GlobalPass Privacy Policy
Version of October 2, 2026. In force from October 2, 2026.
This policy explains what personal data we process when you use the GlobalPass shop (the "Shop"), why, for how long, who we share it with, and what rights you have. We apply Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR").
1. Controller
Your data is controlled by Aliaksandr Nazaruk, a sole trader entered in the Polish business register CEIDG, NIP 9512452796, REGON 529368437, address for correspondence: ul. Marcina Kasprzaka 31 lok. 119, 01-234 Warszawa, Poland ("we", the "Seller").
For anything about personal data, write to [email protected]. We have not appointed a data protection officer.
2. What data we process and where it comes from
We collect only what is needed to sell and support an eSIM. We do not ask for your name, postal address, phone number or date of birth.
| Category | What exactly | Source |
|---|---|---|
| Account data | email address; password — we keep only a cryptographic hash of it, never the password itself; the date the Account was created; if you enabled a second sign-in factor, its technical data | you |
| Session and security data | the IP address and browser details (user agent) recorded when you sign in, sign-in and session expiry times, security events (such as a password reset or change) | your browser |
| Orders | the Plan chosen, price, currency, time and status of the order; the two statements you ticked before paying, with the version of the Terms and the time | your actions in the Shop |
| Partner referral | which partner's link brought you to the Shop, and when — only if you arrived through a link from a partner (such as a price comparison site) and then signed in or created an Account at checkout. The partner's code travels in the page address and, if you agree, is kept for 30 days in the globalpass.partner cookie | the link you followed |
| Payments and refunds | the Stripe payment identifier, amount, currency, payment status, refunds and their status. We never receive your card number or BLIK code | Stripe |
| eSIM | eSIM identifiers (such as the ICCID), the Installation code (stored encrypted), the eSIM's status (for example whether it has been installed), data usage readings, a record of every time the Installation code was shown (when, and on what basis) | the eSIM supplier and your actions in the Shop |
| Correspondence | messages to support, refund requests, complaints, withdrawals and our replies; emails you send to [email protected] | you |
| Technical visit data | IP address and request headers; the country derived from the IP address — used only to pick the default language and currency and to mark your country on the globe on the home page, and not stored; server logs | your browser, through Cloudflare |
| Preferences | your chosen language, currency and theme (light/dark); the language of each purchase, kept with the order | your settings — see the Cookie Notice |
When you use data through the eSIM, local network operators process connection data (such as traffic data and the network your device connects to) as independent controllers, under their own rules. From the eSIM supplier we receive only the total data used and the eSIM's status.
3. Purposes, legal bases and how long we keep data
| Purpose | Legal basis | How long |
|---|---|---|
| Creating and keeping your Account | Art. 6(1)(b) GDPR (contract) | until the Account is deleted |
| Selling the Plan, taking payment, delivering the eSIM, showing the Installation code and data usage | Art. 6(1)(b) GDPR | while the Contract is performed, then as in the rows below |
| Emails about your Account and orders: the eSIM is ready and how to install it, a link to set a new password, the password was changed, the eSIM could not be delivered and the money is on its way back, a refund has been sent, most of a Plan's data has been used | Art. 6(1)(b) GDPR | the Shop's database records only that and when a message was sent and the language it was written in; a copy of every message goes to the Seller's mailbox (section 5) and is kept as long as the data of the order it concerns |
| Support conversations | Art. 6(1)(b) and (f) GDPR — answering your message | until the Account is deleted; where they concern a refund or complaint, as in the row below |
| Cancellations, refunds, withdrawals and complaints | Art. 6(1)(c) GDPR (duties under consumer law) and (b) | until claims under the Contract become time-barred |
| Tax and accounting (records of sales and refunds) | Art. 6(1)(c) GDPR (tax law) | 5 years from the end of the calendar year in which the tax payment deadline passed |
| Account and Installation-code security (sessions, the record of code views, locking an eSIM after a password reset) | Art. 6(1)(f) GDPR — our legitimate interest in protecting your eSIM from takeover | session data until the Account is deleted; the view record as long as sales records, because it proves the eSIM was delivered |
| Preventing payment fraud (automatic hold for review — section 6) | Art. 6(1)(f) GDPR — protecting Customers and the Seller from fraud | as long as the order data |
| Establishing, pursuing and defending claims | Art. 6(1)(f) GDPR | until the claims become time-barred |
