Legal

Privacy policy

How Globbi collects, uses and protects your personal data when you buy and use our travel eSIMs.

Last updated 6 October 2026

Draft — not yet ready to publish. Fill in the highlighted details in assets/js/config.js (legal) and have this document reviewed by a qualified adviser for your jurisdiction. This banner disappears once every detail is filled in.

1Who we are

Globbi (“Globbi”, “we”, “us”) is the trading name of [COMPANY LEGAL NAME], a company registered under number [COMPANY REGISTRATION NUMBER], whose registered address is [REGISTERED ADDRESS].

We sell prepaid, data-only travel eSIMs through this website. For the personal data described in this policy we are the controller, which means we decide how and why it is used.

Questions about privacy, or want to use your rights? Email support@globbi.example.

2The short version

  • We collect only what we need to sell you an eSIM, deliver it, support it and meet our legal obligations.
  • We never see or store your full card details — payments are handled by Stripe.
  • We don't sell your personal data, and we don't use advertising or analytics cookies.
  • We can't see the websites you visit or the content of your traffic while using your eSIM.
  • You can ask us for a copy of your data, or to delete it, at any time.

3What we collect

Information you give us

  • Contact details: your email address when you buy, top up, join our email list or contact support.
  • Order details: the plan you bought, quantity, price, promo code, order number and date.
  • Support information: what you tell us when you ask for help or a refund, including any screenshots you send.
  • Device confirmation: your confirmation that your phone is eSIM-compatible and carrier-unlocked. We don't collect your phone's IMEI or EID.

Information created when we deliver your eSIM

  • eSIM identifiers: the ICCID (eSIM serial number), SM-DP+ address and activation code for each eSIM we issue.
  • Service and usage data from our eSIM supplier and its partner mobile networks: whether and when your eSIM was installed and activated, how much data it has used, which country and network it connected to, and technical error logs. We use this to show your remaining data, process top-ups, troubleshoot problems and assess refund requests.

Information from payment processing

  • Stripe tells us whether your payment succeeded and may share limited details such as card brand, last four digits, card country and fraud-risk signals. Stripe collects your full card details directly.

Technical information

  • When you visit the site, our hosting provider's servers receive your IP address, browser type and the pages requested. These are held in standard server logs.

We don't ask for sensitive information (such as health or biometric data) or for identity documents.

4How and why we use it

Data protection law requires a legal basis for each use of personal data. Ours are:

PurposeData usedLegal basis
Taking your order, issuing your eSIM and showing your QR code and install detailsEmail, order details, eSIM identifiersPerformance of our contract with you
Taking paymentOrder details, payment status from StripePerformance of contract
Top-ups, showing remaining data and service messages about your orderEmail, eSIM identifiers, usage dataPerformance of contract
Customer support and assessing refund requestsEmail, support messages, order details, usage and activation dataPerformance of contract; our legitimate interest in resolving issues fairly
Preventing fraud and keeping our site and service secureIP address, server logs, payment risk signalsOur legitimate interests in protecting customers and our business
Keeping accounting and tax recordsOrder and payment recordsCompliance with legal obligations
Sending offers and travel tips by emailEmail addressYour consent, which you can withdraw at any time
Dealing with legal claims or requests from authoritiesAny relevant dataLegal obligation; our legitimate interests

Where we rely on legitimate interests, we have weighed them against your rights and expectations. You can object to these uses — see “Your rights”.

We don't make decisions about you that are based solely on automated processing and have legal or similarly significant effects. Refund decisions are made by our team using the information above.

5Marketing emails

We only send marketing emails if you've signed up for them. Every email has an unsubscribe link, or you can email support@globbi.example. Order and service messages (for example, your eSIM details or a top-up receipt) aren't marketing and are still sent after you unsubscribe.

