Privacy policy
Last updated: 30 Aug 2026 · GDPR (EU 2016/679)
Controller
ESIM SOLARSERV · esim.solarserv.ro — office@ecosolaris.ro.
What we collect and why
- Email address — to deliver the eSIM, sign you in (one-time code) and send order-related messages. Legal basis: contract.
- Name, phone, country (optional) — invoices and support. Legal basis: contract / legitimate interest.
- Order and eSIM data — plan, price, ICCID, activation code (stored encrypted), usage figures reported by the carrier. Legal basis: contract; retention for accounting as required by law.
- Payment — processed by Stripe; we receive only a payment reference, card brand and last 4 digits. We never see your full card number.
- Technical data — IP address, browser, device type, for security (fraud and abuse prevention), rate limiting and audit logs. Legal basis: legitimate interest. Kept for up to 90 days (security logs) or as part of the order record.
- Cookies — strictly necessary cookies only: session, CSRF protection, currency preference, "remember me" and referral attribution when you arrive through a partner link. No advertising trackers.
Who receives your data
Our eSIM carrier partners (to provision the eSIM — they receive the order reference and, where required, the ICCID), Stripe (payments), and our hosting provider in the EU. We do not sell personal data.
How long we keep it
Orders, invoices and payment records: as required by accounting law (typically 10 years). Login codes: 10 minutes. Security logs: 90 days. If you delete your account, personal fields are anonymised after 30 days while invoice records are kept as required by law.
Your rights
You can access, export, correct or delete your data and object to processing. Export and deletion are self-service in Account → Settings; you can also email us. You may lodge a complaint with your supervisory authority (in Romania: ANSPDCP).
Marketing
We send marketing emails only if you opted in; every message has an unsubscribe link and the preference can be changed in your account.
Security
TLS everywhere, activation codes and partner credentials encrypted at rest, passwordless sign-in with short-lived codes, strict access control and audit logging.