Search for your (e)SIM Card:

Privacy and Cookies policy

Last Updated: June 25 2025

This Privacy & Cookies Policy explains how Internet Advertising Solutions BV (“PrepaidZero,” “we,” “us,” “our”) collects, uses, discloses and safeguards your information when you visit www.prepaidzero.com, purchase or manage eSIM plans in the PrepaidZero mobile app, or interact with any related product, software, tool or data feed (collectively, the “Services”).

By using our Services you acknowledge that you have read and understood this Policy and agree to its terms. If you do not agree, please do not access or use the Services.


1. Who We Are

Controller: Prof. R. Casimirstraat 34-D, 1068 KC Amsterdam, The Netherlands The Netherlands
Data-protection e-mail:
[email protected]

2. What Data We Collect & Why

We collect only the data that is relevant and proportionate to deliver, secure and improve the Services (data-minimisation principle).

  • Account Data – name, e-mail, mobile number, hashed password.
    • Why: create and secure your account, send transactional messages.
  • Purchase & Payment Data – billing address, last 4 digits of card, payment token (processed by Stripe, Adyen or Apple Pay/Google Pay).
    Why: fulfil eSIM orders, detect fraud, issue refunds.
  • eSIM Plan Data – ICCID, activation time, country, data/usage counters.
    Why: deliver mobile-data service, show usage, enforce fair-use rules.
  • Device & App Data – device model, OS version, app version, language, crash logs.
    Why: debug, optimise performance, secure log-ins.
  • Usage Analytics – screens visited, clicks, marketing campaign UTM tags (collected via Plausible Analytics / Firebase with IP-anonymisation).
    Why: improve UX and measure feature adoption.
  • Location Data (Optional) – coarse network location if you allow it.
    Why: recommend local eSIM plans. Never collected in background without consent.
  • Support Interactions – chat transcripts, e-mails, call recordings.
    Why: answer questions, resolve disputes, train agents.

We do not collect: social-security numbers, health or biometric data, nor do we store full payment-card numbers.

3. Legal Bases (GDPR Art. 6)

  • Contract: processing required to deliver the eSIM you purchase.
  • Legitimate interests: fraud prevention, network security, analytics.
  • Consent: marketing e-mails, optional location permissions, non-essential cookies.
  • Legal obligation: tax/financial-audit records, law-enforcement requests.

You may withdraw consent at any time via account settings or by emailing [email protected].

4. Cookies, Pixels & Similar Tech

  • Strictly Necessary Cookies – session ID, CSRF token (cannot be disabled).
  • Functional Cookies – remember language, login state (7 days).
  • Performance Cookies – anonymous analytics (first-party only, 13 months).
  • Marketing Cookies – Facebook Pixel / Google Ads (set only if you opt-in).

You can disable non-essential cookies through our Cookie Settings banner or via your browser. For details visit www.youronlinechoices.eu.

5. How We Share Data

  • Payment processors: Stripe, Adyen, Apple Pay, Google Pay.
  • Mobile-network partners: to provision your eSIM on their core network.
  • Cloud & IT vendors: AWS (EU-Central), Firebase Crashlytics, Help Scout.
  • Analytics & marketing providers: Plausible (EU), Meta/Facebook (only if you accept marketing cookies).
  • Legal & compliance: regulators, tax authorities, courts – when required.
  • Corporate events: merger or acquisition, subject to confidentiality.

We never sell your personal data.

6. International Transfers

Your data may be processed outside the EEA (e.g., U.S.) where privacy laws may differ. We rely on EU Standard Contractual Clauses or an EU-adequacy decision to ensure equivalent protection (GDPR Art. 46).

7. Your Rights

  • Access – receive a copy of the data we hold.
  • Rectification – correct inaccurate data.
  • Erasure – “right to be forgotten.”
  • Restriction – limit processing.
  • Portability – obtain data in machine-readable form.
  • Objection – to direct marketing or processing based on legitimate interest.
  • Complaint – lodge with your local supervisory authority (Dutch DPA / Autoriteit Persoonsgegevens).

Exercise any right by e-mailing [email protected] or via in-app Privacy Tools.

8. Data Retention

Account & eSIM records: kept for the life of the account + 7 years (tax law). Analytics logs: 25 months. Support transcripts: 18 months, unless tied to an unresolved dispute.

9. Security

We apply ISO 27001-aligned controls: TLS 1.3, AES-256 at rest, MFA-protected admin access, regular penetration tests. No internet transmission is 100 % secure; if you believe your account has been compromised, contact [email protected] immediately.

10. Children’s Privacy

Our Services are not directed to children under 13, and we do not knowingly collect their data. Users aged 13–17 require verifiable parental consent (COPPA & GDPR-Kids). If we learn we have personal data of a child under 13, we will delete it promptly.

11. California Privacy (CCPA/CPRA)

We disclose the following categories of information for “business purposes”: identifiers, commercial information, internet activity, geolocation (coarse), in line with sections 1798.100–1798.199 of the California Civil Code. We do not “sell” or “share” personal data as defined by the CPRA.

12. Changes to This Policy

We may update this Policy to reflect legal, technical or business changes. The “Last Updated” date will change accordingly. If changes are material we will notify you via e-mail or in-app banner 30 days before they take effect.

13. Contact Us

Questions or concerns? Write to [email protected] or PrepaidZero – Data Protection, Prof. R. Casimirstraat 34-D, 1068 KC Amsterdam, The Netherlands.


Reviewed by external counsel on June 24 2025 for compliance with EU GDPR, UK DPA 2018, CPRA and the latest Apple App Store & Google Play privacy rules.

We use cookies and process data for essential purposes and, with your consent, for analytics and personalized advertising. By continuing, you agree to our Cookie Policy.