Privacy Policy
We explain the permitted processing of data when you buy an eSIM, use your account, and interact with analytics or marketing measurement.
Version 2026-07-24 · effective 24 July 2026
1. Data controller
Who runs the site and where we are based.
Legal name
Company ID
Data box
Commercial register
Registered address
Telephone contact
2. What we process
Only the data the site actually needs.
- Standard consumer checkout can be completed with only an email. Name, contact phone, and billing address are optional for personalization, details on the payment document or invoice under the applicable tax regime, or a saved profile; we do not require or verify them as mandatory subscriber-identification data, and leaving them blank does not block the service. We do not collect date of birth, a mandatory residential address, a national identifier, an identity-document number, or a document copy. A wholesale supplier's KYC flag is disclosed only, is not used as a checkout gate, and we attempt fulfilment without identity verification; if the upstream rejects that activation after payment, the service is not supplied and we do not request an identity document. Byte promptly initiates the refund and its accounting reconciliation; if the automatic refund does not complete for technical reasons, Byte completes it manually without asking for an identity document.
- Email and order details for eSIM delivery, billing and support.
- Billing profile and company details only when the customer saves them or enters them in checkout.
- IP address, CSRF token and order code for fraud prevention and ownership verification.
- Technical identifiers required for operations. Non-essential analytics (Umami, GA4, and PostHog including session replay) run only after analytics consent; advertising and marketing identifiers and pixels run only after marketing consent. The cookie banner stores your choice and lets you change it.
- For Flex, Stripe retains the payment method and Stripe customer/payment-method identifiers to charge the next agreed prepaid period automatically; Byte does not store full card details.
- Browser storage used by the consent banner, cart persistence and security checks.
- We do not automatically load the Chatwoot SDK or its storage during an ordinary visit. It loads only when you actively open support; Chatwoot then processes the chat content and technical context needed to handle the request.
- Connection-quality diagnostic records after eSIM activation: reachability result, speed estimate, latency, app version, related profile/order reference, network status and provider usage delta where available. Automatic tests are off by default; they run only when you explicitly enable them or start a manual test. One test usually uses up to 1 MB and can be turned off again in app Settings.
3. Purposes and legal bases
Purpose, legal basis and retention in one table.
| Purpose | Legal basis | Retention |
|---|---|---|
| Concluding and performing the prepaid electronic-communications service contract, eSIM provisioning, and order management | GDPR Art. 6(1)(b) | For the contract and no more than 3 years after its end or completion of the order for complaints and legal claims; accounting and tax documents for 10 years |
| Invoicing and accounting | GDPR Art. 6(1)(c) | 10 years |
| Optional personalization and saved billing profile | GDPR Art. 6(1)(b) (at the user's request) | Until the user deletes the profile or closes the account; data copied to an accounting record is retained as required by law |
| Customer support and complaints by email or Chatwoot | GDPR Art. 6(1)(b) and (f) | An ordinary conversation for no more than 3 years after the request is closed; longer only for specific evidence needed for an unresolved complaint, dispute, or legal duty |
| Fraud prevention, operational security, and error diagnostics including Sentry and hosting/CDN logs | GDPR Art. 6(1)(f) | Ordinary technical and security logs for no more than 90 days; a record of a specific incident until closure and then for no more than 3 years where needed to protect legal claims |
| Automatic connection-quality diagnostics and public aggregate speed reporting | GDPR Art. 6(1)(f) | An identifiable diagnostic record for no more than 90 days; a record needed for a complaint during its handling and for no more than 3 years afterwards. Anonymous public aggregates without profile, order, ICCID, QR code, or precise location may be retained long term |
| Non-essential analytics (Umami, GA4, PostHog, and Firebase Analytics in the app) | Analytics consent under GDPR Art. 6(1)(a) and Section 89(3) of the Czech Electronic Communications Act | GA4/Firebase for no more than 14 months; PostHog events and session replay and Umami for no more than 12 months; earlier following a valid erasure request or withdrawal where a record can be linked to the user |
| Advertising conversion measurement, attribution, and remarketing | Marketing consent under GDPR Art. 6(1)(a) and Section 89(3) of the Czech Electronic Communications Act | Ad-click identifiers and our attribution link ordinarily for 30 days and no more than 90 days; external advertising systems for no more than their disclosed period, and in all cases no later than withdrawal where a record can be linked to the user |
| Consent-based lifecycle and marketing email through Dittofeed | GDPR Art. 6(1)(a) | Until consent is withdrawn, the account is deleted, or no more than 3 years of inactivity; a minimal suppression record is retained so we can respect an opt-out |
| Push notifications through Expo and Apple/Google platform push services | GDPR Art. 6(1)(a); transactional order status also GDPR Art. 6(1)(b) | Encrypted push token until device opt-out, account deletion, or no more than 12 months of inactivity; delivery records for no more than 90 days |
| Sign-in with Apple or Google | GDPR Art. 6(1)(b) | The verification token only while processing the sign-in; the link to the external identifier for the account lifetime and until deletion, except a security record retained for no more than 90 days |
| Recording and settling an already-earned partner commission without a client-side tracker | Performance of the partner agreement and GDPR Art. 6(1)(f) (protecting accounting and contractual claims) | The accounting record for the statutory retention period; a personal link only as long as needed for settlement, complaints, or legal claims. Conversion emails are erased when the account is deleted; an anonymized accounting record containing the amount, status, and one-way hash remains for the statutory period. |
| `td_attribution`, affiliate/referral tracking, ad-click identifiers, and advertising attribution | Marketing consent only under GDPR Art. 6(1)(a) and Section 89(3) of the Czech Electronic Communications Act | Ordinarily 30 days. A longer partner attribution window applies only where it is expressly agreed and shown to the user; never beyond withdrawal of consent or expiry of the relevant cookie. Disclosure to ad networks is limited to the consent given |
4. Processors, recipients, and technical suppliers
Who helps us run the service and accept payments.
