Privacy policy

This website and the “eSIMony” mobile app are operated with the involvement of Shopify, which enables us to provide our services to you. The following Privacy Policy describes the type, scope and purpose of the processing of personal data in the context of the provision of our services, our online offering, our online shop, the “eSIMony” mobile app, the customer account, the purchase and management of travel eSIMs, the “eSIMiles” bonus points and loyalty program, as well as all connected websites, functions, content and external online presences, for example social media profiles. With regard to the terms used, we refer to the definitions in Article 4 of the General Data Protection Regulation, GDPR.

1 Definition of terms

Our Privacy Policy contains the terms used by the European legislator for the adoption of the General Data Protection Regulation, GDPR.

Among other things, we use the following terms:

Personal data: any information relating to an identified or identifiable natural person, data subject. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, for example a cookie, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Data subject: any identified or identifiable natural person whose personal data is processed by the controller.

Processing: any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, deletion or destruction.

Pseudonymization: processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures.

Profiling: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.

Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Processor: a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller.

Third party: a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

2 General notes on mandatory information

Information on the responsible entity

The controller responsible for data processing on this website and in the “eSIMony” mobile app is:

HD Solutions GmbH
Danckelmannstr. 9
14059 Berlin
Germany

Email: hello@esimony.com
Phone: +49-30-95 999 65 56

Managing directors: Holger Zimmermann, Diana Bohlinth
Commercial register entry: HRB 250803
Register court: Charlottenburg Local Court (Berlin)
VAT ID: DE291049963

If you have any questions about the collection, processing or use of your personal data, or if you wish to request information, correction, restriction or deletion of your data, or if you wish to withdraw your consent, you can contact us directly.

Processed data

We process the following data:

  • Inventory data, for example names, addresses
  • Contact data, for example email addresses, telephone numbers
  • Content data, for example texts, photos, videos
  • Usage data, for example websites visited, interest in content, access times
  • Metadata, for example device information, IP addresses
  • Customer account and login data, for example email address, name, customer ID, authentication and session data
  • App data, for example app version, device information, operating system, login status and technical usage data
  • eSIM data, for example order/eSIM allocation, ICCID, installation data, activation information, status and usage snapshots
  • Push notification data, for example push token, device token, notification type and delivery status
  • App error and diagnostic data, for example crash reports, error messages, device and diagnostic data
  • Bonus program data, for example points balance, points movements, status level, referral relationships, welcome bonus data and pending or released point status
  • Cancellation, withdrawal and refund data, for example withdrawal requests, cancellation status, affected eSIMs, timestamps and refund status

Purpose of processing

We process personal data for the following purposes:

  • To make our online offering available
  • To respond to contact requests and communicate with users
  • Security measures
  • Reach measurement and marketing
  • Providing, operating and securing the “eSIMony” mobile app
  • Creating, managing and securing the customer account and login
  • Allocating orders, customer accounts and eSIMs
  • Providing eSIM installation data, QR codes, activation information, status displays and usage displays
  • Sending order, eSIM, usage, expiry, security and support notices
  • Error analysis, crash monitoring and technical improvement of the app
  • Operating the “eSIMiles” bonus points and loyalty program
  • Operating the referral program within eSIMiles
  • Managing welcome bonuses, pending point status and release after waiting periods in eSIMiles
  • Processing cancellation, withdrawal and refund requests, including via the native withdrawal function in the app
  • Prevention of misuse, fraud prevention and technical security

Legal basis

The legal basis for our data processing is Article 13 GDPR. If the legal basis is not mentioned in this Privacy Policy, the following applies to users from the area of application of the General Data Protection Regulation, GDPR, i.e. the EU and the EEA:

  • The legal basis for obtaining consent is Article 6(1)(a) and Article 7 GDPR.
  • The legal basis for processing for the fulfillment of our services and the implementation of contractual measures as well as answering enquiries is Article 6(1)(b) GDPR.
  • The legal basis for processing to fulfill our legal obligations is Article 6(1)(c) GDPR.
  • In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) GDPR serves as the legal basis.
  • The legal basis for processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller is Article 6(1)(e) GDPR.
  • The legal basis for processing to preserve our legitimate interests is Article 6(1)(f) GDPR.
  • The processing of data for purposes other than those for which it was collected is governed by Article 6(4) GDPR.
  • The processing of special categories of data in accordance with Article 9(1) GDPR is governed by Article 9(2) GDPR.

