Esta página se muestra en inglés. El texto en inglés es el vinculante; si algo que leas en otro lugar difiere de él, se aplica el texto en inglés. Abrir la página en inglés
This notice covers three things: browsing this website, buying an eSIM from it, and the optional account. Accounts are opened only with Google sign-in — there is no password and no profile beyond what is described below. There is no advertising, no advertising network and no analytics service. We do not sell your data and we do not build a marketing list from your visit or your order. The only cookies we set ourselves are a one-line security cookie on pages with a form, and a session cookie if you sign in (both described below).
Three things, all automatic and all ordinary for any website:
csrftoken. It exists only to make
sure a form submitted to us really came from this site, it identifies nothing about
you, and it is not used for tracking. Apart from the session cookie on an account (below), it is the only cookie we set. At the time of
writing, neither Cloudflare's protection nor the Turnstile check sets a cookie on
gojowa.com either; if that changes we will update this notice.
The lawful basis for all of this is our legitimate interest in operating a secure website (UK GDPR Article 6(1)(f)). We do not use this data to profile you and we do not sell or share it with anyone else.
Buying an eSIM creates an order record. This is everything in it, and why it is there. We collect nothing for the sake of it.
Where we rely on legitimate interest — the IP address and browser record from the order, the email delivery record, bot protection, server logs and page counts — we keep that data to defend ourselves against fraud and payment disputes and to keep the service secure, not to identify you or to show you advertising. You can object to this processing at any time by writing to privacy@gojowa.com. The one thing we process on the basis of consent is the marketing choice on an account, and you can switch it off there at any time
You do not need an account to buy, and we never ask for one before payment. An account is optional and is opened only by signing in with Google. There is no password: we do not store one, so none can be stolen from us. Google sign-in gives us three things and nothing more — we ask Google only for the "openid, email, profile" scopes.
sessionid, set only when you sign in.
It keeps you signed in for up to 30 days, is sent only over HTTPS, cannot be read by
scripts (HttpOnly) and is not sent on requests that start from other sites (SameSite=Lax).
Signing out deletes it. Basis: strictly necessary for the service you asked for.
Deleting your account. You can delete it yourself on the account page. We then delete your name, your Google identifier, your sessions, your marketing choice and your points (which are forfeited — we say so before you confirm). Order records are kept, because UK tax law requires us to keep sales records for six years, but they are disconnected from you: they keep the delivery email, the plan and the payment, and no longer belong to any account. We confirm what was deleted and what was kept by email.
We cannot sell to customers who live in the EU yet, and the plan page says so before you pay. On that screen you can ask us to tell you when this changes. If you do, we keep:
Travel businesses can apply for a reseller account. The reseller is our customer; its own travellers are not, and we never receive their details. For a reseller account we keep:
If you write to one of our addresses, we keep your message and reply so we can deal with what you asked and keep a record of the correspondence. Our email runs on Google Workspace, which acts as our processor. We keep business correspondence for up to two years unless it needs to be kept longer for legal or accounting reasons.
There is none. Until 20 September 2026 our order emails contained a small invisible image that told us when a message was opened; we switched that off and our emails now load nothing from the internet at all. Links in our emails go straight to the page they name and are not rewritten through a tracking service.
What we do keep is what our email provider reports back to us: that an email was sent, delivered, or bounced, and when. That is our evidence if you tell us an eSIM never arrived or a card issuer asks us to prove delivery.
These companies handle data on our behalf, as our processors, and only for the purpose shown.
| Who | What for | Where |
|---|---|---|
| DigitalOcean | Our server and database | London, United Kingdom |
| Cloudflare | The network in front of the site; bot check (Turnstile) | Global network |
| Stripe | Taking payment, refunds, handling payment disputes | Ireland / United States |
| Resend | Sending your order emails | Ireland (EU) |
| Google Workspace | Human correspondence (hello@, privacy@) | Global |
| eSIM Access | Issuing the eSIM | Receives no personal data about you (see "Our supplier does not see you") |
Our server is in London, United Kingdom. Stripe, Cloudflare and Google Workspace are international providers and may process data outside the UK; those transfers take place under the safeguards UK GDPR requires. Order emails are sent through Resend, which processes them in Ireland, in the European Union.
| What | How long | Why |
|---|---|---|
| Server logs | 30 days | Running and securing the site |
| Order, payment and refund records | Six years | Company accounting and tax records must be kept for six years; it is also the general limitation period for claims under a contract |
| IP address and browser record from the order | With the order record | Payment-dispute and fraud defence |
| Country you live in and card billing country | With the order record | Showing which country's tax rules applied to the sale |
| Email delivery record | With the order record | Proof of delivery |
| Account (name, Google identifier, delivery email, marketing choice, points) | Until you delete the account | Running the account; orders are then disconnected, not deleted |
| Session cookie | 30 days, or until you sign out | Keeping you signed in |
| Page counts (no personal data) | Indefinitely — they identify no one | Seeing which destinations are looked at and bought |
| Human correspondence | Two years | Dealing with what you asked, and keeping a record of it |
| Reseller account (business details, balance ledger, orders, discount history) | Six years after the last order or top-up; a rejected application is deleted after 12 months | Running the reseller account; sales records must be kept for six years |
| EU waiting list (email, country, plan, language) | Until you click the removal link; otherwise 30 days after our one announcement, or 24 months at most | Sending the one announcement, and counting how many people are waiting by country |
We do not keep any of this beyond the period shown.
Under UK GDPR you may ask us for a copy of the personal data we hold about you, ask us to correct or erase it, object to our processing it, or ask us to restrict it. Write to privacy@gojowa.com and we will respond within one month.
If you are not satisfied with our response you can complain to the UK Information Commissioner's Office at ico.org.uk. We are registered with the ICO under registration number ZC251853.
The data controller for this website is GOJOWA TECHNOLOGIES LTD, a private limited company registered in England and Wales on 15 September 2026 under company number 17460599. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Write to privacy@gojowa.com about anything in this notice and it reaches a person, not a queue.
When this notice changes we will update the version and date at the top. This is version 2.5 (22 September 2026): reseller accounts — the section "If you apply as a reseller" describes the business details, the prepaid balance ledger, orders and the discount history we keep, with their legal basis and retention. Version 2.4 (22 September 2026): the EU waiting list — the section "If you ask to be told when we open to the EU" describes the email address, country, plan and language kept with your consent, the single announcement email it is used for, the one-click removal link and the retention limit. Version 2.3 (22 September 2026): optional customer accounts with Google sign-in — the section "If you open an account" describes the name, Google identifier, connected order history, points balance, delivery email, marketing choice and session cookie, each with its legal basis, and what deleting an account removes and what it keeps. Version 2.2 (21 September 2026): email open tracking has been switched off and the "Email tracking" section rewritten to say so, server logs no longer record IP addresses, and a cookie-free page counter that stores no personal data has been added. Version 2.1 (20 September 2026) added the country you live in and the billing country of your card, both collected at checkout to apply the right tax rules. Version 2.0 (20 September 2026) covered eSIM orders — what an order record contains and why, retention periods, Stripe as payment processor, the Turnstile bot check and the one security cookie. Version 1.2 (19 September 2026) added Resend as the processor for order emails and the "Email tracking" section. Version 1.1 (15 September 2026) named the company as the data controller. Version 1.0 (13 September 2026) was published before the company existed and named the site's founder as its operator.