Legal
Privacy Policy
Last updated: May 19, 2026
1. Overview
eSIMion ("we", "our") is committed to handling your information responsibly. This policy explains what we collect, how we use it, and your rights. By using the Service, you agree to the practices described here.
2. Information We Collect
We collect the following categories of information:
- Email address — provided when you register, sign in, or email your itinerary to us.
- Trip and itinerary data — destination countries, travel dates, and trip segments you provide or that we parse from forwarded emails or uploaded files.
- Uploaded files — if you upload a screenshot, PDF, or itinerary document, we process its contents to extract travel information.
- Device information — IMEI, EID, and eSIM support details you optionally provide in your device profile.
- Payment information — handled entirely by Stripe. We do not receive or store full card details.
- Session data — server-side session tokens used to keep you signed in.
3. Itinerary and File Handling
When you forward an email or upload a file, we extract travel-relevant information (countries, cities, dates, flight segments) to generate eSIM recommendations. The raw text content of your email or file is stored securely and linked to your trip record.
We do not use your itinerary content for advertising, profiling, or sharing with third parties beyond what is necessary to provide the Service. Uploaded files are processed on our servers and are not retained beyond operational necessity.
4. How We Use Your Information
We use your information to:
- Parse your itinerary and generate eSIM plan recommendations
- Provision eSIM profiles through third-party providers on your behalf
- Send transactional emails — including magic-link sign-in links, plan recommendations, install instructions, and pre-departure reminders
- Process payments through Stripe
- Improve recommendation accuracy and platform reliability
We do not sell your personal information. We do not use your data for behavioral advertising.
5. Email Communications
By providing your email address, you may receive the following types of messages from us:
- Magic-link authentication emails
- eSIM plan recommendation emails after your trip is processed
- Order confirmations and eSIM install instructions
- Pre-departure and activation reminders (if enabled)
These are transactional communications tied to your use of the Service. You may contact us at support@esimion.com to request removal.
6. Payment Processing
All payments are processed by Stripe, a PCI-DSS certified payment processor. When you check out, your payment details are submitted directly to Stripe — we never see or store your full card number. We receive confirmation of payment outcome and a Stripe session reference for order records. Stripe's privacy practices are governed by their own Privacy Policy.
7. Third-Party eSIM Providers
To provision eSIMs, we share necessary order details (such as destination country and plan identifiers) with our eSIM provider partners. These providers receive only the information required to fulfill your order. We do not share your email address or personal profile with providers unless it is required by their activation process.
8. Cookies and Analytics
We use server-side sessions (stored as secure HTTP-only cookies) to maintain your authenticated state. We do not currently use third-party advertising cookies or behavioral tracking services. If we introduce analytics tools in the future, we will update this policy and provide appropriate disclosures.
9. Data Retention
We retain your account and trip data for as long as your account is active or as needed to provide the Service. Order records may be retained longer for legal, accounting, or compliance purposes.
You may request deletion of your account and associated data by contacting support@esimion.com. Note that some information (such as transaction records) may need to be retained for legal or financial compliance reasons even after account deletion.
10. Security
We use industry-standard security practices including HTTPS encryption in transit, hashed session tokens, and HMAC-verified webhook signatures. Passwords are hashed using bcrypt. Magic-link tokens are single-use and time-limited. No system is perfectly secure — if you discover a potential security issue, please report it to support@esimion.com.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and data
- Object to or restrict certain processing activities
To exercise any of these rights, contact us at support@esimion.com.
12. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we do, we will update the "Last updated" date at the top of this page. Continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
13. Contact
Privacy questions or concerns? Reach us at support@esimion.com.