For the provision of app functions, the customer account, eSIM management, order allocation and the “eSIMiles” bonus program, we process personal data in particular on the basis of Article 6(1)(b) GDPR, insofar as the processing is necessary for the performance of a contract, for pre-contractual measures or for carrying out program participation.

Where we process personal data for app security, error analysis, prevention of misuse, fraud prevention, enforcement of our terms or securing our systems, this is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and misuse-free provision of our services.

Where we process personal data due to statutory retention, accounting or tax obligations, this is carried out on the basis of Article 6(1)(c) GDPR.

Rights of data subjects

You have the right to obtain confirmation as to whether personal data concerning you is being processed, as well as access to this data and further information, including a copy of the data, in accordance with legal requirements. You also have the right to request completion or correction of inaccurate data concerning you.

Furthermore, you have the right to request the immediate deletion of the relevant data or, alternatively, the restriction of processing.

You have the right to receive the data concerning you that you have provided to us and to request its transmission to other controllers. You also have the right to lodge a complaint with the competent supervisory authority.

Right of withdrawal

You have the right to withdraw your consent at any time. An informal email to us is sufficient. The legality of the data processing carried out until withdrawal remains unaffected by the withdrawal.

Right of objection

You may object to the future processing of data concerning you at any time in accordance with legal requirements. In particular, you may object to processing for direct marketing purposes.

Deleting data

In accordance with applicable laws, the data processed by us will be deleted or restricted in its processing. Unless otherwise stated in this Privacy Policy, we delete the data we store as soon as it is no longer required for its purpose. Data that may not be deleted due to statutory retention obligations or that is required for other legally permissible purposes will be restricted in processing.

This means that such data will be blocked and not processed for other purposes. This applies, for example, to data that must be stored for commercial or tax law reasons.

You can also delete your customer account via the account deletion function provided in the app or request deletion via support.
In the app, you can find this option in the profile area via the ‘Delete account’ button.

After an account deletion request, personal data will be deleted or anonymized to the extent it is no longer required for contract processing, statutory retention obligations, documentation purposes, prevention of misuse, open matters or the establishment, exercise or defense of legal claims.

Updates to the Privacy Policy

Please regularly inform yourself about the content of our Privacy Policy, as we update it whenever necessary. We will inform you if the changes require your cooperation, for example consent, or other individual communication.

Business-related processing

We also process the following data from our customers, interested parties and business partners for the purpose of providing contractual services and customer care, as well as for marketing, advertising and market research:

  • Contract data, for example subject matter of the contract, term, customer category
  • Payment data, for example payment history, insofar as we receive it
  • Order data, for example order number, purchase amount, purchased products, payment status and refund status
  • eSIM data, for example eSIM allocation, ICCID, installation data, status and usage information

3 “eSIMony” mobile app, customer account and eSIM management

Customer account, login and authentication in the app

Certain functions of the “eSIMony” mobile app require a customer account. Authentication is carried out via Shopify Customer Account or Shopify functions used for this purpose.

In particular, email address, name, customer ID, login status, session and authentication data and technical login information may be processed.

After successful login, a session token may be securely stored on your device, for example in the iOS Keychain or Android Keystore. This is used to maintain the session and make repeated logins easier.

If you activate optional biometric login, for example Face ID or Touch ID, biometric authentication is carried out via the security functions of your device or operating system. Raw biometric data remains on your device. The app only receives a technical yes/no confirmation as to whether authentication was successful.

The legal basis is Article 6(1)(b) GDPR. Where processing serves security, fraud prevention or prevention of misuse, the legal basis is Article 6(1)(f) GDPR.

Recipients may include Shopify, hosting providers, technical app service providers and support service providers.

The data is stored for as long as the customer account exists and processing is necessary for the purposes described above. Statutory retention obligations remain unaffected.

eSIM data and app backend

To provide, install, manage and top up travel eSIMs, we process app-related and order-related eSIM data. This may include in particular order number, customer ID, order/eSIM allocation, ICCID, booked eSIM product, installation data, QR code data, activation information, activation status, status and usage snapshots, validity, expiry and top-up data.

