Your choice about storage on this device

We store a few things in your browser so the site works: your language, your colour scheme, and your session if you sign in. We run no analytics and no advertising — nothing here reports your visit to anyone else. One convenience is yours to decide.

← All legal documents

Privacy Policy

What Esimbit does with the personal data of resellers and visitors to esimbit.com — and what it deliberately does not do.

Last updated August 18, 2026

Draft — not yet in force

These texts are complete but have not been through legal review yet, so they are not in force and are not indexed.

This document is published in English. The English text is the authoritative version.

Who this policy covers

This policy explains what LOKUM TECH LLC ("Esimbit", "we") does with personal data on esimbit.com: the marketing site, and the reseller panel you sign in to. For everything described here, we are the controller — we decide why the data is held and what happens to it.

If you bought an eSIM from a store built on Esimbit, this is not your policy. Each store publishes its own privacy notice, and the reseller who runs that store is the controller for your order. Read the notice on the store you bought from.

We still hold that shopper data, because the store runs on our software. We hold it on the reseller’s instructions, as their processor, and what we may do with it is set by the Data Processing Addendum rather than by this policy.

DetailValue
ControllerLOKUM TECH LLC
Registered address8 The Green, Suite A Dover, DE 19901
Registration4872118
Privacy contact[email protected]

What we collect, and where it comes from

Most of this you type in yourself. The rest arrives because you used the service, or because Stripe told us your subscription changed.

WhatSpecificallyWhere it comes from
Account detailsCompany name, your name, your work email, your chosen language, and your password — kept only as a hash, never as text we could read.You, at signup and whenever you edit your profile.
Your teamEach member’s name, email, language and role, and when they were last active. For an invitation that has not been accepted: the email address, the role offered, who sent it, and when it expires.You and your colleagues, in the panel. An invited person’s address reaches us from whoever invited them.
Subscription stateYour plan, billing interval, trial end date, subscription status, and the Stripe identifiers that point at your record there.You, when you choose a plan; Stripe, when your subscription starts, renews, fails or ends.
Support correspondenceWhat you write to us and what we write back, including anything you attach.You, when you get in touch.
Marketing-form leadsYour email address, which form it came from, and your language.You, if you ask to be notified or ask for a demo. Nothing else on the marketing site collects anything.
Server logsYour IP address, the time, what was requested, and what our server answered.Automatically, whenever a browser or a client calls our servers.

We never see your card number. Subscribing sends you to Stripe’s own hosted checkout page, and the card details you type there go to Stripe, not to us. What comes back is a status and a reference.

Separately from personal data, your workspace holds the provider and payment-gateway keys you connect. Those are your secrets, not your identity: they are encrypted at rest, used only to call those services on your behalf, and never returned in full — the panel is sent only the last four characters of a stored key, so that you can tell two connections apart. The Data Processing Addendum and the Security page describe how they are handled.

Why we process it, and on what legal basis

What we doWhyLegal basis
Create your workspace, sign you in, and run the panelThis is the service you asked for.Performance of a contract (GDPR Art 6(1)(b)).
Charge your subscription, run your trial, and handle renewal and failed paymentsYou subscribed, and we have to bill you correctly.Performance of a contract (Art 6(1)(b)).
Keep invoices, tax records and accounting entriesThe law requires us to keep them, whatever either of us would prefer.Legal obligation (Art 6(1)(c)).
Send service email: password resets, verification codes, invoices, and notices about your accountYou cannot use the account without them. These are not marketing and you cannot unsubscribe from them while the account is open.Performance of a contract (Art 6(1)(b)).
Answer your support messagesYou asked us a question.Performance of a contract (Art 6(1)(b)), or our legitimate interest in helping people who write to us (Art 6(1)(f)).
Email an invitation to a colleague you addedAn account that only one person can reach is not much use to a company.Our legitimate interest, and the inviting company’s, in letting a team share one workspace (Art 6(1)(f)).
Keep server logs, block abuse, and investigate faultsTo keep the service standing up and to work out what went wrong when it does not.Our legitimate interest in a secure, working service (Art 6(1)(f)).
Email you after you fill in a "notify me" or demo formYou asked to hear from us.Your consent (Art 6(1)(a)), which you can withdraw at any time.
Answer a lawful request from a court or a regulatorWe have no choice.Legal obligation (Art 6(1)(c)).

