Privacy Policy
Last updated: July 12, 2026
0xEsim ("we", "us", "the Service") sells data eSIMs paid for in cryptocurrency. We do not run identity checks (no KYC), we never ask for your name, address, or government ID during storefront checkout, and we never touch your bank card. If you contact us or use our Telegram bot, that channel may provide profile information as described below. This policy explains what data we collect, why we collect it, and who processes it on our behalf. We limit collection to operating and securing the Service, fulfilling and supporting orders, and measuring aggregate acquisition and conversion performance.
1. Data we collect
Depending on how you use the Service, we collect the following limited data:
- Email address (optional). If you choose email delivery, we use it to send your eSIM QR code and order-related notices and to look up your order later. We also receive your email address if you contact support by email. We do not use order or support email addresses for marketing. If you instead choose anonymous delivery, checkout does not ask for an email and identifies your order by a private retrieval code (see below).
- Order, payment and eSIM records. The plan you bought, your order number, the crypto payment status, and the resulting eSIM activation details (such as ICCID and activation profile) so we can deliver and support your order.
- Anonymous retrieval code. For anonymous orders we generate a high-entropy private retrieval code. After normalising the code, our server stores only its SHA-256 one-way hash — not the plaintext code. The plaintext code is shown at checkout and saved in this browser's local storage so it can be shown again after the payment round-trip. If you clear that storage or lose the code, we cannot recover it for you.
- IP address (rate limiting). We read the IP address of incoming requests to rate-limit abuse (for example, to stop checkout and lookup endpoints from being hammered). Before using it as our own counter key, the server combines the normalised endpoint scope and address into a keyed HMAC-SHA-256 pseudonym. The raw address is not written to our order database. Counters are held in memory and, in production, the pseudonym, count and fixed-window timestamps are stored in a restricted database table. Expired rows are deleted after their fixed window expires through bounded scheduled cleanup; a temporary backlog may remain until the next cleanup run. Our hosting and analytics providers process normal request metadata as described under Service providers below.
- Attribution and analytics data. When a landing request contains UTM parameters or an external referrer, we record a limited first and latest source record. We also use Plausible for aggregate pageview and conversion analytics. Purchase events include the USD amount, payment coin, coupon code (if any), and coarse acquisition source; they do not include your email, retrieval code, delivery token, or eSIM activation credentials.
- Support communications. If you email us, we process the sender address and name (if supplied), recipients, subject, message, attachments and related order reference needed to receive, investigate and answer the request.
- Telegram interactions (optional). If you use our Telegram bot, Telegram provides your numeric chat or user ID and may provide your username, first name and language code. We also receive the messages, button actions, and membership or block status needed to operate the conversation. If you send a retrieval code to bind an order, Telegram transmits that plaintext message to us; we use it to find the matching one-way hash and do not persist the message text or code in our webhook event log. That log keeps the provider, update ID and event type, processing state, and created and processed timestamps. Separately, we store your numeric chat ID, optional username and first name, Telegram language code, selected bot language and block state. We may link a verified chat ID to an order so we can confirm payment and deliver the eSIM in that chat.
- Telegram payment instructions (optional). If you start a Direct Payment in the bot, a delivery outbox temporarily holds the order number, plaintext retrieval code, plan, USD total, provider payment ID, crypto amount, selected currency and network, payment address, and expiry time so we can send the exact instruction to your chat. This short-lived outbox is restricted to our server service role. After successful delivery, its copy of the payment instruction and retrieval code is cleared. Expiry handling clears the payment instruction before an expiry notice is sent and clears the remaining retrieval code when that handling completes. If delivery fails, the restricted outbox copy can remain until a retry or expiry handler claims it.
Checkout does not request or require your name, postal address, phone number, or any government-issued identification. The public storefront does not offer customer accounts and no account is needed to buy or retrieve an order. Information you voluntarily include in a support message is processed as described above.
2. What we do not do
- We do not perform KYC or identity verification.
- We never see or store your card or bank details — payments are made in cryptocurrency through our payment processor.
- We do not sell, rent, or trade your data to anyone.
4. How we use your data
- To process your crypto payment and confirm it.
- To provision and deliver your eSIM and QR code.
- To let you retrieve your eSIM later using your retrieval code, or your email and order number.
- To respond to support requests and process eligible refunds.
