Privacy Policy
How we collect, use, and protect your personal data in compliance with GDPR.
Effective Date: April 29, 2026 · Version 1.4
1. Introduction
YTI Digital OÜ, trading as esimystic ("Company", "we", "us", or "our"), is committed to protecting your privacy and personal data. Your trust matters to us, and we take our data protection responsibilities seriously.
This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal data when you use the esimystic website, mobile applications (iOS and Android), and related services (the "Service"). It also describes your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you have any questions, please visit our Help Center or contact us at [email protected].
2. Data Controller
The data controller responsible for processing your personal data is:
YTI Digital OÜ
Registry Code: 17298015
Address: Loitsu tn 5-166, 13622 Tallinn, Estonia
Email: [email protected]
3. Data Minimisation Principle
In accordance with Article 5(1)(c) of the GDPR, we adhere to the principle of data minimisation. This means we only collect personal data that is:
- Adequate — sufficient to properly fulfill our stated purposes;
- Relevant — directly related to those purposes;
- Limited — not more than necessary for the purposes.
We do not collect personal data "just in case" it might be useful later. We regularly review the data we hold to ensure we are not retaining more than necessary.
4. Categories of Personal Data We Collect
We collect and process the following categories of personal data:
4.1 Data You Provide Directly
| Category | Examples |
|---|---|
| Contact Information | Email address, name (optional) |
| Account Data | Login credentials (password stored as cryptographic hash) |
| Transaction Data | Order details, purchase history, billing country |
| Communication Data | Support inquiries, feedback, correspondence |
4.2 Data Collected Automatically
| Category | Examples |
|---|---|
| Device Information | Browser type, operating system, device type |
| Usage Data | Pages visited, features used, session duration |
| Mobile App Diagnostics | App version, OS version, crash logs, performance events, push token (if notifications are enabled) |
| Network Data | IP address (used for security, fraud prevention, approximate geolocation) |
| Cookie Data | As described in our Cookie Policy |
4.3 Data from Third Parties
| Source | Data |
|---|---|
| Stripe | Payment confirmation, partial card details (last 4 digits), billing country |
| Partner Referrals | Referral source identifier (if you arrived via an affiliate link) |
| Identity Providers | Google/Apple Sign-In account identifiers and verified profile data (when you choose social login) |
5. Purposes and Legal Bases for Processing
Under Article 6 of the GDPR, we process your personal data based on the following lawful bases:
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Processing and fulfilling your Orders | Performance of a contract (Art. 6(1)(b)) |
| Sending Order confirmations and eSIM delivery emails | Performance of a contract (Art. 6(1)(b)) |
| Providing customer support | Performance of a contract (Art. 6(1)(b)) |
| Processing payments | Performance of a contract (Art. 6(1)(b)) |
| Fraud prevention and security | Legitimate interests (Art. 6(1)(f)) |
| Improving Service functionality and user experience | Legitimate interests (Art. 6(1)(f)) |
| Compliance with legal obligations (e.g., tax records, anti-money laundering) | Legal obligation (Art. 6(1)(c)) |
| Marketing communications (with consent) | Consent (Art. 6(1)(a)) |
| Website analytics, advertising measurement (e.g. Google Ads, Meta Pixel), and other non-essential cookies | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms.
6. Data Sharing and Third Parties
We share your personal data with the following categories of recipients, only to the extent necessary for the stated purposes:
6.1 Google Analytics and Google Ads (Web)
With your consent, we use Google Analytics 4 (GA4) to analyze website usage and improve our Service. Google LLC processes analytics data as a data processor under our instructions. Where we enable Google Ads conversion linking, Google may also use consent-gated data for advertising measurement and conversion attribution in line with your choices and Google's policies.
Data collected: Pages visited, session duration, device information, approximate location (country/city), e-commerce interactions. Your IP address is anonymized before processing in GA4 as configured.
Purpose: Website analytics, service improvement, and (where enabled) ads conversion measurement (with consent).
Safeguards: Google is certified under the EU-U.S. Data Privacy Framework. We use Consent Mode so that non-essential measurement is aligned with your cookie choices. See Google's Privacy Policy.
