Legal/Privacy Policy
Last updated
31 August 2026

Data requests are answered within 30 days, usually the same week.

Make a request
Privacy Policy

What we know about you, and why.

We are a connectivity company, not an advertising one. We collect what selling and running an eSIM requires, and nothing whose only purpose would be profiling you.

Never sold
your personal data
No card
numbers on our servers
Your choice
analytics cookies, opt-out anytime
01
Who runs this
Contact for anything data-related

eSIM Agora, operated at esimagora.com, decides what data is collected and why for everything described on this page. For any privacy question, correction, deletion or export request, write to support@esimagora.com — we treat every one of them personally, and you can also complain to your local data protection authority at any time.

02
What we collect
Four categories, each with a reason
Account data

Email address, name if you give one, password (hashed by our authentication provider, never visible to us), and your language/currency preference.

Kept while your account exists, plus 3 years after your last order
Order data

Plans bought, prices, receipts, and the Stripe transaction reference. Never your full card number — Stripe handles that end to end.

Kept as long as legally required for accounting purposes
eSIM technical data

The ICCID/EID of the profile, activation state, data volume consumed, and the country of the attached network. We do not see the sites you visit or the content you send.

Kept for 12 months after the plan expires
Site and support data

Anonymised page analytics (only if you allow analytics cookies), device type, and the messages you send our support team.

Kept for up to 14 months
03
Who we share with
A short list of processors, no data brokers
Payments — Stripe

Handles the card transaction end to end. We receive a reference and a status, never the card details.

Login — Supabase

Runs account creation and sign-in, including "Continue with Google". Your password never reaches our own servers.

Connectivity partner

The eSIM platform and roaming operators that issue and run your profile receive technical identifiers — never your name or email.

Email — Resend

Delivers receipts, activation codes and account emails. Sees your email address and the content of those messages, nothing else.

Hosting — Vercel & Railway

Runs the website and the backend that processes your orders. Standard infrastructure logs only.

Analytics — Google Analytics

Anonymised page statistics, only if you leave analytics cookies enabled in Cookie Policy. No advertising signals are ever sent.

Some of these processors operate outside your country, always under a recognised transfer safeguard (such as standard contractual clauses). The full list is available on request at support@esimagora.com.

04
Your rights
Access, correction, deletion, export, objection

You can ask for access to your data, correction of anything wrong, a portable export, restriction of processing, or object to processing based on legitimate interest. None of it is ever charged for.

Account deletion is self-service — see Delete your account for exactly what gets removed and how long it takes. For everything else, write to support@esimagora.com — we reply within 30 days, usually within a few days. Order and invoice records are kept for the legally required period even after account deletion, which is the one thing we cannot erase on request.

05
Security
Encrypted in transit, encrypted at rest

HTTPS on every connection, encryption at rest for stored data, and access restricted to the people who need it. Passwords are hashed by our authentication provider — never stored in readable form, not even by us. If a breach ever affects your data, we tell you directly, with what happened, not a euphemism.

Want a copy of everything we hold?

Ask at support@esimagora.com and we send an export, no forms to fill.

Request my data