Kolay Esim
← Back to the store

Privacy Notice

What Kolay Esim does with your personal data when you buy an eSIM, and how to ask about it.

Last updated August 18, 2026

Draft — not yet in force

10 details are still to be completed by this shop’s operator. The page is not indexed by search engines until they are.

This document is published in English. The English text is the authoritative version.

Who is responsible for your data

This notice covers Kolay Esim, the store you are reading it on. It explains what happens to your personal data when you buy an eSIM here, write to support, or create an account.

The store is run by LOKUM TECH LLC, of 8 The Green, Suite A Dover, DE 19901. They are the data controller: they decide what is collected in this store and what it is used for. Where this notice says "we", it means them.

The shop software is Esimbit, operated by LOKUM TECH LLC, which hosts the store, holds the records and sends the emails — but only on the operator’s instructions, and only for this store. In data-protection terms Esimbit is the processor and the operator is the controller.

Practically, that means a question or a request about your data goes to the store operator first — their contact details are in the last section. Esimbit cannot decide it on their behalf; a request sent to Esimbit is passed to the operator to answer.

This notice is published in English only, although the store itself is available in other languages.

What we collect

Everything below is collected because of something you did: you placed an order, you created an account, or you wrote to us. There is no sign-up wall and no data collected before you act.

  • Your delivery email address. This is required: the eSIM and its installation details are sent to it, so an order cannot be placed without one.
  • The order record — the order number, the package you bought, the price and currency, the status, and the times the order was created and fulfilled.
  • The eSIM itself — its ICCID, and whatever activation details the eSIM provider returns (an SM-DP+ address, a matching ID, an LPA string, a QR code).
  • Data-usage readings for that eSIM: how much data is left, how much has been used, when it expires, and when the reading was taken. These are fetched from the eSIM provider when you open the usage page, so that the figure shown is the provider’s and not a guess.
  • A store account, only if you choose to create one: your name, your email address, the language you picked, and a hash of your password. The password itself is never stored, here or anywhere else.
  • The one-time code emailed to you when you create an account, sign in or reset your password, and the record that the address was proven with it. No order history is shown until that check passes.
  • Which eSIM notices you want — a warning when data runs low, when a package is about to expire, and when an eSIM you bought has not been installed. These are held against your email address whether or not you have an account, and every notice carries a link to turn them off.
  • Anything you send to support, and the reply to it.
  • Server logs — your IP address, the request, the time, and the user-agent string your browser sends.

A store account is optional. If you do not create one, your orders still reach you by email, and the store holds an order record against the email address you gave.

What never reaches us

Your card details do not. When you check out, the store creates the order and sends you to the hosted payment page of [TO BE COMPLETED: the payment provider this store uses]. You enter your card details there, on that provider’s own page, and they go to that provider.

No card number, expiry date or security code is ever typed into a page this store serves, and none is held by the store operator or by Esimbit. What comes back from the payment provider is whether the payment succeeded, and a reference for it.

  • We do not sell or rent personal data, and we do not pass it to anyone for their own marketing.
  • We do not profile you, and nothing about you here is decided solely by automated means in a way that produces a legal or similarly significant effect (GDPR Art 22).
  • We do not ask for a date of birth, a postal address, a phone number or an identity document in order to sell you an eSIM.

Why we use it, and the legal basis

If you are in the EEA or the UK, the GDPR requires a legal basis for each use. This is the whole list.

