Who is responsible for your data
Tsernskin keiys OÜ, a private limited company registered in Estonia under registry code 17587191, with its registered address at P. Kerese tn 17-20, 20309 Narva, Ida-Viru maakond, Estonia, runs MUSTER (the website at muster.boutique) and is the controller of the personal data described here. Write to us on the contact form about anything in this policy. We answer requests about your data in writing.
This policy covers two groups of people: organisers, who open an account and buy eSIMs for a group, and travellers, whose names and email addresses an organiser adds to a roster. It also covers people who use ourcontact form and people who apply to join the coordinator desk.
If you are a traveller, the organiser of your trip gave us your details. They are responsible for having your permission to do so. You can still exercise every right in this policy directly with us.
What we collect
| Data | Whose | Where it comes from |
|---|---|---|
| Name, email address, organisation name (optional), country of residence or establishment, a one-way hash of the password, date you accepted the terms, last sign-in time | Organisers | The sign-up form and Settings |
| Trips: name, type, dates, countries, chosen data plan | Organisers | The console |
| Rosters: traveller name, email address, group label (for example "Year 10" or "Camera dept") | Travellers | The organiser, typed or uploaded as a CSV file |
| eSIM identifiers: ICCID, activation code, the private install-page link, when the link was first opened and when it was emailed | Travellers | Created when the eSIM is issued |
| Network state: whether the eSIM has been downloaded or installed, whether it is in use, data used, expiry | Travellers | The mobile network operator that supplies the eSIM profiles |
| Ledger and payment records: amounts, dates, status, our payment reference, whether a transaction was a test. Never the full card number or security code | Organisers | Credit purchases, runs and bookings |
| Coordinator bookings: slot, type, trip, notes you write for the coordinator, cancellation and refund | Organisers | The console |
| Contact messages: name, email, topic, message | Anyone who writes to us | The contact form |
| Coordinator applications: name, email, country of residence, timezone, languages, regions, experience and availability answers, bank details for payouts (account holder, IBAN, BIC, bank country), a copy of a government ID, a CV if the applicant chooses to attach one, date the coordinator terms were accepted | Applicants | The application form |
| Coordinator work and payouts: bookings assigned, earnings, withdrawal requests and the bank transfer reference | Coordinators | The coordinator console and the desk |
| Security logs: IP address, browser type, time of requests and errors | Everyone using the site | Our servers |
We do not ask for passport numbers, dates of birth, home addresses or phone numbers of travellers, and a roster file with extra columns is read only for the name, email and group columns. Please do not put sensitive information, such as health details, in group labels or booking notes.
When you top up your trip budget, you type your card details into the payment form. They go to our card processor to take the payment. We keep only the result and a reference.
Why we use it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Opening and running your organiser account, signing you in | Contract with the organiser |
| Ordering an eSIM for each traveller, creating their install page and emailing them the link | Contract with the organiser; our legitimate interest in delivering the eSIM the organiser bought to the person it is for |
| Showing install and usage state on the install board | Contract with the organiser; legitimate interest in helping travellers get connected before they travel |
| Taking top-up payments, charging runs and bookings, crediting back refused eSIMs, refunds | Contract; legal obligation to keep financial records |
| Arranging coordinator bookings and sharing the trip details the coordinator needs | Contract with the organiser |
| Answering contact messages and reviewing coordinator applications | Legitimate interest in answering the people who write to us; steps before a contract for applicants |
| Refusing sign-ups from sanctioned jurisdictions | Legal obligation |
| Keeping the service secure, preventing fraud and abuse, fixing errors | Legitimate interest |
| Remembering your display currency beyond this browser session | Consent, which you can withdraw at any time |
We do not sell personal data, we do not use rosters for marketing, and we do not email travellers anything except their install link. We send organisers service emails about their account, runs, credit purchases and bookings. We make no automated decisions that have legal or similarly significant effects on anyone.
Who receives it
We share personal data only with the categories of recipient below, and only what each one needs:
- The mobile network operator that supplies the eSIM profiles receives an order reference for each eSIM. It returns the ICCID, activation code and the network state we show on the install board. We do not send it traveller names or email addresses.
- Our card processor receives the card details you type, the amount and your email address in order to take a payment and run 3-D Secure checks with your bank.
- Our hosting and database providers store and run the service on our instructions.
- Our email delivery service sends account emails and install links on our instructions.
- Connectivity coordinators you book see your name, the trip and the notes you add to the booking. They must keep them confidential and delete them when the booking ends.
- Authorities and advisers where the law requires it, or to protect people from fraud or harm, and our professional advisers under a duty of confidence.
All of our service providers act under written contracts that limit their use of the data to providing their service to us.
If you are the organiser: sharing a roster
When you add travellers, you decide whose details go on the roster and why. For the traveller data you upload, you and we each have responsibilities:
- Only add people who are travelling with the group, and only the name, email address and a short group label.
