Privacy & data

Last updated: 2 September 2026.

This page describes what this store actually stores, for how long, and who else sees it. It is written from the code that runs the shop, not from a template.

Who we are

Both stores — Smoozy Go (smoozygo.es) and KRAHS eSIM (esim.krahs.app) — are operated by the data controller:

DC ESCRYPT SL
Calle Torre Bermeja 2, Urb. Marbella Views, Villa 8,
29679 Benahavís (Málaga), Spain
NIF: B55413975

For data requests and anything else: support@smoozygo.es (Smoozy Go) · support@krahs.app (KRAHS eSIM). We have not appointed a data protection officer — we are not required to, and these addresses reach the people who can act.

What we store

DataWhyHow long
Your email address To send the eSIM, to let you sign in, and to reach you if an order needs attention. While the account exists.
Orders: plan, price paid, currency, language, status, dates Delivery, support, refunds, and bookkeeping. While the account exists.
eSIM profile: ICCID, activation code, APN, and the phone number if the plan has one This is the product. Without it the eSIM cannot be installed or re-installed. While the account exists.
Wallet entries: top-ups, purchases, refunds So the balance is the sum of real movements and can be audited. While the account exists.
Sign-in codes To let you in without a password. Stored hashed, never in plain text. 10 minutes, then unusable.
Sign-in session To keep you signed in between visits. 30 days, or until you log out — logging out invalidates it immediately.
Your IP address Counting sign-in attempts and order look-ups, so that someone cannot guess their way into your eSIM. It is a counter, not a profile: we never link it to your purchases. One hour, in memory only. It is never written to the database.

Why we are allowed to (legal basis)

What we doLegal basis (GDPR art. 6)
Take your order, buy the plan, deliver the eSIM, answer support, handle refunds Performance of a contract — art. 6(1)(b). Without an email address there is nowhere to send the eSIM, so this is not optional.
Sign-in codes and sessions Performance of a contract — art. 6(1)(b): you asked to sign in.
Keep invoices and accounting records Legal obligation — art. 6(1)(c): Spanish tax and commercial law.
Detect double payments, fraud and abuse; keep the shop up Legitimate interest — art. 6(1)(f): not being defrauded, and not losing your money to a bug.

We do not rely on consent for any of this, because we do not do any of the things consent would be needed for: no marketing profiling, no advertising, no tracking. There is also no automated decision-making and no profiling that produces legal effects for you.

Your rights

Under the GDPR (Regulation (EU) 2016/679) you can, at any time:

Write to the address above. We answer within one month (art. 12.3), free of charge. We may ask you to confirm the request from the email address the data belongs to — that is the only proof of identity we have, and it stops someone else asking for your data.

Complaining about us

If you think we have handled your data wrongly, tell us first — it is usually faster. You also have the right to complain to the Spanish supervisory authority at any time:

Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan 6, 28001 Madrid, Spain · www.aepd.es

If you live in another EU country, you can complain to your own national authority instead.

What we do not store

Who else sees your data

WhoWhat they getWhy
MobiMatter · eSIM AccessThe order reference and the plan boughtThey issue the eSIM. One of them is the actual mobile provider behind your plan.
StripeEmail and payment details you type on their pageCard payment.
ResendEmail address and the message bodyDelivery of your eSIM and sign-in codes.
BTCPay Server (KRAHS only)Order reference and amountBitcoin payment. It is our own server, not a third party.
Sentry Technical error reports: what broke, in which part of the code, and the address of the page it happened on — which can contain an order reference. Not your email, not your eSIM, not your payment details: the personal-data flag in our configuration is switched off. So a fault that costs you an order is seen by us within seconds instead of when you write in. Hosted in the EU (Frankfurt).

Nobody else. Your data is not sold, rented, or shared for advertising.

Some of these processors operate outside the European Economic Area. Where they do, the transfer rests on the safeguards in their own data-processing agreement with us — the European Commission's standard contractual clauses or an adequacy decision. Ask us and we will tell you which applies to a given provider.

Your choices

Where it lives

On a single server in Germany, operated by OVH. Backups stay on the same server. Traffic is encrypted (HTTPS); the site is not reachable over plain HTTP.