Privacy Policy
Updated: 26 August 2026
Translation notice: The German version prevails in case of discrepancies, subject to mandatory law.
This policy provides information under Articles 13 and 14 GDPR.
1. Controller
Gurbet eSIM, owner Muhammed Akbas, Bremsberg 12, 59229 Ahlen, Germany, info@gurbetesim.de.
2. Hosting and server logs
Hostinger hosts this website. Technical access data such as IP address, time, requested URL, browser, operating system and error data may be processed to provide and protect the website (Article 6(1)(f) GDPR).
3. Orders and contract performance
We process name, email, plan, order and payment status, technical identifiers and communications to process orders, provide the eSIM and provide support (Article 6(1)(b) GDPR). Statutory accounting data is processed under Article 6(1)(c) GDPR.
4. Stripe
Payments are processed by Stripe. Stripe processes payment data under its own responsibility. We normally receive payment status and transaction identifiers, not full card data.
5. eSIM fulfilment
Required order and product data is shared with our technical eSIM supplier/platform (currently eSIM Access and connected network partners) only to create, activate, troubleshoot and support the purchased eSIM.
6. Email and WhatsApp
Contact data is processed to answer requests (Article 6(1)(b) or (f) GDPR). WhatsApp Ireland Limited processes data when WhatsApp is used and data may be transferred outside the EEA. Email is available as an alternative.
7. Cookies, local consent management and optional services
Strictly necessary storage and access are covered by section 25(2) TDDDG; related processing is based on Article 6(1)(b) or (f) GDPR. Statistics or marketing technologies are activated only after your explicit consent under section 25(1) TDDDG and Article 6(1)(a) GDPR.
We use a self-hosted consent solution. Your choice (necessary, statistics and marketing), the consent version and timestamp are stored only in your browser’s local storage under gurbetesim_consent_v1. This necessary record applies to every page and language section on the same domain and expires after no more than 180 days. The banner itself does not send consent data to third parties.
Necessary functions are always active; statistics and marketing are off by default. The solution prepares Google Consent Mode v2 signals locally. This alone neither loads Google tags nor sends data to Google. Before any new measurement or advertising service is activated, this notice will be updated with the provider, purpose, retention period and possible international transfers.
You can change or withdraw your choice at any time through “Cookie settings” in the footer. Withdrawal applies prospectively. You can also remove the locally stored choice in your browser settings.
8. Electronic withdrawal function
Name, email, order/contract details, withdrawal statement, timestamp and security data are processed to handle and document withdrawals (Article 6(1)(b) and (c) GDPR).
8a. Customer overview and data usage
For the protected customer overview, only the order email address is entered. We send a one-time access link valid for 15 minutes to that address; no order number or ICCID digits are requested. Plan, activation, status, duration, usage data and technical provider identifiers are processed for contract performance and security.
8b. Review requests, loyalty bonus and promotional emails
Review and marketing emails rely on separate, optional consent. If the loyalty bonus is selected, we record the email address, name, language, order reference, consent wording/version, timestamps and hashed technical security data. We first send only a double-opt-in confirmation. Marketing and the personal one-time 10% code are activated only after confirmation. The legal basis is Art. 6(1)(a) GDPR. Consent is not required for the purchase and can be withdrawn for the future through the unsubscribe link in every promotional email or by contacting us. Unconfirmed addresses are not used for advertising; evidence is retained only as required for accountability and legal defence.
8c. Current Google Maps reviews
To display current business reviews, our server requests data from Google Places API (New). We may show the overall rating, review count and the first three reviews returned by Google Maps in relevance order, including author attribution, profile image, relative time and a direct source link. The request is made server-side; the visitor’s browser does not connect directly to Google for this purpose. Google receives our hosting server’s IP address and technical request data. We do not permanently store API responses containing review content; only the Google place ID may be stored. If the API is unavailable or not yet configured, the last publicly retrieved status is displayed. The legal basis is our legitimate interest in presenting current and traceable genuine customer feedback under Article 6(1)(f) GDPR. The Google Maps Platform Terms and Google Privacy Policy also apply.
9. Recipients and international transfers
Recipients may include hosting, payment, communication, eSIM and IT service providers and public authorities. Transfers outside the EEA take place only under Articles 44 et seq. GDPR.
10. Retention
Data is retained only as long as needed or required by statutory commercial and tax retention periods.
11. Your rights
Subject to legal requirements, you have rights under Articles 15–21 GDPR, including access, correction, erasure, restriction, portability and objection. Consent may be withdrawn for the future.
12. Complaints
You may complain to a data protection authority, in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
13. Security and automated decisions
Appropriate technical and organisational safeguards are used. No solely automated decision with legal or similarly significant effects is made.
