Privacy policy
Last updated September 30, 2026

Who is responsible
LuKas Holdings sp. z o.o.
ul. Stefana Batorego 18/108, 02-591 Warsaw, Poland
KRS 0001233010 · EU VAT ID PL7011306806
This policy explains what personal data we collect when you visit localsimsouthafrica.com, why, who receives it and what you can ask of us. We are a Polish company, so we handle personal data under the EU General Data Protection Regulation (GDPR).
1. Who we are
localsimsouthafrica.com is run by LuKas Holdings sp. z o.o., the address in the seller block on this page (“Local SIM South Africa”, “we”, “us”). We are the controller of the personal data described here. Write to contact@localsimsouthafrica.com with any question, request or complaint about personal data.
2. What we collect
When you visit. Your browser sends technical data with every request: IP address, browser and device type, the page asked for and the page you came from. Cloudflare, which delivers our pages, uses it to deliver them and to protect the site from attacks.
When you accept analytics cookies. The pages you view, the site and campaign that brought you, the plans you select, your browser and device type, an approximate location worked out from your IP address, and a random visitor id kept in a cookie. We measure this with Umami, which we run on our own server: no analytics company receives it, and Umami does not store your IP address. Nothing is collected for this if you switch analytics off, and your browser’s Global Privacy Control signal counts as a refusal.
When you accept marketing cookies. Only once we use Meta’s tools: the Meta Pixel loads in your browser and, together with our server (Meta’s Conversions API), tells Meta Platforms Ireland Limited which pages you view and which plans you select, with your IP address, your browser and device type, the Meta cookies in section 7, and the ad click id when you came from a Facebook or Instagram ad. Meta uses this to measure and improve our ads, and may link it to your Meta account if you have one. Nothing is sent to Meta if you switch marketing off, and Global Privacy Control counts as a refusal.
When you choose a plan. This site takes no orders. A plan’s button opens it on baobabsim.com, the same company’s store for Africa and the Middle East, where you pay and where your order is kept under that store’s own privacy policy. The link carries the plan, the words that say which of our links you used, and, if you came from an ad, its click id; nothing else about you.
When you write to us. Your email address, name and the content of your message.
3. Why we use it and on what legal basis
| Purpose | Legal basis under the GDPR |
|---|---|
| Delivering the pages and protecting the site | Our legitimate interest in a working, secure site (Article 6(1)(f)) |
| Answering your messages | Our legitimate interest in answering you (Article 6(1)(f)) |
| Measuring how the site is used and which pages and channels bring visitors | Your consent, given in the cookie banner (Article 6(1)(a)) |
| Measuring and improving our ads on Facebook and Instagram | Your consent to marketing cookies (Article 6(1)(a)) |
You can withdraw a consent at any time with Cookie settings at the bottom of every page. We do not send marketing messages and we do not sell personal data.
4. Who receives it
- Cloudflare, Inc. delivers and protects the website.
- Meta Platforms Ireland Limited (Meta Pixel and Conversions API) receives the marketing data in section 2, only if you accept marketing cookies. We and Meta are jointly responsible for collecting that data and passing it to Meta; what Meta then does with it is governed by Meta’s Privacy Policy at facebook.com/privacy/policy.
- Our hosting company runs the server that hosts our Umami.
- BaobabSIM, the company’s store for Africa and the Middle East, receives nothing from this site except the link you follow to it.
- Our accountants and legal advisers, and public authorities where the law requires it.
5. Transfers outside the European Economic Area
Cloudflare and Meta may process data in the United States and other countries. When personal data leaves the European Economic Area, we rely on the safeguards the GDPR provides: the European Commission’s standard contractual clauses, or its adequacy decision for companies certified under the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards that apply.
6. How long we keep it
- Analytics data: no longer than 14 months.
- Messages you send us: as long as needed to handle the matter, and no longer than 3 years after it is closed.
- Data received by Meta: as set out in Meta’s Privacy Policy.
7. Cookies and browser storage
We ask for your consent before we set any analytics or marketing cookie.
| Cookie | Purpose | Kept for |
|---|---|---|
| lsm_consent | Remembers whether you allowed analytics cookies | 180 days |
| lsm_ads | Remembers whether you allowed marketing cookies | 180 days |
| _lsm_id | A random visitor id, set only after you allow analytics, to count visits | 400 days |
| _lsm_sid | The current visit, set only after you allow analytics | 400 days; a visit ends after 30 minutes without activity |
| _fbp | Meta Pixel browser id, set only after you allow marketing | 90 days |
| _fbc | The click id of a Facebook or Instagram ad that brought you, set only after you allow marketing | 90 days |
Switching a category off in Cookie settings deletes its cookies. Cloudflare may set strictly necessary security cookies to tell people from automated traffic.
Your browser also keeps, only for itself: the language you picked (lsm-locale) and whether you turned down our offer of a page in your language (lsm-language-hint), in local storage; and, while the tab is open, the click id of an ad that brought you (lsm-click-ids), in session storage, so the link to checkout can carry it. None of these leaves your browser except that click id in the checkout link.
8. Your rights
Under the GDPR you can ask us for access to your data and a copy of it, to correct it, to delete it, to restrict its use or to receive it in a portable format, and you can object to uses based on our legitimate interests. You can withdraw a consent at any time, without affecting what was done before. We reply within one month.
You can complain to the President of the Personal Data Protection Office in Poland (UODO, uodo.gov.pl), or to the data protection authority of the EU country where you live or work. If you are in South Africa, the Protection of Personal Information Act (POPIA) gives you rights of access, correction and deletion, and you can complain to the Information Regulator at inforegulator.org.za. If you are in the United Kingdom, the UK GDPR gives you the same rights as above.
9. Security and children
The site is served only over HTTPS and keeps no order or payment data. Please never send a real eSIM QR code in a chat or on social media; send the link to your order page instead. localsimsouthafrica.com is not aimed at children under 16, and we do not knowingly collect their data.
10. Changes
When our processing changes, we update this policy and the date at the top of the page. The English privacy policy is the binding text.
Get your eSIM for South Africa
Plans from US$8.99, tax included. Pick one here and pay on the store in US dollars.
See the plansCheckout on BaobabSIM · full refund if it does not work