Logo Karty SIMUSA
ShopHelp
Phone icon

+48 720 746 746

Top Up Card
Phone iconHelp
  1. Shop
  2. Privacy policy

Privacy policy

Last updated: 19 June 2026 PRIVACY POLICY

This Privacy Policy sets out the rules for the processing of personal data in connection with the operation of the online store available at https://kartysimusa.pl/ and the provision of services related thereto. This document is for informational purposes and fulfills the Controller’s information obligations arising from Articles 13 and 14 of the GDPR.

§ 1. General Provisions This policy (hereinafter referred to as the "Privacy Policy") sets out the rules for the processing of personal data by Karty SIM Kamiński spółka jawna, with its registered office in Warsaw, ul. Genewska 6, 03-963 Warsaw, entered into the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register under KRS No. 0001100212, NIP 1133131078, REGON 528366548 (hereinafter referred to as the "Controller" or the "Seller"). This Privacy Policy applies to the personal data of natural persons processed in connection with the operation of the website available at https://kartysimusa.pl/ (hereinafter referred to as the "Store"), in particular in connection with: creating and maintaining a Customer Account, placing and fulfilling orders, the sale and activation of SIM cards and eSIMs, the provision of the Money-Back Guarantee service, operation of the KartySIMUSA Loyalty Program (including the Referral Program), handling complaints, conducting marketing activities, and managing correspondence with the Controller. Nature of the service. The Controller acts as an intermediary in the sale and activation of telecommunications services provided by foreign telecommunications operators, particularly within the territory of the United States of America. The Controller is not an electronic communications undertaking within the meaning of the Act of 12 July 2024 – Electronic Communications Law. This Privacy Policy should be interpreted together with the Store Terms and Conditions, promotional regulations, the KartySIMUSA Loyalty Program Terms and Conditions, the Money-Back Guarantee Terms and Conditions, and the Cookie Policy, which constitute separate documents. The use of cookies is governed by the Cookie Policy available in the Store. Use of the Store is voluntary. Providing personal data is also voluntary, subject to the proviso that in certain cases (e.g., entering into a sales agreement, creating an Account, participating in the Loyalty Program, or submitting a complaint) the provision of specific data is necessary in order to use a given service or Store functionality. This Privacy Policy is effective from [●] and is available for download in the Store.

§ 2. Definitions Capitalized terms used in this Privacy Policy shall have the following meanings:

a) GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC.

b) Personal Data – information relating to an identified or identifiable natural person within the meaning of Article 4(1) GDPR.

c) Customer – a natural person, legal entity, or organizational unit referred to in Article 33¹ § 1 of the Polish Civil Code who concludes an agreement with the Seller through the Store; with respect to natural persons, a person whose personal data is processed by the Controller in connection with placing an order, creating an Account, or otherwise contacting the Store.

d) Consumer – a Customer who is a natural person entering into an agreement with the Seller not directly related to their business or professional activity, within the meaning of Article 22¹ of the Polish Civil Code.

e) User – a natural person actually using a SIM Card or eSIM purchased through the Store, where such person is different from the Customer.

f) SIM Card – a physical SIM card and an eSIM offered through the Store.

g) Operator – a foreign telecommunications operator providing telecommunications services in connection with a SIM Card purchased through the Store, particularly within the territory of the United States of America.

h) EEA – the European Economic Area.

i) Cookie Policy – a separate document governing the use of cookies within the Store, available through the Store.

j) Program – the KartySIMUSA Loyalty Program operated in accordance with separate terms and conditions available in the Store.

k) Money-Back Guarantee – an additional service provided by the Seller under separate terms and conditions available in the Store.

§ 3. Data Controller and Contact Information The Controller of personal data is Karty SIM Kamiński spółka jawna, with its registered office in Warsaw, ul. Genewska 6, 03-963 Warsaw. The Controller may be contacted regarding all matters related to the processing of personal data:

a) in writing – at: ul. Genewska 6, 03-963 Warsaw, Poland;

b) electronically – at: kontakt@kartysimusa.pl;

c) through the communication channels indicated in the Store (chat, WhatsApp).

