Cardholder Authentication Data Storage Policy
Effective from: 13 July 2026
This Policy explains how cardholder payment and authentication data is processed and stored when paying by bank card in the eSIM Surfer application.
By initiating payment (pressing the 'Pay' button), the User acknowledges and accepts this Policy.
1. Payment service provider
Bank-card payments (including Apple Pay and Google Pay) are processed on the Provider's behalf by Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; 'Stripe'). Stripe is a payment service provider certified to the highest PCI-DSS Level 1 security standard set by card networks.
2. Data the Provider does NOT store
The Provider never has access to or stores the following data:
- the full card number (PAN);
- the card expiry date;
- the security code (CVC/CVV);
- authentication data generated during strong customer authentication (3D Secure).
The User enters this data directly on Stripe's secure payment interface; it is not transmitted to the Provider's servers.
3. Data stored by Stripe
If the User chooses to save their card details during payment, Stripe stores the cardholder's name, card number and expiry date ('stored card data', 'Credentials on File') in encrypted, tokenised form so that:
- the User does not need to re-enter card details for later purchases; and
- payments can be processed securely with strong customer authentication (SCA, 3D Secure) under the PSD2 Directive.
Stored card data is used solely for transactions initiated by the User. The Provider will not initiate a charge using stored card data without the User's separate, express consent.
4. Data stored by the Provider
In relation to payments, the Provider stores only data that cannot itself initiate a payment: the card's last four digits and type (masked card data), the token/customer identifier generated by Stripe, and the transaction ID, amount, currency, time and status. Details of processing this data are set out in the Privacy Policy.
5. Transaction confirmation
The User receives confirmation of a successful payment containing the transaction amount, currency, time and masked card data.
6. Deleting stored card data and withdrawing consent
The User may delete saved cards at any time in the application (on the payment screen), or request their deletion at support@esimsurfer.app. Deletion does not affect completed transactions.
7. Amendments to the Policy
The Provider will notify Users of amendments to this Policy at least 7 working days before the change takes effect.
Contact
Please contact us with any questions:
Email: support@esimsurfer.app
Provider: Derecskei Miklós egyéni vállalkozó
Address: 1039 Budapest, Jendrassik György utca 2., Magyarország
Related documents:
Last updated: 13 July 2026.
