Privacy Notice
What Kolay Esim does with your personal data when you buy an eSIM, and how to ask about it.
10 details are still to be completed by this shop’s operator. The page is not indexed by search engines until they are.
This document is published in English. The English text is the authoritative version.
Who is responsible for your data
This notice covers Kolay Esim, the store you are reading it on. It explains what happens to your personal data when you buy an eSIM here, write to support, or create an account.
The store is run by LOKUM TECH LLC, of 8 The Green, Suite A Dover, DE 19901. They are the data controller: they decide what is collected in this store and what it is used for. Where this notice says "we", it means them.
The shop software is Esimbit, operated by LOKUM TECH LLC, which hosts the store, holds the records and sends the emails — but only on the operator’s instructions, and only for this store. In data-protection terms Esimbit is the processor and the operator is the controller.
Practically, that means a question or a request about your data goes to the store operator first — their contact details are in the last section. Esimbit cannot decide it on their behalf; a request sent to Esimbit is passed to the operator to answer.
This notice is published in English only, although the store itself is available in other languages.
What we collect
Everything below is collected because of something you did: you placed an order, you created an account, or you wrote to us. There is no sign-up wall and no data collected before you act.
- Your delivery email address. This is required: the eSIM and its installation details are sent to it, so an order cannot be placed without one.
- The order record — the order number, the package you bought, the price and currency, the status, and the times the order was created and fulfilled.
- The eSIM itself — its ICCID, and whatever activation details the eSIM provider returns (an SM-DP+ address, a matching ID, an LPA string, a QR code).
- Data-usage readings for that eSIM: how much data is left, how much has been used, when it expires, and when the reading was taken. These are fetched from the eSIM provider when you open the usage page, so that the figure shown is the provider’s and not a guess.
- A store account, only if you choose to create one: your name, your email address, the language you picked, and a hash of your password. The password itself is never stored, here or anywhere else.
- The one-time code emailed to you when you create an account, sign in or reset your password, and the record that the address was proven with it. No order history is shown until that check passes.
- Which eSIM notices you want — a warning when data runs low, when a package is about to expire, and when an eSIM you bought has not been installed. These are held against your email address whether or not you have an account, and every notice carries a link to turn them off.
- Anything you send to support, and the reply to it.
- Server logs — your IP address, the request, the time, and the user-agent string your browser sends.
A store account is optional. If you do not create one, your orders still reach you by email, and the store holds an order record against the email address you gave.
What never reaches us
Your card details do not. When you check out, the store creates the order and sends you to the hosted payment page of [TO BE COMPLETED: the payment provider this store uses]. You enter your card details there, on that provider’s own page, and they go to that provider.
No card number, expiry date or security code is ever typed into a page this store serves, and none is held by the store operator or by Esimbit. What comes back from the payment provider is whether the payment succeeded, and a reference for it.
- We do not sell or rent personal data, and we do not pass it to anyone for their own marketing.
- We do not profile you, and nothing about you here is decided solely by automated means in a way that produces a legal or similarly significant effect (GDPR Art 22).
- We do not ask for a date of birth, a postal address, a phone number or an identity document in order to sell you an eSIM.
Why we use it, and the legal basis
If you are in the EEA or the UK, the GDPR requires a legal basis for each use. This is the whole list.
| What | Why | Legal basis |
|---|---|---|
| Delivery email address | Sending you the eSIM, its installation details and the order confirmation | Performance of your contract (Art 6(1)(b)) |
| Order record | Fulfilling the order, answering questions about it, handling refunds, and keeping the accounting record | Contract (Art 6(1)(b)); legal obligation for the accounting copy (Art 6(1)(c)) |
| eSIM identifiers and activation details | Issuing the SIM through the eSIM provider and showing you how to install it | Performance of your contract (Art 6(1)(b)) |
| Data-usage readings | Showing you how much data is left on an eSIM you bought | Performance of your contract (Art 6(1)(b)) |
| eSIM service notices | Telling you your data is running low, your package is expiring, or a purchased eSIM was never installed | Performance of your contract (Art 6(1)(b)) |
| Store account | Letting you sign in and see your past orders without waiting for an email, and proving the address is yours before any order history is shown | Performance of your contract (Art 6(1)(b)) — you only have an account if you created one |
| Support correspondence | Answering you, and keeping a record of what was agreed | Contract (Art 6(1)(b)); legitimate interests in keeping a record (Art 6(1)(f)) |
| Server logs | Keeping the store running, investigating faults, and stopping abuse such as fraud or brute-force sign-in attempts | Legitimate interests in a working and secure store (Art 6(1)(f)) |
Where the basis is legitimate interests, you can object, and we will stop unless there is a reason that overrides your objection.
Where your data goes
The store’s database and its backups are held in Frankfurt, Germany (eu-central-1). If you are somewhere else, your data leaves your country to get there.
The proxy and security network in front of the store decrypts your request at whichever of its own locations serves you, which may be outside your country, before passing it on to the servers running the store.
eSIM providers are international by nature, and the payment provider may also be outside your country. Those transfers happen because they are necessary to do what you asked — to issue the eSIM you bought and to take the payment for it.
