Skip to content
Satello
Destinations How it works Cards Proof Token Help My eSIMs Follow us on X

Privacy policy

Privacy Policy – version of 4 October 2026.

This policy explains what personal data Satello processes, why, for how long, who it's shared with and how to exercise your rights. It covers the satello.io website and eSIM plan orders. We collect as little as we can: an email address to deliver your eSIM, but no account, no ID document and no bank card.

1. Controller

The controller is Satello, the trading name of a French sole trader (entrepreneur individuel). For any question about your data, write to us through our support page at satello.io/support. No data protection officer has been appointed, as this isn't required for our activity.

2. The data we process

CategoryData
Wallet and blockchainThe public address of the wallet you connect; your payment, refund and reclaim transactions (transaction ID, amount, date); your $SATELLO balance, read on the blockchain to decide which Satello card discount applies.
OrderOrder number, plan, destination, price and its breakdown, quote, status, dates; your request for immediate delivery, your acknowledgement that you lose the right of withdrawal on delivery and your acceptance of the Terms, with timestamps; the Cryptorefills order reference and status; your cancellation request, if any.
eSIMThe eSIM details Cryptorefills returns for your order: QR code, activation code, installation links and, when provided, the ICCID (the eSIM's serial number). We don't receive or track your data usage.
ContactThe email address you give at checkout; the content of your messages to support; your first and last name if you provide them (for example in a withdrawal statement).
Technical dataIP address, approximate country derived from the IP address, browser and system type, date and time of requests (server logs).
Compatibility checkerThe device model you select or that your browser reports, if you use this tool.

We don't collect ID documents, bank card details or precise location. Satello doesn't see the content of your internet traffic or the sites you visit with the eSIM.

3. Why we process it and on what legal basis

PurposeLegal basis (GDPR)
Preparing your quote, checking your payment, placing your order with Cryptorefills in your name, delivering the eSIM, helping you install it, handling refunds, cancellations and complaints.Performance of the contract, or steps taken at your request before entering into it (art. 6(1)(b)).
Applying your Satello card discount by reading your $SATELLO balance; answering your compatibility question.Steps taken at your request before entering into a contract (art. 6(1)(b)).
Keeping our accounts, documenting the place of supply for VAT, keeping contracts concluded electronically, answering requests from authorities, complying with international sanctions.Legal obligations (art. 6(1)(c)), including article L123-22 of the French Commercial Code and article L213-1 of the Consumer Code.
Keeping the site secure, preventing fraud and abuse, enforcing fair use of the plans.Our legitimate interest in protecting the service, our customers and our business (art. 6(1)(f)).
Establishing, exercising or defending legal claims.Legitimate interest (art. 6(1)(f)).
Sending you marketing information.Only with your consent (art. 6(1)(a)), which you can withdraw at any time. By default we send none.

We need an email address to place your order: Cryptorefills issues the eSIM in your name and sends it to that address. We use it only to place your order with Cryptorefills and to deliver your eSIM. Your wallet address and order details are also needed to conclude and perform the contract: without them we can't take your order.

If an automated security check blocks an order, you can ask for a person to review it. We don't take any decision producing legal effects about you based solely on automated processing.

4. What you should know about the blockchain

Payments go through Robinhood Chain, a public blockchain. Your wallet address and the amount and date of your transactions are published there by your own wallet and become visible to anyone, permanently. Neither Satello nor anyone else can change or erase them. We don't publish on the blockchain any data that links your wallet to your email address, your eSIM or your destination.

Your wallet (for example MetaMask or Phantom) is third-party software that processes your data under its own privacy policy.