Where we rely on a legitimate interest, you can object, and we will stop unless we can show grounds that override yours. Where we rely on consent, withdrawing it is one email and costs you nothing else — the account carries on as before.

Things we do not do: we do not sell personal data, we do not share it for anyone else’s advertising, we do not build profiles of you, and we make no automated decision that produces a legal effect for you or similarly significantly affects you.

Cookies, local storage, and the tracking we do not do

Your browser loads nothing on esimbit.com from anyone else. There is no analytics, no tag manager, no advertising pixel, no session replay, no social widget and no third-party script or font. Fonts and icons are served from our own servers. Stripe is reached by sending your whole browser to Stripe, not by embedding Stripe’s code in our page. The site is delivered through a proxy and security network, which is listed as a supplier below.

So there is no analytics or advertising storage on this site to consent to, and no toggle offering one. What we store on your device is a short list: your language, your panel theme, your sign-in token, the cookie choice you made, and — only if you allow it — which notices you have already dismissed. The proxy may set a cookie of its own to tell people from automated traffic, which is a security function rather than a tracking one. Every item, what it is for and how long it lasts is set out on the Cookies and local storage page.

This section describes esimbit.com. A reseller’s storefront is a different site with its own register and its own consent choice, described in that store’s own pages.

Who else sees it

We use a small number of suppliers to run the service. They process data on our instructions, under contract, and for nothing of their own.

SupplierWhat they handle
Cloudflare, whose bot-protection cookies (__cf_bm, and cf_clearance after a challenge) may be set on this domainProxies and filters every request to esimbit.com, the panel, the API and the storefronts, terminates the encrypted connection, and screens automated traffic. It therefore sees the address, the IP and the request details of everyone who reaches us.
AWSHosting for the application, the database and the backups.
PostmarkSends the service email — resets, codes, invoices, notices — and therefore handles your address and the message.
StripeOur own subscription billing: the checkout page you are sent to, the card details you give it, and the subscription status it reports back.
SentryReceives diagnostic reports when something breaks, which can include the account involved.

The authoritative list, with each supplier’s role and location, is Annex 2 of the Data Processing Addendum. That list is maintained; this table is a summary of it.

Stripe is in this table and not in that annex, which is correct: it bills our own subscriptions, where we are the controller and you are the customer. It is not a sub-processor of your shoppers’ data and never receives any.

Beyond those: we disclose data to professional advisers where we need advice, to an acquirer if the business is ever sold, and to a court or a regulator where we are legally required to. We tell you before a disclosure of that last kind unless we are forbidden from telling you.

Where the data lives

The production database and its backups are in Frankfurt, Germany (eu-central-1).

Some suppliers in the list above operate outside that region, so data reaches them there. Where a transfer leaves the EEA or the UK to a country without an adequacy decision, we rely on the European Commission’s standard contractual clauses, with the UK addendum where the UK is involved, plus whatever additional measures the transfer needs. Transfers out of Turkey are covered separately below.

You can ask us for a copy of the safeguards that apply to a specific transfer by writing to [email protected].

How long we keep it

Nothing in the platform deletes itself: there is no automatic expiry, no scheduled cleanup and no background job that removes old records. Every period below is a decision the operator makes and then has to carry out.

WhatKept for
Your account and profile, after the account is closed365 days after the account is closed
Subscription, invoice and accounting records7 years, as tax and accounting law requires
Support correspondence24 months after the request is closed
A marketing-form lead that never became an account12 months, or until you ask us to delete it
Server and access logs365 days

Pending team invitations are an exception: each one carries its own expiry date, set when it is sent, and it stops being usable then. You can revoke one earlier from the panel.

Where a record has to be kept for tax or accounting reasons, we keep it for that reason alone and do not go on using it for anything else.

Security

Passwords are stored as hashes. Provider and gateway credentials are encrypted at rest. Traffic to the site and to our API is encrypted in transit. Access to production is limited to the people who need it to do their jobs.

The Security page describes the controls in more detail and gives the address for reporting a vulnerability. We would rather hear about a problem from you than not hear about it.

Your rights under the GDPR

If the GDPR applies to you, you can ask us to do any of the following.