The Controller has not appointed a Data Protection Officer. Any matters concerning the processing of personal data may be directed to the Controller using the contact methods specified in section 2 above.

§ 4. Sources and Categories of Personal Data Processed Data obtained directly from the data subject. The Controller processes personal data provided directly by the data subject, particularly when creating an Account, placing an order, completing the Activation form, participating in the Program, submitting a complaint, or corresponding with the Store. Data concerning a User provided by a Customer. If the User of a SIM Card is a person other than the Customer, the User’s personal data may be provided to the Controller by the Customer solely to the extent necessary for SIM Card activation and technical support (e.g., first and last name, email address, phone number, device model, configuration data, and contact information during travel). By providing such data, the Customer undertakes to inform the User in advance about the processing principles set out in this Privacy Policy. Data obtained from the Operator. In connection with the performance of the agreement, the Controller receives from the Operator, with respect to the Customer’s SIM Card, information regarding the status of the SIM Card (active, inactive, suspended, expired), data package usage, and, for the purposes of complaint handling and fraud prevention, billing data (records of calls, messages, and data sessions). Automatically collected data. In connection with the use of the Store, the Controller also processes data collected automatically, including IP address, device identifier, browser and operating system information, Store activity data, and analytics event data, in accordance with the Cookie Policy. Categories of data. Depending on the purpose of processing, the Controller may process the following categories of personal data:

a) identification and contact data: first name, last name, email address, telephone number, delivery address and/or correspondence address;

b) Account-related data: login (email address), password (stored in encrypted form), login history, and Account activity history;

c) order-related data: order number, order contents, selected Package, Activation date, device model specified in the Activation form, order status, and correspondence related to the order;

d) payment data: information regarding the payment method and payment status, payment processor transaction identifier (the Controller does not process full payment card numbers);

e) SIM Card usage data obtained from the Operator: SIM Card status, data package usage, and billing data, to the extent and for the purposes specified in § 5;

f) data provided in complaints and Money-Back Guarantee claims: description of the circumstances, screenshots (including IMEI number, network settings, and location data), location data, and supporting documentation (e.g., airline emails, deportation confirmation);

g) Loyalty Program participation data: number and history of accrued Points and Złotówki, Status, Złotówki Transfers, use of a Referral Link or Referral Code, and anti-fraud verification data (verified email address and phone number, matching identifiers of the Referrer and Referred Person);

h) analytical, marketing, and technical data: data collected through cookies, as detailed in the Cookie Policy;

i) business-related data (for Customers who are not Consumers): company name, VAT identification number, REGON number, and contact person details.

§ 5. Processing of Personal Data The Controller of the personal data of Customers and Users is the Seller referred to in § 1 section 1 and § 3 section 1 of this Privacy Policy. The Customer’s personal data is processed for the following purposes:

a) providing services related to the sale and support of SIM Cards, including delivery of the SIM Card and Activation within the Operator’s network;

b) providing technical support and customer service before, during, and after the performance of the Service;

c) handling Customer inquiries and complaints, including claims submitted under the Money-Back Guarantee service;

d) operating the KartySIMUSA Loyalty Program, including the Referral Program and Złotówki Transfers;

e) organizing promotional campaigns conducted through the Store;

f) conducting direct marketing activities relating to the Controller’s products and services, including sending newsletters (where the Customer has provided separate consent);

g) conducting analytics and statistical analysis of traffic within the Store and optimizing its operation;

h) fulfilling legal obligations imposed by law, in particular tax, accounting, and consumer complaint-handling obligations;

i) establishing, pursuing, and defending legal claims, as well as preventing fraud and abuse.

