eSimList
USD

eSimList

Privacy Policy

Last updated: 15 August 2026

In short

eSimList compares prepaid eSIM data plans offered by independent providers. We do not sell SIMs, we do not take payments, and you do not need an account to use the site. In practice that means:

  • no advertising cookies and no tracking networks — no Google Analytics, no Meta pixel, no retargeting;
  • we never sell or rent your data;
  • the only things stored in your browser are the preferences the site needs to work — your chosen currency and the exchange rates;
  • you give us personal data only if you choose to write to us through the contact form.

The details are below, and the exact list of what is stored in your browser is in the Cookie policy.

Who the controller is

The controller for personal data processed through this site is the entity operating eSimList. You can reach us at any time through the contact form, including to exercise the rights described below.

What data we process

1. Technical access data (server logs)

Like any website, the servers hosting eSimList automatically record incoming requests: IP address, date and time, the page requested, the response code, browser type and version, operating system and referring page. These logs are needed to deliver pages, to keep the site secure (blocking abuse and automated attacks) and to diagnose errors.

2. Data you send us

If you use the contact form, we process your name, email address, phone number (optional) and the content of your message. We use them solely to reply to you and to keep a record of the correspondence.

3. Preferences stored in your browser

We store locally, on your device, the currency you want prices displayed in and a copy of the exchange rates, so they are not downloaded on every page. This information stays in your browser and is not transmitted to us. The full list is in the Cookie policy.

What we do not process

We never ask for payment details — nothing is bought on eSimList. We do not create accounts, do not build user profiles, and do not process special categories of data (health, political opinions, biometrics and the other categories in art. 9 GDPR).

Why we process data, and on what legal basis

We process personal data only where we have a legal basis under art. 6 GDPR:

PurposeDataLegal basis
Delivering the site and rendering pages correctlytechnical access datalegitimate interest (art. 6(1)(f)) — operating the service
Security, preventing abuse and automated traffictechnical access datalegitimate interest (art. 6(1)(f))
Replying to your messagename, email, phone, messagesteps taken at your request / legitimate interest (art. 6(1)(b) and (f))
Remembering your currency preferencebrowser local storagenecessary for the service you asked for; nothing is transmitted to us
Traffic statistics, if ever enabledaggregated usage dataconsent (art. 6(1)(a)), collected in advance through the cookie banner
Meeting legal obligations and defending legal claimsdata relevant to the situationlegal obligation / legitimate interest (art. 6(1)(c) and (f))

How long we keep data

  • Server logs — normally up to 30 days, except where a security investigation requires longer.
  • Contact form messages — for the duration of the correspondence and, afterwards, no more than 2 years, so we can pick up an earlier conversation.
  • Browser preferences — they stay on your device until you clear them (see below).
  • Your cookie choice — 12 months, after which we ask again.

Once those periods pass, data is deleted or anonymised, unless the law requires us to keep it longer.

Who else has access

We do not sell or rent personal data. The following categories of recipients may process it, strictly in order to provide their service to us:

  • the hosting and content delivery provider, which processes HTTP requests and keeps technical logs;
  • the infrastructure serving our plan data and images (flags, provider logos) — loading them means a request from your browser to that server, which therefore sees your IP address;
  • the exchange-rate service — the call is made from our server, not from your browser, so the rate provider never sees your IP address;
  • public authorities, where the law requires it.

When you press "Buy" you are taken to the provider's own site. From that moment you are on another company's website: it is an independent controller with its own privacy policy and its own cookies, including affiliate ones. We encourage you to read it before buying.

Transfers outside the European Economic Area

Some of our infrastructure providers may process data outside the EEA. Where that happens, the transfer relies on the safeguards in Chapter V GDPR — an adequacy decision of the European Commission or the Standard Contractual Clauses. Write to us if you would like details of the safeguards that apply.

Your rights

As a data subject you have the right to:

  • access your data and receive a copy (art. 15);
  • rectification of inaccurate data (art. 16);
  • erasure — the "right to be forgotten" (art. 17);
  • restriction of processing (art. 18);
  • data portability, in a structured, commonly used format (art. 20);
  • object to processing based on our legitimate interest (art. 21);
  • withdraw consent at any time where processing relies on it, without affecting the lawfulness of processing before withdrawal;
  • not be subject to automated decision-making — we take no automated decisions with legal effect and carry out no profiling.

To exercise any of these, write to us through the contact form. We reply within one month of receiving the request; for complex requests that period can be extended by two months, in which case we will tell you.

If you are not satisfied with our answer, you may lodge a complaint with the data protection supervisory authority in your country of residence, or with the Romanian authority ANSPDCP, B-dul General Gheorghe Magheru 28-30, Bucharest, dataprotection.ro — and to go to court.

Security

The site is served exclusively over an encrypted connection (HTTPS), and access to the systems holding data is limited to the people who need it. We apply reasonable technical and organisational measures to protect data against loss, unauthorised access and disclosure. No method of transmission over the internet is 100% secure, so we cannot guarantee absolute security.

Children

This site is not directed at children under 16 and we do not knowingly collect their data. If you are a parent or guardian and believe a child has sent us personal data, write to us and we will delete it.

Changes to this policy

We may update this policy when the way the site works, or the legal requirements, change. The version in force is always the one published here, with the last-updated date shown at the top. If a change is significant, we will say so visibly on the site.

Cookie policy

This section is part of the privacy policy and explains what is stored in your browser when you use eSimList.

Cookies and local storage — the difference

A cookie is a small file a site saves on your device and which is sent back to the server with every request. Local storage also saves on your device, but the information never leaves the browser. Both fall under the same consent rules, which is why they are covered together here.

What we actually store

eSimList sets no cookies at all. Everything we use is three entries in your browser's local storage:

NameTypeWhat it doesLifetime
esimlist:currencynecessaryRemembers the currency you want prices in, so you do not pick it again on every visit.until you clear it
esimlist:ratesnecessaryA local copy of the exchange rates, refreshed every 12 hours, so prices render instantly.until you clear it
roaming:consentnecessaryRemembers your choice in the cookie banner, so you are not asked on every page.12 months

All three are first-party: they belong to this site, not to a third party.

Third-party cookies

We load no tracking scripts, ad networks or social buttons that set cookies. Fonts are served from our own domain, not from Google Fonts. Images on the pages (flags, provider logos, article covers) load from our content server — that sets no cookies, but, as with any request on the internet, that server sees your browser's IP address.

This changes the moment you press "Buy" and land on an eSIM provider's site: their cookie policy applies there, and some links are affiliate links, so the provider may set a cookie recording that you came from us.

Usage statistics

We currently use no traffic analytics service at all. If we add one, it will run only for visitors who agree in the cookie banner, and the table above will be updated before it launches.

Changing your choice

You can revisit your banner choice at any time using the "Cookie settings" link in the footer of every page. Withdrawing consent is as easy as giving it.

Clearing what is already stored

Clearing your browsing data ("cookies and other site data") removes the entries above. Official instructions: Chrome, Safari, Firefox, Edge. Note that afterwards the site will forget your preferred currency and will ask for your consent again.