security, and improve the Service. These interests are notoverridden by your data protection rights.
Consent (Article 6(1)(a) GDPR): Where we rely on consent (e.g., for marketing communications), you may withdraw consent at any time by contacting support@mugensim.com.
5. How We Use Your Personal Data
We use your personal data for the following purposes:
-
To process your order and deliver the eSIM QR code to your email address;
-
To activate and provision the eSIM service on the Operator’s network;
-
To communicate with you regarding your order, service status, or support requests;
-
To comply with our legal and tax obligations under Japanese law;
-
To detect, prevent, and investigate fraud or unauthorized use of the Service;
-
To operate and improve the Site and Service;
-
To respond to your inquiries and data subject rights requests.
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
6. Data Processors and Third-Party Recipients
We share your personal data with the following categories of recipients, strictly as necessary for the purposes set out in this Policy:
6.1 Shopify Inc.
Shopify processes order and payment data on our behalf as a dataprocessor. Shopify is GDPR compliant and processes data in accordance with its Data ProcessingAgreement. For more information, see Shopify’s Privacy Policy at shopify.com/legal/privacy.
6.2 Mobile Network Operator
Our Operator receives technical provisioning data (as described in Section 3.2) to activate and deliver the eSIM service. The Operator processes this data as a data processor on our behalf, and may also act as an independent data controller under Japanese telecommunications law for network management purposes.
Customer data is accessible only through the account to which the line plan has been assigned and is not shared with any third parties by the Operator beyond what is required for network operation.
6.3 Legal and Regulatory Authorities
We may disclose your personal data to competent authorities where required by law, court order, or regulatory obligation under Japanese or applicable foreign law.
We do not sell, rent, or otherwise commercially disclose your personal data to any third party.
6.4 Postmark / AC PM, LLC (Transactional Email)
Order confirmation emails, eSIM QR code delivery emails, and other transactional communications are sent via Postmark, a transactional email delivery service operated by AC PM, LLC, a US-based company and wholly owned subsidiary of ActiveCampaign LLC (“Postmark”). Postmark processes your email address and the content of transactional emails (including your QR code and order details) on our behalf as a data processor.
Key facts about Postmark’s data handling:
-
Data processed: your email address, email content, and email delivery activity (delivery status, opens, bounces).
-
Retention: Postmark retains message content and activity data for 45 days by default, after which it is automatically deleted.
-
Location: data is stored and processed in the United States.
-
Transfer mechanism: please check Postmark Data Processing Addendum (DPA) to handle cross-border data transfers under GDPR.
-
Postmark Privacy Policy: https://postmarkapp.com/privacy-policy
-
Postmark EU/GDPR information: https://postmarkapp.com/eu-privacy
7. International Data Transfers
Mugen Links is established in Japan. Japan has been recognized by the European Commission as providing an adequate level of protection for personal data (adequacy decision under Article 45 GDPR, adopted January 2019).
Shopify may process data in countries outside Japan and the EEA. Shopify implements appropriate safeguards for international transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission.
Wix Ltd. processes website visitor data in Israel. The European Commission has adopted an adequacy decision in respect of Israel under GDPR Article 45, recognizing Israel as providing an adequate level of data protection. Accordingly, transfers of personal data to Wix in Israel do not require additional safeguards such as SCCs. For APPI Article 24 purposes, Israel maintains a personal information protection system that Mugen Links has assessed as providing equivalent protection. Further details are available at wix.com/about/privacy.
Postmark (AC PM, LLC) processes email address and transactional email content in the United States. Cross-border transfer is governed by Standard Contractual Clauses (SCCs) under Postmark’s Data Processing Addendum. For APPI Article 24 purposes: the United States does not have a statutory framework equivalent to the APPI; Postmark maintains an internal personal information protection system. Further details are available at postmarkapp.com/eu-privacy.
Where international data transfers occur, we ensure that appropriate safeguards are in place in accordance with GDPR Chapter V requirements.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was
collected, including compliance with legal obligations.