WhatWhyLegal basis
Delivery email addressSending you the eSIM, its installation details and the order confirmationPerformance of your contract (Art 6(1)(b))
Order recordFulfilling the order, answering questions about it, handling refunds, and keeping the accounting recordContract (Art 6(1)(b)); legal obligation for the accounting copy (Art 6(1)(c))
eSIM identifiers and activation detailsIssuing the SIM through the eSIM provider and showing you how to install itPerformance of your contract (Art 6(1)(b))
Data-usage readingsShowing you how much data is left on an eSIM you boughtPerformance of your contract (Art 6(1)(b))
eSIM service noticesTelling you your data is running low, your package is expiring, or a purchased eSIM was never installedPerformance of your contract (Art 6(1)(b))
Store accountLetting you sign in and see your past orders without waiting for an email, and proving the address is yours before any order history is shownPerformance of your contract (Art 6(1)(b)) — you only have an account if you created one
Support correspondenceAnswering you, and keeping a record of what was agreedContract (Art 6(1)(b)); legitimate interests in keeping a record (Art 6(1)(f))
Server logsKeeping the store running, investigating faults, and stopping abuse such as fraud or brute-force sign-in attemptsLegitimate interests in a working and secure store (Art 6(1)(f))

Where the basis is legitimate interests, you can object, and we will stop unless there is a reason that overrides your objection.

Who else sees it

Several companies are involved in getting an eSIM to you, and each gets only what its part needs.

WhoWhat they getWhy
[TO BE COMPLETED: the eSIM provider or providers this store buys from]What was ordered, and an identifier for the order. Your email address where the provider needs it to issue or deliver the profile.They issue the eSIM and report its status and usage back to the store.
[TO BE COMPLETED: the payment provider this store uses]The card or payment details you enter on their own page, plus the amount, the currency and an order reference from us.They take the payment. The details you type there never pass through the store.
LOKUM TECH LLCEverything described in the sections above — it is the software the store runs on.Platform operator, acting as the store operator’s processor.
AWSThe servers, database and backups the records sit on.Hosting, engaged by Esimbit.
Cloudflare, whose bot-protection cookies (__cf_bm, and cf_clearance after a challenge) may be set on this domainEvery request your browser makes to this store, your IP address included, and the encrypted connection itself, which is decrypted there before the request is passed on.Proxying and filtering all storefront traffic, terminating the encryption and blocking automated abuse. Engaged by Esimbit.
PostmarkYour email address and the contents of the message sent to you.Delivering the eSIM email, password resets, verification codes and service notices.

Beyond those, data is disclosed only where the law requires it — to a court, a regulator or a tax authority — or to the operator’s professional advisers under a duty of confidence.

The suppliers Esimbit engages to run the store are listed in full in Annex 2 of the data processing addendum between Esimbit and the operator. That annex is the authoritative list; the rows above summarise the ones your own data reaches, and the operator can give you a copy.

Where your data goes

The store’s database and its backups are held in Frankfurt, Germany (eu-central-1). If you are somewhere else, your data leaves your country to get there.

The proxy and security network in front of the store decrypts your request at whichever of its own locations serves you, which may be outside your country, before passing it on to the servers running the store.

eSIM providers are international by nature, and the payment provider may also be outside your country. Those transfers happen because they are necessary to do what you asked — to issue the eSIM you bought and to take the payment for it.

For transfers out of the EEA or the UK, the safeguard relied on is [TO BE COMPLETED: the transfer safeguard relied on, for example EU standard contractual clauses or an adequacy decision]. Ask the store operator for a copy of it. Turkish law sets its own rules for transfers abroad — see the section below.

How long it is kept

These periods are the store operator’s policy. Tax and accounting law usually fixes the one for order records; the rest is their decision.

RecordKept for
Order records, eSIM identifiers and usage readings[TO BE COMPLETED: how long the store operator keeps order and eSIM records]
A store account and the email address on it[TO BE COMPLETED: how long the store operator keeps a closed account]
Support correspondence[TO BE COMPLETED: how long support correspondence is kept]

Server logs are the exception, because they are Esimbit’s rather than the operator’s: they are kept on the platform’s servers for 365 days, on one policy for every store, and the operator does not set that period.

Nothing is deleted on a timer today. The store software has no scheduled clean-up, so a record stays until it is deleted in response to a request or the operator removes it. Treat every period above as policy applied by hand rather than as something the software enforces.

Your rights, and how to use them

If you are in the EEA or the UK, the GDPR gives you these rights over the data described above.

