Privacy Policy
Revision of 02.10.2026
1. General provisions
1.1. This Privacy Policy (the “Policy”) describes what data the ESimGo service — the Telegram bot, the Telegram Mini App and the website (the “Service”) — processes, why, to whom it is passed and how it is stored. Data is processed by the Service’s administration.
1.2. By using the Service, the User agrees to this Policy. If the User does not agree, they must stop using the Service.
2. What data we collect
2.1. Data from Telegram — passed in signed form when you open the Mini App:
- Telegram ID;
- first name, last name (if set in Telegram) and username (if any);
- Telegram interface language.
2.2. Purchase data:
- orders: plan, country, price, currency, status, order number, dates;
- payments: payment method, payment provider, the provider’s payment ID, amount, currency, status and the provider’s payment status notifications;
- eSIMs: ICCID, installation data (activation string, SM-DP+ address, activation code), status, remaining data.
2.3. Technical data: server logs — request time, page address without parameters, response code and internal identifiers. Passwords, sign-in tokens and eSIM installation data are not written to logs. The IP address is used only in the server’s memory to protect against brute force and overload and is not stored in the database. We do not collect device model or browser details; the Telegram app type (iOS, Android, etc.) is used only on your device to show suitable payment methods and is not sent to the server.
2.4. We do not collect:
- phone number, e-mail, passport data, documents or photos;
- bank card numbers or other payment details — they are entered on the payment provider’s page; the Service neither receives nor stores them. From the provider we receive only the payment status, its ID, amount and currency;
- chats with the bot — the bot answers commands and opens the Mini App but does not store messages.
2.5. If you contact support (on Telegram), we see what you tell us in your message.
3. How we use data
- running the Service: password-free sign-in via Telegram, showing your orders and eSIMs;
- placing orders, confirming payments, issuing eSIMs;
- support and answering requests;
- protection against fraud, brute force and double charges;
- accounting for payments and refunds.
We do not use data for advertising and do not sell it.
4. Sharing data with third parties
4.1. Data is passed only to those the Service cannot work without:
- Telegram — the platform the bot and Mini App run on (Telegram’s rules apply).
- The payment provider you pay through: amount, currency, a description with the order number, the return address of the order page and our internal payment ID. Your Telegram ID, name, username and other data about you are not passed to the provider. Data you enter on the payment page is processed by the provider under its own rules.
- The eSIM supplier (network operator or aggregator): only what is needed to issue the eSIM — plan, country, data allowance and validity, internal order numbers. No data about you is passed to it.
- Cloudflare — traffic to the website and Mini App passes through its network; it processes the IP address and technical request data.
- The hosting provider whose server runs the Service and stores the database.
- Public authorities — only where expressly required by law.
4.2. Inside the Service, the owner and the administrators appointed by the owner have access to the extent needed for operation and support: the buyer’s Telegram ID, name and username, orders, payments and technical eSIM data (ICCID, status). eSIM installation data is not shown to administrators. Administrator actions are logged.
5. Storage and protection
5.1. How and where data is stored:
- Location: the database on the Service’s server at the hosting provider.
- Retention: profile, order, payment and eSIM data is kept while it is needed to run the Service and to fulfil obligations to the User (eSIM delivery, support, refunds), and for the periods required by law.
- Web server logs — up to 14 days; application logs — while the allotted space allows.
- Database backups (they contain user data) are made daily and before updates and are kept on the same server: the last 14 daily copies and up to 20 pre-update copies.
- Protection: HTTPS connections, sign-in with data signed by Telegram, orders and eSIMs accessible only to their owner, administrator rights checked on every action, the Service’s secrets are not stored in the code.
5.2. Your rights: you can request information about your data, its correction or deletion by contacting support on Telegram @esimgosupport. Some order and payment data may be kept longer where the law requires it (accounting).
5.3. Cookies are not used on the website or in the Mini App. Only the chosen Mini App interface language is stored in the browser (localStorage). No analytics or advertising trackers are used.
6. Limitation of liability
6.1. Transmitting information over the internet always carries risks, and absolute protection is impossible.
6.2. The Seller is not liable for disclosure of data caused by the User (for example, if they shared the QR code or activation code with others) or by third parties beyond the Seller’s control. This does not limit the Seller’s liability where the law does not allow such limitation.
7. Changes to the Policy
7.1. The Seller may change this Policy.
7.2. The current revision and its date are published on this page. Changes do not apply to orders already paid: the revision in force at the time of payment applies to them.
7.3. Questions about your data: contact support on Telegram @esimgosupport.