Installation data is stored in encrypted form.
Encryption is performed server-side using AES-256-GCM (authenticated encryption) with a randomly generated initialization vector per record. The key is held exclusively on the server side and is not stored in the app; decrypted installation data is accessed only by the backend where required for provisioning, display or support.

The purpose of processing is to allocate purchased eSIMs to the customer account, provide installation data, display status and usage, enable top-ups, perform technical error analysis and handle support cases.

The legal basis is Article 6(1)(b) GDPR. Where processing is carried out for error analysis, system security, prevention of misuse or fraud prevention, the legal basis is Article 6(1)(f) GDPR.

Recipients may include eSIM network providers or eSIM provider partners, hosting providers, technical backend service providers, Shopify, support service providers and IT service providers.

eSIM and order data is stored for as long as this is necessary for contract performance, provision of the eSIM, app display, support, traceability of purchases and top-ups and compliance with statutory retention obligations.

Installation, status and usage data is stored for the duration of the contractual or customer-account relationship and is then deleted or anonymized once it is no longer required for providing the eSIM, in-app display, support and the traceability of purchases and top-ups. Status and usage snapshots are continuously updated and kept only at the level of recency required. Statutory retention obligations, in particular commercial and tax retention periods of up to ten years for invoice- and order-related data, remain unaffected.

Withdrawal, cancellation and refund function in the app

Where the app provides a native withdrawal function, for example via the button “Withdraw from contract”, we process the data required to receive, document and handle your withdrawal request.

This may include in particular customer account data, order number, affected eSIM or eSIMs, time of the request, withdrawal or cancellation status, refund status, communication data and technical log data required for documentation and security.

The purpose of processing is to receive and process withdrawal requests, cancellations and refunds, allocate them to the relevant order or eSIM, document the request and, where applicable, invalidate affected eSIMs or mark them as canceled.

The legal basis is Article 6(1)(b) GDPR where processing is necessary for contract performance or for handling statutory cancellation or withdrawal rights. Where processing is required for statutory documentation or retention obligations, the legal basis is Article 6(1)(c) GDPR. Where processing serves misuse prevention, legal defense or technical security, the legal basis is Article 6(1)(f) GDPR.

Recipients may include Shopify, payment service providers integrated into Shopify Checkout, eSIM provider partners, hosting providers, technical backend service providers, mail service providers, support service providers and tax, legal or accounting service providers.

The data is stored for as long as this is necessary for processing the withdrawal, cancellation or refund, for documentation, for traceability of the order and for compliance with statutory retention obligations.

Travel groups: processing of fellow travelers' data

Using the “Travel groups” feature, you can buy eSIMs not only for yourself but also for fellow travelers. To do so, you enter each fellow traveler’s name and email address. We process this data in order to provide the respective eSIM and to send the associated activation information (in particular the QR code and installation data) by email to the address you provide for the fellow traveler.

We process in particular the name and email address of the fellow traveler, the assignment to the order and to the respective eSIM, as well as the sending, delivery and error status of the email.

The travel groups you create, including the names and email addresses of the fellow travelers, are stored locally on your device. For the purchase and delivery, the name and email address of the respective fellow traveler are transmitted to Shopify (as part of the order) and to our backend and our email service provider, to the extent required to provide and send the eSIM.

The legal basis in relation to you as the purchaser is Art. 6(1)(b) GDPR. In relation to the fellow travelers, the legal basis is our legitimate interest and the fellow traveler’s interest in carrying out the order you placed and in delivering the purchased eSIM (Art. 6(1)(f) GDPR). You warrant that you are entitled to provide us with the fellow travelers’ data for this purpose.

Recipients of the data may include Shopify, our hosting provider and our email service provider. The storage period depends on the fulfilment of the order and on statutory retention obligations. Fellow travelers may exercise their data subject rights at any time via the entity named under “Information on the responsible entity”.

Push notifications

The app may send push notifications where you have allowed them on your device.

In particular, push tokens or device tokens, app and device information, language setting, notification type and delivery status may be processed.

