Skybyte — a trading name of Banxs Technologies EOOD
Version 1.0
In short
Skybyte accepts Apple Pay and Google Pay only. There is no card form anywhere on this site, so your card number, expiry date and security code are never typed into, transmitted by, or stored on our systems. Your device wallet returns a single-use network token instead, and you approve each purchase on your own device with Face ID, Touch ID, a fingerprint or your screen lock. Every page of this site is served over TLS, and our card-data environment is scoped to PCI DSS SAQ A — the smallest possible scope for an e-commerce merchant.
1. Cardholder data environment
Skybyte operates a fully outsourced payment page model:
- Card number, expiry, and CVC are entered into fields rendered and controlled by our PCI DSS Level 1 certified payment service provider.
- Those values are transmitted directly from your browser to the provider. They do not traverse, and are not logged by, Skybyte application servers.
- Skybyte receives only a payment token, the card brand, the last four digits, the expiry month and year, the issuing country, and the authorisation result. That subset is what appears in your order record and in any refund we later process.
- The full Primary Account Number (PAN) is never written to our database, our logs, our error-tracking system, or our analytics.
Because of this design our annual validation obligation is SAQ A, the self-assessment questionnaire for merchants who have outsourced all cardholder-data functions to validated third parties. Our payment provider's Attestation of Compliance is on file and is reviewed at each renewal.
2. Encryption in transit and at rest
- All traffic to
skybytesim.comandwww.skybytesim.comis served over TLS 1.2 or higher; HTTP requests are redirected to HTTPS and HSTS is enabled. - A Content Security Policy restricts which origins may execute script or receive form submissions, with violation reporting enabled.
- Data at rest — orders, eSIM records, invoices, support tickets — is stored in an encrypted managed database in the European Union.
- Backups are encrypted and retained in line with the retention schedule set out in the Privacy Policy.
3. Strong Customer Authentication and 3-D Secure 2
Because every purchase is authorised through Apple Pay or Google Pay, the cardholder is authenticated on the device itself before the payment reaches the acquirer. Wallet payments carry the scheme's own authentication data and liability shift, and satisfy the Strong Customer Authentication requirement of Article 97 of Directive (EU) 2015/2366 (PSD2) for transactions inside the European Economic Area. Where your issuer additionally requires a step-up, your wallet or banking app prompts you before the payment is authorised.
Skybyte does not apply exemptions that would bypass authentication. Every purchase is a separate, customer-initiated transaction authenticated with 3-D Secure 2. Skybyte does not store credential-on-file mandates for merchant-initiated transactions, because there are no subscriptions, renewals or recurring charges.
4. Fraud prevention
We operate proportionate, automated fraud controls: velocity limits per device token, per email, and per IP address; issuing-country checks; the authentication and risk results returned by the wallet and the issuer; and manual review of orders flagged by those controls. Declined or reviewed orders never result in an eSIM being issued.
These controls are automated but they do not produce legal effects for you within the meaning of Article 22 GDPR: a blocked order can always be reviewed by a human on request to support@skybytesim.com.
5. Card brand acceptance
Skybyte accepts payment only through Apple Pay and Google Pay. Any Visa or Mastercard credit or debit card held in your device wallet can be used. We do not accept typed card details, bank transfers, American Express, Discover, JCB, UnionPay, or Diners Club. Acceptance marks are displayed at checkout and in the site footer, reproduced in accordance with each scheme's brand-mark rules and without alteration to their proportions or colours.
Card brand marks are the property of their respective owners. Their display indicates acceptance only and does not imply sponsorship or endorsement of Skybyte.
6. Merchant descriptor
Charges appear on your statement as SKYBYTE BANXS BG, followed by the customer service contact where your issuer's statement format allows it. If you do not recognise a charge, please check that descriptor against your order history before contacting your bank — recognising your own transaction is faster than a dispute, and it avoids an unnecessary chargeback.
7. Your responsibilities
Keep your Skybyte account password unique and confidential, keep the email address on your account current, and tell us immediately at support@skybytesim.com if you believe your account or your card has been compromised. We will never ask you for your card number, CVC, PIN, or password by email, chat, or telephone — we have no way to accept them at all. Any message that does is not from us.
8. Reporting a vulnerability
If you believe you have found a security vulnerability in our website or systems, email contact@banxs.com with enough detail to reproduce it. We acknowledge reports within three business days and will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us reasonable time to remediate before disclosure.
9. Incident notification
Where a personal-data breach is likely to result in a risk to your rights and freedoms, we notify the Bulgarian Commission for Personal Data Protection within 72 hours of becoming aware of it, and we notify affected customers without undue delay where the risk is high, as required by Articles 33 and 34 GDPR. Where a payment-data incident occurs, we additionally notify our acquiring institution, PayNovus AD (Bulgaria), and the affected card schemes in accordance with their incident-response rules.
10. Contact
Banxs Technologies EOOD, trading as Skybyte Blvd. Alexander Malinov 31, Sofia 1000, Bulgaria EIK 206285017 · VAT BG206285017
Security and vulnerability reports: contact@banxs.com
Payment and billing queries: support@skybytesim.com