Privacy policy

Last updated 27 September 2026

This policy explains what personal data we collect when you visit baobabsim.com or buy an eSIM, how we use and protect it, which cookies are used and what you can ask of us. We are a Polish company, so we handle personal data under the EU General Data Protection Regulation (GDPR). Section 9 also sets out the rights you have under the data protection laws of Morocco, Egypt and South Africa.

1. Who we are

baobabsim.com is operated by LuKas Holdings sp. z o.o., ul. Stefana Batorego 18/108, 02-591 Warsaw, Poland, KRS 0001233010, NIP 7011306806 (“BaobabSIM”, “we”, “us”). We are the controller of the personal data described here.

For every question, request or complaint about personal data, write to contact@baobabsim.com.

2. What we collect

When you visit baobabsim.com

  • Your browser sends technical data with every request: IP address, browser and device type, the page requested and the referring page. Our content delivery network, Cloudflare, uses it to deliver pages and to protect the site from attacks. Our own web server does not keep access logs.

When you accept analytics cookies

  • The pages you view, the referring site and campaign parameters, the plans you select and when you start a checkout, your browser and device type, an approximate location derived from your IP address, and a random visitor id kept in a cookie. Nothing is collected for this purpose if you switch analytics off, and your browser’s Global Privacy Control signal is treated as a refusal.

When you accept marketing cookies

  • The Meta Pixel loads in your browser and, together with our server (Meta’s Conversions API), tells Meta Platforms Ireland Limited which pages you view, which plans you select and when you start a checkout, with your IP address, your browser and device type, the Meta cookies listed in section 8, and the ad click id when you arrived from a Facebook or Instagram ad.
  • When you buy, our server reports the purchase to Meta: the plan, price, currency and order number, with your email address and billing country sent only as one-way hashes (SHA-256), and the Meta cookies, IP address and browser captured when you started the checkout.
  • Meta uses this to measure and improve our ads on Facebook and Instagram, and may link it to your Meta account if you have one. Nothing is sent to Meta if you switch marketing off, and your browser’s Global Privacy Control signal is treated as a refusal. Order pages, which show your eSIM, never load the pixel.

When you buy an eSIM

  • The details you enter on the Stripe payment page: email address, name on the card, billing country and, for some cards, postal code. Card numbers are handled by Stripe and never reach us.
  • Order data: the plan, price, currency, language, time of purchase, the version of the Terms of sale you accepted, and the eSIM delivered to you (its ICCID and activation code, which we store encrypted).
  • Where the order came from: the campaign parameters of the link that brought you (for example utm_source), the referring site and the pages you visited before buying. We keep these with the order to know which channels bring customers.
  • When your order page is opened, we record the time and a one-way hash of the IP address, to protect your eSIM code against misuse.
  • When you start a checkout, your IP address is used in memory to limit repeated attempts. It is not stored.

When you write to us

  • Your email address, name and the content of your message.
Purpose Legal basis under the GDPR
Selling and de­liv­er­ing the eSIM, support and refunds Per­form­ance of the contract with you (Article 6(1)(b))
Ac­count­ing and tax records Our legal ob­lig­a­tions (Article 6(1)(c))
Pre­vent­ing fraud, securing payments and eSIM codes, pro­tect­ing the site Our le­git­im­ate interest in a secure shop (Article 6(1)(f))
Answering your questions and part­ner­ship enquiries Our le­git­im­ate interest in answering you, or steps before a contract you ask for (Article 6(1)(f) or (b))
Measuring how the website is used, which pages and channels bring visitors and customers Your consent, given in the cookie banner (Article 6(1)(a)); you can withdraw it at any time with Cookie settings at the bottom of every page
Measuring and improving our ads on Facebook and Instagram Your consent to marketing cookies, given in the cookie banner (Article 6(1)(a)); you can withdraw it at any time with Cookie settings at the bottom of every page

We use personal data only for these purposes. We do not send marketing messages and we do not sell personal data.

4. Automated decisions

Stripe screens payments for fraud with automated risk scoring. A payment judged high risk may be blocked or may need extra verification such as 3D Secure. If you think a payment was blocked by mistake, write to us and a person will review it.

5. Who receives your data

  • Stripe processes payments and screens them for fraud, under its privacy policy at stripe.com/privacy.
  • Cloudflare, Inc. delivers and protects the website.
  • Meta Platforms Ireland Limited (Meta Pixel and Conversions API) receives the marketing data described in section 2, only if you accept marketing cookies. We and Meta are jointly responsible for collecting that data and passing it to Meta; what Meta then does with it is governed by Meta’s Privacy Policy at facebook.com/privacy/policy, where you can also exercise your rights with Meta.
  • Our server hosting provider runs the virtual server in Singapore that hosts the website and the order database.
  • Our eSIM distributor receives no personal data from us. We buy eSIM profiles without sending your details.
  • Our accountants and legal advisers, and public authorities where the law requires it.