6.2 Meta (Facebook) Pixel (Web)
With your consent, we may load the Meta Pixel so Meta can help us measure advertising effectiveness (e.g. conversions, optimization). Meta processes related data under its own terms and privacy policy. Details of typical identifiers and cookies are summarized in our Cookie Policy.
Purpose: Advertising measurement and optimization (with consent).
Safeguards: We only activate the Pixel after you choose non-essential cookies in our banner. Meta participates in the EU-U.S. Data Privacy Framework. See Meta's Privacy Policy.
6.3 Stripe, Inc. (Payment Processing)
Stripe processes your payment data as an independent data controller under their own Privacy Policy. We do not have access to your full payment card details. Stripe is certified under PCI-DSS Level 1 and is subject to the EU-U.S. Data Privacy Framework.
6.4 eSIM Suppliers
We share minimal order data (typically Order ID only) with eSIM suppliers to fulfill your purchase. These suppliers act as data processors under our instructions.
6.5 Hosting and Infrastructure
Our Service is hosted on Vercel, Inc. Server logs may contain technical data (IP address, request timestamps) for operational purposes.
6.6 Email Service Providers
We use email service providers to send transactional emails (Order confirmations, support responses). These providers act as data processors under appropriate Data Processing Agreements (DPAs).
6.7 Partner Program (Affiliate & Wholesale B2B)
We operate two types of Partner relationships, with different data flows:
Affiliate Partners. If you arrived at the Service via an affiliate link, we share only commission-related, aggregated data (Order value, Order date, Order ID) with that Partner. We do not share your name, email, IP address, or other personal identifiers with affiliate Partners.
Wholesale (B2B) Partners. When you purchase an eSIM from a third-party reseller that uses our Wholesale Partner Program (e.g., a travel agency, MVNO, or corporate reseller), the Partner is the entity that holds the direct customer relationship and provides the eSIM to you. In that case:
- The Partner is the data controller for the personal data they collect from you (name, email, contact details). The Partner's own privacy policy governs that processing.
- We act as a data processor for the Partner under Article 28 GDPR and a Data Processing Addendum included in our Partner Program Agreement (Section 28). We process the data the Partner submits via our API or dashboard solely to provision, deliver, and support the eSIM the Partner has assigned.
- We do not use end-customer data submitted by Wholesale Partners for our own marketing.
Partner business data. Where you yourself are signed up to our Partner Program (i.e., as the Partner principal — company representative, contact name, business email, payout details), we are the data controller for that data and process it on the legal bases described in Section 5 (performance of the Partner Program Agreement, legitimate interests, and legal obligations including tax and accounting).
6.8 Legal Disclosures
We may disclose your data if required by law, legal process, or governmental request, or to protect our rights, property, or safety.
6.9 Mobile SDK Providers (iOS/Android Apps)
Our mobile apps may use selected SDKs for analytics, crash diagnostics, push notifications, and social login. Depending on the feature used, these providers may act as processors or independent controllers under their own terms:
| Provider | Purpose |
|---|---|
| Google Firebase (Analytics, Crashlytics, Cloud Messaging) | App analytics, crash/performance diagnostics, push notification delivery |
| Google Identity Services | Google account sign-in and authentication |
| Apple Identity Services | Apple account sign-in and authentication (iOS only) |
| Stripe | Payment processing via web and native mobile payment flows |
We configure SDK features to collect only data required for service operation, security, and improvement, and we apply consent controls where required by law or platform rules.
7. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States.
When we transfer data outside the EEA, we ensure appropriate safeguards are in place, including:
- EU-U.S. Data Privacy Framework: For U.S. recipients certified under the framework (e.g., Stripe, Google, Meta);
- Standard Contractual Clauses (SCCs): EU Commission-approved contractual safeguards;
- Adequacy Decisions: Transfers to countries deemed adequate by the EU Commission.
You may request a copy of the applicable safeguards by contacting us at [email protected].
