Datenschutzerklärung.

Zuletzt aktualisiert: 15. Juni 2026

eSIM Spotter helps travelers compare eSIM plans, providers, prices, coverage, and plan features. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

Controller and privacy contact

The controller for this website is the eSIM Spotter operator identified in the Legal Notice. Full operator identity, geographic address, registration details, VAT details if applicable, subprocessors, and transfer safeguards must be completed before an EU/EEA/UK launch. Privacy requests can be sent to legal@esimspotter.com.

Information we collect

  • Preference data such as language and currency.
  • Consent records: consent id, policy version, timestamp, categories, method, and locale.
  • Internal product metrics such as page type, destination country, provider slug, price bucket, locale, event type, and timestamp.
  • Affiliate redirect logs such as plan id, provider, destination country, price, timestamp, referrer, user agent, click id, and a salted IP hash. The IP hash is pseudonymous personal data, not anonymous data.
  • Messages you send to us by email or contact forms, if enabled.

We do not need your passport, phone number, travel documents, or payment card details to compare plans. Purchases and checkout happen on provider websites.

Legal bases

  • Essential site operation, security, fraud prevention, debugging, and lightweight server-side metrics: legitimate interests.
  • Language/currency preferences and consent storage: requested preference / legitimate interests for operating the site.
  • Non-essential analytics and persistent affiliate attribution cookies: consent.
  • Responding to messages you send us: legitimate interests or steps requested by you before a contract, depending on the request.
  • Legal compliance and claims: legal obligation or legitimate interests.

Cookies, local storage, and consent

NameTypePurposeDuration
NEXT_LOCALECookieRemember selected language.Up to 12 months
currencyLocal storageRemember selected display currency.Until changed or cleared
cookie-consentLocal storageRemember consent choices in the browser.Until changed or cleared
esim_consentHttpOnly cookieAllow the server to apply the consent choices, including affiliate attribution gating.Up to 180 days
aff_click_idHttpOnly cookieAffiliate attribution after consent.30 days
Umami script/cookies, if enabledAnalyticsAudience measurement after analytics consent or a counsel-approved exemption.Configured by the analytics provider

You can change or withdraw consent at any time through the Cookie settings link in the footer. Withdrawing affiliate attribution consent deletes the persistent affiliate click cookie for future redirects.

Affiliate links and redirects

Some deal buttons route through /r/... before sending you to a provider. If affiliate attribution consent is enabled, we may set a first-party aff_click_id cookie for 30 days. If consent is rejected or unknown, the redirect still works without a persistent affiliate cookie. We may still keep a minimal server-side click log under legitimate interests for reporting, abuse prevention, debugging, and commission reconciliation.

Internal metrics

Our internal /api/events endpoint records lightweight product metrics without setting cookies or reading device identifiers. We use this to understand which pages and filters work, measure funnel health, and improve the service. You can object by contacting legal@esimspotter.com.

Sharing and processors

We may use hosting, database, analytics, security, email, and affiliate partners to operate the service. A complete subprocessor list, Article 28 data processing agreements, and transfer mechanism details must be completed before EU/EEA/UK launch. When you leave eSIM Spotter for an eSIM provider, that provider's own privacy policy applies.

International transfers

Depending on vendors, information may be processed outside your country. Before EU/EEA/UK launch, transfer safeguards such as adequacy decisions, SCCs, UK IDTA/Addendum, and transfer impact assessments must be documented where needed.

Retention

  • Internal events and affiliate click logs: currently 90 days.
  • Persistent affiliate cookie: 30 days after consent.
  • Consent records: up to 397 days, unless a longer period is required for legal claims or compliance.
  • Server logs, backups, support messages, and legal/accounting records: according to the retention matrix that must be completed before launch.

Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, port, or object to processing of your personal data, and to withdraw consent at any time. You may also have the right to complain to a supervisory authority. Contact legal@esimspotter.com to exercise these rights. The operator details and lead supervisory authority must be completed before EU/EEA/UK launch.

Changes

We version Privacy, Terms, Cookie, and consent texts and show a last updated date. Older versions should be retained internally to identify which text applied at the time of consent or use.