Privacy Policy – Zyroam
GDPR – Art. 13 / 14

Privacy Policy

Datenschutzerklärung gemäß DSGVO

Last updated: March 2026
01 — Controller

Data Controller

The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:

NameAndre Ang
Trading asZyroam
AddressBäckerreut 5e, 94113 Tiefenbach, Germany
A Data Protection Officer (DPO) is not required under Art. 37 GDPR for this business size and processing activities.
02 — Data Collected

What Data We Collect

Depending on how you interact with our site, we may process the following categories of personal data:

CategoryExamplesSource
Contact dataName, email address, phone numberProvided by you
Billing & shipping dataAddress, country, postcodeProvided by you at checkout
Order dataProducts purchased, order value, order statusGenerated on purchase
Payment dataCard type, last 4 digits (tokenised)Processed by Stripe / PayPal
Account dataUsername, password (hashed)Provided by you (optional)
Usage dataIP address, browser type, pages visited, referrerAutomatically via server logs
Device dataDevice type, OS, screen resolutionAutomatically via browser
Communication dataSupport emails, contact form messagesProvided by you
03 — Purpose & Legal Basis

Why We Process Your Data

PurposeLegal Basis (GDPR)
Processing and fulfilling ordersArt. 6(1)(b) – Contract performance
Sending order confirmations & eSIM deliveryArt. 6(1)(b) – Contract performance
Processing paymentsArt. 6(1)(b) – Contract performance
Customer support & communicationArt. 6(1)(b) – Contract / Art. 6(1)(f) – Legitimate interest
Legal obligations (tax, retention)Art. 6(1)(c) – Legal obligation
Fraud prevention & securityArt. 6(1)(f) – Legitimate interest
Website analytics (if applicable)Art. 6(1)(a) – Consent
Marketing emails (if opted in)Art. 6(1)(a) – Consent
04 — Hosting & Server

Hosting – Hostinger

This website is hosted by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. When you visit our website, your browser automatically transmits technical data to our server, including your IP address, browser type, operating system, referrer URL, and the date and time of the request.

This data is processed on the basis of Art. 6(1)(f) GDPR (legitimate interest in operating a technically secure website) and is automatically deleted after 30 days unless required for security investigations.

Hostinger acts as a data processor under Art. 28 GDPR. A Data Processing Agreement (DPA) is in place. For details, see Hostinger's Privacy Policy.

05 — WooCommerce Shop

Online Shop – WooCommerce

Our online shop is built with WooCommerce, a plugin for WordPress by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. WooCommerce processes personal data to manage orders, cart sessions, and customer accounts.

WooCommerce sets technically necessary cookies to maintain cart state and session. These do not require consent as they are strictly required for the service.

Data processing is based on Art. 6(1)(b) GDPR (contract performance). Automattic is EU–US Data Privacy Framework certified. See Automattic's Privacy Policy.

06 — Payment Services

Payment Processing

Stripe

For card payments (Credit/Debit Card, Apple Pay, Google Pay) we use Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. When you pay by card, Stripe processes your payment data directly and securely. We only receive a tokenised reference and the last four digits of your card — we never store full card numbers.

Legal basis: Art. 6(1)(b) GDPR. See Stripe's Privacy Policy.

PayPal

For PayPal Express payments we use PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg. If you select PayPal at checkout, you will be redirected to PayPal's platform where their own privacy policy applies.

Legal basis: Art. 6(1)(b) GDPR. See PayPal's Privacy Policy.

07 — Google Services

Google Services

Google Fonts

This website loads fonts from Google Fonts (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). When fonts are loaded, your IP address is transmitted to Google. We use server-side font loading where possible to minimise this. Legal basis: Art. 6(1)(f) GDPR.

Google Places API

Our checkout uses the Google Places API (Google Ireland Ltd.) for address autocomplete on billing and shipping fields. When you begin typing an address, your partial input is sent to Google's servers to return suggestions. No address data is stored by us beyond what you submit in the order form. Legal basis: Art. 6(1)(b) GDPR.

See Google's Privacy Policy.

08 — Cookies

Cookies & Local Storage

We use the following types of cookies and browser storage:

Cookie / StoragePurposeTypeRetention
woocommerce_cart_hashStores cart contents hashNecessarySession
woocommerce_items_in_cartIndicates items in cartNecessarySession
wp_woocommerce_session_*Customer session dataNecessary2 days
wordpress_logged_in_*Authentication (logged-in users)NecessarySession
sessionStorage (esim_*)Client-side product data cacheNecessarySession
_stripe_*Stripe fraud preventionNecessaryUp to 1 year
We do not use tracking or analytics cookies without your explicit consent. If we add analytics tools in the future, a cookie consent banner will be displayed.
09 — Your Rights

Your Rights Under GDPR

Under Arts. 15–22 GDPR you have the following rights regarding your personal data:

Art. 15 – Access
Request a copy of the personal data we hold about you.
Art. 16 – Rectification
Have inaccurate or incomplete data corrected.
Art. 17 – Erasure
Request deletion of your data ("right to be forgotten").
Art. 18 – Restriction
Request that processing of your data be restricted.
Art. 20 – Portability
Receive your data in a structured, machine-readable format.
Art. 21 – Objection
Object to processing based on legitimate interest.
Art. 7(3) – Withdraw Consent
Withdraw consent at any time without affecting prior processing.
Art. 77 – Complaint
Lodge a complaint with a supervisory authority (e.g. Berliner Beauftragte für Datenschutz).

To exercise any of these rights, contact us at privacy@zyroam.com. We will respond within 30 days as required by Art. 12 GDPR.

Supervisory Authority: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstr. 219, 10969 Berlin — datenschutz-berlin.de
10 — Data Retention

How Long We Keep Your Data

Data TypeRetention PeriodReason
Order & billing records10 years§ 147 AO (German Tax Code)
Customer account dataUntil deletion requestArt. 17 GDPR
Server / access logs30 daysSecurity, Art. 6(1)(f)
Support correspondence3 years after last contactLimitation period § 195 BGB
Payment data (tokenised)Per Stripe / PayPal retentionContract & legal obligation
11 — Changes

Changes to This Policy

We may update this Privacy Policy as our services evolve or legal requirements change. The date at the top of this page reflects the most recent revision. We recommend reviewing this page periodically. For material changes that affect your rights, we will notify you by email if you have an account with us.

Privacy Policy · Zyroam (Max Mustermann) · Berlin, Germany · March 2026
Shopping Cart