| Proving the statements you made before paying (accepting the Terms, asking for the eSIM to be delivered at once) | Art. 6(1)(c) GDPR (duties under consumer law) and (f) (defending claims) | until claims under the Contract become time-barred; kept after the Account is deleted |
| Data usage readings | Art. 6(1)(b) GDPR | until the Account is deleted |
| Server logs | Art. 6(1)(f) GDPR — running and securing the Shop | overwritten automatically once a size limit is reached (currently 3 files of 10 MB per service) |
| Database backups | Art. 6(1)(f) GDPR — restoring the Shop after a failure | at most 12 months from when the backup was made |
| Remembering language, currency and theme | Art. 6(1)(f) GDPR; storage in your browser strictly necessary for the service you asked for | 12 months (cookies) or until you clear your browser (theme) |
| Keeping the language of each purchase, which is the language of the Contract and of our emails about the order | Art. 6(1)(b) GDPR | in the Shop's database, as long as the order data |
| Paying the partner whose link brought you to the Shop its commission on your order | Art. 6(1)(f) GDPR — our legitimate interest in paying partners for the sales they bring | a referral counts orders paid within 30 days of it; the record itself is kept as long as the sales records it was used to settle |
| Keeping a partner's code in a cookie when you arrive through its link | your consent (Art. 6(1)(a) GDPR and Art. 399 of the Polish Electronic Communications Law), given with the "Yes, remember" button; you withdraw it by deleting the cookie in your browser | 30 days |
Database backups kept on the Shop's server are deleted automatically: all backups from the last 14 days stay, of older ones only the newest of each calendar month, and none older than 12 months. Apart from that, the Shop does not yet delete data automatically when these periods end — we delete it by hand, for example when you ask for your Account to be deleted (section 8).
4. Do you have to give us data
Giving your email address and a password is voluntary, but without them you cannot create an Account, and without an Account you cannot buy an eSIM. You give payment details to Stripe; without them you cannot pay.
5. Who we share data with
We share data only with those the Shop needs in order to work. Processors act on our instructions.
| Recipient | Role | What data | Where |
|---|---|---|---|
| IONOS SE (Montabaur, Germany) | processor: the server that runs the Shop and its database, and the Seller's mailbox that receives email sent to [email protected] and copies of the notifications sent to Customers | all data in section 2; in the mailbox, your email address and the text of messages | Germany (data centre in Frankfurt am Main) |
| Cloudflare, Inc. | processor: DNS, content delivery and protection for the Shop — all traffic to the Shop passes through Cloudflare; forwarding email sent to [email protected] to the Seller's mailbox | IP address, request headers and content in transit; email content while it is forwarded | USA and global network — section 7 |
| home.pl S.A. (Szczecin) | processor: the outgoing mail server, and the standby database used to restore order state after a failure | your email address and the text of our messages; in the standby database, order and payment identifiers and an encrypted copy of the Installation code (without the key that can read it) | Poland |
| Stripe Payments Europe, Limited (Ireland) | payment processor; for some purposes (such as fraud prevention and legal duties) Stripe acts as an independent controller | the payment details you enter in Stripe's form; your Account's email address, which the form is filled in with so that Stripe Link can look you up by it — Stripe receives it as soon as the form is shown, whether or not you pay; amount, currency, device data for risk assessment | Ireland; Stripe transfers data to Stripe, Inc. (USA) — section 7 |
| ESIM ACCESS LIMITED — the eSIM supplier | issues the eSIM and reports its status and data usage to us | we pass only our order identifier and the Plan code — never your email address or any contact details; the supplier processes the eSIM's technical data (such as the ICCID and data usage) | outside the European Economic Area — section 7 |
| Local network operators | independent controllers of connection data | data about your use of the network | the country you are in |
| Apple (Apple Pay), Google (Google Pay), Polski Standard Płatności (BLIK), your bank | independent controllers, if you choose that payment method | the data needed for the payment | under their own terms |
| An accounting firm — if the Seller entrusts its books to one | processor: bookkeeping | data from records of sales and refunds | Poland |
| The partner whose link brought you to the Shop (a price comparison or review site) | receives a statement of the orders its links brought, to invoice its commission | for each such order: the date, the Plan, the price and whether it was refunded — never your email address or anything else that identifies you | — |
| Public authorities | where the law requires | the data the request concerns | — |
We do not sell data and do not share it for marketing.
