Version 1.0 · Effective 18 September 2026
The short version. Orders and accounts are stored in the European Union. Your card number never reaches us. Our eSIM supplier gets an order identifier and a plan code, and nothing that could identify you. Analytics run only if you accept them, and there are no tracking cookies either way.
The English version is the one that applies; translations are provided for convenience. See also our Privacy Policy and the list of subprocessors.
Orders, accounts and eSIM records live on Amazon Web Services in Frankfurt (eu-central-1). Error reports go to Sentry’s European region, and personal data is not attached to them.
Card details are entered on a page hosted by Stripe. The number does not pass through our servers, is not logged and is not stored — our exposure to card data is the narrowest one there is (PCI DSS SAQ A). We learn whether the payment succeeded, for how much, and enough to issue a refund.
Our eSIM connectivity supplier receives an order identifier and a plan code. No name, no email, no phone — it cannot identify you from what we send. The SM-DP+ platform that installs the profile sees your device identifier and your IP at that moment, because that is how installation works; it is named on the subprocessors page.
Product analytics start only after you accept the banner, and nothing analytical loads before that. There are no advertising or cross-site tracking cookies at all. Error reporting runs for everyone, because a checkout that breaks for the people who declined analytics still has to be fixed; it carries no session recording.
Server logs: 30 days. Database backups: 7 days, then overwritten, so data from a closed account can survive in a backup for up to a week after deletion. Account data lives as long as the account does.
No SOC 2 report, no ISO 27001 certificate, no third-party penetration test. We are a small company and have not bought those yet. We would rather say so here than let a badge imply otherwise — and when any of it changes, this page changes with it.
Security questionnaires and vendor reviews: trust@nerds.boutique. Found a vulnerability: security@nerds.boutique, and see our security page for what we promise in return. Anything else: service@nerds.boutique.