Privacy Policy
Updated: 23 July 2026
Translation notice: The German version prevails in case of discrepancies, subject to mandatory law.
This policy provides information under Articles 13 and 14 GDPR.
1. Controller
Gurbet eSIM, owner Muhammed Akbas, Bremsberg 12, 59229 Ahlen, Germany, info@gurbetesim.de.
2. Hosting and server logs
Hostinger hosts this website. Technical access data such as IP address, time, requested URL, browser, operating system and error data may be processed to provide and protect the website (Article 6(1)(f) GDPR).
3. Orders and contract performance
We process name, email, plan, order and payment status, technical identifiers and communications to process orders, provide the eSIM and provide support (Article 6(1)(b) GDPR). Statutory accounting data is processed under Article 6(1)(c) GDPR.
4. Stripe
Payments are processed by Stripe. Stripe processes payment data under its own responsibility. We normally receive payment status and transaction identifiers, not full card data.
5. eSIM fulfilment
Required order and product data is shared with our technical eSIM supplier/platform (currently eSIM Access and connected network partners) only to create, activate, troubleshoot and support the purchased eSIM.
6. Email and WhatsApp
Contact data is processed to answer requests (Article 6(1)(b) or (f) GDPR). WhatsApp Ireland Limited processes data when WhatsApp is used and data may be transferred outside the EEA. Email is available as an alternative.
7. Cookies, local consent management and optional services
Strictly necessary storage and access are covered by section 25(2) TDDDG; related processing is based on Article 6(1)(b) or (f) GDPR. Statistics or marketing technologies are activated only after your explicit consent under section 25(1) TDDDG and Article 6(1)(a) GDPR.
We use a self-hosted consent solution. Your choice (necessary, statistics and marketing), the consent version and timestamp are stored only in your browser’s local storage under gurbetesim_consent_v1. This necessary record applies to every page and language section on the same domain and expires after no more than 180 days. The banner itself does not send consent data to third parties.
Necessary functions are always active; statistics and marketing are off by default. The solution prepares Google Consent Mode v2 signals locally. This alone neither loads Google tags nor sends data to Google. Before any new measurement or advertising service is activated, this notice will be updated with the provider, purpose, retention period and possible international transfers.
You can change or withdraw your choice at any time through “Cookie settings” in the footer. Withdrawal applies prospectively. You can also remove the locally stored choice in your browser settings.
8. Electronic withdrawal function
Name, email, order/contract details, withdrawal statement, timestamp and security data are processed to handle and document withdrawals (Article 6(1)(b) and (c) GDPR).
8a. Review requests and promotional emails
Only after separate, freely given consent will we send one satisfaction and review request by email after the expected eSIM usage period. It may contain a link to our Google review profile. Google’s privacy terms apply when the link is opened; we do not independently disclose your email address to Google. Occasional offers and news require a separate marketing consent. We document consent with its time, version, language and order reference. Consent is optional, is not required to order and may be withdrawn at any time for the future through the unsubscribe link or by contacting us. After withdrawal, the relevant use stops; minimal suppression and evidence data may be retained to respect and demonstrate the withdrawal.
9. Recipients and international transfers
Recipients may include hosting, payment, communication, eSIM and IT service providers and public authorities. Transfers outside the EEA take place only under Articles 44 et seq. GDPR.
10. Retention
Data is retained only as long as needed or required by statutory commercial and tax retention periods.
11. Your rights
Subject to legal requirements, you have rights under Articles 15–21 GDPR, including access, correction, erasure, restriction, portability and objection. Consent may be withdrawn for the future.
12. Complaints
You may complain to a data protection authority, in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
13. Security and automated decisions
Appropriate technical and organisational safeguards are used. No solely automated decision with legal or similarly significant effects is made.