- To detect, prevent and limit fraud and abuse of the Service.
- To measure aggregate traffic and conversions and connect an order with its first and latest acquisition source.
- To operate the optional Telegram bot, remember your language, bind an order after verification and deliver updates.
5. Service providers
We rely on a small number of third-party processors to run the Service. They receive only the data needed to perform their function:
- NOWPayments — processes your cryptocurrency payment. For website checkout, it receives the order reference and description, USD amount and currency, and selected payment coin needed to create and reconcile a hosted invoice. For Telegram Direct Payment, it receives the order reference and description, USD amount and currency, selected cryptocurrency and network, fixed-rate and fee settings, and our Direct Payment callback URL; it returns the payment ID, crypto amount, payment address and expiry needed for the instruction. We do not send it your delivery email, retrieval code, delivery token, Telegram profile, or eSIM activation credentials.
- eSIMAccess — our upstream eSIM provider. It receives the package code and service transaction references needed to provision, query and manage the eSIM profile; we do not send it your delivery email or retrieval code.
- Resend — sends payment confirmations, eSIM delivery emails, order notices and support mail. When email is used, it receives the sender or destination address, order reference, message, attachments or eSIM delivery content needed to receive or send that email.
- Telegram— provides the optional bot channel. It processes the Telegram profile and interaction data described above and the order status or eSIM delivery content we send back through its Bot API. When you choose Direct Payment, the Bot API message also contains the payment amount, address, network, expiry and retrieval code that are displayed to you. Your use of Telegram is also subject to Telegram's own terms and privacy policy.
- Supabase — our database provider and restricted-admin authentication provider. It stores order, payment, eSIM, attribution, support and Telegram records, including the one-way credential hashes described above.
- Vercel — hosts and serves the website and runs its server routes, processing the request and network metadata needed to do so.
- Plausible — provides aggregate website and conversion analytics. Its browser analytics does not set analytics cookies; it processes pageview, referrer, device and network context and the limited conversion event fields described above.
- Bitmedia — displays paid advertising and measures eligible purchases. When a qualifying non-internal paid order is confirmed, our server may send Bitmedia the pseudonymous click identifier, the actual USD order value, and configured event and conversion identifiers. We do not send your email, retrieval code, delivery token, payment address, or eSIM activation credentials.
6. Data retention
We retain order, payment, eSIM and related support records for as long as needed to deliver and support your order, to comply with our legal and accounting obligations, and to resolve disputes. Attribution copied into an order is retained with that order record; the attribution cookies themselves last up to 90 days. The delivery-token cookie expires, and its token stops being accepted, after 7 days. Anonymous retrieval codes and saved plans in local storage remain on that device until you clear the relevant list or the site's browser storage. Telegram profile identifiers and preferences (chat ID, optional username and first name, language code, selected bot language and block state), minimal webhook processing metadata, and order bindings are retained for as long as needed to operate, secure and support that channel and its linked orders. The restricted Direct Payment outbox copy of a payment instruction and retrieval code is short-lived as described above. Separate payment records needed for reconciliation — including the provider payment ID, selected currency and network, expected crypto amount, payment address, deadlines and provider status response — may be retained with the order. Rate-limit records contain a keyed pseudonym, count and window timestamps rather than the raw IP address or order lookup value. A counter stops limiting requests when its fixed window expires; expired rows are removed by the scheduled cleanup described above. Analytics and infrastructure providers retain the data they process according to our service configuration and their applicable service terms. You can ask us to delete data associated with your order where we are not legally required to retain it.
7. Your rights
Depending on where you live, you may have rights to access, correct, or delete the personal data we hold about you, and to object to or restrict certain processing. Anonymous delivery avoids collecting an email address, but the order still has payment, eSIM and potentially attribution records as described above. To make a request, contact us at the address below; we may need your order number to locate your records.
8. Security
Access to order data is restricted. Retrieval codes and delivery tokens are stored server-side only as SHA-256 one-way hashes, and provider API keys are kept server-side and never exposed to the browser. No method of transmission or storage is completely secure, but we take reasonable measures to protect your data.
9. Children
The Service is not directed to children and is intended for users who are able to form a binding contract under the laws that apply to them. We do not knowingly collect data from children.
10. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be reflected on this page.
11. Contact
For privacy questions or requests, contact us at [email protected].