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Category | Retention Period | Reason |
|---|---|---|
| Order and Transaction Data | 7 years | Legal/tax obligations under Estonian law |
| Account Data | Until account deletion + 30 days backup | Service provision |
| Support Communications | 3 years from last contact | Legitimate interest in resolving recurring issues |
| Analytics Data (GA4) | 14 months | Consent-based; configured in Google Analytics |
| Advertising / conversion measurement (Google Ads, Meta) | Per provider defaults and policies | Consent-based on the website; retention controlled by Google/Meta |
| Marketing Preferences | Until consent withdrawal | Consent-based |
| Server Logs | 90 days | Security and fraud prevention |
After the retention period, data is securely deleted or anonymized.
9. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR:
| Right | Description |
|---|---|
| Access (Art. 15) | Obtain confirmation of processing and a copy of your personal data |
| Rectification (Art. 16) | Correct inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion of your data ("right to be forgotten"), subject to legal retention requirements |
| Restriction (Art. 18) | Limit processing in certain circumstances |
| Data Portability (Art. 20) | Receive your data in a structured, machine-readable format |
| Object (Art. 21) | Object to processing based on legitimate interests or for direct marketing |
| Withdraw Consent (Art. 7) | Withdraw consent at any time where processing is consent-based |
To exercise your rights, contact us at [email protected]. We will respond within thirty (30) days. We may request identity verification before processing your request.
Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority. For Estonian residents, this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at www.aki.ee.
10. Cookies and Tracking Technologies
We use cookies and similar technologies as described in our Cookie Policy. Essential cookies are necessary for the website to function. Non-essential cookies and similar technologies (analytics, advertising measurement such as Google Ads and Meta Pixel, affiliate tracking) require your consent.
Mobile applications: Our iOS and Android apps do not use cookies. They may collect device identifiers and usage data for analytics and crash reporting, subject to your consent where required by the platform (e.g., App Tracking Transparency on iOS).
10.1 Mobile App Permissions and Controls
The mobile apps may request limited device permissions only when needed for specific features:
- Push Notifications: To send Order updates, operational notices, and account/security alerts.
- Network Access: Required to deliver eSIM data, account content, and payment/authentication requests.
- Device/App Diagnostics: Used to detect crashes, prevent abuse, and improve reliability.
You can manage these permissions at any time in your device settings. Disabling certain permissions may limit app functionality.
10.2 App Store and Google Play Privacy Disclosures
We aim to keep our App Store Connect privacy labels and Google Play Data Safety disclosures consistent with this Privacy Policy. If a disclosure in a store listing appears inconsistent, please contact us at [email protected] so we can investigate and correct it promptly.
10.3 Mobile Store Billing Classification Disclosure
In our mobile applications, purchases relate to real-world eSIM connectivity services (mobile data plans and top-ups). The app is used to activate and manage telecom connectivity, check remaining data, and manage Orders/account settings. We do not monetize app-only digital items or in-app virtual goods. This classification is reflected in our store compliance and legal documentation.
10.4 Account Deletion in Web and Mobile Apps
You can request account deletion directly inside both web and mobile app settings without contacting support. Deletion triggers an irreversible anonymization flow for account credentials and authentication links. Active sessions are revoked, linked sign-in providers are disconnected, and personal profile identifiers are removed.
Some transaction-related records may be retained for legally required periods (e.g., accounting/tax obligations), in line with Section 8 ("Data Retention"). Retained records are minimized and dissociated from your active account identity.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- TLS/SSL encryption for all data in transit;
- Secure password hashing (bcrypt);
- Access controls and principle of least privilege;
- Regular security reviews and updates;
- Incident response procedures.
While we strive to protect your data, no method of transmission or storage is 100% secure.
12. Children's Privacy
The Service is not directed to individuals under eighteen (18) years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email (for registered Users) or a prominent notice on the Service at least fourteen (14) days before taking effect.
The "Effective Date" at the top of this policy indicates when it was last revised.
14. Contact Us
For privacy-related inquiries or to exercise your data protection rights:
Data Protection Contact
YTI Digital OÜ
Loitsu tn 5-166, 13622 Tallinn, Estonia
Email: [email protected]