Skip to content

Privacy policy

How we handle information you share with us.

Last updated September 28, 2026.

This policy explains what personal data we collect when you visit yuzusim.com or buy an eSIM, how we use and protect it, and what you can ask of us. We are a Polish company, so we handle personal data under the EU General Data Protection Regulation (GDPR). Section 9 also sets out the rights you may have under the data protection laws of Japan, South Korea, mainland China and Hong Kong. Cookies and similar technologies are explained in our Cookie information.

1. Who we are

yuzusim.com is operated by LuKas Holdings sp. z o.o., ul. Stefana Batorego 18/108, 02-591 Warsaw, Poland, KRS 0001233010, NIP 7011306806 (“YuzuSIM”, “we”, “us”). We are the controller of the personal data described here.

For every question, request or complaint about personal data, write to [email protected].

2. What we collect

When you visit yuzusim.com

  • Your browser sends technical data with every request: IP address, browser and device type, the page requested and the referring page. Our content delivery network, Cloudflare, uses it to deliver pages and to protect the site from attacks. Our own web server does not keep access logs.
  • With your permission, our self-hosted Umami analytics records public page views, plan selections, checkout starts and purchases or refunds. It uses a random browser identifier, a session identifier, the page path, language, browser/device information, referring site, and plan, amount and currency where relevant. IP address and browser information are used to derive approximate location and device statistics. We do not send your email, name, card details, eSIM codes, private order links or URL query strings to Umami. We do not load advertising pixels or track you across other websites.
  • Your display currency is kept in browser session storage until you close the tab. Your selected plan is carried in the form or page address, without payment or activation details.

When you buy an eSIM

  • The email address you give at checkout, where we send your eSIM, and the details you enter on the Stripe payment page: name on the card, billing country and, for some cards, postal code. Card numbers, including those of cards in Apple Pay and Google Pay, are handled by Stripe and never reach us.
  • Order data: the plan, price, currency, language, time of purchase, the version of the Terms of sale and Refund policy you accepted when you asked for immediate delivery, and the eSIM delivered to you (its ICCID and activation code, which we store encrypted).
  • When you start a checkout, your IP address is used to limit repeated attempts. Security rate-limit records use a salted one-way hash. If you have agreed to analytics, your analytics identifiers, IP address and browser information are also stored with the order for purchase and refund measurement, then removed after 90 days.
  • When your order page is opened, we record the time and a salted one-way hash of the IP address, to protect your eSIM code against misuse.

When you use a form on this site

  • Find my eSIM. We use the email address you enter to look for orders placed with it in the last 12 months, and email the links to that address. The page gives the same answer whether or not the address has orders.
  • Waiting list. If you tick the box to join a waiting list, we keep your email address, the language of the page and the page where you signed up, and use them only to send you the email you asked for. You can ask to be removed at any time.
  • Contact form. A message sent through the contact form (your name, email address and topic, your phone model and the link to your order page if you add them, and the message itself) is passed to our support mailbox and answered by email. Our support desk stores the message and our replies so we can handle your request.
  • Each of these forms uses your IP address to limit repeated attempts, in the same way as the checkout.

When you write to us

  • Your email address, name and the content of your message.
Purpose Legal basis under the GDPR
Selling and delivering the eSIM, the order emails, sending your order links when you ask, support and refunds Performance of the contract with you (Article 6(1)(b))
Accounting and tax records Our legal obligations (Article 6(1)(c))
Preventing fraud, securing payments and eSIM codes, limiting repeated attempts, protecting the site Our legitimate interest in a secure shop (Article 6(1)(f))
Answering your questions and partnership enquiries Our legitimate interest in answering you, or steps before a contract you ask for (Article 6(1)(f) or (b))
Understanding visits, shopping activity and conversions through optional Umami analytics Your consent (Article 6(1)(a)); reject or withdraw using Cookie settings, without affecting shopping
Emailing you from a waiting list you joined Your consent, given when you tick the box (Article 6(1)(a)); you can withdraw it at any time by writing to us

We use personal data only for these purposes. We send no marketing emails other than the waiting-list email you ask for, and we do not sell personal data.

4. Automated decisions

Stripe screens payments for fraud with automated risk scoring. A payment judged high risk may be blocked or may need extra verification such as 3D Secure. If you think a payment was blocked by mistake, write to us and a person will review it.

