Privacy Policy
This policy explains what personal data eSimko (“eSIMko”, “we”, “us”) collects when you use the eSIMko website, web app and mobile apps (together, the “Service”), why we collect it, and the choices you have. We are based in Yerevan, Armenia. You can reach us at support@esimko.net.
1. Data we collect
- Account data — your name, e-mail address and a hashed password when you create an account; or your Google account name, e-mail address and profile picture if you sign in with Google. A 6-digit code is e-mailed to verify your address.
- Purchase data — the plans and top-ups you buy, prices, promo codes used, order references and the delivery e-mail you enter at checkout. Card details are handled by our payment processor and never stored by us.
- eSIM data — the eSIM profiles issued to you (ICCID, activation code, QR code), the destination, data allowance, data used, activation and expiry dates, as reported by our eSIM provider so the app can show your live usage.
- Support messages — what you write to us in the in-app support chat.
- Preferences — language, notification settings, claimed promotions, referral code.
- Technical data — IP address, device and browser type, and basic server logs needed to run and secure the Service. We do not use advertising trackers.
2. How we use it
- To create and secure your account and let you sign in.
- To issue, deliver and manage your eSIMs and show your data usage.
- To send service e-mails: the verification code, and — if switched on in Profile → Notifications — alerts when a plan is running low, out of data, about to end or ended. You can turn each of these off in the app at any time.
- To answer your support requests.
- To prevent fraud and abuse, and to meet legal and accounting obligations.
We do not sell your personal data and we do not send marketing e-mail unless you opt in to “Deals & promos”.
3. Who we share it with
- eSIM connectivity provider (Yesim) — receives what is needed to provision your eSIM and report usage.
- E-mail delivery (Brevo) — to send verification codes and service alerts to your address.
- Sign-in provider (Google) — only if you choose “Login with Google”; Google tells us your name, e-mail and picture.
- Hosting (Amazon Web Services) — our servers and database.
- Payment processor — when card payments are enabled, your card is charged by a PCI-compliant processor; we receive only a confirmation.
- Authorities where the law requires it.
4. Retention
Account, order and eSIM records are kept while your account exists and for as long as tax and accounting rules require afterwards. Guest sessions that never make a purchase are removed periodically. Support chats are kept for up to 2 years. You can ask us to delete your account at any time.
5. Your rights
You can delete your account yourself at any time at esimko.net/delete-account (we e-mail you a code to confirm). You can also access, correct or delete your data, object to or restrict processing, and receive a copy of your data, by e-mailing support@esimko.net from your account address. If you are in the EU/EEA or UK you also have the right to complain to your local data-protection authority.
6. Security
Passwords are stored only as bcrypt hashes, sessions use signed cookies, and traffic to http://localhost:3010 is encrypted with HTTPS. No method is perfectly secure, so please keep your password private.
7. Children
The Service is not directed at children under 16 and we do not knowingly collect their data.
8. Changes
We will post any changes here and update the date above. Material changes will be announced in the app.
eSimko · Yerevan, Armenia · support@esimko.net