Push notifications are delivered via Apple Push Notification service, APNs, or Google Firebase Cloud Messaging, FCM.

The purposes of push notifications are in particular order notices, eSIM provision and activation notices, usage and remaining volume notices, expiry and validity notices, top-up notices, security-related or support-related app messages and notices relating to the bonus program, where there is a legal basis for this.

The legal basis for transaction-related and functionally necessary push notifications is Article 6(1)(b) GDPR. The legal basis for security-related notifications is Article 6(1)(f) GDPR. For promotional push notifications, we obtain separate consent where required. The legal basis is then Article 6(1)(a) GDPR.

You can deactivate push notifications at any time via your device settings.

Recipients may include Apple, Google, hosting providers and technical push service providers.

Push tokens are stored for as long as the push function is enabled on the device and the customer account exists. On logout, deactivation of notifications or account deletion, the associated push token is decoupled from the account and marked invalid; invalid tokens are subsequently deleted.

Error, crash and performance monitoring with Sentry

To detect, analyse and fix errors, crashes and performance issues in the app, we may use Sentry.

In particular, device information, operating system, app version, technical diagnostic data, crash reports, error messages, time of the error, technical event logs, IP address and, where necessary, user or session identifiers may be processed.

The purpose of processing is the technical stability, security and improvement of the app as well as the analysis and resolution of technical problems.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in providing the app securely, stably and functionally.

Where error reports may contain personal content, they will be minimized, shortened, masked or pseudonymized where possible.

The recipient is in particular Sentry or the provider used for this purpose.
Error and crash monitoring with Sentry is technically prepared in the app but is not active at launch: data is only transmitted to Sentry if the feature is enabled via a corresponding access key (DSN). In that case the provider is Functional Software, Inc. (Sentry), 45 Fremont Street, San Francisco, CA 94105, USA, acting as a processor; the transfer to the USA is based on appropriate safeguards (see the section on transfers to third countries). If Sentry is activated, we will update this privacy policy with the configuration and retention period.

Email delivery, order confirmations and eSIM confirmations

We may send emails, in particular to confirm orders, provide eSIM information, transmit installation instructions, provide information about top-ups, account security, support or program information in connection with eSIMiles.

In particular, email address, name, order number, product and eSIM information, installation instructions, sending status, delivery and error status and communication content may be processed.

The legal basis is Article 6(1)(b) GDPR where the email is necessary for contract performance, provision of purchased services, account management or handling support requests. The legal basis is Article 6(1)(f) GDPR where emails are necessary for security, prevention of misuse, verifiability or improvement of communication.

Recipients may include mail service providers, Shopify, hosting providers and support service providers.

Transactional emails – in particular order confirmations as well as eSIM and QR code confirmations – are sent via the SMTP service serverpool.net (provider: Netsource) acting as a processor. Sending and delivery logs, e.g. sending and error status, are stored only for as long as required to ensure delivery, for error analysis and for evidentiary purposes, and are then deleted.

4 “eSIMiles” bonus points and loyalty program

If you participate in the “eSIMiles” bonus points and loyalty program, we process personal data to operate the program.

In particular, customer account and identification data, purchase and order history within the app, gross purchase amounts actually paid, points balance, points movements, status level, discount codes and referral data may be processed. Referral data includes in particular the personal invitation code, the invitation code used and the allocation of which participant invited which new user.

Where applicable, we also process data relating to the welcome bonus, the status of points as pending or released, waiting periods before points can be redeemed and whether a user registered with or without an invitation code.

The purpose of processing is setting up and managing program participation, calculating and crediting points, calculating the status level, creating and managing discount codes, operating the referral program, reversing points in the event of cancellation, refund or chargeback, displaying the points balance and preventing misuse.

This also includes granting and documenting welcome bonuses, applying waiting periods before purchase-related points can be redeemed, releasing points after the waiting period or after earlier activation of the relevant eSIM, and preventing the combined use of welcome bonuses and referral rewards where this is excluded by the program terms.

The legal basis for carrying out program participation is Article 6(1)(b) GDPR. The legal basis for prevention of misuse, fraud prevention, system security and enforcement of program terms is Article 6(1)(f) GDPR. Where statutory retention obligations exist, the legal basis is Article 6(1)(c) GDPR.