6. Transfers outside the European Economic Area

The website and the order database are hosted in Singapore, and Stripe, Cloudflare and Meta may process data in the United States and other countries. When personal data leaves the European Economic Area, we rely on the safeguards the GDPR provides: the European Commission’s standard contractual clauses, or its adequacy decision for companies certified under the EU-US Data Privacy Framework. We transfer personal data outside Singapore only to recipients that are bound, by law or by contract, to protect it to a standard comparable to the PDPA. You can ask us for a copy of the safeguards that apply. You can ask us for a copy of the safeguards that apply.

7. How long we keep it

We keep personal data only as long as we need it for the purposes above or as the law requires:

  • Order and payment records, including the encrypted eSIM details: as long as accounting and tax law requires, normally 5 years from the end of the year of purchase.
  • Order page access records (hashed IP address): 12 months.
  • Email correspondence: as long as needed to handle the matter and related claims, and no longer than 3 years after it is closed.
  • Analytics data: no longer than 14 months.
  • Analytics and Meta ids stored with an order (the visitor id, the Meta cookies, IP address and browser captured at checkout): 90 days.
  • Data received by Meta: as set out in Meta’s Privacy Policy.

8. Cookies

baobabsim.com asks for your consent before it sets any analytics or marketing cookie. Marketing cookies are set on our domain by the Meta Pixel and let Meta recognise your browser on other websites that use Meta’s tools.

Cookie Purpose Kept for
bsim_consent Remembers whether you allowed analytics cookies 180 days
bsim_ads Remembers whether you allowed marketing cookies 180 days
_bsim_id A random visitor id, set only after you allow analytics, to count visits and link a purchase to the visit 400 days
_bsim_sid The current visit, set only after you allow analytics 30 minutes of in­activ­ity
_fbp Meta Pixel browser id, set only after you allow marketing 90 days
_fbc The click id of a Facebook or Instagram ad that brought you, set only after you allow marketing 90 days

You can change your choice at any time with Cookie settings at the bottom of every page; switching a category off deletes its cookies.

For the duration of a browser tab we keep, in that tab’s session storage, the campaign parameters and referring site of the visit, so an order can record which channel brought the buyer; closing the tab clears it. It is not shared and is not used to follow you around. Your choice of light or dark theme and of language hint is kept in your browser’s local storage and never leaves it.

  • Cloudflare may set strictly necessary security cookies to tell people from automated traffic.
  • The Stripe payment page, which is served by Stripe, uses its own cookies for payment processing and fraud prevention; see stripe.com/legal/cookies-policy.

If we add other cookies, we will update this section and ask for your consent where required. You can delete or block cookies in your browser settings; blocking Stripe’s cookies may prevent payment.

9. Your rights

Under the GDPR you can ask us:

  • for access to the personal data we hold about you and a copy of it;
  • to correct data that is wrong or incomplete;
  • to delete data we no longer need or have no basis to keep;
  • to restrict how we use your data while a question about it is settled;
  • for the data you gave us in a portable format;
  • to stop using data we process on the basis of our legitimate interests (you can object);
  • and you can withdraw a consent at any time, without affecting what was done before.

Write to contact@baobabsim.com. We reply within one month, or tell you within that time why we need longer.

You can complain to the President of the Personal Data Protection Office in Poland (UODO, uodo.gov.pl), or to the data protection authority of the EU country where you live or work.

If you are in Morocco, you also have the rights that Law No. 09-08 on the protection of individuals with regard to the processing of personal data gives you, and you can contact the Commission nationale de contrôle de la protection des données à caractère personnel (CNDP, cndp.ma).

If you are in Egypt, you also have the rights that Law No. 151 of 2020 on the Protection of Personal Data gives you, and you can contact the Personal Data Protection Center (pdpc.gov.eg).

If you are in South Africa, you also have the rights that the Protection of Personal Information Act 4 of 2013 (POPIA) gives you, and you can complain to the Information Regulator (inforegulator.org.za).

You can use all of these rights the same way, by writing to us.

10. Security

Card data stays with Stripe. eSIM activation codes are encrypted at rest with AES-256-GCM. Access to the order system is restricted, and every time an eSIM code is shown to an administrator it is logged. The site is served only over HTTPS. If a data breach is likely to put your rights at risk, we notify the supervisory authority within 72 hours and, where the risk is high, you as well, as the GDPR requires.

11. Children

baobabsim.com is not aimed at children under 16, and we do not knowingly collect their data.

12. Changes

When our processing changes, we update this policy and the date at the top of this page.