eSIM Tabby

Privacy Policy

Last updated 22 July 2026

This policy explains how we handle personal data under Regulation (EU) 2016/679 (GDPR) and Act No. 110/2019 Coll., on Personal Data Processing.

1. Controller

Josef Rousek, Kytlická 862/6, 190 00 Praha 9, Czech Republic, IČO 02568535, trading as eSIM Tabby, is the controller of your personal data. Contact us at [email protected] for anything in this policy, including to exercise your rights.

We have not appointed a Data Protection Officer; we are not required to.

2. What we collect

We do not receive or store card numbers. Card data goes directly to Stripe on their hosted checkout page.

3. Why we process it, and on what legal basis

We do not use your data for advertising, we do not sell it, and we do not profile you or make decisions about you by automated means.

4. Who else processes it

We use a small number of providers, each under a data processing agreement and only for the purposes above:

We also disclose data where the law requires it, for example to public authorities acting within their powers.

5. Transfers outside the EEA

Some of these providers are established outside the European Economic Area. Where data is transferred there, it is done under an adequacy decision of the European Commission or under Standard Contractual Clauses together with appropriate safeguards. You can ask us for details of the safeguards used.

6. How long we keep it

7. Your rights

You have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to receive it in a portable machine-readable format. Where processing rests on legitimate interests you may object to it at any time. Write to [email protected]; we respond within one month.

If you think we have handled your data unlawfully you may complain to the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz.

8. Cookies

We use strictly necessary cookies only: a session cookie that keeps you signed in, and a CSRF token cookie that protects forms from cross-site request forgery. Both are essential to operate the service, so no consent banner is required and there is nothing to opt out of. We run no analytics, no advertising, and no third-party trackers, and all scripts are served from our own domain.

9. Changes

If we change this policy we will update the date above and, for significant changes, tell account holders by email.

See also our Terms and Conditions and company details.