Privacy policy
Last updated: 7 October 2026
At Glowi we process your personal data transparently and only as far as necessary. This policy explains what data we collect when you visit the website or buy an eSIM, what we use it for and what rights you have, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
1. Data controller
- Controller
- Pablo Alfaya Fernández
- Tax ID (NIF)
- 29514449K
- Registered address
- Calle La Santa María, 86, 41927 Mairena del Aljarafe (Sevilla)
- Contact
- hello@glowisim.com
2. What data we process
- Contact and order data: email address, order reference, destination, plan, number of eSIMs, amount and date of purchase.
- Payment data: processed directly by the payment institution or payment gateway. We do not see or store your full card number; we only receive confirmation of the payment and limited data, such as the card type or its last digits.
- eSIM data: technical identifiers of the profile (such as the ICCID or the activation code), its status and the plan’s data usage, as provided to us by our supplier.
- Billing data, if you ask us for an invoice: name or company name, tax ID (NIF) and address.
- Communications: whatever you tell us when you contact us.
- Technical browsing data: IP address, browser and device type, and access logs needed for the security of the website. For cookies and similar technologies, see the Cookie policy. With each order we also store the country that matches your IP address (only the country, not the IP address), as one of the pieces of evidence VAT rules require to establish in which country the service is supplied. Also, if you haven’t chosen a currency, when you open the website we use the country of your IP address to show prices in your currency, without storing the country: your browser only remembers the currency, just as if you had chosen it, and you can change it whenever you like. We do not use it for anything else.
- Website usage statistics: with Umami, a cookie-free analytics tool, we measure in aggregated, anonymous form how many visits the website gets, which pages are viewed, from which country and device type, where visitors come from (including campaign parameters in links) and how many move forward in the checkout process. It uses no cookies, stores no personal data, does not identify you and does not track you across websites. We never send it your email address, your name or your order details.
We do not ask you for special categories of data, and we do not access your precise location or the content of what you browse using the eSIM. The data marked as mandatory in the forms is necessary to provide the service: if you do not provide it, we will not be able to complete the purchase.
3. What we use your data for and on what legal basis
| Purpose | Legal basis |
|---|---|
| Managing your purchase, sending you the eSIM and its instructions, and providing the service you have bought. | Performance of the contract (Art. 6(1)(b) GDPR). |
| Handling your enquiries, issues, withdrawal requests and complaints. | Performance of the contract and compliance with legal obligations (Art. 6(1)(b) and 6(1)(c) GDPR). |
| Issuing invoices and complying with accounting, tax and consumer-law obligations. | Legal obligation (Art. 6(1)(c) GDPR). |
| Preventing payment fraud and protecting the security of the website. | Legitimate interest (Art. 6(1)(f) GDPR). |
| Measuring, in aggregated and anonymous form, how the website is used, with cookie-free analytics, in order to improve it. | Legitimate interest (Art. 6(1)(f) GDPR). |
| If you arrive from a comparison site or an affiliate (for example, eSIMDB) or from a campaign, storing that origin with your order to calculate and pay their commission and to measure our campaigns. We only share the order number, date, destination, plan and amount with the affiliate: never your email or your name. | Legitimate interest (Art. 6(1)(f) GDPR). Remembering that origin in your browser for 30 days only happens if you accept advertising cookies. |
| If you answer the optional question “How did you hear about us?” on the order confirmation page, storing your answer with your order so we know which channels bring us customers. It is voluntary and we do not share it with anyone. | Your consent (Art. 6(1)(a) GDPR), given when you answer. You can ask us to delete it at any time. |
| If you start a purchase and don’t finish it, sending you a single email reminder, between 1 and 24 hours later, with the plan you had chosen. No discounts or promotions. You can unsubscribe with one click from the email itself and we won’t write to you for that reason again. | Legitimate interest (Art. 6(1)(f) GDPR). You can object using the unsubscribe link in the email or by writing to us. |
| If you are already a customer, sending you communications about products or services similar to those you bought. | Legitimate interest (Art. 6(1)(f) GDPR and Art. 21.2 LSSI-CE). You can object in each message and at any time. |
| Sending you other commercial communications and using analytics or advertising cookies. | Consent (Art. 6(1)(a) GDPR), which you can withdraw whenever you like. |
We do not take decisions based solely on automated processing that produce legal effects concerning you.
4. How long we keep your data
- Orders and billing: for as long as the contractual relationship lasts and, afterwards, for the periods required by law; for example, 6 years for accounting records under the Spanish Commercial Code, plus any periods required by tax legislation.
- Enquiries and complaints: for as long as needed to resolve them and, afterwards, until any possible legal claims become time-barred.
- Technical security logs: for a limited period, generally no longer than 12 months, unless they are needed to investigate an incident.
- Commercial communications: until you unsubscribe or withdraw your consent.
Once those periods have passed, the data is blocked for as long as liability may be claimed and is then erased, in accordance with Article 32 of the LOPDGDD.
5. Who we share your data with
We do not sell your data. We only disclose it to third parties when this is necessary to provide the service or required by law:
- Suppliers that process data on our behalf (processors), under a contract that complies with Article 28 GDPR: web hosting and cloud services, payment gateway, wholesale eSIM and connectivity provider, email delivery, customer service tools, and accounting and tax advisers.
- Umami (umami.is), our cookie-free web analytics provider, which hosts the aggregated, anonymous website usage data. The analytics data is hosted in the European Union region of Umami Cloud, so this service involves no international transfer. We do not send it your email address, your name or your order details.
- Telecommunications operators at the destination and our wholesale provider, which process the technical connection data needed to provide service to the eSIM under their own regulations.
- Public authorities, courts and law enforcement agencies, where there is a legal obligation to do so.
If you ask us, we will give you the up-to-date list of suppliers.
6. International transfers
Some suppliers, such as the wholesale eSIM provider or certain technology tools, may be located outside the European Economic Area. In that case, transfers are made with the safeguards provided for in the GDPR: an adequacy decision of the European Commission or standard contractual clauses adopted by it (Art. 46 GDPR). You can ask us for more information about these safeguards.
7. Your rights
You can exercise the following rights at any time:
- Access: to find out what data about you we process.
- Rectification: to correct inaccurate or incomplete data.
- Erasure: to ask us to delete your data when it is no longer needed.
- Objection: to object to processing based on legitimate interest, including commercial communications.
- Restriction: to ask us to suspend processing in certain cases.
- Portability: to receive your data in a structured, commonly used format.
- Withdrawal of consent where processing is based on it, without affecting the lawfulness of processing carried out before withdrawal.
Email us at hello@glowisim.com stating which right you wish to exercise. If we have reasonable doubts about your identity, we may ask you for additional information to confirm it. We will reply within one month, which may be extended by a further two months if the request is complex.
If you believe we have not processed your data properly, you can lodge a complaint with the Spanish Data Protection Agency, AEPD (www.aepd.es).
8. Minors
You must be of legal age to buy on the website. We do not knowingly collect data from children under 14; if we find that we have done so, we will delete it.
9. Other people’s data
If you buy eSIMs for other travellers or give us data about third parties, you confirm that you have informed them and have their permission.
10. Security
We apply technical and organisational measures appropriate to the risk to protect your data against loss, unauthorised access or misuse, in accordance with Article 32 GDPR.
11. Changes to this policy
We may update this policy to reflect changes in the law or in the service. We will publish the new version on this page with its date and, if the changes are significant, we will let you know by email.
This is a translation for convenience. The Spanish version is the legally binding one.