Skip to main content

Privacy Policy

Last updated: September 4, 2026

This policy explains how eSiMAZE handles personal data when you browse esimaze.com, create an account, and buy travel eSIM data plans. If you have a privacy question or concern, please contact us at support@esimaze.com so we can help.

1. Who we are

eSiMAZE is operated by eSIMAZE LTD, the data controller for the personal data described in this policy. eSIMAZE LTD is registered in England and Wales (company number 17013914), with its registered office at 6 Commercial Street, Brierfield, Lancashire, BB9 5HH, United Kingdom. You can reach us about any privacy matter at support@esimaze.com. Some providers we work with — for example our payment processor and our connectivity partners — also act as independent data controllers for their own regulatory, network, or payment-compliance purposes, and their own privacy notices cover that processing.

2. Information we collect

  • Account details, such as your name, email address, and login identifiers.
  • Order details, such as the destination and package you chose, and its provisioning status.
  • Payment status and payment or provider references for your order. Checkout is hosted by our payment processor, so eSiMAZE does not receive or store your full card number or security code.
  • eSIM identifiers and installation or lifecycle information linked to your order.
  • Support messages and any files you send us when you contact support.
  • Fraud, security, and abuse-prevention signals linked to checkout and account activity.
  • Basic technical information, such as IP address and request metadata, processed by our infrastructure to run the service.

3. How we use information

  • To create and secure your account and process your order.
  • To fulfil your eSIM and send installation and service emails.
  • To provide customer support and handle refunds and disputes.
  • To detect and prevent fraud, security incidents, and abuse.
  • To keep the platform reliable and to meet our legal obligations.

We rely on the lawful bases of contract (to provide the service you bought), legal obligation (where the law requires us to keep or disclose information), and legitimate interests (for security, fraud prevention, and support), balanced against your rights. We ask for consent only where a specific feature requires it. eSiMAZE does not currently run a marketing programme.

4. When information may be shared

We share personal data only with the service providers needed to run eSiMAZE, and only for the purposes above. These fall into the following categories:

  • authentication, account, and database services;
  • payment-processing services;
  • eSIM, connectivity, and network services;
  • hosting and infrastructure services;
  • customer email delivery services; and
  • fraud and security services.

We may also disclose information where we are required to by law, or to establish, exercise, or defend a legal claim. We do not sell your personal data.

5. International processing

Some of our service providers process personal data outside the United Kingdom. Where that happens, we rely on the transfer safeguards required by UK data protection law that apply to the provider in question. If you would like more information about the safeguards that apply to a particular transfer, contact us at support@esimaze.com.

6. Retention

We keep personal data only for as long as it is needed for the purpose it was collected for. Account data is kept while your account is active; commerce, payment, and support records are kept while needed for fulfilment, disputes, fraud prevention, and accounting or legal obligations; and technical and security data is kept only as long as reasonably necessary for the security purpose it was collected for.

7. Your privacy rights

Depending on the lawful basis that applies and any legal exemptions, you may have the right to access the personal data we hold about you, have inaccurate data corrected, request erasure, restrict certain processing, receive certain data in a portable format, and withdraw consent where we rely on it. Where we process your data on the basis of legitimate interests, you also have the right to object; if you object, we will stop unless we have compelling legitimate grounds that override your interests or the processing is needed for a legal claim, assessed case by case.

To exercise a right or request account deletion, contact support@esimaze.com. Some commerce, security, and legal records may need to be retained after an account is deleted. If you have a privacy concern, please contact us first so we can resolve it. You also have the right to raise a complaint with a relevant data protection authority.

8. Security and automated controls

We use reasonable technical and organisational measures to protect personal data, including access controls and secure infrastructure. No online system can be guaranteed fully secure. We also use automated security, fraud, and rate-limiting controls to protect checkout and account activity from abuse; these support security monitoring and human review and do not make legally or similarly significant automated decisions about you.

9. Cookies and similar technologies

eSiMAZE uses only essential cookies and similar browser storage: session and authentication cookies to keep you signed in, and a short-lived guest checkout token to connect a purchase to your order. Account signup and login also run an anti-bot security check. We do not use analytics, advertising, or marketing cookies or trackers. If this changes, we will update this policy and provide appropriate controls before any non-essential tracking is enabled.

Separately, checkout is protected by server-side automated rate-limiting rather than a cookie or browser-storage technology. This is a security control, not marketing or analytics tracking.

10. Changes

We may update this policy from time to time. Material changes apply from the date they are published.