5. Who receives your data

Only the operator of Satello has access to your data. We use the following providers:

RecipientRoleLocation and safeguards
Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USAHosting of the site and server functions, technical logs (processor).United States; Vercel is certified under the EU–US Data Privacy Framework and has signed standard contractual clauses.
ChiselStrike Inc. (Turso), 2093 Philadelphia Pike #6336, Claymont, DE 19703, USAOrder database (processor).Data stored in the AWS us-east-1 region (United States); US company; European Commission standard contractual clauses.
Cryptorefills (cryptorefills.com)Issuing your eSIM and sending it to you. We place the order in your name and send Cryptorefills only your email address and the plan ordered; we receive back the eSIM details. We don't send it your wallet address or IP address. Cryptorefills acts as a separate controller for its own order, under its own privacy policy.As described in Cryptorefills' privacy policy. Where it processes your data outside the European Union, the transfer is necessary to perform the contract you asked us to carry out (article 49(1)(b) GDPR).
Partner mobile networksWhen you use the eSIM, the eSIM issuer and the networks in the country you're in process, as separate controllers, the technical data needed to carry your traffic (for example which network the eSIM is attached to).The countries you travel to; this transfer is necessary to perform the contract you concluded (article 49(1)(b) GDPR).
Robinhood Chain access nodes (RPC)Reading the blockchain from our server (balances, payments, confirmations). These requests contain wallet addresses but come from our server, not from your browser.Operators of the Robinhood Chain network.

We may also share data with our accountant, or with administrative and judicial authorities where the law requires it. We don't sell or rent your data, and we don't use it for advertising.

6. Transfers outside the European Union

Some providers are located outside the European Union (United States). These transfers rely on the EU–US Data Privacy Framework for certified companies and, otherwise, on the standard contractual clauses adopted by the European Commission. You can get a copy of these safeguards by writing to us through our support page at satello.io/support. Where Cryptorefills processes your email address outside the European Union, that transfer is necessary to perform the contract you asked us to carry out (article 49(1)(b) GDPR). When you travel, the connection data handled by local networks is processed in the country you're in, which is necessary to perform your contract.

7. How long we keep it

DataPeriod
Orders, payments, refunds, ICCID, approximate country kept as tax evidence, requests for immediate delivery, cancellation requests10 years from the order (accounting and tax obligations, keeping contracts concluded electronically).
Activation code, installation links and QR codeUp to 12 months after the order (support and complaints), then deleted.
Email address3 years after your last order or last contact, unless you ask us to delete it sooner; the order record is then kept without it. Cryptorefills keeps its own copy under its own policy.
Support messages3 years from the last exchange.
Technical logs (IP address, browser, requests)12 months.
Device model entered in the compatibility checkerNot kept beyond your visit; we may keep anonymous statistics.
Your browser's local storageOn your device, until you clear it.

Transactions published on the blockchain stay there permanently, independently of us.

8. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and the right to object to processing based on our legitimate interest, as well as the right to withdraw your consent at any time. Under French law you can also give instructions on what happens to your data after your death (article 85 of Law No. 78-17 of 6 January 1978).

To exercise these rights, write to us through our support page at satello.io/support, quoting your order number or wallet address. To check that a wallet address is yours, we may ask you to sign a message with your wallet; signing is free and doesn't trigger any transaction. We answer within one month, which can be extended by two months for complex requests; we'd let you know.

Some rights have limits: we can't erase data the law requires us to keep for as long as that obligation lasts, nor transactions recorded on the public blockchain.

9. Complaints to the CNIL

If you believe your rights aren't being respected, you can lodge a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés (CNIL), Service des plaintes, 3 place de Fontenoy, 75007 Paris, France, or online at www.cnil.fr/fr/plaintes. If you live in another EU country, you can also contact that country's data protection authority.

10. Cookies and local storage

Satello uses no advertising or audience-measurement cookies. We only use your browser's local storage for what is strictly necessary for the service you ask for: your wallet connection, your cart and current order, the email address you entered at checkout (so you don't have to type it again), and your display language and currency. Because this storage is exempt from consent (article 82 of Law No. 78-17 of 6 January 1978), no banner is shown. See our cookie note.

11. Security

Traffic to and from the site is encrypted (HTTPS), access to data is limited to the operator, and our providers are bound by security and confidentiality obligations. If a data breach puts you at risk, we'll notify the CNIL and, where the risk is high, inform you, as the GDPR requires.

12. Minors

The service is only for people aged 18 or over. We don't knowingly collect data about minors.

13. Changes

We may update this policy, for example if we change providers. The date of the latest version is shown at the top of the page. If we make a significant change, we'll say so visibly on the site.