Privacy
Privacy policy
Last updated July 2026
Controller and contact
The business identified as the seller in checkout and the order confirmation is the controller for the purchase. Privacy requests can be sent to support@esimterra.com with Privacy request in the subject line.
Data we process
Order data can include email, selected product, price, currency, payment status, supplier fulfillment identifiers, delivery status and support history. We are designed not to receive or store a full card number.
Account and feature data can include verified identity, claimed orders, trips, planner workspaces, preferences, referral attribution and Credits ledger entries.
Technical data can include IP address, device and browser information, timestamps, pages or actions, security events, consent state and limited fraud-prevention signals.
Purposes and legal bases
We process data to form and perform a contract, deliver products, provide support, secure the service, prevent fraud, maintain records and meet legal obligations. Where required, optional analytics or marketing relies on consent.
Legitimate interests may support service security, diagnostics, product improvement and abuse prevention when those interests are not overridden by the person’s rights.
Service providers and recipients
Necessary recipients can include hosting and database providers, the configured payment provider, email delivery, connectivity suppliers, support tooling, fraud prevention and professional advisers. Each should receive only the data needed for its role.
We do not sell or rent personal data. A processor list and international-transfer safeguards should be kept current as production providers are finalized.
International transfers
Providers may process data outside the customer’s country. Where transfer restrictions apply, we use an available legal mechanism such as adequacy, contractual safeguards or another permitted basis.
Retention
Records are kept only as long as needed for delivery, support, security, disputes, accounting and legal obligations. Different categories can have different retention periods, after which data is deleted or de-identified where practical.
Your rights
Depending on location, rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a regulator. Identity may need to be verified before a request is completed.
Where GDPR or UK GDPR applies, requests are handled without undue delay and normally within one month, subject to lawful extensions or exceptions.
Cookies and local storage
Essential storage supports sign-in, cart, language, currency, security and feature continuity. Optional analytics or marketing storage should remain off until the required consent is obtained.
Read the cookie policyChildren and changes
The service is not directed to children who cannot enter the contract under applicable law. We may update this notice as providers and features change; the updated date identifies the current version.
Seller identity
Live payment remains closed until the seller identity is configured.