Privacy Policy
Last updated: April 4, 2026
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Madalina Moman
Watzmannstraße 12
71067 Sindelfingen, Germany
Phone: +49 162 289 6798
E-Mail: info@esimoon.com
2. Types of Data Collected
- Account Data: E-mail address, first and last name, password (encrypted)
- Billing Data: Address, city, postal code, country
- Payment Data: Processed by third-party providers (Braintree, PayPal). We do not store credit card or bank details.
- Usage Data: IP address, browser type/version, pages visited, date/time of access, device identifiers
- Order Data: Products purchased, order history, eSIM activation data (ICCID)
3. Legal Basis for Processing (Art. 6 GDPR)
- Art. 6(1)(a) — Consent: Where you have given consent (e.g., analytics cookies).
- Art. 6(1)(b) — Contract Performance: Processing necessary for contract performance (e.g., eSIM purchase and delivery).
- Art. 6(1)(c) — Legal Obligation: Processing necessary to comply with legal obligations (e.g., tax records, invoicing).
- Art. 6(1)(f) — Legitimate Interest: Fraud prevention, website security, service improvement.
4. Purpose of Processing
- Providing and maintaining our eSIM services
- Processing orders and delivering digital products
- Customer support and communication
- Fraud prevention and security
- Website analytics and service improvement
- Compliance with legal and tax obligations
5. Data Retention
- Account data: Until account deletion or 3 years after last activity
- Order/invoice data: 10 years (§ 147 AO, § 257 HGB — German tax law)
- Server log files: 30 days
- Analytics data: 26 months (anonymized)
6. Recipients and Third Parties
- eSIM Providers: To activate and deliver your eSIM products
- Payment Processors: Braintree Inc., PayPal — for secure payment processing
- Google Analytics: Website usage analysis (with IP anonymization)
- Firebase: Authentication services (Google LLC)
Some providers are based in the USA. Data transfers are safeguarded by EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR, and/or the EU-U.S. Data Privacy Framework.
7. Cookies
This website uses cookies. For details, see our Cookies Policy.
8. SSL/TLS Encryption
This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content.
9. Your Rights (Art. 15–21 GDPR)
- Right of Access (Art. 15): Request information about data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate data.
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten").
- Right to Restriction (Art. 18): Request restriction of processing.
- Right to Data Portability (Art. 20): Request your data in a machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent (Art. 7(3)): Withdraw any consent at any time.
To exercise any of these rights, contact us at: info@esimoon.com
10. Right to Lodge a Complaint
You have the right to lodge a complaint with the supervisory authority (Art. 77 GDPR):
Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de