Privacy Policy
Last updated: 6 May 2026
This Privacy Policy explains how Hubby B.V. (“Hubby”, “we”) handles personal data on the Hubby Agent Platform (the “Service”). It is written for agents and agency owners who use the Service. End-traveller eSIM users are covered by the separate consumer privacy notice on the main Hubby website.
Who we are
Hubby B.V. is the data controller for personal data processed in the Service. You can reach us at support@hubbyesim.com for any privacy question, including to exercise the rights described below.
What we collect
- Account information — name, email, password (hashed), country, preferred currency, optional avatar, optional phone number for WhatsApp linking.
- Agency relationships — the agency you belong to, your role (owner / agent / admin), referral links between agents.
- Transaction data — promo codes you generate, the bundles attached to them, customer reference text you optionally enter, redemption status, commission earned and payout history.
- Conversation history — if you use the WhatsApp bot, we store inbound and outbound messages on your linked session for support and product improvement.
- Operational data — rate-limit counters, login timestamps, error logs (which may include your account id and request metadata), email delivery status.
- Cookies — a single first-party session cookie (“hubby_session”) for authentication. We do not use third-party advertising or tracking cookies.
How we use it
- To operate the Service — authenticate you, generate codes, track commission.
- To pay out commission — we share necessary information with our payment partner for legitimate payment processing.
- To send transactional and onboarding emails (welcome, password reset, code-sharing confirmations, traveller follow-ups). You can unsubscribe from non-essential emails from the link in every message.
- To provide support — admins may review WhatsApp conversations flagged for review, and may add internal notes about an agent.
- To improve the Service — aggregate analytics and bug reports. We don’t sell personal data to anyone.
Legal bases (GDPR)
We rely on the following GDPR bases: contractual necessity (operating your account, paying commission), legitimate interest (fraud prevention, support, product improvement), and consent (optional communications). You can withdraw consent at any time without affecting prior processing.
Sharing with third parties
We share data only with vetted processors that help us run the Service: our database host, email-delivery provider (Resend), the Anthropic API for the WhatsApp bot’s help feature, and any future WhatsApp gateway. Each is bound by a Data Processing Agreement. We do not sell or rent personal data.
International transfers
Some processors are based outside the European Economic Area. When that’s the case we rely on the European Commission’s Standard Contractual Clauses or an equivalent approved transfer mechanism.
Data retention
Account and commission records are retained for the life of your account plus six years thereafter to satisfy bookkeeping obligations. Operational logs are retained for at most 30 days. WhatsApp conversation history is retained for 12 months unless you ask us to delete it sooner.
Your rights
Under the GDPR you have the right to:
- Access — request a copy of the personal data we hold.
- Rectification — correct anything that’s inaccurate.
- Erasure — ask us to delete your account and associated personal data, subject to bookkeeping obligations.
- Portability — receive your data in a machine-readable format.
- Restriction & objection — pause or object to certain processing.
- Complaint — lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe we’ve mishandled your data.
Security
Passwords are hashed with bcrypt; sessions use signed tokens; transport is TLS. Access to production data is restricted to engineers who need it. We don’t store API keys or payout credentials in plaintext.
Children
The Service is not intended for users under 18 and we do not knowingly collect data from children.
Changes to this policy
Material changes are announced via email or in-product notice at least 14 days before taking effect.
Contact
Questions or requests? support@hubbyesim.com.