Privacy Policy
Last updated: August 2026
This policy is short on purpose. We have nothing to hide, and we collect almost nothing to hide. Read it once and you'll know exactly where you stand.
The short version
We do not know who you are. We cannot identify you. We do not track you. We do not sell your data, because we do not have your data to sell. The only information we hold is what is strictly required to deliver the eSIM you bought, and we delete it on a fixed schedule.
What we collect
Everything we collect is necessary to fulfill your order, plus minimal aggregate analytics (below). Nothing more.
- Order data: Product purchased, amount paid, payment currency, order status. Required to deliver your eSIM and process your payment.
- Email (optional): Only if you choose to provide one for QR code delivery. We do not require an email to purchase. You can buy with no email at all.
- PGP public key (optional): Only if you choose encrypted email delivery. Used solely to encrypt your eSIM QR code.
- Aggregate traffic stats (no identity): referring domain + landing page, coarse device/OS/region, and a one-way daily hash used to count unique visitors. No IP addresses, user agents, or anything tied to you are stored. Two functional cookies (currency, language) are set only if you change them; strictly necessary, no tracking.
What we never collect
These are never collected and structurally can't be — the system has no fields for them:
- Your name, address, or phone number
- Government ID or KYC documents
- IP addresses (never written to logs or the database)
- Browser fingerprints or full user agents
- Tracking cookies, advertising pixels, or analytics scripts
- Payment card numbers (card payments are handled entirely by Stripe, a third-party processor)
The "we can't identify you" guarantee
There is no account system. Your order ID is a random string generated at purchase. We do not link your order to your identity, your email (unless you provide one), or your payment. If you pay with crypto and provide no email, there is no record connecting the purchase to you. We could not identify you if we tried, because the data to do so does not exist.
Payment privacy
We accept Bitcoin, Monero, USDT/USDC, ETH, and card payments. How private each is depends on the method you choose:
- Monero (XMR): Private by default. The transaction is untraceable on the blockchain. This is the most private option, which is why it carries a 5% discount.
- Bitcoin (BTC) and altcoins: Pseudonymous. Your wallet address is visible on the blockchain, but we do not link it to any personal information.
- Card (Stripe): Handled entirely by Stripe, a third-party payment processor. Your card details never touch our servers. Stripe's privacy policy applies to the card transaction.
Encrypted delivery (PGP)
We offer three delivery modes for your eSIM QR code:
- Email + PGP: Your QR code is encrypted with your PGP public key before it is emailed. Only your private key can decrypt it.
- Email only: Your QR code is emailed in plain text. Less private, but simpler.
- Key-only (no email): No email at all. Your QR code is delivered on-screen only. The most private option.
Data retention
We delete data on a fixed schedule. Nothing is kept indefinitely.
- Order records (no eSIM delivered): Retained for 90 days for customer support, then permanently deleted.
- Order records (eSIM delivered): Retained for 270 days — the full life of your eSIM (up to 180-day plans) plus a 90-day support window — so QR re-download and top-ups keep working as long as you might need them, then permanently deleted.
- Download tokens: Single-use, expire after 10 minutes.
- Webhook logs: Retained for 30 days for debugging only, then deleted.
- Referrer logs: Aggregate traffic-source data (referring domain + landing path, coarse device/OS/region — no IP, no full user agent), used for analytics, retained on a rolling 30-day window.
Third-party processors
We use a small number of third parties, each with a specific, limited role:
- Stripe: Processes card payments. Handles card details; we never see them.
- eSIM suppliers: Provision the eSIM you purchased. They receive only the order details needed to activate your plan, not your identity.
- Email provider: Delivers your QR code if you choose email delivery.
- Fonts: Self-hosted (Manrope, JetBrains Mono). No font CDNs — your browser never contacts Google Fonts.
Our server fetches exchange rates from Frankfurter/ECB (fiat) and CoinGecko (crypto) to display prices in your currency. Those calls are made by our server, not your browser, and carry no customer data.
What we will never do
- Sell, rent, or share your data with advertisers or data brokers
- Run advertising or tracking pixels on our site
- Build a profile of you across visits
- Hand over data we do not have to any third party, because we do not collect it
Your rights
Because we hold so little, your rights are simple. You can request deletion of your order record at any time. You can request a copy of the data we hold about you. You can ask us to confirm what we hold. In all cases, we can only act on the data we actually have, which is limited to your order ID and anything you chose to provide.
Contact
For privacy inquiries, contact us with your order ID. We cannot verify your identity (by design), so please include your order ID for any support or privacy request. Reach us at info@simzilla.io.