Back to Legal Center

    Privacy Policy

    Last updated: May 21, 2026

    The short version: we collect what we need to sell you an eSIM and keep your account working. We don't sell your data, we don't track you across the web, and you can ask us to delete everything at any time. The longer version is below, written by humans for humans, but still GDPR-compliant.

    This Privacy Policy explains how Goomla B.V. ("JamboSim", "we", "us") handles your personal data when you visit jambosim.com or use one of our eSIMs. We're the data controller under the EU General Data Protection Regulation (GDPR).

    1. Who we are

    A Dutch company: Goomla B.V., P.J. Oudweg 5, 1314 CH Almere, the Netherlands. Chamber of Commerce (KvK) 39101067. Privacy questions go to [email protected], a real person replies.

    2. What we collect

    Only what we genuinely need:

    • Account stuff: your email, optionally a name, your country, optionally a phone number, and a hashed password (we never see the actual password).
    • Order & payment: what you bought, how much you paid, any discount code, your Stripe customer ID, and the last 4 digits + brand of your card. Full card numbers stay with Stripe, we never touch them.
    • eSIM & usage: ICCID, when you activated, how much data is left, when it expires, and the country it's used in. This comes from our network partners.
    • Conversations: emails you send us and our replies, so we can actually help you.
    • Technical bits: IP address, browser, device, OS, pages you viewed, and where you came from. Mostly via cookies and server logs (see our Cookie Policy).

    We only process your data when the law gives us a reason to:

    • To deliver what you bought (Art. 6(1)(b) GDPR): make your account, take your order, deliver the eSIM, handle top-ups and renewals, and answer your questions.
    • Because we have to (Art. 6(1)(c) GDPR): Dutch and EU tax, accounting and consumer law (e.g. keeping invoices for 7 years).
    • Because it makes sense for both of us (Art. 6(1)(f) GDPR): catching fraud, keeping the service secure, improving the product, and sending you transactional emails about your orders.
    • Because you said yes (Art. 6(1)(a) GDPR): optional marketing emails. You can unsubscribe with one click whenever you feel like it.

    4. How long we keep it

    • Account data: until you delete the account, plus a 30-day backup window.
    • Orders & invoices: 7 years (Dutch tax law, sorry, not optional).
    • eSIM usage data: up to 90 days after the eSIM expires.
    • Support emails: 24 months after our last chat.
    • Server logs: 30 days, longer only if we're investigating something dodgy.

    5. Who else touches your data

    Only the partners we genuinely need to make this work. All have a Data Processing Agreement with us:

    • Stripe Payments Europe Ltd (Ireland): processes your payment.
    • Supabase Inc. (EU region): runs our database, login and file storage.
    • Airalo Singapore Pte Ltd: our network partners. They get your email and order details so they can actually hand you a working eSIM.
    • Resend: sends our transactional and login emails.
    • Rollbar Inc.: tells us when something breaks. No payment data goes here.

    6. Data leaving Europe

    Some partners (like Stripe and Rollbar) might process data outside the EEA. When they do, we use the European Commission's Standard Contractual Clauses (SCCs) plus extra safeguards, so your data still gets the same level of protection it does at home.

    7. Your rights (and we mean it)

    The GDPR gives you the right to:

    • See the personal data we hold about you.
    • Fix anything that's wrong or incomplete.
    • Have your data deleted ("right to be forgotten") where the law allows.
    • Pause or object to certain processing.
    • Get your data in a portable format.
    • Withdraw marketing consent whenever, no questions asked.
    • Complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl. We'd rather hear from you first though, we usually fix things faster.

    To use any of these rights, just email [email protected]. We reply within 30 days, often a lot sooner.

    8. How we protect it

    The standard playbook done properly: TLS encryption in transit, encryption at rest, role-based access, row-level security on the database, and regular dependency audits. No system on earth is 100% bulletproof though, so please do yourself a favour and use a strong, unique password.

    9. Kids

    JamboSim isn't for under-16s. We don't knowingly collect their data. If you think a child has signed up, let us know and we'll delete it straight away.

    10. Abandoned cart reminder

    If you place an eSIM in your cart but don't complete your order, we may send you a single reminder email. This is only to help if you forgot to check out. You can unsubscribe at any time via the link in that email or by emailing [email protected].

    11. Changes to this policy

    We'll tweak this page now and then. The "Last updated" date at the top always shows the current version. Anything material gets announced by email or a banner on the site, so you're never blindsided.

    12. Get in touch

    Questions, concerns, compliments? Email [email protected] or write to Goomla B.V., P.J. Oudweg 5, 1314 CH Almere, the Netherlands.