  • Confirm whether we hold data about you, and give you a copy of it.
  • Correct anything inaccurate, or complete anything that is missing.
  • Erase data where we no longer have a good reason to hold it.
  • Restrict what we do with it while a dispute about it is being sorted out.
  • Give you the data you provided in a portable, machine-readable form, or send it to someone else where that is technically feasible.
  • Stop processing you object to, where we relied on a legitimate interest.
  • Withdraw a consent you gave. That does not undo what we did while the consent stood.

Some of this is faster to do yourself: your name, email and language are editable in the panel, and you can change your password there. For everything else, write to [email protected]. We may have to check who you are before we act, which for an account holder normally means writing from the address on the account.

The GDPR gives us one month to answer. We can extend that by two further months if the request is complex, and if we do, we will tell you within the first month and say why. Requests are free unless one is manifestly unfounded or excessive.

Turkey: your rights under the KVKK

This section is the aydınlatma — the notice Article 10 of Law No. 6698 requires us to give you when we collect your data. The data controller (veri sorumlusu) is LOKUM TECH LLC, at 8 The Green, Suite A Dover, DE 19901. Our representative in Turkey is [email protected]. What we collect, why, and who we share it with are the same as the sections above.

Article 11 gives you a list of rights that is not the same list as the GDPR’s, so it is set out here in its own terms rather than folded into the section above. You may:

  • learn whether we process your personal data at all;
  • request information about it if we do;
  • learn the purpose we process it for, and whether it is used in line with that purpose;
  • learn who we transfer it to, in Turkey or abroad;
  • have it corrected if it is incomplete or wrong;
  • have it erased or destroyed where the conditions in Article 7 are met;
  • require that a correction, erasure or destruction is notified to the third parties we transferred the data to;
  • object to a result reached against you purely by automated analysis of your data;
  • claim compensation if unlawful processing has caused you damage.

The eighth right has nothing to bite on here: we run no automated analysis that produces a decision about you. We list it because Article 11 lists it, not because we do it.

Turkey: how to apply, and transfers abroad

Article 13 sets how to ask. Apply to us in writing, or by any other method the Personal Data Protection Board has approved, at [email protected] or at the address above. Say what you want and give us enough to identify you. We will answer within thirty days at the latest, and free of charge — unless answering has a cost of its own, in which case we may charge the fee in the Board’s tariff.

If we refuse, if our answer does not satisfy you, or if we do not answer in time, you can complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) within thirty days of learning our answer, and in any case within sixty days of the date you applied to us.

Your data may be transferred abroad, because some of the suppliers listed above operate outside Turkey. Since the amendments made by Law No. 7499, such transfers rest on an adequacy decision by the Board, on an appropriate safeguard such as a standard contract notified to the Board within five business days of signature, or on one of the case-by-case exceptions in Article 9, including your explicit consent. The route we rely on is a standard contract under KVKK Article 9(5), notified to the Personal Data Protection Authority within five business days of signature.

This policy is published in English only, including this section. That is a deliberate choice: one authoritative text avoids the situation where a translation and an original quietly say different things. If you would rather correspond in Turkish, write to us in Turkish.

Children

Esimbit is a business tool sold to companies that resell eSIMs. It is not designed for children, not marketed to them, and not something a child would have a reason to sign up for. We do not knowingly collect data from children.

If you believe a child has given us personal data, write to [email protected] and we will delete it. As elsewhere on this platform, deletion is done by hand rather than by a scheduled job.

Changes to this policy

When this text changes, we publish the new version with a new date at the top. The date is the honest signal: if it has not moved, nothing has changed.

If a change materially affects what we do with your data, we will email account holders before it takes effect, so that anyone who disagrees has the chance to close their account first.

Contacting us, and complaining about us

ForWrite to
Anything about your personal data, and any request under this policy[email protected]
Legal notices[email protected]
Reporting a security problem[email protected]
Our Data Protection OfficerNo data protection officer is appointed; data-protection questions go to [email protected].
Our EU representative (GDPR Art 27)[email protected]

Please come to us first. Most of what goes wrong is something we can fix faster than a regulator can ask us to.

You do not have to, though. If the GDPR applies to you, you can complain to the supervisory authority where you live, where you work, or where you think the problem happened. Our lead supervisory authority is Esimbit has no establishment in the EU, so no single lead supervisory authority applies; you may complain to the authority where you live, where you work, or where the problem happened.. In Turkey, the authority is the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).