6. Automated decisions
For every paid order the system automatically checks its value and the number and value of paid purchases on the same Account in the last 24 hours. If these are unusual, delivery of the eSIM is held for review by a person, and the payment page and your Account say that the order is being checked. The system never refuses to deliver an eSIM on its own. If the person confirms the order, the eSIM is delivered; if it is not confirmed within 60 minutes of the payment being accepted, the order is cancelled and the full amount goes back to your payment method. You can give your view and ask for a reconsideration by writing to support. Refund requests are always decided by a person.
7. Transfers outside the European Economic Area
Cloudflare and Stripe (through Stripe, Inc.) also process data in the USA. The transfers rely on the European Commission's adequacy decision under the EU-US Data Privacy Framework, for certified companies, or on standard contractual clauses approved by the Commission. We do not give the eSIM supplier your email address or any other contact details; it processes the eSIM's technical data itself, outside the European Economic Area. You can ask about the safeguards at the address in section 1.
8. Your rights
You have the right:
- of access to your data and to a copy of it (Art. 15 GDPR);
- to rectification (Art. 16);
- to erasure (Art. 17);
- to restriction of processing (Art. 18);
- to data portability for the data you gave us (Art. 20);
- to object to processing based on our legitimate interest (Art. 21);
- to complain to the President of the Polish Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warszawa, www.uodo.gov.pl) or to the supervisory authority of the country where you live.
How to use your rights. Write from your Account's email address to the address in section 1. We answer within one month; for complex requests we may extend this by two more months and will tell you if we do. We reply to the Account's email address; if you write from another address, we will ask you to confirm from the Account's address. This is free of charge.
A copy of your data (export). On request we will email the Account's address a JSON file with your data: Account data, orders and the statements you made before paying for them, payments and refunds, eSIMs and their status, data usage and your support conversations. We never email the Installation code — it stays available in the Account.
Deleting your Account and data. On request we will delete your Account. First we settle open matters (such as a refund owed to you), and data the law requires us to keep (such as sales records) we keep for the period in section 3 and use for nothing else. After deletion you will no longer see the Installation codes or data usage; an installed eSIM keeps working until the Plan ends. Data in backups disappears with the backup, within 12 months at the latest; if we ever restore the Shop from a backup, we delete the data of deleted Accounts again.
9. How we protect data
- The Installation code is stored encrypted and shown only to the Account's signed-in owner; every view is recorded. We never send it by email.
- Passwords are stored only as a cryptographic hash.
- The session cookie cannot be read by the page's scripts and is sent only over an encrypted connection.
- You enter card details and the BLIK code in Stripe's form; they never reach us.
- After a password reset, an eSIM whose code has never been shown stays locked — access to a mailbox alone is not enough to open it.
10. Children and minors
The Shop is not meant for children under 13, and we do not knowingly collect their data; if we learn that such a child has opened an Account, we delete it. People aged 13 to 17 may use the Shop as set out in § 2(1) and § 4(6) of the Terms; we process their data in the same way as other Customers' data (section 3).
11. Cookies
The Shop uses the cookies and browser storage it needs to work (session, language, currency, theme), Stripe's cookies on the payment page and — only with your consent — a cookie with a partner's code when you arrive through its link. We use no analytics or advertising cookies. Details: the Cookie Notice.
12. Changes to this Policy
We will tell Account holders about significant changes by email before they take effect. The current version is always available in the Shop.