- Tell your travellers, or their parents or guardians, that you are using MUSTER to issue their eSIM and point them to this policy.
- Keep roster files you download or upload somewhere safe, and delete them when the trip is over.
- Remove a traveller from the roster if they leave the trip before their eSIM is issued. We then delete their details from the roster.
We use traveller details only to issue and deliver eSIMs and show the install board to you. We do not contact travellers for any other reason, and we do not let one organiser see another organiser's rosters.
Emails we send
We send a small number of emails, all connected to the service:
- To organisers: a welcome email when the account opens, password reset links you ask for, and messages about credit purchases, coordinator bookings and replies to your questions.
- To travellers: one email with the link to their own install page, sent when their eSIM is issued and our email service is available, and again only if the organiser asks us to resend it.
- To applicants and people who contact us: our reply.
We do not send newsletters or promotional emails, and we do not add anyone to a mailing list. If an email you receive from MUSTER seems wrong, for example an install link for a trip you are not on, write to us on the contact form and we will remove your details.
Transfers outside the EEA
Some of our providers process data outside the European Economic Area, and the mobile network operator that supplies the eSIM profiles may process order references in other countries. Where data leaves the EEA to a country without an adequacy decision, we rely on the European Commission's standard contractual clauses, with additional safeguards where needed. Write to us for a copy of the relevant safeguards.
How long we keep it
- Organiser account data while the account is open. When you close it, we delete it within 30 days, apart from what we must keep below.
- Ledger, payment and booking records for six years after the transaction, because the law requires us to keep financial records.
- Rosters, install links and eSIM data until 12 months after the trip's return date, or sooner when the organiser deletes the trip, removes a traveller or closes the account. The ICCID and order reference stay in the financial record for the charge, without the traveller's name or email.
- Contact messages for 24 months after the conversation ends.
- Coordinator applications for 12 months if unsuccessful; for successful applicants, for as long as they are on the desk and six years after. A copy of an applicant's government ID is kept in our database, never at a public link, and only desk staff can open it. An optional CV (PDF or Word) is kept the same way and for the same period as the rest of the application; it is used only to assess the application and is opened only by the desk staff who review applications.
- Security logs for up to 90 days, unless we need them to investigate an incident.
How we protect it
The site is served over encrypted connections only. Four controls are worth naming, each with the thing it is there to stop:
- Passwords are stored as one-way hashes. Nobody here can read your password, and a stolen database does not hand anyone your account.
- An unknown email and a wrong password fail with the same wording. The sign-in form cannot be used to find out who has an account.
- Signing out clears the session cookie on the server's response. A request still in flight cannot sign you back in after you have left.
- Password reset links work once, for an hour. A forwarded or forgotten reset email stops being a key.
Every traveller's install page sits behind a private address carrying a random 144-bit token. It cannot be guessed and it cannot be listed, and it shows that traveller's eSIM and nothing about anyone else on the roster. Treat the link like a key: anyone who opens it can install that eSIM. If one reaches the wrong person, tell us through the contact form before the eSIM is installed and we will replace it.
Every console request checks that the trip belongs to the signed-in organiser, so changing an id in the address bar does not open someone else's trip. Staff access to production data is limited to people who need it to run the service. We neither sell roster data nor use it for marketing. We hold no security certifications and claim none.
If a breach puts your rights at risk, we will tell you and the relevant authority as the law requires. If you have found a hole, write on the contact form with "Security" in the first line — security reports are answered before anything else in the queue.
Your rights
Under the EU General Data Protection Regulation and the Estonian Personal Data Protection Act you have the right to:
- Ask for a copy of the personal data we hold about you (access);
- Have inaccurate data corrected (rectification). Organisers can change their name and organisation in Settings;
- Have your data deleted (erasure), subject to the records we must keep;
- Ask us to restrict how we use your data while a question is resolved;
- Receive the data you gave us in a machine-readable format (portability);
- Object to uses based on our legitimate interests;
- Withdraw consent to optional cookies at any time, on the cookie policy page;
- Complain to a supervisory authority: our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee), and you can also complain to the data protection authority in the country where you live or work.
To use a right, write to us on the contact form, giving the email address we hold for you. A traveller should tell us the trip or organiser so that we can find the roster. We answer within one month. We may ask you to confirm your identity first. Please consider writing to us before complaining to an authority, so that we can try to put things right.
Travellers under 18
School trips and youth teams include travellers under 18. Organiser accounts are for adults only. When an organiser adds a traveller under 18, the organiser confirms that a parent or guardian has agreed to the traveller's name and email being shared with us for the eSIM. We use a young traveller's details only to issue and deliver their eSIM, and we apply the same retention and rights as for every traveller. A parent or guardian can exercise those rights on the child's behalf.
Changes to this policy
We update this policy when what we collect or how we use it changes. The date at the top shows the last update. If a change matters to how we use organisers' data, we publish it here with the new date before it takes effect, so this dated page is the notice. We also email account holders when we do.