Bidaiesim

Privacy policy

Controller

Urko Cornejo Merodio (Bidaiesim), Wilhelmstraße 27, 74072 Heilbronn, Germany. Email: [email protected].

What data we process and why

When you buy. Your email address, the destination and plan, the price, the country your card was issued in (to comply with VAT rules), the date you agreed to immediate delivery and the payment references in Stripe. We never see or store your card details. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and legal tax obligations (Art. 6(1)(c) GDPR).

Your eSIM. The ICCID, the activation code, the QR code, the status and the data usage the provider reports to us. We need them to deliver your eSIM, show your usage, let you top up and process refunds (Art. 6(1)(b) GDPR).

Your account, if you use it. Buying does not require an account. If you sign in to "My eSIMs", we email you a sign-in link that expires after 15 minutes, and your session lasts 30 days through a technical cookie (below). We store your email and hashed versions of the link and the session, never the original values.

Support. If you write to us, we keep your email, your message, the language and, if you give it, the order reference (Art. 6(1)(b) and 6(1)(f) GDPR).

Running and securing the site. We count visits per step of the purchase without cookies or visitor identifiers, and for each request we record only the page category, the method, the result and the response time. The server's technical logs hide private links, activation codes, full email addresses and full ICCIDs. We do not store IP addresses. Cloudflare, which delivers and protects the site, processes your IP address to do so. Legal basis: legitimate interest in a secure, working service (Art. 6(1)(f) GDPR).

Cookies

We use only one technical cookie, the "My eSIMs" session cookie, if you sign in: it is necessary for the service you ask for, cannot be read by JavaScript, lasts 30 days and is deleted when you sign out. We use no analytics or advertising cookies.

Who we share data with

  • Stripe Payments Europe, Limited (Ireland) processes payments. It may transfer data to Stripe, Inc. (United States), which is certified under the EU-US Data Privacy Framework.
  • Plus Five Five, Inc. ("Resend", United States) sends our emails. It is certified under the EU-US Data Privacy Framework, and we have also signed standard contractual clauses.
  • Cloudflare, Inc. (United States) delivers and protects the site and forwards the email we receive. It is certified under the EU-US Data Privacy Framework.
  • Google Ireland Limited (Ireland) hosts the mailbox where we receive support messages. It may transfer data to Google LLC (United States), which is certified under the EU-US Data Privacy Framework.
  • Hetzner Online GmbH (Germany) hosts the server and database in Falkenstein (Germany), and the encrypted backups in Hetzner data centres in the European Union.
  • eSIM Access Limited (Hong Kong) is our eSIM provider. We do not send it your name or email: only an internal order reference and the plan. However, as with every travel eSIM, your data traffic passes through its network, and the provider sees the usage and the approximate location of the connection. Hong Kong has no adequacy decision from the European Union; this transfer is necessary to perform the contract you make with us (Art. 49(1)(b) GDPR).

How long we keep data

  • Orders, payments and records, including the eSIM data and provider responses that form part of the order: 8 years from the end of the year the order was placed, as German tax law requires (§ 147 AO).
  • Business correspondence about an order: 6 years.
  • Support messages that are not part of an order: 2 years after they are resolved.
  • Sign-in links: deleted when they expire. Sessions: 30 days.
  • Site performance statistics: 35 days.
  • Encrypted backups: 30 days.

Your rights

You can ask us for access to your data, its rectification or erasure, restriction of processing and portability, and object to processing based on legitimate interest (Arts. 15 to 21 GDPR). Write to [email protected].

You can also complain to a data protection authority, in particular the one where you habitually live or ours: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, Germany.

We make no automated decisions that produce legal effects concerning you.

Last updated: 6 October 2026.