esimdir.
← Back

Privacy

What we know about you.

In plain language: very little, and we'd like to keep it that way. You don't have an account, you don't give us a card, and we don't sell anything. Here's the whole list.

Effective May 15, 2026

The short version

If you trust this paragraph, you can skip the rest. We store your last search and locale in your browser (not on our servers). We use one analytics service that anonymizes IPs. Carrier sites you visit through esimdir use their own tracking — we have no control over theirs. We never sell data. There is nothing to delete because there is nothing to keep.

What we collect

  • Local browser data. Your last destination and locale preference are kept in localStorage on your own device. We can't read it remotely.
  • Anonymous analytics. We use Plausible Analytics, which doesn't use cookies and doesn't store IP addresses. We see page counts and referrers in aggregate.
  • Outbound clicks. When you click through to a carrier, the affiliate program records that visit so we get credit. The tracker passes a session ID — not your name or email.
  • Support emails. If you write to us, we keep that email thread until your issue is resolved, then we archive it for one year for legal reasons.

What we don't collect

  • Personal identifiers. No name, address, phone number, or date of birth.
  • Payment information. We never see your card. The carrier collects payment directly.
  • An account. esimdir has no login. There is no password to forget.
  • Marketing emails. We have no mailing list. We can't send you offers because we don't have your email.
  • Cross-site tracking. We don't use Meta Pixel, Google Ads, or third-party advertising trackers anywhere on the site.

Third parties

A few outside services touch your visit. Each is listed below with what they see.

  1. 01

    Carrier sites (Airalo, Holafly, etc.)

    When you click "Continue to provider", you leave esimdir entirely. From that point, the carrier's own privacy policy applies. We recommend reading theirs before you buy.

  2. 02

    Plausible Analytics

    Tracks page views in aggregate without cookies. They publish their own privacy policy — their data sheet describes exactly what's collected.

  3. 03

    Cloudflare

    We use Cloudflare as our content delivery network and DDoS protection. They process IP addresses for security purposes per their data processing agreement.

  4. 04

    Affiliate networks

    Impact, Awin, and CJ track which carrier visits convert to purchases. They use a one-time session cookie set when you click through. You can opt out via your browser's third-party cookie settings.

Your rights — by region

You have rights over the data we hold about you. Because we hold almost nothing, most of these are easy to honour — but they apply regardless. Email privacy@esimdir.com to exercise any of them; we reply within 30 days.

  1. 01

    EU / EEA / UK — GDPR & UK GDPR

    Lawful basis: legitimate interest (running the site) and consent (where required for non-essential cookies). You have the right to access, rectify, delete, restrict, port, and object to processing. You can lodge a complaint with your national data protection authority — CNPD is the Portuguese supervisory authority for our jurisdiction. We do not have a DPO because we sit below the GDPR threshold, but privacy@esimdir.com is the single point of contact.

  2. 02

    United States — CCPA / CPRA & state laws

    California, Virginia, Colorado, Connecticut, Utah and other state residents have rights to know, delete, correct, and opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under state law, and we do not process sensitive personal information. There is no "Do Not Sell or Share" link because there is nothing to opt out of. You can still request access or deletion by email.

  3. 03

    Mainland China — PIPL

    If you access esimdir from mainland China, the Personal Information Protection Law applies. We do not transfer personal information out of China in a way that requires a CAC security assessment because we collect only browser-local data and anonymised analytics. We do not process sensitive personal information and do not use automated decision-making. We do not have a local representative in China; for PIPL requests, email privacy@esimdir.com. Carrier sites you click through to may have their own China-specific terms.

  4. 04

    Hong Kong — PDPO

    Under the Personal Data (Privacy) Ordinance and its six Data Protection Principles, you have the right to access and correct any personal data we hold about you. Submit a Data Access Request in writing to privacy@esimdir.com. Complaints can be filed with the Privacy Commissioner for Personal Data (PCPD).

  5. 05

    Rest of world

    If your jurisdiction has comparable laws (Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, Singapore's PDPA, Japan's APPI, India's DPDP Act, etc.), we honour analogous rights on a best-effort basis. Email us with your jurisdiction and request; we will respond within 30 days.

International data transfers

Our servers are hosted in the EU (Frankfurt). Plausible Analytics is also EU-hosted. Cloudflare may route traffic through regional edge nodes worldwide; this is governed by their Standard Contractual Clauses and data processing agreement. Affiliate trackers may process data in the US under Data Privacy Framework certifications where applicable.

If you are accessing the site from a jurisdiction with data-localisation rules (China, Russia, etc.), the only personal data leaving your jurisdiction is what your browser sends in standard HTTP headers — the same as any website visit.

Cookies

We use one cookie: a session token that remembers if you've already dismissed a banner or notice. It expires when you close the browser. Under GDPR and the ePrivacy Directive we don't need consent for strictly necessary cookies, but the cookie banner is shown for transparency.

Third-party services may set their own cookies when you click through to them. Those are governed by their policies, not ours.

Children

esimdir is intended for adult travelers buying their own cellular service. Consistent with GDPR (under-16), COPPA (under-13 in the US), PIPL (under-14 in China) and PDPO (Hong Kong) thresholds, we don't knowingly collect data from minors. If you're a parent and believe your child has used our service, write to privacy@esimdir.com and we'll help.

Changes to this policy

If we change anything material, we'll update the date at the top and publish a note in our changelog. For substantive changes (e.g. adding a new third-party processor), we'll surface a banner on the site for at least 30 days.

Contact

Privacy questions, deletion requests, or general concerns: privacy@esimdir.com. We're a small team. Expect a reply within two working days.

That was painless.

Now go find an eSIM that doesn't ask for your life story.

Find my eSIM →