  • Access — a copy of the personal data held about you.
  • Rectification — correcting data that is wrong or incomplete.
  • Erasure — deleting it, where there is no longer a reason to keep it and no law requiring it to be kept.
  • Restriction — freezing its use while a dispute about it is resolved.
  • Portability — receiving the data you gave us in a machine-readable form, or having it sent to someone else.
  • Objection — objecting to any use based on legitimate interests.
  • Withdrawing consent, where consent was the basis. Withdrawing it does not undo what was done beforehand.

Send the request to the store operator, at [email protected]. They are the controller and they answer it. If you send it to Esimbit instead, it will be passed to the operator rather than acted on directly, because Esimbit may only act on their instructions.

Expect to be asked to confirm the email address the order was placed with. For most shoppers that address is the only identifier the store holds, so it is both how your records are found and how we avoid handing them to someone else.

The law allows one month to answer (GDPR Art 12(3)), extendable for complex requests. If you are unhappy with the answer, you can complain to the data protection authority in the country where you live or work.

If you are in Turkey (KVKK)

Turkish law 6698 (KVKK) applies to shoppers in Turkey, and it asks for things the GDPR does not. This section is the aydınlatma notice under Art 10. The veri sorumlusu — the data controller — is LOKUM TECH LLC, and the data, purposes, recipients and bases are the ones set out in the sections above.

VERBİS registration for this store: [TO BE COMPLETED: the store operator’s VERBİS registration number, or a statement that registration is not required].

Art 11 gives you the right to:

  • learn whether your personal data is processed at all, and request information if it is;
  • learn the purpose of the processing and whether the data is used in line with it;
  • know the third parties at home or abroad that the data is transferred to;
  • have incomplete or incorrect data corrected, and have that correction notified to those third parties;
  • have the data deleted or destroyed under Art 7, and have that notified to those third parties;
  • object to a result reached solely by automated analysis, where it works against you;
  • claim compensation for damage caused by unlawful processing.

Applications are made under Art 13, in writing to [TO BE COMPLETED: the address or registered KEP address for written KVKK applications] or by the other means the Board permits. They are answered within 30 days and are free unless answering has a real cost, in which case the Board’s tariff applies. If the answer does not satisfy you, or none arrives, you may complain to the Kişisel Verileri Koruma Kurulu within the time limits in Art 14.

Transfers abroad follow Art 9 as amended by Law 7499: an adequacy decision, or an appropriate safeguard such as a standard contract notified to the Board within five business days of signature, or one of the exceptional cases the article lists, including your explicit consent for a one-off transfer. Because the store is hosted outside Turkey and eSIM providers are international, transfers abroad do happen.

Cookies and local storage

What the store keeps in your browser is the language you picked, the light or dark setting, your sign-in token if you have an account, the order you are part-way through paying for, and — only if you turn it on — a list of your recent orders on this device. The Cookies and local storage page lists each of them by name, what it is for and how long it lasts, and it is where you change or withdraw your choice.

There is no analytics, no advertising pixel, no tag manager, no session replay and no social widget on this store, and no third-party script or font runs in your browser. Fonts and flag icons are served by the store itself.

The store is delivered through a proxy and security network that sits between you and the servers running it, and that network may set a cookie of its own to tell shoppers from automated traffic. It is a security measure, not a tracking one, and the store cannot switch it off for you. The Cookies and local storage page names it, and "Who else sees it" above sets out what it sees.

Changes to this notice

The date at the top of this page is the date the text last changed, and the version on this page is always the current one. It is worth re-reading before you buy again.

We do not send shoppers a mailing about policy changes. If a change is significant and the law requires you to be told directly, the store operator will tell you.

Contact

The controller for this store is LOKUM TECH LLC, of 8 The Green, Suite A Dover, DE 19901. Privacy questions and data requests go to [email protected].

Data protection officer for the store, if one is appointed: [TO BE COMPLETED: the store operator’s data protection officer, or a statement that none is appointed].

Esimbit runs the software behind this store as the operator’s processor. For questions about the platform itself, write to [email protected] — but a request about your own data is faster sent to the operator, because Esimbit will only forward it to them.