Your Privacy Matters
Last updated: December 2025
Privacy Policy
eSIM Sell Applicable to: esimsell.com, esimsell.de, esimsell.net and the eSIM Sell mobile application
We take the protection of your personal data very seriously. This Privacy Policy informs you, in accordance with the EU General Data Protection Regulation (GDPR) and applicable German data protection law, about the nature, scope and purpose of the processing of personal data within our website, our mobile application, and in connection with the sale of our eSIM products and services.
1. Controller
The controller responsible for data processing on this website and within the mobile application, within the meaning of the GDPR, is:
eSIM Sell β Zahra Zahedinezhad TDPB 74580116 c/o Margit Winzer Lanzstr. 35 80689 MΓΌnchen, Germany
Email: [email protected]
2. General Information on Data Processing
2.1 Scope of Processing of Personal Data
We only process personal data of our users to the extent necessary to provide a functioning website and app, along with our content and services. The processing of personal data is carried out regularly only with the consent of the user, or where processing is permitted by law, in particular where processing is necessary for the performance of a contract with the user or for the performance of pre-contractual measures.
2.2 Legal Basis for the Processing of Personal Data
Insofar as we obtain the consent of the data subject for processing operations of personal data, Art. 6 (1) lit. a GDPR serves as the legal basis. For the processing of personal data necessary for the performance of a contract to which the data subject is party, Art. 6 (1) lit. b GDPR serves as the legal basis. This also applies to processing operations necessary for carrying out pre-contractual measures. Insofar as processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6 (1) lit. c GDPR serves as the legal basis. Where processing is necessary to protect a legitimate interest of our company or a third party, and the interests, fundamental rights and freedoms of the data subject do not override the first-mentioned interest, Art. 6 (1) lit. f GDPR serves as the legal basis.
3. Provision of the Website and Creation of Server Log Files
Each time our website is accessed, our system automatically collects data and information from the accessing computer system. The following data is collected:
- IP address
- Date and time of the request
- Name and URL of the requested file
- Website from which access occurs (referrer URL)
- Access status / HTTP status code
- Browser type
- Language and version of the browser software
- Operating system
This data is not merged with other data sources. The collection of this data is technically necessary to display our website to you correctly, and to ensure the security and stability of our website and the underlying IT systems (Art. 6 (1) lit. f GDPR).
The data is deleted as soon as it is no longer required for the purpose for which it was collected. In the case of the logging of website access, this is generally the case once the respective session has ended. Longer storage may occur in individual cases where required by law.
4. Use of Cookies
Our website uses cookies. Cookies are small text files that are stored on your device by your browser and allow certain information to flow to the party that set the cookie.
4.1 Strictly Necessary Cookies
We only use cookies that are strictly necessary for the technical operation of our website (e.g. to enable session management, keep you logged in, or provide basic security functions such as protection against fraudulent activity). We do not use marketing or advertising cookies, and we do not use third-party cookies for tracking purposes.
The legal basis for the use of strictly necessary cookies is Art. 6 (1) lit. f GDPR, based on our legitimate interest in ensuring the technical operability, security and proper functioning of our website. Because these cookies are technically essential to the operation of the website, your consent is not required for their use under Art. 25 TTDSG / GDPR.
4.2 Analytical Cookies
At present, we do not use analytical, performance, or statistics cookies (e.g. for web analytics or usage tracking) on our website. Should we introduce such cookies in the future, we will only do so with your prior consent (Art. 6 (1) lit. a GDPR), obtained via a cookie consent banner, and this Privacy Policy will be updated accordingly to describe the specific providers, purposes, and retention periods involved.
4.3 Can I Block or Delete Cookies?
Yes. You are free to decide whether to accept cookies. Most browsers accept cookies automatically, but you can configure your browser settings to refuse the setting of cookies, or to delete cookies that have already been stored on your device. You can also usually see which cookies have been stored and delete them individually through your browser's settings.
Please note that if you block or delete strictly necessary cookies, certain functions of our website (such as staying logged in to your account or completing an order) may not work correctly or may not be available at all.
4.4 How to Disable Cookies
You can manage or disable cookies directly through your browser settings. Instructions for the most common browsers can be found here:
- Google Chrome: Settings β Privacy and security β Cookies and other site data
- Mozilla Firefox: Settings β Privacy & Security β Cookies and Site Data
- Safari: Preferences β Privacy β Manage Website Data
- Microsoft Edge: Settings β Cookies and site permissions β Manage and delete cookies
If you use our mobile application, equivalent controls may be available through your device's operating system privacy settings, since mobile apps typically do not use browser cookies but may use comparable local storage technologies for the same strictly necessary purposes described above.
5. Registration and Customer Account
5.1 Data Collected During Registration
When you register on our website or in our app, we collect the following data:
- Name
- Email address
Additionally, technical information necessary for providing and administering the customer account is stored (e.g. login credentials and an encrypted password).
Registration is required if you wish to use certain services and content on our website, or where registration is necessary for the performance of a contract with you, or for carrying out pre-contractual measures (Art. 6 (1) lit. b GDPR).