Recipients may include Shopify, hosting providers, technical app and backend service providers, mail and push service providers, support service providers and analytics or security service providers.

Points and program histories are stored for as long as this is necessary for operating the program. Under the program terms, unredeemed points generally expire if there has been no activity on the customer account for 24 months. Activity includes, in particular, a purchase, top-up, redemption or confirmed referral. Each such activity resets the 24-month period for the entire points balance. Pure system postings, in particular cancellations, refunds, technical corrections or the expiry of points itself, do not count as activity.

Information on pending points, release status, welcome bonuses and waiting periods is stored for as long as this is necessary for the correct operation of the eSIMiles program, misuse prevention and traceability of points movements.

The underlying points movements and program data may be stored beyond the expiry of individual points or beyond the end of program participation to the extent this is necessary for traceability, misuse prevention, accounting, defense or enforcement of claims or compliance with statutory retention obligations.

5 Cookies

The term “cookie” refers to a small file that is stored on users’ computers. Cookies are mainly used to store information about users and the devices they use. Temporary cookies, also known as “session cookies” or “transient cookies”, are cookies that are deleted after a user leaves an online service and closes the browser, for example the contents of a shopping cart in an online shop.

“Permanent cookies” or “persistent cookies” are cookies that remain stored even after the browser is closed. In such a cookie, for example, users’ interests may be stored in order to use this information for reach measurement or marketing purposes. “Third-party cookies” are cookies that originate from providers other than the operator of the online offering. Cookies of the operator are also called “first-party cookies”.

We may use temporary and permanent cookies.

Users who do not wish cookies to be stored on their computer can delete cookies already stored in the system settings of their browser and deactivate the corresponding option. We would like to point out that deactivating cookies may lead to functional restrictions of the online offering.

You can deactivate the storage of cookies in your browser settings. Furthermore, you can declare a general objection to the use of cookies for marketing purposes, especially tracking, via various services on the American website https://www.aboutads.info/choices/ or the European website https://www.youronlinechoices.com/.

We would like to point out that deactivating cookies may lead to functional restrictions of the online offering.

6 Cooperation with processors, joint controllers and third parties

If we disclose data to other persons and companies, for example processors, joint controllers or third parties, transfer it to them or grant them access to the data, this is done only on the basis of legal permission.

This is the case, for example, if the transfer of data to third parties, such as payment service providers, is necessary for contract performance, users have consented, a legal obligation provides for this or the transfer is based on our legitimate interests, for example when using agents, web hosts, app service providers or technical partners.

If we disclose, transfer or otherwise grant access to data to other companies within our group of companies, this is done in particular for administrative purposes as a legitimate interest and on a basis corresponding to the legal requirements.

In connection with the website, online shop, app and eSIMiles, the following recipients or categories of recipients may be relevant in particular:

  • Shopify for commerce, customer account, checkout, order management and, where applicable, discount code functions
  • Payment service providers within Shopify Checkout
  • eSIM network providers or eSIM provider partners for eSIM provision, eSIM management, status and usage data
  • Apple, in particular for Apple Push Notification service, APNs
  • Google, in particular for Firebase Cloud Messaging, FCM, Android-related services and, where applicable, Google Analytics
  • Sentry for error, crash and performance monitoring
  • Hosting providers for app backend, databases, servers and technical infrastructure
  • Mail service providers for transactional emails, order confirmations, eSIM notices, newsletters and support communication
  • Support and IT service providers
  • Tax, legal and accounting service providers
  • Authorities, courts or other bodies where we are legally obliged or entitled to do so

In particular, we currently use the following service providers: Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, Ireland (commerce, customer account, checkout, order and, where applicable, discount-code functions; Ireland/USA); eSIM Go Ltd, United Kingdom (eSIM provisioning, status, usage and top-up; United Kingdom); Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (hosting of app backend, database and infrastructure; Germany); serverpool.net, provider Netsource, Germany (sending of transactional emails; Germany); Inxmail GmbH, Wentzigerstr. 17, 79106 Freiburg, Germany (newsletter distribution and statistical analysis; Germany); 650 Industries, Inc. (Expo), San Francisco, CA, USA (push infrastructure; USA); Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA (Apple Push Notification service; USA); Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Firebase Cloud Messaging and, where applicable, Google Analytics; Ireland/USA); Functional Software, Inc. (Sentry), 45 Fremont Street, San Francisco, CA 94105, USA (error and crash monitoring, currently inactive; USA); AWIN AG, Eichhornstraße 3, 10785 Berlin, Germany (website affiliate program; Germany). Where these service providers process personal data on our behalf, they act as processors on the basis of corresponding agreements.

