SIMDU← Back to SIMDU

Privacy Policy

EAssure Solutions India Private Limited

Effective 11 July 2026 · Last updated 13 August 2026

This Privacy Policy explains how EAssure Solutions India Private Limited (“SIMDU”, “Company”, “we”, “our”, or “us”) collects, uses, stores, shares and protects your personal information when you use the SIMDU website, software and related services (together, the “Services”).

SIMDU has not launched. Today the Services consist of this website and a free email waitlist, and that is all this policy currently describes in practice. This website sets no cookies and builds no profile of you: its analytics are configured to store nothing on your device, and it carries no advertising or social tag. Section 4 describes exactly what is measured. Sections 7, 8 and 9 describe accounts, payments and software telemetry that do not exist yet; they are published in advance and take effect only when those parts of the Services are released.

1. Scope

This policy applies to visitors to simdu.co, to people who join the SIMDU waitlist, and to anyone who contacts us for support. It will also apply to users of the SIMDU software and any account system when those are released.

It does not apply to third-party websites or services that we do not control, nor to Microsoft Flight Simulator or any add-on aircraft you use with SIMDU.

2. Definitions

Personal information means information that identifies, relates to, or can reasonably be associated with an individual.

Services means the SIMDU website, waitlist, software, documentation and customer support.

Software means the SIMDU mobile application and bridge application, when released.

You means any individual using the Services.

3. What we collect today

This section describes the whole of our current processing. It is short because the site does very little.

3.1 Waitlist reservation

When you reserve a place on the waitlist, we record:

  • your name, as you typed it, trimmed and capped in length;
  • your email address, as you typed it, normalised to lowercase;
  • the package you selected from the list on the form;
  • your country, as a two-letter code chosen from a list;
  • the date and time of your reservation;
  • a fixed source label recording that the reservation came from this website; and
  • the payment reference, amount, currency and payment time returned to us by Razorpay — see section 8.

Your name is the only free-text field on the form. It is stripped of control characters and capped at 120 characters before it is stored. The package and country selections are validated against fixed lists, so neither can carry anything you did not choose from it.

We never receive your card number, expiry date or security code. Those are given directly to Razorpay — see section 8.

3.2 Abuse prevention

To stop a script submitting the form thousands of times, our server counts recent submissions per network address. It does this by computing a keyed cryptographic hash of the caller’s IP address and counting against that hash.

The hash is held in memory only, for at most one hour, and is discarded when the server process restarts. Your IP address itself is never written to our database and never stored alongside your waitlist entry. The hash cannot be reversed to recover the address.

The legal basis for this is our legitimate interest in protecting the Services from abuse. It is not used for analytics, profiling, advertising or marketing.

3.3 Server logs

Our hosting provider generates operational logs when a page is requested. These may contain an IP address, the page requested, a timestamp, and browser and operating system information. They are generated and retained by the hosting provider for the purposes of operating, securing and debugging the service, and we use them only for those purposes.

3.4 Website analytics

We measure how the website is used with Google Analytics 4, run in cookieless mode. When you open a page, the tag sends Google: the page address, the site that referred you, your browser and device type and screen size, an approximate location derived from your IP address, and the time.

Google receives your IP address in order to make that request at all, and uses it to derive the approximate location before discarding it; it is not passed to us and we never see it. What we see is aggregate: how many people opened the site, from where, on what kind of device, and which parts of the page they reached.

Nothing is stored on your device and no identifier persists between page loads, so we cannot recognise you on a later visit and cannot connect your visit to your waitlist reservation, your email address or your payment. Google Signals and ad personalisation are switched off, so your visit is not added to a Google advertising profile.

The legal basis is our legitimate interest in understanding whether the site works and where people leave it. Because nothing is written to your device, no consent is required under the UK Privacy and Electronic Communications Regulations or the EU ePrivacy Directive — which is why you are not being asked to dismiss a banner. See our Cookie Policy.

3.5 Support correspondence

If you email us, we keep your message and our reply for as long as needed to deal with your request and to keep a record of it.

4. Cookies, analytics and tracking

This website sets no cookies. It runs one analytics tool, Google Analytics 4, configured so that it writes nothing to your device — no cookie, no local storage, no identifier that outlives the page. It carries no session recording, no advertising tag, no social media pixel, no third-party font, and no consent banner, because nothing is stored on your device for you to consent to.

Section 3.4 describes exactly what that tag sends and what we can see as a result. In short: page addresses, referrers, approximate country, browser and device type — and no way to recognise you on a later visit.

We do not track you across websites and we do not build a profile of you. Google Signals and ad personalisation are switched off in our configuration, so your visit is not joined to a Google advertising profile.

We do not currently behave differently in response to a Do Not Track or Global Privacy Control signal. Those signals principally address the sale of personal information and cross-site profiling, and we do neither. If you would rather not be counted at all, blocking the Google Analytics script in your browser is sufficient and breaks nothing on this site.

If this changes we will update our Cookie Policy and this section first, and where the law requires consent we will ask for it before setting anything.

5. How we use your information

We use what we collect to:

  • hold your place on the waitlist;
  • send you a confirmation that your registration was received;
  • notify you about early access, launch and significant development milestones;
  • understand which aircraft to support first, in aggregate;
  • respond to your support enquiries;
  • protect the Services from abuse and fraud; and
  • comply with our legal obligations.

We do not send marketing for anything other than SIMDU, and every email we send you carries a one-click unsubscribe.