5.2 Storage and Deletion
Data collected during registration is stored by us for as long as you maintain a registered account with us and is deleted once you cancel or delete your account, without prejudice to any statutory retention obligations, which remain unaffected. You may at any time correct or amend the personal data you provided, or request its complete deletion from our records, subject to statutory retention periods.
5.3 No Disclosure to Third Parties
Your login data is not disclosed to third parties. Where you use a social login option, the provisions of Section 7.2 ("Social Login") apply.
6. Data Processed in Connection with eSIM Contracts
For the fulfilment of contracts for the purchase and use of our eSIM products, we collect and process the following categories of data:
- Contract and order data (e.g. booked tariff/package)
- eSIM-related technical data (ICCID, EID, activation code, usage data)
- Payment data, processed exclusively by our selected payment service provider (see Section 7)
We process this data exclusively for the purpose of performing the contract with you or carrying out pre-contractual measures at your request (Art. 6 (1) lit. b GDPR).
Data will be deleted once it is no longer required for the purpose for which it was processed, subject to statutory retention obligations under German commercial and tax law (e.g. Β§Β§ 147 AO, 257 HGB), which may require retention of certain invoice-related data for up to 10 years.
7. Payment Processing and Third-Party Providers
7.1 Payment Service Provider: Stripe
For the processing of payments, we use the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
When you make a payment via Stripe, the information required for the order or payment process is transmitted on the basis of Art. 6 (1) lit. b GDPR. This includes, in particular:
- Name
- Address
- Invoice amount, currency, and transaction number
- Where applicable, account number, bank sort code, or credit card data
We do not collect, process or store complete credit card or bank account data ourselves. Payment data is collected and processed directly by Stripe. Where necessary for payment processing, Stripe may forward relevant data to other participating financial institutions.
Further information on Stripe's data processing is available in Stripe's own privacy policy: https://stripe.com/de/privacy
7.2 Social Login (Google, Apple)
To simplify registration and login, we offer social login functionality via the following third-party providers:
- Login with Google
- Login with Apple
When you use these functions, the respective provider is informed that you wish to log in to our service. The following data may be processed and transmitted to the provider concerned:
- Email address
- Name
- User ID provided by the respective provider
These providers may transfer personal data to servers in the USA. Google and Apple are certified under the EUβU.S. Data Privacy Framework, which the European Commission has recognized as providing an adequate level of data protection pursuant to Art. 45 GDPR.
No further disclosure of your data takes place beyond what is described above, unless we are legally obliged to do so or you have given your express consent.
8. Data Transfer to Our Technical Partner (BNESIM)
To provide our eSIM services and ensure effective customer support, we transfer certain personal data exclusively to our technical contractual partner:
BNESIM Limited β European branch of the BNESIM Group
This concerns, in particular:
- eSIM-related data (ICCID, EID, activation code, usage data)
- Contact data (e.g. name, email address), where necessary for support purposes
This data is processed within the European Union by the European branch of BNESIM. The legal basis for this transfer is Art. 6 (1) lit. b GDPR, as it is necessary for the performance of our contract with you.
Login and account data are not transferred to third parties unless a legal obligation exists or you have given your express consent.
9. Contact by Email
You may contact us by email. In this case, we only collect the email address you use to contact us, together with any personal data you voluntarily provide in your message. This data is used solely to respond to and process your inquiry (Art. 6 (1) lit. b and/or lit. f GDPR) and is deleted once it is no longer required for this purpose, subject to statutory retention obligations.
10. Data Security
We are committed to protecting your privacy and keeping your personal data confidential. To this end, we implement appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access. These measures are regularly reviewed and adapted in line with technological developments.
11. Your Rights as a Data Subject
Under the GDPR, you have the following rights with respect to your personal data:
- Right of access (Art. 15 GDPR) β to obtain confirmation of and information about the personal data we process concerning you.
- Right to rectification (Art. 16 GDPR) β to request the correction of inaccurate data or completion of incomplete data.
- Right to erasure (Art. 17 GDPR) β to request deletion of your data where, for example, it is no longer necessary for the purposes for which it was collected, you have withdrawn consent, or it has been processed unlawfully.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR).
- Right to object to processing based on legitimate interests (Art. 21 GDPR).
- Right to withdraw consent (Art. 7 (3) GDPR) β at any time, with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR) β you have the right to complain to a data protection supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement. We would, however, appreciate the opportunity to address your concerns directly before you contact a supervisory authority.
12. How to Contact Us
For any questions regarding your personal data, this Privacy Policy, or to exercise your rights under the GDPR, please contact our data controller:
- By post: eSIM Sell β Zahra Zahedinezhad, c/o Margit Winzer, Lanzstr. 35, 80689 MΓΌnchen, Germany
- By email: [email protected]
13. Amendments to this Privacy Policy
We reserve the right to amend this Privacy Policy from time to time to ensure it remains compliant with current legal requirements, or to reflect changes to our services (e.g. the introduction of new features). The revised policy will apply to your next visit to our website or use of our app.
Last updated: [insert date]