Privacy policy
Last updated: 13 June 2026
1. Who we are
eSIM Ara, operated by GEEDCO INC (120 N. Washington Sq Ste 300, Lansing, MI 48933, United States), is the controller of the personal data described here. Contact us about privacy at privacy esim-ara com.
Our representative in the EU/EEA for the purposes of Article 27 of the GDPR is GEEDCO OÜ, Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia. If you are in the EU or EEA, you may contact our representative on data-protection matters in addition to, or instead of, contacting us directly.
2. What we collect
- Your email address — to deliver your eSIM and order link, and to send a one-time verification code at checkout.
- Order details — the plan you bought, its price and status, and once fulfilled the eSIM identifier (ICCID) and install link.
- Payment confirmation — we receive confirmation of your card or cryptocurrency payment from our payment processors (Stripe for card payments). Card details are entered on the processor’s own page; we never see or store your full card number.
- Live-chat data — if you use chat: the messages you send, an optional name, and the page you opened chat from.
- Technical data — your IP address (used to rate-limit and protect the service from abuse) and standard server logs.
- Functional tokens — your private order link, and a chat token stored in your browser’s local storage.
3. Cookies and local storage
We keep this minimal. We use one signed session cookie to run the checkout email-verification step, and your browser’s local storage to remember your chat session and order link. We also use Google’s conversion tag (Google Ads) to measure how well our advertising performs; it may set cookies in your browser. Beyond that we use no other analytics or third-party tracking.
4. Why we use your data, and our legal bases
We use your data to provide the service you bought (performance of a contract); to verify your email and keep the service secure and free of abuse (our legitimate interests); and to meet our legal, tax, and accounting obligations (legal obligation).
5. Who we share it with
We use a small number of providers to run the service, and we do not sell your personal data:
- eSIMCard (our eSIM supplier) and its mobile-network partners provision your eSIM and carry your traffic. We send them only the package purchase — not your email or personal details. As the network operator, they and their carriers process network-usage data (such as data consumed and the networks your eSIM connects to); their handling is governed by eSIMCard’s privacy policy.
- Resend, our email provider, receives your email address to deliver your eSIM and verification messages.
- Our payment processors (Stripe for card payments, and our crypto processor for cryptocurrency) confirm your payment. Card details are entered on the processor’s page and we never receive your full card number; note that cryptocurrency transactions are recorded on a public blockchain outside our control.
- Google receives measurement data from our advertising conversion tag (see “Cookies and local storage” above).
- Our hosting provider (in the European Union) stores the data needed to run the site.
6. International transfers
Our servers are in the European Union; our email provider is in the United States. Where data crosses borders we rely on appropriate safeguards as required by law.
7. How long we keep it
- Order and transaction records: up to 6 years, to meet tax and accounting obligations.
- Live-chat conversations: up to 12 months.
- Server and security logs: about 90 days.
- Email verification codes: they expire within 15 minutes.
8. Your rights
Depending on where you live, you have rights over your data. Under the EU/UK GDPR these include the right to access, correct, delete, restrict, or port your data, to object to certain processing, to withdraw consent, and to complain to your data-protection authority. Under the California CCPA you have the right to know, to delete, to opt out of the “sale” of personal information (we do not sell it), and not to be discriminated against for exercising your rights. To exercise any of these, email us at privacy esim-ara com.
9. Children
The service is not directed to children (under 16 in the EU, under 13 in the US) and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
10. Security
We protect your data with HTTPS everywhere, capability links instead of accounts and passwords, no stored payment-card data, and by collecting as little as we can.
11. Changes to this policy
We may update this policy; the current version is always posted here with its “last updated” date.
12. Contact
Privacy questions or requests: privacy esim-ara com, or GEEDCO INC, 120 N. Washington Sq Ste 300, Lansing, MI 48933, United States. EU/EEA residents may also contact our Article 27 representative, GEEDCO OÜ (Ahtri tn 12, Kesklinna linnaosa, Tallinn, Estonia).