-
Order and transaction data (email address, purchase records): retained for 5 years from the date of purchase, in accordance with Japanese tax and commercial law retentionrequirements.
-
Technical eSIM provisioning data (IMEI, activation data, usage logs): retained by the Operator for 3 months following the end of your service (i.e., expiry of the plan validity period orexpiry of the 180-day maximum validity, whichever occurs first). Data is deleted in bulk in thecalendar month following the end of the 3-month retention period.
-
Site analytics data: retained for up to 26 months in accordance with Shopify’s standard retention practices.
Following the expiry of the applicable retention period, personal data is securely deleted or anonymized.
9. Your Rights Under GDPR
If you are located in the EEA or UK,you have the following rights with respect to your personal data:
-
Right of access (Article 15): You may request a copy of the personal data we hold about you.
-
Right to rectification (Article 16): You may request correction of inaccurate or incomplete personal data.
-
Right to erasure (Article 17): You may request deletion of your personal data, subject to our legal retention obligations.
-
Right to restriction of processing (Article 18): You may request that we restrict processing of your data in certain circumstances.
-
Right to data portability (Article 20): You may request to receive your personal data in a structured, commonly used, and machine-readable format.
-
Right to object (Article 21): You may object to processing based on legitimate interests.
-
Right to withdraw consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
-
Right to lodge a complaint: You have the right to lodge a complaint with your local supervisory authority. In Japan, the relevant authority is the Personal Information ProtectionCommission (PPC). In the EU, you may contact your national data protection authority.
To exercise any of the above rights, please contact us at support@mugensim.com. We will respond within 30 days of receipt of your request. We may ask you to verify your identity before processing your request.
10. Rights Under Japanese Law
If you are located in Japan or your data is processed under the Act on the Protection of
Personal Information (APPI) of Japan, you have the right to:
-
Request disclosure of retained personal data we hold about you;
-
Request correction, addition, or deletion of inaccurate personal data;
-
Request cessation of use or erasure of personal data;
-
Request cessation of provision of personal data to third parties.
To exercise these rights, please contact us at support@mugensim.com.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal
data against unauthorized access, accidental loss, destruction, alteration, or disclosure.
These measures include:
-
Encryption of data in transit using TLS/SSL;
-
Access controls limiting personal data access to authorized personnel only;
-
Use of PCI-DSS compliant payment processing infrastructure through Shopify Payments;
-
Regular review of our data protection practices.
While we take all reasonable steps to protect your data, no method of transmission over the internet or method of electronic storage is 100% secure. In the unlikely event of a personal data breach affecting your rights and freedoms, we will notify you and relevant supervisory authorities as required by applicable law.
12. Cookies and Tracking Technologies
The Site uses cookies and similar tracking technologies operated by Shopify for essential site functionality, security, and analytics. By using the Site, you consent to the use of cookies in accordance with Shopify’s Cookie Policy.
You may manage your cookie preferences through your browser settings. Disabling certain
cookies may affect the functionality of the Site.
13. Children's Privacy
The Service is not directed at persons under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected personal data from a person under 18, we will take steps to delete such data promptly. If you believe we may have collected data from a minor, please contact us at support@mugensim.com.
14. Changes to This Privacy Policy
We may update this Privacy Policyfrom time to time to reflect changes in our practices, technology, legal requirements, or otherfactors. The updated Policy will be published on the Site with a revised effective date.
For materialchanges, we will take reasonable steps to notify you, such as by posting a prominent notice on theSite or sending an email to the address associated with your order.
Your continued use of theService after the effective date of any changes constitutes acceptance of the revised Policy
15. Contact
For any questions, requests, or complaints regarding this Privacy Policy or our data processing practices, please contact:
Mugen Links LLC
Attn: Privacy / Data Protection
Tsukiji MS Building 4F, 4-10-16, Tsukiji, Chuo-ku, Tokyo, 104-0045, Japan
Website: www.mugenlinks.com
