Privacy
In short: we keep what is needed to sell you an eSIM, get it onto your phone, and help you when something does not work. Nothing more. Here is exactly what that is.
Last updated: 16 September 2026
Controller
The controller is the provider named in the imprint. Questions about privacy: support@aynet.ai.
What we process and why
Your trip description. The sentence you type on the homepage or in the chat is sent to OpenAI so a language model can read the destination, the duration and the usage from it. It contains no account data. Legal basis: steps prior to a contract, Art. 6 (1) (b) GDPR.
Your order. Email address, chosen plan, price and order status, so we can deliver, send you the eSIM, and help you later in My eSIMs. Legal basis: the contract, Art. 6 (1) (b) GDPR. Kept for the periods commercial and tax law require.
Your payment. Payment runs entirely through Stripe. We never see card details; we receive the confirmation, the amount and a payment id. Stripe is independently responsible for payment data.
Your eSIM. To issue the eSIM we pass the chosen plan to our network partner and receive the eSIM identifier (ICCID), the activation code and, later, the usage figure. These are needed for the eSIM to work, for you to see your usage, and for top-ups.
Your account. You sign in with a link we send to your email address. There is no password. The session lives in a cookie that exists for that purpose alone.
Support conversations. What you write to the support assistant is sent to OpenAI together with the state of your eSIM so it can help. When it hands a case to a person, we store your summary with your order.
Transactional email. Order confirmation, eSIM credentials and sign-in links are sent through Resend.
What we do not do
We do not sell data. We show no advertising. We use no advertising trackers. Usage statistics, where enabled, are collected with PostHog without advertising identifiers, and errors with Sentry so we can fix them.
Recipients and third countries
Our processors: Vercel (hosting), Supabase (database and sign-in), Stripe (payment), OpenAI (language model), Resend (email), our network partner (eSIM issuing), and optionally PostHog and Sentry. Some process data in the United States. Transfers rest on standard contractual clauses or the EU-US Data Privacy Framework.
Your rights
You have the right of access, rectification, erasure, restriction, data portability and objection, Art. 15 to 21 GDPR, and the right to complain to a supervisory authority. An email to support@aynet.ai is enough.
Cookies
We set only strictly necessary cookies: the sign-in session and, during a recommendation, the draft of your trip in your browser. There is no cookie banner because there is nothing to decline.
