Privacy Policy
This policy explains what personal data esimXK collects, why, who it is shared with, how long it is kept and how you can delete it. It applies to the website esimxk.eu and to the esimXK app for iPhone. Both use the same account and the same server.
Who we are. esimXK is operated by Granit Murati, Switzerland (the "controller").
Contact for privacy questions: support@esimxk.eu
1. Data we collect
- Account data: email address, first name (optional), password (stored only as a one-way hash). If you sign in with Google or Apple, we receive your email address and a user identifier from that provider. With Apple you may hide your email; we then receive an Apple relay address.
- Order data: purchased plans, amounts, payment method type, date, refund status, and the eSIM details needed to install and use the plan (ICCID, order number, QR code / activation code, data usage and expiry).
- Payment data: payments are processed by Stripe. We never see or store your full card number.
- Referral and loyalty data: your referral code, who referred you, number of referrals, credit balance and loyalty level.
- Support data: messages you send through the website chat or by email, and reviews you choose to publish.
- Technical data: IP address (for security, rate limiting and an approximate country for website visit statistics), and an anonymous visitor ID on the website.
- On your device (app): your sign-in token is kept in the iOS secure storage (Keychain); your cart, language, currency and theme settings are kept locally on the device.
2. Why we use it
- To create and manage your account and let you sign in (contract).
- To process orders, deliver your eSIM, show data usage and send order and account emails (contract).
- To apply referral credit and loyalty discounts (contract).
- To answer support requests (contract / legitimate interest).
- To protect the service against fraud and abuse (legitimate interest).
- To keep accounting and tax records (legal obligation).
We do not sell your data. We do not use your data for advertising, and the app does not track you across other companies' apps or websites.
3. Who we share it with
Only the minimum needed, with these service providers:
- Stripe - payment processing.
- eSIM Access - our eSIM supplier, to issue the eSIM and report usage (no name or email is needed for activation).
- Our hosting provider - stores the server and its data.
- Email delivery provider - sends verification, password reset and order emails.
- Google - Google Sign-In (if you use it) and reCAPTCHA on the website registration form.
- Apple - Sign in with Apple (if you use it).
- DeepSeek - when no support agent is online, website chat messages may be answered by an AI assistant; your message text is sent to DeepSeek to create the reply.
- ipwho.is - converts a website visitor's IP address into an approximate country for visit statistics.
Some of these providers process data outside the EU/EEA; where this happens they rely on appropriate safeguards such as Standard Contractual Clauses. We may also disclose data if required by law.
4. How long we keep it
- Account data: until you delete your account.
- Order records: kept after account deletion for as long as accounting and tax law requires.
- Website visit statistics: 90 days.
- Support messages: until the conversation is closed and no longer needed, or until you ask us to delete them.
5. Deleting your account
You can delete your account at any time:
- In the app: Profile → Delete account.
- On the website: My account → Delete account.
- Or by email to support@esimxk.eu.
Deleting your account removes your profile, referral code and credit. eSIMs you already bought keep working until they expire, and order records are kept as described above. If you used Sign in with Apple, you can also remove esimXK under Settings → Apple ID → Sign in with Apple on your iPhone.
6. Your rights
You can ask for access to, correction, deletion or a copy (portability) of your personal data, object to or restrict its processing, and withdraw any consent you gave. Write to support@esimxk.eu; we reply within 30 days. You may also complain to your local data protection authority.
7. Security
Connections use HTTPS, passwords are hashed, sign-in tokens are signed and expire, and access to the administration panel requires two-factor authentication.
8. Children
The service is not intended for children under 16. We do not knowingly collect data from them.
9. Changes
We may update this policy. The date at the top shows the latest version. Important changes will be announced on the website or in the app.