- Stripe for one-off payments, payment documents or invoices under the applicable tax regime, and secure retention of the payment method for the next agreed Flex period
- Appwrite for database and account operations
- eSIM Access and MobiMatter as wholesale technical suppliers for eSIM provisioning and technical usage-status checks during diagnostics; they are not the customer's contracting party
- Appwrite Messaging with MailerSend SMTP for transactional email
- Vercel and the DNS/CDN provider in use for hosting, content delivery, network security, and short-lived operational logs; they may process IP address, URL, request headers, and technical device data
- Sentry for error diagnostics, stability, and security; it processes technical error context, app version, URL, or stack trace, while we filter secret keys, authorization headers, and cookies
- Chatwoot on Byte infrastructure for customer chat and complaints when you use that channel; it processes contact details, conversation content, attachments, and technical request context
- Dittofeed for consent-based lifecycle and marketing email; it receives email, an internal pseudonymous identifier, consent status, and limited events needed for the relevant journey
- Expo and Apple/Google push services for notification delivery; they use the push token, platform, language, and the content of the specific notification
- Firebase Analytics/Google Analytics for analytics and conversion measurement in the mobile app only after the corresponding consent
- Apple and Google as sign-in providers; they verify identity and disclose a stable identifier and email or name only to the extent made available by the provider and the user. We do not receive the Apple or Google password
- GA4, PostHog including session replay, and Umami only after analytics consent
- Meta, Google Ads, Seznam/Sklik, TikTok, Microsoft Ads and Reddit for advertising pixels, server-side conversions, attribution, and remarketing only after marketing consent; marketing communications are sent only with the corresponding consent
- Heureka Group a.s. for the Ověřeno zákazníky (Verified by Customers) programme and conversion measurement – after a paid order we share your email and the ordered items under legitimate interest (GDPR Art. 6(1)(f)) so Heureka can send its satisfaction questionnaire; you can decline it via the link in the questionnaire email
- mPOHODA for invoicing and accounting records
- Where a recipient processes data outside the EEA, we use an adequacy decision or standard contractual clauses and appropriate safeguards.
5. Your rights
What you can request and through which channel.
- Right of access, rectification, erasure, portability, objection and restriction.
- You can withdraw consent at any time in cookie settings or through support; withdrawal does not affect processing lawfully performed before it.
- Authenticated export and deletion for data belonging to the signed-in user are also available through the GDPR portal.
- On deletion, we erase or anonymize unnecessary profile data; data recorded on an accounting or tax document is retained unchanged for the statutory period.
- You can lodge a complaint with the supervisory authority — the Czech Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz (Article 77 GDPR).
Use the GDPR portal or email support@tvojedata.cz for export or deletion requests.
6. Cookies and browser storage
Map of essential, analytics, ads and affiliate/referral cookies.
- Essential: `td_session` with Appwrite session secret for account login
- Essential: `csrf_token` for form protection and `cookie_consent` for storing your choice
- Marketing — only after consent: `td_attribution` stores referral, affiliate, or white-label tenant identifiers and ad-click identifiers (e.g. gclid, sznaiid, UTM) for purchase attribution; it is a first-party cookie that is not necessary for purchase and is neither stored nor used without marketing consent
- Accounting records and settlement of a commission already earned from a completed order may be handled separately without a client-side tracker; this does not make `td_attribution` an essential cookie
- Analytics: Umami, GA4, and PostHog including session replay load only after analytics consent; consent can be withdrawn at any time in cookie settings
- Advertising cookies and conversions: Meta, Google Ads, Seznam/Sklik, TikTok, Microsoft Ads and Reddit pixels and server-side advertising conversion measurement run only after marketing consent; where consent is given they may process hashed email and IP address, and we do not send the optional phone number to ad networks
- Cart state and consent choices may be stored in localStorage/cookies according to your settings
7. Contact
Last stop and service contact.
Contact: support@tvojedata.cz. GDPR requests can also be submitted through the GDPR portal.