Cookie Notice
Version of October 2, 2026.
The GlobalPass shop stores in your browser what it needs to work: your sign-in session and your chosen language, currency and theme. We use no analytics or advertising cookies, and we do not track you on other sites. That is why there is no consent banner: storing information that is strictly necessary for a service you asked for does not need consent. The one exception: when you arrive through a partner's link (such as a price comparison site), we ask whether to remember that partner's code, and store it only if you agree.
The Shop's cookies
| Name | Purpose | When it is set | How long |
|---|---|---|---|
__Host-globalpass_customer_session | keeps you signed in; unreadable by page scripts, sent only over an encrypted connection | when you sign in or create an Account | until you sign out, at most 7 days after the session was last refreshed |
__Host-globalpass_customer.two_factor | links the two steps of signing in | only when signing in with a second factor, if you enabled one | 10 minutes |
globalpass.locale | remembers the language you chose | only when you change the language yourself | 12 months |
globalpass.currency | remembers the currency for prices (EUR, zł or USD) | only when you change the currency yourself | 12 months |
globalpass.partner | remembers which partner (such as a price comparison site) brought you to the Shop, so that it earns a commission from us if you buy an eSIM within 30 days; your price does not change | only when you arrive through a partner's link and click "Yes, remember" | 30 days |
Browser storage
| Name | Purpose | How long |
|---|---|---|
globalpass.theme (localStorage) | remembers the theme: light or dark | until you clear your browser data |
Stripe cookies on the payment page
The payment form is provided by Stripe. When you open the payment step, Stripe's script stores cookies on our domain to prevent payment fraud — according to Stripe's documentation these are __stripe_mid (1 year) and __stripe_sid (30 minutes) — and Stripe's own cookies work inside the form on Stripe's domains. Stripe's script is not loaded on any other page of the Shop. Stripe's policy: stripe.com/privacy.
Cloudflare
All traffic to the Shop passes through Cloudflare. On 25 September 2026 Cloudflare set no cookies on the Shop's pages. If we turn on bot protection, Cloudflare may set a technical cookie that recognises automated traffic (such as __cf_bm, 30 minutes); we will update this notice if we do.
Deleting or blocking cookies
You can delete or block cookies in your browser settings. Without the session cookie you cannot sign in to your Account, and without Stripe's cookies a payment may fail. Without the language and currency cookies the Shop still works but will not remember your choice. You withdraw your consent to the partner cookie by deleting globalpass.partner — nothing but the partner's commission depends on it.
More about personal data: the Privacy Policy.