AhlanetAhlanet
Welcome back
AhlanetAhlanet

Privacy policy

Understand the information we process, why we use it, who may receive it and how to exercise your rights or contact us.

Last updated:

This policy explains how Ahlanet handles personal information when you browse the website, create an account, buy an eSIM or contact support. It covers the platform's processing; payment services, sign-in providers and network operators also have responsibilities under their own privacy notices.

Who is responsible and how to contact us

The business operating Ahlanet is responsible for the account, order and support information it processes. The business and contact details available for this website appear below. Use the contact page or support email for privacy questions, including if you cannot sign in. State which information or request you want us to review.

Information you provide

  • Account details: name, email address, password stored as a hash, and language and currency preferences.
  • Optional profile details: photo, gender, country, city, telephone number, postal address and travel date, when you choose to add them.
  • Purchase details: selected plan, billing country, currency, amounts, payment references, order status and purchase history.
  • Support information: messages, screenshots and files you submit. Avoid sending unnecessary identity documents, full payment-card details or installation codes.

Technical and service information

We process session and security information such as IP addresses, sign-in activity, device/session identifiers and information needed to prevent misuse. For delivery and account management, we process eSIM identifiers, installation credentials, activation and expiry status, and usage information received from the provider. These service records are different from the content of your internet browsing; network operators process connection data as necessary to run their networks.

Why we use information

We use information to create and secure accounts, accept payment, deliver purchases, manage eSIMs, send service updates and resolve support requests. Where applicable, the legal bases are performing our contract with you, complying with legal obligations, and legitimate interests in security, fraud prevention and service administration, balanced against your rights. Optional activities that require consent rely on that consent; it can be withdrawn without affecting earlier lawful processing.

Payments and external sign-in

Payment-card details are entered on Stripe's payment page. Ahlanet stores order and transaction references, not full card numbers or card security codes. If you choose an available Google, Facebook or Microsoft sign-in option, we receive the identity and basic account details authorised for that connection, such as name and email. We do not receive the password for your external account. Those providers explain their own processing in their privacy policies.

Who receives information

Access is limited to people and service providers who need it for a defined purpose. Depending on the services enabled, recipients include hosting and email providers, Stripe for payment, eSIM suppliers such as eSimerge and network operators for delivery and service support, and notification providers for requested alerts. We may disclose relevant records when legally required or necessary to investigate fraud or protect rights. We do not sell account information to advertisers.

Cookies, preferences and notifications

The website uses a necessary session cookie for sign-in, security and session preferences. Your chosen appearance is stored locally in your browser until you clear or change it. Blocking necessary cookies can prevent sign-in or checkout. The supplied website does not include advertising or audience-tracking scripts. External payment or sign-in pages may use their own cookies. Account preferences control supported service alerts; changing them does not necessarily stop essential security, payment or account-recovery messages.

Processing across borders

The hosting location and the locations of payment, email and connectivity providers may mean information is processed outside your country. When a transfer is subject to data-protection restrictions, the legally required transfer basis and safeguards must apply. You can ask us which recipients and transfer arrangements are relevant to your data; the safeguards depend on the actual service and destination.

How long information is kept

Retention depends on the purpose: account details while needed to maintain the account; purchase records for delivery, accounting and lawful dispute handling; support records while needed to resolve and document the issue; and security records while needed to protect the service. Expired temporary credentials are removed through routine housekeeping. Closing an account does not automatically remove records that must lawfully be retained. We review deletion or anonymisation requests against these requirements and explain any necessary retention.

Keeping information secure

The platform uses password hashing, restricted account access and encryption for stored eSIM installation credentials. Secure connections protect information in transit when using the HTTPS website. These measures reduce risk but do not guarantee absolute security. Protect your password and QR code, sign out of shared devices, and report suspected unauthorised access promptly.

Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection or a portable copy of your data, and withdraw consent where processing relies on it. Profile settings let you edit details and download a summary of key account data; contact us for a fuller request. We may reasonably verify identity before disclosure. We respond within the applicable legal time limits and explain any refusal. You may complain to the competent data-protection authority without first completing an internal complaints process.

Children and policy changes

The service is intended for people with legal capacity to buy it, or use under appropriate adult responsibility where permitted. If a child's information has been provided without a valid basis, contact us for review. We update this policy when processing changes and use an appropriate notice for significant changes. The displayed update date helps you identify the current version.