1. Who we are
eSIM Shyp (esim-shyp.com) is operated by SHYP DIGITAL S.R.L. and is the controller of your personal data. Contact us anytime at [email protected] for any privacy-related question.
2. What data we collect
- Identification and contact data: name, email address.
- Billing data: company name, address, and for businesses, tax details needed for invoicing.
- Order data: purchased plan, amount, date.
- Technical data: IP address, device and browser type, collected via cookies (see Cookie policy).
We do not request or store your full card details — payment is processed by a specialized provider (e.g. Stripe) that meets industry security standards.
3. Why we collect this data
- to deliver your activation code and process your order;
- to issue your invoice and meet tax obligations;
- to support you when you have a question or problem;
- to improve the site and understand which plans are useful (aggregated, anonymized where possible).
4. Legal basis (GDPR)
- Contract performance – for plan delivery and related support.
- Legal obligation – for invoicing and keeping financial records.
- Legitimate interest – for site security and service improvement.
- Consent – for marketing cookies and optional communications, which you can withdraw anytime.
5. Who we disclose data to
Only partners we need to operate: payment processor, email provider, partner issuing eSIM plans, and upon request authorities if the law requires. We do not sell your data to anyone.
6. How long we keep data
Order and billing data are kept as long as tax law requires (usually 10 years). Support messages are kept as long as needed to help you, then deleted or anonymized.
7. Your rights
- Access – to know what data we hold about you;
- Rectification – to correct wrong data;
- Erasure – "right to be forgotten", within legal limits;
- Restriction – to temporarily limit processing;
- Portability – to receive your data in a reusable format;
- Objection – to object to certain processing;
- Withdrawal of consent – anytime, without affecting prior processing.
To exercise any right, write to [email protected]. We respond within 30 days. You also have the right to complain to the National Supervisory Authority for Personal Data Processing (ANSPDCP).
8. Security
We use encrypted connections (HTTPS), restricted data access, and trusted partners. No system is perfect, but we take security seriously and react quickly if a problem arises.