6. Legal bases

Where applicable data protection law requires a legal basis:

  • Consent — sending you waitlist and launch emails. You may withdraw it at any time by unsubscribing or by emailing us, and doing so removes you from the waitlist.
  • Legitimate interests — rate limiting, abuse prevention, security monitoring, keeping our records, and measuring how the website is used. We have considered these against your rights and limited the data accordingly: the analytics store nothing on your device and cannot identify you, which is the limit we chose for that one.
  • Legal obligation — where we are required to retain or disclose information.
  • Performance of a contract — when you licence the Software, once that is available.

7. Accounts (not yet in operation)

There is no SIMDU account system at present and you cannot create an account. When one is released, we expect to process an account identifier, credentials, licence and activation status and account preferences, and we will update this policy before that happens. Credentials will be stored hashed and never in plain text.

8. Payments

The one payment this website takes is the $1.00, ₹99, £1.00 or €1.00 waitlist reservation. It is handled by Razorpay, a third-party payment processor: you are taken to Razorpay’s secure checkout and your card or payment instrument details are given to them rather than to us.

SIMDU does not collect, see or store complete card numbers, expiry dates, security codes or banking credentials. What we receive back from Razorpay and keep is the payment identifier, the order identifier, the amount, the currency and the time of payment. We use that to confirm your reservation, to apply your discount at launch, to keep accounting records, to prevent fraud and to meet our tax obligations.

Razorpay is a separate controller of the payment data you give them, and their own privacy policy governs it. If the processor changes, this policy and our Refund Policy will be updated to name the new one before the change takes effect.

9. Software diagnostics (not yet in operation)

The SIMDU Software is not released. When it is, it will work by exchanging data with your flight simulator over your own local network. In normal operation that data stays on your network and is not transmitted to us.

If the Software crashes, it may collect diagnostic information about the session — the interface state, the connected aircraft type and technical logs — to investigate the fault. That information will be used only for troubleshooting and reliability, retained only as long as needed for it, and this policy will describe the mechanism in detail before the Software ships.

10. Who we share it with

We do not sell your personal information, and we do not share it for anyone else’s marketing.

We use a small number of service providers who process data on our behalf, under contract and only on our instructions:

  • Our hosting provider — serves this website and runs the waitlist endpoint.
  • Our database provider — stores waitlist registrations.
  • Our email provider — delivers the confirmation and any later waitlist emails.
  • Google — provides the website analytics described in section 3.4. It receives page and device information and your IP address at the moment a page loads; it stores nothing on your device on our behalf, and it is given nothing that identifies you, no email address and no payment information.

We may also disclose information to professional advisers, to authorities where the law requires it, and to a successor entity in a merger, acquisition or sale of assets — in which case we would notify you.

11. International transfers

Our providers operate infrastructure outside India, so your information may be processed in other countries. Where it is transferred internationally we rely on the safeguards those providers operate, including standard contractual clauses where applicable.

12. How long we keep it

Waitlist registrations are kept until SIMDU launches and the launch communications are complete, or until you ask us to remove you — whichever comes first. If the product is cancelled we will delete the list.

Rate-limit hashes are held in memory for at most one hour.

Analytics records are held by Google for the retention period configured on our property. They contain no identifier for you, so there is nothing in them to link back to a person once the page has closed.

Support correspondence is kept for as long as needed to handle the matter and to keep a reasonable record of it.

When information is no longer needed we delete or anonymise it.

13. Security

We take reasonable technical and organisational measures to protect personal information, including transport encryption on every request, server-side validation and rate limiting on the waitlist endpoint, a restrictive content security policy, strict transport security, and keeping database credentials server-side only and out of the browser.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information and the law requires it, we will notify you and the relevant authority.

14. Your rights

Subject to applicable law, you may ask us to:

  • confirm what personal information we hold about you;
  • provide a copy of it;
  • correct it if it is wrong;
  • delete it;
  • restrict or object to how we use it; and
  • withdraw your consent to our emails.

For the waitlist specifically, the fastest route is the unsubscribe link in any email we send you, which removes your entry. Otherwise email support@simdu.co and we will respond within one month. We may ask you to confirm your identity — ordinarily by replying from the address you registered — before we act on a request.

If you are unhappy with our response you may complain to your local data protection authority.

15. Children

You must be at least 18 years old to join the waitlist, hold an account, or accept these policies. A person under 18 may use the Services only under the supervision of a parent or legal guardian, who accepts these policies and remains responsible for that use.

We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact support@simdu.co and we will delete it.

16. Third-party links

The Services may link to third-party websites. We are not responsible for their content, security or privacy practices, and we encourage you to read their policies.

17. Changes

We may update this policy. The current version is always at simdu.co/privacy, and the “last updated” date at the top of this page changes whenever the substance does. Where a change is material we will make reasonable efforts to tell you — by email to waitlist members, or by a notice on the site.

18. Contact

For any question or request about this policy or your personal information:

EAssure Solutions India Private Limited
Email: support@simdu.co
Web: https://simdu.co

Concerns that are not resolved through ordinary support may be escalated to our grievance officer — see Contact.

19. Governing law and severability

This policy is governed by the laws of the Republic of India, without regard to conflict of law principles. Nothing in it limits any right that cannot be excluded under applicable privacy or consumer protection law.

If any provision is found invalid or unenforceable, the remaining provisions continue in full force, and the invalid provision is modified only so far as needed to make it enforceable.

20. Related documents

This policy should be read with our Terms & Conditions, Waitlist Terms, Cookie Policy, End User Licence Agreement and Refund Policy.

  • Terms
  • Privacy
  • Cookies
  • Waitlist
  • EULA
  • Refunds
  • Contact

© 2026 EAssure Solutions India Private Limited. All rights reserved.