For transfers out of the EEA or the UK, the safeguard relied on is [TO BE COMPLETED: the transfer safeguard relied on, for example EU standard contractual clauses or an adequacy decision]. Ask the store operator for a copy of it. Turkish law sets its own rules for transfers abroad — see the section below.
How long it is kept
These periods are the store operator’s policy. Tax and accounting law usually fixes the one for order records; the rest is their decision.
| Record | Kept for |
|---|---|
| Order records, eSIM identifiers and usage readings | [TO BE COMPLETED: how long the store operator keeps order and eSIM records] |
| A store account and the email address on it | [TO BE COMPLETED: how long the store operator keeps a closed account] |
| Support correspondence | [TO BE COMPLETED: how long support correspondence is kept] |
Server logs are the exception, because they are Esimbit’s rather than the operator’s: they are kept on the platform’s servers for 365 days, on one policy for every store, and the operator does not set that period.
Nothing is deleted on a timer today. The store software has no scheduled clean-up, so a record stays until it is deleted in response to a request or the operator removes it. Treat every period above as policy applied by hand rather than as something the software enforces.
Your rights, and how to use them
If you are in the EEA or the UK, the GDPR gives you these rights over the data described above.
- Access — a copy of the personal data held about you.
- Rectification — correcting data that is wrong or incomplete.
- Erasure — deleting it, where there is no longer a reason to keep it and no law requiring it to be kept.
- Restriction — freezing its use while a dispute about it is resolved.
- Portability — receiving the data you gave us in a machine-readable form, or having it sent to someone else.
- Objection — objecting to any use based on legitimate interests.
- Withdrawing consent, where consent was the basis. Withdrawing it does not undo what was done beforehand.
Send the request to the store operator, at [email protected]. They are the controller and they answer it. If you send it to Esimbit instead, it will be passed to the operator rather than acted on directly, because Esimbit may only act on their instructions.
Expect to be asked to confirm the email address the order was placed with. For most shoppers that address is the only identifier the store holds, so it is both how your records are found and how we avoid handing them to someone else.
The law allows one month to answer (GDPR Art 12(3)), extendable for complex requests. If you are unhappy with the answer, you can complain to the data protection authority in the country where you live or work.
If you are in Turkey (KVKK)
Turkish law 6698 (KVKK) applies to shoppers in Turkey, and it asks for things the GDPR does not. This section is the aydınlatma notice under Art 10. The veri sorumlusu — the data controller — is LOKUM TECH LLC, and the data, purposes, recipients and bases are the ones set out in the sections above.
VERBİS registration for this store: [TO BE COMPLETED: the store operator’s VERBİS registration number, or a statement that registration is not required].
Art 11 gives you the right to:
- learn whether your personal data is processed at all, and request information if it is;
- learn the purpose of the processing and whether the data is used in line with it;
- know the third parties at home or abroad that the data is transferred to;
- have incomplete or incorrect data corrected, and have that correction notified to those third parties;
- have the data deleted or destroyed under Art 7, and have that notified to those third parties;
- object to a result reached solely by automated analysis, where it works against you;
- claim compensation for damage caused by unlawful processing.
Applications are made under Art 13, in writing to [TO BE COMPLETED: the address or registered KEP address for written KVKK applications] or by the other means the Board permits. They are answered within 30 days and are free unless answering has a real cost, in which case the Board’s tariff applies. If the answer does not satisfy you, or none arrives, you may complain to the Kişisel Verileri Koruma Kurulu within the time limits in Art 14.
Transfers abroad follow Art 9 as amended by Law 7499: an adequacy decision, or an appropriate safeguard such as a standard contract notified to the Board within five business days of signature, or one of the exceptional cases the article lists, including your explicit consent for a one-off transfer. Because the store is hosted outside Turkey and eSIM providers are international, transfers abroad do happen.
The store logo may load from another host
The operator can set the store’s logo by giving a web address for the image. If that address points at a host neither the operator nor Esimbit runs, your browser fetches the image straight from that host. That host therefore sees your IP address, your browser’s user-agent and the time you loaded the page, and it may set storage of its own.
That image is the only thing in a store page your browser fetches from a third party. Every other file, fonts and flag icons included, comes from the store’s own servers, through the proxy and security network described above.
For operators: uploading the logo to the store instead of linking to one hosted elsewhere removes this entirely.
Changes to this notice
The date at the top of this page is the date the text last changed, and the version on this page is always the current one. It is worth re-reading before you buy again.
We do not send shoppers a mailing about policy changes. If a change is significant and the law requires you to be told directly, the store operator will tell you.
Contact
The controller for this store is LOKUM TECH LLC, of 8 The Green, Suite A Dover, DE 19901. Privacy questions and data requests go to [email protected].
Data protection officer for the store, if one is appointed: [TO BE COMPLETED: the store operator’s data protection officer, or a statement that none is appointed].
Esimbit runs the software behind this store as the operator’s processor. For questions about the platform itself, write to [email protected] — but a request about your own data is faster sent to the operator, because Esimbit will only forward it to them.