Identity
Full name
Required for the customer contract.
Not requested. Email-only support.
Mobile networks and internet infrastructure process traffic data. Our standard checkout stays limited to email for QR delivery, Stripe payment handling and technical security data.
Our checkout minimum
QR
(email for delivery)
What your carrier has
47+
(per Czech law § 97)
●DNS queries Czech ISPs are logging right now / s
0
What your carrier actually knows about you
This is a model day for a Prague user. Telecom providers process traffic and location data under electronic communications rules. Access by public authorities depends on the specific legal process and request.
§ 97 Czech EC Act · 6-month retention
Typical mobile data trail
00:00BTS HOME-7-12
Praha 7 — domov (Holešovice)
© OpenStreetMap · © CARTO
Last 24h record
What's actually collected
15 data points showing exactly what we keep vs what your carrier keeps. Where we keep something (Stripe token, email, provider session), we admit it. No creative accounting.
Identity
Full name
Required for the customer contract.
Not requested. Email-only support.
Identity
Permanent address
For invoicing and contract registry.
Standard B2C checkout does not ask for address.
Identity
ID number
Identity verification at contract signing.
Standard checkout does not ask you to upload ID.
Identity
Phone number
Central key linking everything.
Not requested.
Identity
Invoicing, marketing, recovery.
QR delivery and (optional) order communication.
Technical
Phone IMEI / IMSI
Device + SIM identifier, paired with location.
eSIM provider technically sees the session; we don't have an identity link.
Location
Cell-tower (BTS) location
Each call / SMS / data session records the cell. Time series = movement trace.
We don't have it. Roaming runs through an Austrian provider not linked to your name.
Connections
Call metadata (who, when, how long)
Including called number, duration, conference parties.
We don't do voice. Zero call records.
Connections
SMS metadata (who-to-whom, when)
Without content, but full metadata.
We don't do SMS.
Connections
Session IP + timestamp
Pairs with identity + visited domains (DNS/SNI).
Provider technically sees, we don't. Provider has no identity link.
Connections
DNS queries / visited domains
ISP DNS resolver sees every domain. TLS SNI handshake is plaintext.
DNS goes via our provider's APN (outside Czech ISP). We don't log it.
Payment
Bank account number
For direct debit. Pairs with identity.
Card via Stripe (PCI-DSS). We see only the Stripe token.
Payment
Card number
Card flows via the carrier's payment gateway.
Stripe holds it, we don't see it. PCI-DSS Level 1.
Technical
Consents / marketing preferences
Segmentation, A/B campaigns.
No identified behavioral marketing.
Technical
Login / password / account
For self-service, recovery questions.
You don't have an account. No password, no security questions.
HTTPS encrypts content; metadata is plaintext
Most people think HTTPS = private. Not true. SNI (Server Name Indication) in the TLS handshake is plaintext, so your ISP sees every domain you visit. The DNS query tells them the same thing.
Browser → HTTPS request
GET https://<doména>/account
[ ŠIFROVÁNO TLS ]
Request bodies (POST data, cookies, URL paths) are encrypted, but the ISP already knows where you went.
With our eSIM
Your data session rides our provider's APN (Austrian carrier). Czech ISPs / mobile carriers see neither SNI nor DNS — because you're not using them.
Pick an eSIM with less data sharingOur privacy discipline
We describe what checkout needs and where the limits are: email, payment, security logs and provider processing to deliver the service.
Used for QR delivery, support and claims. Standard checkout does not ask for ID upload or phone.
We use European hosting and application partners where operationally suitable; processors are listed in the privacy policy.
Security logs are limited for incident response. No DPI and no keyword matching of communication content.
Send a mail from that address → we erase within 30 days per GDPR Art. 17. No queue, no paper.
PCI-DSS Level 1. We only see the tokenized handle and paid / unpaid status.
Optionally create an account to manage multiple eSIMs. Default = no account.
iPhone 11+ and all eSIM Androids (from 2020)
Privacy questions
We primarily use the email address from checkout. If you contact us from that address, we can find the order through internal order data and payment metadata. No PIN or security questions.
Less data in checkout
For standard checkout, email for QR delivery and payment are enough. We do not ask for ID upload, national number, phone or Czech bank account.