Privacy Policy
Last updated: September 2025
At EsimPanel.io, we are committed to protecting the privacy and data of our business users and their customers. This Privacy Policy explains our data handling practices for our white-label eSIM marketplace platform.
Information We Collect
- Business account information (company name, registration details)
- Contact person details (name, email, phone number)
- Billing and payment information
- Technical integration data (API keys, webhook configurations)
- Usage analytics and performance metrics
- eSIM transaction records (anonymized and aggregated)
- Device and browser information for platform access
Data Processing Purposes
- Platform service delivery and account management
- Billing and financial transaction processing
- Technical support and troubleshooting
- Platform improvement and feature development
- Compliance with telecommunications regulations
- Fraud prevention and security monitoring
- Marketing communications (with explicit consent)
Our Commitment: We Never Sell Your Data
- EsimPanel.io NEVER sells, rents, or trades customer data to third parties
- Your data is used exclusively for platform operation and improvement
- We do not engage in data brokerage or monetization of user information
- Customer trust is our foundation - your data privacy is non-negotiable
- All data processing serves only legitimate business purposes outlined in this policy
- Third-party integrations are strictly for service delivery, never for data selling
Data Security and Protection
- ISO 27001 certified data infrastructure
- AES-256 encryption for data at rest and in transit
- Regular third-party security audits
- Multi-factor authentication for account access
- Secure API token management
- GDPR and CCPA compliant data handling
- Automated threat detection systems
International Data Transfers
- Data may be processed in multiple jurisdictions
- Standard contractual clauses for GDPR compliance
- Localized data storage options available
- Transparent cross-border data transfer policies
User Rights
- Access and download your account data
- Request data correction or deletion
- Export complete account information
- Withdraw consent for marketing communications
- Object to specific data processing activities
- Request comprehensive data processing records
Third-Party Integrations
- Carefully selected payment processors
- Telecommunications provider APIs
- Analytics and performance monitoring services
- Customer support and CRM tools
- Each provider undergoes strict security review
Data Processing Roles and Responsibilities
- EsimPanel.io acts as a Data Processor for customer (end-user) data collected through white-label platforms
- The business operating the white-label eSIM marketplace is the Data Controller
- All end-user personal data is encrypted using industry-standard AES-256 encryption
- Comprehensive audit logs track all data access, modifications, and processing activities
- Data Controllers can access, export, and request deletion of their customer data at any time
- We provide data processing transparency through detailed activity logs
- Data Processing Agreements (DPA) available upon request for GDPR compliance
Data Security and Encryption
- End-to-end encryption for all personal data in transit and at rest
- AES-256 encryption standard for database storage
- Secure API token management with bcrypt hashing
- Advanced audit logging for compliance and security monitoring
- Regular security assessments and penetration testing
- Encrypted backups with multi-region redundancy
Browser Storage and Local Data
- We use browser local storage to remember user preferences and enhance platform experience
- Cookie consent preferences stored in 'esimpanel_cookieConsent' key
- User interface preferences (language, theme, dashboard layout)
- No sensitive personal data stored in local storage
- Users can clear local storage through browser settings at any time
- Local storage data remains on user's device and is not transmitted to servers
Regulatory Compliance and Jurisdictions
- GDPR compliance for European Economic Area users
- UK GDPR and Data Protection Act 2018 for UK users
- Turkish KVKK (Law No. 6698) for Turkish jurisdiction
- CCPA compliance for California residents
- International data transfer safeguards via standard contractual clauses
- Dedicated Data Protection Officer for privacy inquiries
Questions About Our Privacy Policy?
For privacy-related inquiries, contact our Data Protection Officer at [email protected]