6Who we share it with

We share personal data only where needed for the purposes above, with:

  • Stripe — payment processing and fraud prevention. Stripe acts as an independent controller for some payment data; see Stripe's privacy policy.
  • Our eSIM supplier ([ESIM SUPPLIER NAME]) and its partner mobile network operators — to issue, activate, top up and support your eSIM. The networks that carry your data traffic process it under their own legal obligations and policies.
  • Our hosting provider ([HOSTING PROVIDER, COUNTRY]) — to run this website and store order records.
  • Our email provider ([EMAIL PROVIDER, e.g. Postmark / Resend]) — to send order, service and (if you opted in) marketing emails.
  • Professional advisers such as accountants, auditors and lawyers, under confidentiality.
  • Authorities, regulators or courts, where the law requires it or to protect our rights, our customers or others.
  • A buyer or successor, if all or part of our business is sold or reorganised, under the same protections described here.

Our service providers may only use your data on our instructions. We do not sell or rent your personal data.

7Content loaded from other services

To display this website, your browser fetches some files directly from other providers, which therefore receive your IP address and basic browser information:

  • Google Fonts (fonts) — Google privacy policy
  • jsDelivr (flag images)
  • cdnjs / Cloudflare (the QR-code generator)

If you use “Install directly on iPhone”, your eSIM's activation details are passed to Apple's eSIM setup service so your iPhone can install it. Apple handles that under its own privacy policy.

8Cookies and data stored on your device

We don't use cookies for advertising or analytics. To make the shop work, we store a few items in your browser's local storage:

  • Your basket — the plan you're buying, until checkout.
  • My eSIMs — your orders and eSIM install details, so you can view your QR codes and top up later on this device.
  • Your email address — to pre-fill checkout next time.
  • Your currency preference.

These stay on your device and are strictly necessary for features you ask for, or are simple preferences. You can delete them at any time by clearing your browser's site data — your eSIM details remain available from us on request. Stripe may set its own cookies on its checkout page for security and fraud prevention.

If we ever add analytics or advertising tools, we'll update this policy and ask for your consent where the law requires it.

9International transfers

Our service providers and eSIM partners may process data outside the country where you live, including in countries whose data protection laws differ from yours — this is unavoidable when your eSIM works on networks around the world. Where the law requires it, we protect these transfers with recognised safeguards such as adequacy decisions or standard contractual clauses. Contact us for more information.

10How long we keep it

DataHow long
Order, payment and invoice recordsAs long as tax and accounting law requires — typically 6–7 years after purchase
eSIM identifiers and usage dataFor the life of your eSIM plus 24 months, so we can handle top-ups, support and refund questions
Support messages24 months after your request is closed
Marketing listUntil you unsubscribe
Server logsUp to 90 days, unless needed to investigate a security issue

After that we delete the data or anonymise it so it no longer identifies you.

11Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and get a copy;
  • correct data that's inaccurate or incomplete;
  • delete your data, where we no longer need to keep it;
  • restrict or object to our use of it, including at any time for direct marketing;
  • port your data — receive it in a portable format or have it sent to another provider;
  • withdraw consent where we rely on it, without affecting earlier use.

To use any of these rights, email support@globbi.example. We may need to confirm your identity first — usually by asking you to write from the email address used for your order. We'll respond within one month (or sooner if your local law requires it). It's free, unless a request is clearly unfounded or excessive.

If you're unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to [DATA PROTECTION REGULATOR, e.g. the ICO (UK) or PDPC (Singapore)] or the data protection authority where you live.

12Security

We use HTTPS encryption across the site, restrict access to personal data to people who need it, and choose providers with strong security practices. No method of transmission or storage is completely secure, but if a breach affecting your data occurs we'll notify you and the regulator where the law requires.

Treat your eSIM QR code and activation code like a key: anyone who has them can install your eSIM, so don't share them publicly.

13Children

Our services aren't aimed at children under 16, and we don't knowingly collect their data. If you believe a child has given us personal data, contact us and we'll delete it.

14Changes to this policy

We may update this policy as our service or the law changes. We'll post the new version here with a new “last updated” date and, for significant changes, let customers know by email.

Questions about this policy?

Email support@globbi.example and a real person will reply.

Email us