Transfers to third countries

Where we have data processed in a third country outside the European Union or the European Economic Area or transfer data to recipients in such third countries, this is done only where the requirements of the GDPR are met.

Where an adequacy decision of the European Commission exists for the relevant third country, the transfer may be based on that decision. Where no adequacy decision exists, we rely on appropriate safeguards, in particular EU Standard Contractual Clauses, supplemented by additional protective measures where required.

For providers based in the United States or with relevant processing in the United States, certification under the EU-U.S. Data Privacy Framework may also be relevant where applicable.

In particular: for recipients in the USA (in particular Apple, Google, Expo/650 Industries and – if activated – Sentry), we base transfers on the EU-U.S. Data Privacy Framework where the respective provider is certified under it, supplemented by EU Standard Contractual Clauses. For the United Kingdom (eSIM Go) there is an adequacy decision of the European Commission. Recipients established in Germany or Ireland (Hetzner, Netsource, Shopify, Google Ireland) process data within the EU/EEA. The safeguards actually used for each provider are to be verified before publication.

7 Newsletter

Newsletter data

If you would like to receive the newsletter offered on the website, we require an email address and information that allows us to verify that you are the owner of the specified email address and that you agree to receive the newsletter. Additional data is not collected or is collected only on a voluntary basis. We use this data exclusively to send the requested information and do not pass it on to third parties unless otherwise stated in this Privacy Policy.

The processing of the data entered in the newsletter registration form is carried out exclusively on the basis of your consent, Article 6(1)(a) GDPR. You may withdraw your consent to the storage of the data, the email address and its use for sending the newsletter at any time, for example via the “unsubscribe” link in the newsletter. The legality of data processing operations already carried out remains unaffected by the withdrawal.

The data you provide to us for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and deleted after unsubscribing from the newsletter. Data stored by us for other purposes, for example email addresses for the customer account, remains unaffected.

Inxmail

Our email newsletters are sent via the technical service provider Inxmail GmbH, Wentzigerstr. 17, 79106 Freiburg, Germany, Tel.: +49 761 296979-0, email: info@inxmail.de, https://www.inxmail.de, to whom we pass on the data you provided when registering for the newsletter. This transfer takes place within the scope of processing by Inxmail. Please note that your data is usually transferred to an Inxmail server and stored there.

Inxmail uses this information to send and statistically evaluate the newsletters on our behalf. For the evaluation, the emails sent contain so-called web beacons or tracking pixels, which are one-pixel image files stored on our website. This makes it possible to determine whether a newsletter message has been opened and which links, if any, have been clicked on. Technical information is also recorded, for example time of retrieval, IP address, browser type and operating system. The data is collected only in pseudonymous form and is not linked to your other personal data, direct personal reference is excluded. This data is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses may be used to better adapt future newsletters to the interests of recipients.

If you wish to object to data analysis for statistical evaluation purposes, you must unsubscribe from the newsletter.

You can withdraw your consent at any time. You can also prevent the processing at any time by unsubscribing from the newsletter. You can also prevent the storage of cookies by setting your web browser accordingly. You can also prevent the storage and transmission of personal data by deactivating JavaScript in your web browser or installing a JavaScript blocker, for example https://noscript.net or https://www.ghostery.com. We would like to point out that these measures may mean that not all functions of our website are available.

Furthermore, Inxmail may use this data itself in accordance with Article 6(1)(f) GDPR on the basis of its own legitimate interest in the needs-based design and optimization of the service and for market research purposes, for example to determine from which countries the recipients come. However, Inxmail does not use the data of our newsletter recipients to write to them itself or to pass it on to third parties.

You can view Inxmail’s privacy policy here: https://www.inxmail.de/datenschutz.