In connection with providing technical support, the Controller may obtain access from the Operator to operational data relating to the Customer’s telecommunications services, in particular information concerning the status and active services of the SIM Card, data package usage, and billing information, solely to the extent necessary for customer support, technical assistance, and complaint handling. The legal basis for processing personal data is:

a) Article 6(1)(a) GDPR – the consent of the data subject, with respect to electronic marketing, including newsletter distribution, and the use of analytical and marketing cookies;

b) Article 6(1)(b) GDPR – performance of a contract or taking steps prior to entering into a contract, with respect to fulfilling sales agreements, maintaining an Account, providing customer service, and participation in the Loyalty Program;

c) Article 6(1)(c) GDPR – compliance with legal obligations to which the Controller is subject, particularly tax, accounting, and consumer complaint-handling obligations;

d) Article 6(1)(f) GDPR – the Controller’s legitimate interests, including in particular ensuring proper customer service and technical support, establishing and defending claims, conducting direct marketing, preventing fraud and abuse, and verifying compliance with the terms of participation in the Loyalty Program (including the Referral Program).

Personal data is processed for the period necessary to achieve the purposes for which it was collected, in particular:

a) data related to an agreement – for the duration of the agreement and for the period required for the limitation of claims arising from that agreement;

b) Account-related data – until the Account is deleted and, following deletion, for the applicable limitation period for claims;

c) data processed for accounting and tax purposes – for the period required by law, in particular 5 years from the end of the calendar year in which the tax payment deadline expired;

d) data processed on the basis of consent – until consent is withdrawn;

e) data processed on the basis of the Controller’s legitimate interests – until a valid objection is submitted or the purpose of processing ceases to exist;

f) data processed within the Loyalty Program – for the duration of participation in the Program and for 3 years following its termination, in accordance with the Program Terms and Conditions.

The Customer has the right to access personal data, rectify personal data, erase personal data, restrict processing, data portability, object to processing, and withdraw consent in accordance with applicable GDPR provisions. Detailed rules governing the exercise of these rights are specified in § 10 of this Privacy Policy.

§ 6. Data of Users Who Are Not Customers Where the User of a SIM Card is a person other than the Customer, the User’s personal data is processed for the purpose of performing the agreement concluded by the Customer, pursuant to Article 6(1)(b) GDPR, and for purposes arising from the Controller’s legitimate interests pursuant to Article 6(1)(f) GDPR, particularly with respect to SIM Card technical support, complaint handling, processing requests under the Money-Back Guarantee service, and preventing fraud and abuse. By providing the User’s personal data to the Controller, the Customer represents that they are authorized to do so and undertakes to provide the User with the information referred to in this Privacy Policy before the User begins using the SIM Card. The User is entitled to all rights described in § 10 with respect to the Controller. Such rights may be exercised in accordance with the rules specified therein, regardless of the legal relationship between the User and the Customer. User data obtained from the Customer is processed solely to the extent necessary for the performance of the agreement and the provision of services related to the SIM Card.

§ 7. Recipients of Personal Data Personal data may be disclosed to entities cooperating with the Controller and entrusted with the processing of personal data to the extent necessary for providing services to the Controller, including in particular:

a) the telecommunications Operator – a foreign operator (particularly one based in the United States of America), for the purposes of SIM Card activation, provision of telecommunications services, SIM Card deactivation, verification of status and billing information, and complaint handling; this cooperation may also involve the transfer of personal data outside the EEA (see § 8);

b) payment service providers – entities processing electronic payments for the purpose of settling orders;

c) carriers and logistics providers – courier companies, postal operators, and parcel locker providers for the purpose of delivering SIM Cards;

d) IT service providers – hosting providers, software providers (including the Store platform), email service providers, chat providers (e.g., Crisp Chat), analytics providers (e.g., Google Analytics), and marketing service providers (e.g., Google Ads and Meta), to the extent specified in the Cookie Policy;

e) accounting firms and auditors – for bookkeeping and compliance with the Controller’s statutory financial obligations;

f) law firms and professional advisors – to the extent necessary for establishing, pursuing, or defending legal claims and obtaining legal advice;

g) public authorities, courts, law enforcement agencies, and other entities authorized under applicable law – to the extent required by applicable legal provisions.

