Updated 2026-08-15
Privacy Policy
1. Who we are
esim.coffee is operated by S12V Labs LLC, a limited liability company registered in the State of Wyoming, United States. Mailing address: 1021 E Lincolnway #9338, Cheyenne, WY 82001, USA.
S12V Labs LLC is the data controller for everything described in this policy. For anything concerning your data, use the contact page — it reaches the person responsible directly, because there is no department to route you through.
2. What we collect
We do not collect card details. Payment happens entirely in the payment provider's environment. We receive only confirmation that payment succeeded, and a reference for a possible refund.
- Email. Required to deliver your QR code and give access to your order page. Without it there is no way to deliver the product.
- Order data. Plan, destination, amount, date and status.
- Compatibility confirmation. We record that you confirmed your device supports eSIM. We do not collect the model or any device identifier.
- Technical data. IP address and server access logs, kept for security and diagnostics.
3. Why we process it
We do not sell your data and we do not use it for third-party advertising.
- Performing the contract. Delivering the eSIM you bought, supporting it and processing refunds.
- Legal obligation. Retaining tax and payment records for the period the law requires.
- Legitimate interest. Preventing fraud and keeping the service running.
4. Who we share it with
- Payment provider (Stripe). Receives what it needs to process the charge.
- Connectivity supplier. Receives only the order reference and the plan to provision — not your email or personal data.
- Infrastructure. Servers and database used to run the service.
- Telegram. When someone starts a checkout or completes a payment, a message goes to a private group we run so a small team can see orders as they happen. It contains the destination, the plan, the price, the order reference, your email address, and — for a checkout that has only been started — the IP address the request came from. It is an operational alert, not analytics and not marketing, and the group is not public. If you would rather this did not happen, write to us before you buy and we will take the order by email instead.
5. How long we keep it
- Order data: for the statutory tax retention period.
- Payment webhook records: 30 days.
- Server access logs: a short period, for diagnostics.
6. Your rights
You can request access, correction, deletion or portability of your data, and object to certain processing. Write to us from the contact page using the email you bought with. We answer within the applicable statutory period.
If you are in the EU these rights come from the GDPR; in Brazil, from the LGPD (Law 13.709/2018); in the UK, from the UK GDPR.
7. Cookies
The site uses no advertising cookies and takes no part in cross-site advertising tracking. We store one local preference — your chosen language — in your browser, which never leaves your device.
We do use Google Analytics to count page views and see which pages people arrive on. It runs with storage consent denied by default, which means it sets no analytics cookie and no identifier that would let anyone recognise you on a second visit. The trade is deliberate: we can see that a page was read and roughly where the visit came from, and we cannot see that it was you. If we ever turn that on, it will be behind a consent banner and this page will say so first.
Google Analytics is operated by Google, and the measurement data it collects is processed on Google’s infrastructure outside your device. That is the one third party on this site. If you would rather not be counted at all, any tracker blocker will stop it, and nothing on the site will break.
8. Changes
When this policy changes we update the date at the top. Material changes are emailed to anyone with an active order.