Newsletter tracking

Our newsletters contain so-called tracking pixels. A tracking pixel is a miniature graphic embedded in emails sent in HTML format to enable log file recording and log file analysis. This allows statistical evaluation of the success or failure of online marketing campaigns.

Based on the embedded tracking pixel, it can be determined whether and when an email was opened and which links contained in the email were accessed.

Such personal data collected via the tracking pixels contained in the newsletters is stored and evaluated by us in order to optimize newsletter delivery and to better adapt the content of future newsletters to your interests. This personal data will not be passed on to third parties unless otherwise stated in this Privacy Policy. Data subjects are entitled at any time to withdraw the relevant declaration of consent.

After withdrawal, this personal data will be deleted by us. We automatically interpret unsubscribing from the newsletter as withdrawal.

Such evaluation is carried out on the basis of your consent pursuant to Article 6(1)(a) GDPR, where such consent is required.

8 Awin affiliate program

On the basis of our legitimate interests, operation of our online offering within the meaning of Article 6(1)(f) GDPR, we participate in the affiliate program of AWIN AG, Eichhornstraße 3, 10785 Berlin, Germany. The program was designed to provide a medium for websites through which advertising cost reimbursement can be earned by placing advertisements and links to AWIN, affiliate system. To determine the origin of the conclusion of a contract, AWIN uses cookies.

AWIN can track that you clicked on the partner link on this website and concluded a contract with or via AWIN.

Further information is available in AWIN’s privacy policy: https://www.awin.com/gb/legal/privacy-policy.

9 Google Analytics

This website uses functions of the web analytics service Google Analytics. Provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics uses so-called “cookies”. These are text files stored on your computer that enable analysis of your use of the website. The information generated by the cookie about your use of this website may be transferred to and stored on Google servers.

The use of Google Analytics is based on your consent pursuant to Article 6(1)(a) GDPR where legally required. Where processing based on legitimate interests is permissible, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in analysing user behavior in order to optimize both our website and our advertising.

10 Payment and order processing

The purchase of eSIMs, data packages, top-ups or other paid services is processed via Shopify or via the payment service providers integrated there.

Within the app, we do not process full payment data such as full credit card numbers, full bank account details or comparable payment instrument data.

Where necessary, we receive and process purchase-related and order-related information, for example order number, purchased products, purchase amount, payment status, refund status, customer allocation and invoice information.

The purpose of processing is order processing, allocation of eSIMs, fulfillment of purchase-related obligations, customer support, fraud and misuse prevention, tax documentation and, where you participate, points calculation in the bonus program.

The legal basis is Article 6(1)(b) GDPR where processing is necessary for the performance of the purchase or provision of the purchased service. The legal basis is Article 6(1)(c) GDPR where data is processed to comply with statutory retention, accounting or tax obligations. The legal basis is Article 6(1)(f) GDPR where data is processed for fraud prevention, prevention of misuse, legal defense or enforcement of legitimate claims.

Recipients may include Shopify, the payment service providers integrated into Shopify Checkout, hosting providers, tax and accounting service providers, support service providers and technical IT service providers.

11 Relationship with Shopify

The services are hosted by Shopify, which collects and processes personal data about your access to and use of the services in order to provide and improve the services for you. Information that you submit via the services is transmitted to and shared with Shopify and third parties, which may be located in countries other than your country of residence, in order to provide and improve the services for you.

In addition, in order to protect, grow and improve our business, we use certain advanced Shopify features that incorporate data and information from your interactions with our shop, with other merchants and with Shopify. To provide these advanced features, Shopify may use personal data about your interactions with our shop, other merchants and Shopify.

In these cases, Shopify is responsible for the processing of your personal data, including responding to your requests to exercise your rights in relation to the use of your personal data for these purposes.

Further information on how Shopify uses your personal data and what rights you may have can be found in the Shopify Consumer Privacy Policy. Depending on where you live, you may exercise certain rights in relation to your personal data via the Shopify Privacy Portal.

12 Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices or for other operational, legal or regulatory reasons. We will publish the revised Privacy Policy on this website, update the “Last updated” date and, where applicable, provide notice in accordance with applicable laws.

Last updated: 14.07.2026