Privacy Policy
BuyUKeSIM is built so there is almost nothing to collect. No account, no email required, no KYC, and checkout settled only in cryptocurrency. This page explains exactly what that means.
Last updated:
No account
Nothing to sign up for, no password, no profile.
No KYC
No name, ID, or identity check to buy.
Crypto only
No card or bank details ever touch us.
What we do not collect
To buy from BuyUKeSIM you never give us, and we never store:
- Your name
- Your home or billing address
- Any government ID, passport, or KYC document
- A credit or debit card, or bank details
- An account or password - there are no accounts
- A required email address
What we do process
Only what is strictly needed to take a crypto payment and deliver a digital eSIM:
- Order details. The product you bought, the crypto amount, payment status, and a lookup code so you can find the order later.
- eSIM identifiers. The QR and ICCID of the eSIM we assign to you, so we can deliver it and help if activation fails.
- Country signal. A coarse country (from Cloudflare), stored with your order and in our own server-side statistics. We use it to see where orders and visits come from, to spot a coverage problem in a country, and to credit an affiliate referral. Not a precise location, and it never changes the price you pay.
- Optional email. Only if you choose to enter one, at checkout or later from your own order page. We email you only about your own order: the link to your eSIM, the expiry reminders you switched on yourself, and one notice if an order expired before you paid. Every one of them carries an unsubscribe link, and the address is never sold, shared, or used to sell you something you did not order. An address you add from your order page is deleted the moment you switch the reminder off there.
- Support messages. If you use live chat or the Telegram bot, the messages you send and a random visitor id so we can reply. No account is created. Live chat is answered first by an AI assistant, which means the recent messages of that conversation are sent to our AI provider to compose a reply - see the table below.
Analytics, self-hosted and minimal
Our analytics are first-party and self-hosted: no Google, no third-party analytics product, no advertising network. Here is exactly how they work, because "privacy-friendly analytics" is a phrase that hides a lot. Every public page runs a small beacon that pings our server about every 50 seconds with the page you are on, the page you came from, and a random id your browser generates and keeps in local storage. Our server records that ping together with the IP address it arrives from and your browser’s user agent string. The reporting we actually look at is built from a one-way hash of those two that is rebuilt every day, so the charts hold no IP address and no user agent; the raw pair sits in the live visitor table, which is deleted two days after your last page view. None of it is shared with an analytics company, and none of it builds a profile that follows you off this site.
What we do not do
- Send newsletters, promotions, or offers for anything you did not order
- Sell, rent, or share your data with data brokers or advertisers
- Build advertising or behavioural profiles of you
- Place third-party advertising pixels or cross-site trackers
- Ask you to verify your identity to buy
Payments and crypto
Checkout is cryptocurrency only. You pay directly in crypto, confirmed on the blockchain - there is no card form and no bank transfer, so no card or bank data exists to leak. We read only the on-chain payment status to release your eSIM.
Data retention
Real windows, taken from the cleanup job that enforces them. It runs hourly. Where a store has no deletion date we say so, rather than writing "as long as necessary".
| Visit records | The beacon row: visit id, page, referrer, country, IP address and browser string. The whole row is deleted two days after your last page view. If you keep coming back the row stays alive, so the IP address and browser string inside it are erased once the row itself is 90 days old. |
| Page statistics | One row per page view: page, section, source, country, device, browser and language, plus a visitor hash that is rebuilt from scratch every day. No IP address, no browser string. Kept as counts. |
| Request and security logs | The API log records endpoint, status code, duration and country, and nothing that identifies you: 30 days, or 7 for the admin panel’s own traffic. The security log, which does record an IP address and browser string for a blocked or suspicious request, is kept 90 days. Web server logs rotate after 14 days. |
| Support messages | Chat and Telegram messages, 180 days. Images you attach to a chat, 90 days. The AI assistant’s own copy of a question and answer is erased at 180 days too, so no second transcript outlives the first. |
| Order records | Kept while the product is alive and support is still possible: what you bought, the crypto amount, payment status, the eSIM identifiers, the lookup code, the country signal, and an email address only if you gave one. These have no fixed deletion date, because your eSIM, your top-ups and your refund window all depend on them. An email you added yourself from your order page is deleted the moment you switch reminders off there; for anything else, ask us. |
| Email records | For every message we send: the address, the subject, the date, and whether it arrived. The message body itself is erased after 180 days, because an order email contains a link that opens your order. |
| Backups | The database is backed up nightly. Copies on the server are replaced after 14 days. The off-site copies are encrypted with a key the server does not hold, so nobody with access to the server can read them. |
We hold no accounts, no identity documents and no payment credentials, so most of what a shop would normally retain never exists here in the first place.
Third parties we rely on
A few processors are needed to run the service. Each sees only what its job requires, and this is the whole list:
| Cloudflare | CDN, TLS and DDoS protection. Every request to the site passes through it, and it is where the coarse country signal comes from. |
| Telegram | Optional support and purchases via our @buyukesimbot bot. |
| eSIM network supplier | Issues the eSIM profile we hand you. It receives no personal data at all: we ask for a profile, it returns one. |
| Wholesale VPN network | Carries VPN traffic. It receives a generated username, a generated password and an expiry date, and nothing about you. See the VPN section below. |
We do not control how these providers handle data. Several processors are described by what they do rather than by name: the provider behind our live chat assistant, the service that sends our email, the crypto payment gateways, the network supplier that issues eSIM profiles, and the VPN operator we buy capacity from. None of them is a company you have a relationship with.
VPN access and your traffic
The VPN is capacity we buy on a wholesale network rather than servers we own. When you buy a plan we send that network a generated username, a generated password and an expiry date, and nothing about you: no email, no order id, no payment detail, no IP address. Your traffic then leaves through their servers, which run from RAM and are operated on the terms we publish on the VPN page: source IP addresses and connection timestamps are not stored. We hold the operator to that; we cannot audit it for you, so treat it as their commitment carried by us, not a claim we can prove on their behalf.
Access over Tor
For readers who want to reach us anonymously, BuyUKeSIM is also available as a Tor hidden service. Open it in Tor Browser at l4wvrny7rzf7ec2cmp7w4frl6okcvxmq662zrbhe7v3pvxplcuzf2gyd.onion. We publish a warrant canary as well.
Your rights
Depending on where you live, you may have rights to access, correct, or delete personal data (for example under the GDPR or CCPA). You are welcome to ask - though because we collect so little, a request will usually turn up very little. Contact us using the details below.
Security
The site is served only over HTTPS. We never take or store card or bank data - payments settle directly on the blockchain in cryptocurrency - and the deliberate lack of accounts and identity documents means a breach has very little to expose.
Who can see what
This policy says what we collect. The threat model says what every other party can see, and names what we cannot protect at all.
Children
BuyUKeSIM is intended for adults (18+, or the age of majority where you live). We do not knowingly sell to or collect data from children.
Changes and contact
If this policy changes, we update the date at the top and post the revised version here. Questions about privacy? Reach us on Telegram at @buyukesimbot or via the contact page.