The Controller entrusts personal data processing to the entities referred to above only on the basis of data processing agreements that comply with Article 28 GDPR, unless a given entity acts as an independent controller or as a recipient authorized to receive data under applicable law. Mobile information and SMS consent data. Telephone numbers and information regarding consent to receive SMS messages (opt-in data) are not sold or shared with third parties or affiliated entities for marketing or promotional purposes. Such data may only be disclosed to processors acting on behalf of the Controller to the extent necessary to provide services and deliver messages (including communication platform providers, SMS aggregators, and customer support providers), who are not authorized to use such data for their own purposes. The disclosures referred to in section 1 do not include SMS consent (opt-in) data, which is never shared with third parties for marketing or promotional purposes. In accordance with telecommunications carrier requirements and industry standards governing SMS communications (A2P 10DLC and CTIA), the following statement applies:

"No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties."

§ 8. Transfers of Personal Data Outside the European Economic Area Necessity of transfer. Due to the nature of the services provided—namely acting as an intermediary in the sale and activation of telecommunications services offered by foreign telecommunications operators, particularly those based in the United States of America—the processing of personal data may involve transfers to third countries outside the EEA. Scope of transfer. Data transferred to the Operator includes information necessary for SIM Card activation and provision of telecommunications services, particularly SIM Card technical information, device model, IMEI number, Activation date, and other information required by the Operator within its operational processes. Transfer mechanisms. Transfers of personal data outside the EEA are carried out using one of the mechanisms provided for in Chapter V GDPR, including in particular:

a) an adequacy decision adopted by the European Commission pursuant to Article 45 GDPR, where applicable to the recipient (for example, where a U.S. recipient participates in the EU-U.S. Data Privacy Framework);

b) Standard Contractual Clauses approved by the European Commission pursuant to Article 46(2)(c) GDPR, together with additional technical and organizational safeguards where necessary;

c) the derogation provided for in Article 49(1)(b) GDPR, where the transfer is necessary for the performance of a contract concluded with the data subject or for the implementation of pre-contractual measures taken at the data subject’s request, particularly in relation to activation of a SIM Card purchased through the Store;

d) the derogation provided for in Article 49(1)(c) GDPR, where the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject, particularly with respect to data relating to a User who is not the Customer.

Information regarding risks. The Customer and the User acknowledge that transferring personal data to the United States may involve risks arising from differences between the legal data protection systems of the European Union and the United States, particularly with respect to access to data by public authorities. Despite implementing the safeguards described above, the Controller may not always be able to eliminate such risks entirely. Data subjects may obtain a copy of the safeguards applied by contacting the Controller at the email address specified in § 3 section 2. Other transfers. Personal data may also be transferred outside the EEA in connection with the use of IT service providers established outside the EEA (e.g., Google LLC and Meta Platforms Inc.), in accordance with the Cookie Policy.

§ 9. Profiling and Automated Decision-Making Personal data may be subject to profiling within the meaning of Article 4(4) GDPR, particularly for marketing, analytical, and fraud prevention purposes (e.g., analysis of referral patterns within the Referral Program and analysis of claim histories submitted under the Money-Back Guarantee service). Profiling is carried out in accordance with GDPR principles. Decisions affecting the situation of a Customer or User (including decisions regarding the refusal of a refund, cancellation of Złotówki, suspension of a Referral Program reward, or refusal to process a Złotówki Transfer) are always made by a human, taking into account the results of automated analysis. The Controller does not make decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect the data subject within the meaning of Article 22 GDPR.

§ 10. Rights of Data Subjects Data subjects are entitled to the following rights:

a) Right of access (Article 15 GDPR) – to obtain confirmation from the Controller as to whether personal data concerning them is being processed and, where that is the case, access to such data and information regarding its processing, as well as a copy of the data;

b) Right to rectification (Article 16 GDPR) – to request the prompt correction of inaccurate personal data and completion of incomplete personal data;

c) Right to erasure (Article 17 GDPR, the “right to be forgotten”) – to request the prompt deletion of personal data in circumstances specified by the GDPR; this right does not apply where processing is necessary for compliance with a legal obligation, for the establishment, exercise, or defense of legal claims, or for other reasons specified in Article 17(3) GDPR;

