1. Data controller
HOPON SOLUTIONS S.A., 60 rue François Ier, 75008 Paris, France, RCS Paris 934 517 582, is the controller for the processing described here. Privacy contact: contact@hopon.fr.
2. Data we process
We process order and contact data (name, email, telephone and billing address), payment references and amounts, eSIM plan and technical identifiers (including ICCID, IMSI or MSISDN where necessary), provisioning and top-up status, security logs and the content of support communications. Stripe processes full card details; HopOn does not receive them.
3. Purposes and legal grounds
Data is used to create, pay for, deliver and top up the eSIM under the contract; issue and retain invoices under legal obligations; provide support and handle claims; secure the service and prevent fraud based on legitimate interests; and comply with lawful requests. Mandatory information is necessary to supply the service. Order data is not used for marketing without an appropriate legal basis.
4. Recipients and providers
Authorised HopOn personnel and providers receive only the data required for their role. These include Stripe for payments and fraud prevention; Transatel and partner mobile networks for eSIM provisioning and connectivity; Hostinger for hosting, databases and email; and competent authorities or advisers where legally required. Their own policies may apply when they act as separate controllers.
5. Transfers outside the EEA
International connectivity and some providers may involve processing outside the European Economic Area. Where required by GDPR, transfers rely on an adequacy decision, standard contractual clauses or another recognised safeguard. Information about applicable safeguards may be requested at contact@hopon.fr.
6. Retention
Orders, consent evidence and contractual records are retained for the commercial relationship and applicable limitation periods. Invoices are retained for ten years. Top-up verification codes expire after ten minutes and their technical records are deleted within thirty days. Support records and security logs are kept only as long as necessary, unless law, an authority request or a dispute requires longer retention.
7. Cookies and local storage
The public site currently uses no advertising or audience-measurement cookie. Browser local storage may retain a destination image address. Google Fonts and Wikimedia/Wikivoyage may receive technical request information such as IP address; Stripe uses its own technologies on the payment page. Prior choice will be offered if non-essential trackers are added.
8. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, objection and portability, and withdraw consent where processing relies on it. Contact contact@hopon.fr. Identification may be requested only where there is reasonable doubt. You may also complain to the French CNIL or your competent data protection authority.
9. Security
HopOn uses technical and organisational safeguards including encrypted communications, access controls, data minimisation, temporary-code verification for top-ups and cryptographic validation of payment notifications. No system can guarantee absolute security.
10. Updates
This policy may change with the service or applicable law. The current date and version are shown above. Material changes will be communicated appropriately.