5. Who receives your data

  • Stripe processes payments, including Apple Pay and Google Pay, and screens them for fraud, under its privacy policy at stripe.com/privacy.
  • Cloudflare, Inc. delivers and protects the website.
  • Resend (Plus Five Five, Inc., United States) sends our emails, including the order email with your eSIM’s QR code and the order links you ask for, and receives the email sent to our addresses at yuzusim.com.
  • The provider of our support mailbox stores the emails and contact form messages we receive, and our replies.
  • Our server hosting provider runs the virtual server in the European Union that hosts the website, order database, support desk and our self-hosted analytics.
  • Our eSIM distributor receives no personal data from us. We buy eSIM profiles without sending your details.
  • Our accountants and legal advisers, and public authorities where the law requires it.

6. Transfers outside the European Economic Area

The website, order database and self-hosted analytics are hosted in the European Union. Stripe, Cloudflare and Resend may process data in the United States and other countries. Their data processing terms provide for applicable transfer safeguards, including the European Commission’s standard contractual clauses or, where applicable, the EU-US Data Privacy Framework. You can ask us for information about the safeguards that apply to a particular provider.

7. How long we keep it

We keep personal data only as long as we need it for the purposes above or as the law requires:

  • Order and payment records, including the encrypted eSIM details: as long as accounting and tax law requires, normally 5 years from the end of the year of purchase.
  • Order page access records (hashed IP address): 12 months.
  • Hashed IP addresses used to limit repeated attempts at checkout and on the forms: 24 hours, with expired records removed by scheduled maintenance.
  • Waiting-list sign-ups: up to 24 months from sign-up, or until you ask to be removed, if that is sooner.
  • Email correspondence, including contact form messages: as long as needed to handle the matter and related claims, and no longer than 3 years after it is closed.
  • Display currency in browser session storage: until you close the tab.
  • Analytics identifiers, IP and browser details attached to orders: 90 days.
  • Analytics browser identifier and consent choice: up to 180 days. The session cookie expires after 30 minutes of inactivity.
  • Umami reporting data: retained while needed to assess traffic and sales trends, reviewed at least annually for deletion or aggregation. You may request deletion of identifiable analytics records by contacting us.
  • Finished email-delivery troubleshooting records: 90 days; brand order-recovery requests: 30 days.

8. Cookies

We save your cookie preference for 180 days. Optional analytics cookies are set only after you agree, and analytics is disabled for browsers sending Global Privacy Control. You can reject or withdraw through Cookie settings in the footer; withdrawal deletes the analytics cookies and stops future storefront tracking. It does not undo processing already performed. To remove analytics identifiers already attached to an order, contact support. We use no advertising cookies. Cloudflare may set strictly necessary security cookies, and the Stripe payment page uses its own cookies for payment processing and fraud prevention. Our Cookie information gives the details.

9. Your rights

Under the GDPR you can ask us:

  • for access to the personal data we hold about you and a copy of it;
  • to correct data that is wrong or incomplete;
  • to delete data we no longer need or have no basis to keep;
  • to restrict how we use your data while a question about it is settled;
  • for the data you gave us in a portable format;
  • to stop using data we process on the basis of our legitimate interests (you can object);
  • and you can withdraw a consent at any time, without affecting what was done before.

Write to [email protected]. We reply within one month, or tell you within that time why we need longer.

You can complain to the President of the Personal Data Protection Office in Poland (UODO, uodo.gov.pl), or to the data protection authority of the EU country where you live or work.

If you are in Japan, you also have the rights that the Act on the Protection of Personal Information gives you, and you can contact the Personal Information Protection Commission (ppc.go.jp).

If you are in South Korea, you also have the rights that the Personal Information Protection Act gives you, and you can contact the Personal Information Protection Commission (pipc.go.kr).

If you are in mainland China, you also have the rights that the Personal Information Protection Law of the People’s Republic of China gives you, and you can contact the Cyberspace Administration of China (cac.gov.cn).

If you are in Hong Kong, you also have the rights that the Personal Data (Privacy) Ordinance (Cap. 486) gives you, and you can contact the Office of the Privacy Commissioner for Personal Data (pcpd.org.hk).

You can use all of these rights the same way, by writing to us.

10. Security

Card data stays with Stripe. eSIM activation codes are encrypted at rest with AES-256-GCM. Access to the order system is restricted, and every time an eSIM code is shown to an administrator it is logged. The site is served only over HTTPS. If a data breach is likely to put your rights at risk, we notify the supervisory authority within 72 hours and, where the risk is high, you as well, as the GDPR requires.

11. Children

yuzusim.com is not aimed at children under 16, and we do not knowingly collect their data.

12. Changes

When our processing changes, we update this policy and the date at the top of this page.