d) Right to restriction of processing (Article 18 GDPR) – to request restriction of processing in circumstances specified by the GDPR;

e) Right to data portability (Article 20 GDPR) – with respect to data processed by automated means based on consent or a contract, to receive personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller;

f) Right to object (Article 21 GDPR) – to object at any time to processing based on Article 6(1)(f) GDPR; objections to direct marketing are unconditional;

g) Right to withdraw consent (Article 7(3) GDPR) – where processing is based on consent, to withdraw consent at any time without affecting the lawfulness of processing carried out prior to such withdrawal;

h) Right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, if the data subject believes that the processing of personal data violates the GDPR.

To exercise the rights listed above, the data subject should contact the Controller using the contact details specified in § 3 section 2. The Controller shall provide information regarding actions taken without undue delay and no later than one month after receipt of the request. This period may be extended by an additional two months where necessary due to the complexity or number of requests. In such cases, the data subject will be informed of the extension within one month of receipt of the request, together with the reasons for the delay. The exercise of certain rights may require prior verification of the identity of the data subject in order to prevent disclosure of personal data to unauthorized persons.

§ 11. Cookies The Store uses cookies and similar technologies that enable information to be stored on, or accessed from, the end device of a person using the Store. Detailed rules regarding the use of cookies, including the types of cookies used, their purposes, legal bases, storage periods, and procedures for granting and withdrawing consent, are set out in the Cookie Policy available in the Store. Analytical and marketing cookies are used only after obtaining the consent of the person using the Store through the cookie banner. Consent may be withdrawn at any time using the “Change Cookie Settings” functionality available in the Store or through the settings of the user's web browser.

§ 12. Data Security The Controller implements technical and organizational measures designed to ensure the protection of personal data appropriate to the risks involved and the categories of data protected. In particular, the Controller safeguards personal data against unauthorized disclosure, loss, damage, destruction, or unauthorized modification. Despite the safeguards implemented, the use of the Internet involves risks inherent in the nature of a public communications network. Customers are required to keep their Account passwords confidential and prevent unauthorized persons from accessing their Accounts.

§ 13. Amendments to the Privacy Policy The Controller reserves the right to amend this Privacy Policy, particularly in the event of changes in applicable laws, changes to the Store’s functionality, changes to the scope or conditions of services provided, changes affecting data recipients or Operators, or for the purpose of enhancing personal data protection. The date of the most recent update of the Privacy Policy is indicated at the beginning of this document. Amendments to the Privacy Policy shall not limit rights acquired by data subjects under previous versions of the Privacy Policy.

§ 14. Final Provisions Matters not regulated by this Privacy Policy shall be governed by the GDPR, the Polish Personal Data Protection Act of 10 May 2018, the Act of 18 July 2002 on the Provision of Electronic Services, the Act of 12 July 2024 – Electronic Communications Law, and other generally applicable laws. In the event of any inconsistency between this Privacy Policy and the Cookie Policy, the provisions of the Cookie Policy shall prevail with respect to matters governed by the Cookie Policy. Any correspondence relating to the processing of personal data should be addressed to:

Karty SIM Kamiński spółka jawna ul. Genewska 6 03-963 Warsaw Poland

or by email to:

kontakt@kartysimusa.pl

This Privacy Policy shall enter into force on 15 May 2026.

Logo Karty SIMUSA+48 720 746 746Whatsapp iconContact via WhatsAppMessenger iconContact via Messenger

KARTY SIM KAMIŃSKI spółka jawna

ul. Genewska 6,

03-963 Warszawa

NIP: 1133131078

ShopAbout UsHelpBlogMy SIM cardReturns & withdrawal
facebookinstagramtiktok
Payment options:
Przelewy 24
BLIK
Visa
Mastercard
Google Pay
Delivery options:
InPost Paczkomat 24/7
InPost Kurier
Odbiór osobisty - map icon

Personal pickup

ul. Genewska 6, 03-963 Warszawa

Monday - Friday 9.00-17.00

©2026 Karty SIMUSA

Privacy policyStatute