Nainstalujte před odletem, připojte se ihned po přistání — 210+ destinací
eSIMonline

How is my eSIM data stored?

Author: eSIMonline Editorial · eSIMonline editorial teamNaposledy aktualizováno: 6. září 2026
How is my eSIM data stored?

Activation codes and QR images are treated as sensitive order data: they are shown only to the order's account or a holder of the order link, and supplier credentials never appear in the frontend. Never post your QR publicly — whoever installs it first gets the plan.

This page explains how your eSIM data — the activation code, the QR image, and the plan detail behind it — is handled within our system, who is entitled to see it, and what you can do to stop it landing in the wrong hands by accident. Unlike a physical SIM, which needs to be physically stolen, eSIM data can leak simply through a screenshot or a link shared in the wrong place.

This is written for anyone wondering exactly who can see their QR, anyone who has read about a QR being shared in public and wants to understand what that actually means, and anyone wanting to know the very first thing to do if they suspect their own data has been exposed.

How is my eSIM data stored?

What counts as sensitive data

The activation code and QR image are treated as the most sensitive order data in our system, because they are the only thing needed to install that plan on any device at all. Unlike a customer name or a destination country, which cannot be acted on by themselves, the code and QR sit in a higher tier of importance than the rest of the order's detail.

Related information such as the email used to buy, the purchase date and the top-up history also counts as personal data, but the risk differs, because none of that can be used to install a profile on someone else's behalf. What we treat with particular care is stopping the activation code itself leaking out by accident.

Who can see this data

We show the activation code and QR only to the account that owns that order, or to whoever holds the order's own link directly. No page on the site displays your code to anyone else without going through one of those two routes. That means anyone holding your order link in their hand can open the QR just as you can, even without ever signing in with your email at all.

The order link should be treated with exactly the same secrecy as the QR itself, since it opens the same code without needing your account password at all. Do not paste it into a public chat group or attach it to any post a stranger could reach.

Why supplier credentials never appear on the frontend

Behind the scenes, issuing each eSIM involves a connection to the supplier system that provides that profile, and that connection needs its own credentials to function. Those credentials are never surfaced on any page you see. What you see is only the end result — the QR and activation code for the plan you bought.

The separation exists for a straightforward reason: if something goes wrong on the customer-facing side, it does not directly touch the supplier's own backend, and conversely, a supplier-side issue does not require their credentials to ever appear on a page a customer can reach.

The QR behaves like a first-come credential

The single most important point to understand is that a QR not yet installed is not automatically bound to you personally. It binds to whoever scans it or enters the code first, whether or not that happens to be you. Posting a QR image publicly, even just to show off which plan you bought, carries a genuine risk that someone else installs it before you do.

The one point at which the QR stops carrying this risk is once installation has succeeded, since a profile normally cannot be installed a second time. Once installed, the original QR image is no use to anyone else for reactivating that plan. Before that point, treat the QR as being worth exactly as much as cash — whoever picks it up first gets to spend it.

If you have already shared a QR by accident

If you accidentally send the QR or order link to someone who should not have it, the first thing to do is check that profile's status in your order history. If it is not yet installed, install it yourself immediately before anyone else can scan it, or, if you genuinely no longer intend to use that plan, contact us to explain the situation.

We cannot promise in advance that a replacement profile can always be issued in every case, since it depends on that particular supplier's own terms. Contacting us as quickly as possible keeps more options open than waiting does.

Protecting yourself on a shared device

If you open the order page from a work computer, an internet café, or someone else's device, sign out the instant you finish, and check that the browser has not been set to remember the password or to leave the page open in a tab. Whoever uses that device after you will see exactly what you can see.

On your own personal device, the main risk is usually not a stranger but an accidental screenshot share — sending a friend photos from an album that also happens to contain the QR, or uploading that same image to social media without remembering it sat in the same album.

How is my eSIM data stored?

What we ask you to avoid

  • Do not post an uninstalled QR image to social media or a public group
  • Do not send the order link to anyone other than the actual user of that plan
  • Do not let a browser remember the password on a device shared with others
  • Do not keep a QR image inside an album that is shared publicly
  • Do not delete a profile without being sure no validity or allowance remains, since removal is usually irreversible

Your data once the trip is over

Once a plan has expired or been used up, the order's detail remains in your account so you can look back at it later — for example, when you need the receipt afterwards. The installed eSIM profile on the device, however, cannot be brought back into service again, even though it may still appear listed among the phone's devices.

If you would like us to review or remove any part of your data for personal reasons, contact us directly and explain what you need. We will tell you honestly which parts can be actioned and which must be retained under the requirements of the transaction itself.

Telling our part apart from what is beyond our control

AreaWhose responsibility
Showing the activation code and QR on the siteUs, controlling who can see it via the account or the order link
Security of the network the profile connects toThe mobile network operator at the destination
Protecting your own browser and passwordYou, such as signing out on a shared device
The supplier system that issues the profileThe supplier, whose own credentials we never expose on the site
We cannot confirm a destination network's own security measures on that operator's behalf. Questions about a network's security are best directed straight to that network operator.

Reporting something you suspect

  1. 1Stop using the old link at onceIf you suspect the order link or QR has leaked, do not forward or reopen that same link again until you have checked its status first
  2. 2Check the status in order historySee whether the profile has already been installed, to judge how real the risk actually is
  3. 3Contact us with the order numberExplain whatever detail you have through phone, LINE or email, describing what you believe happened
  4. 4Wait for our reply and follow the guidanceWe check with the supplier as far as we are able and tell you honestly what options are available

Často kladené otázky

Security has a side you control, not just a side we do

When people think about the security of eSIM data, they picture what a provider does behind the scenes. That part matters. But in practice, the events that actually cost a customer their plan rarely start in the system. They start when a QR image is forwarded into a group chat, when an order link is parked in a note shared with someone else, or when a phone is handed over and somebody scans the code out of curiosity and taps install. This page is about the side you control, alongside the side we look after.

The distinction to grasp early is that an eSIM profile does not behave like a password you can rotate after a leak. It behaves much closer to a single-use ticket. Once the profile has been downloaded onto one device, the same code usually cannot be used again. So a leak does not mean "someone might be able to read your data" — it means "your plan may already have been consumed". That is far harder to undo after the fact, and it is why we press this point harder than the technical-sounding question usually invites.

Before you send a QR image to anyone, pause on one fact: whoever receives that image can install the plan in your place immediately — no password, no identity check, no further approval from anybody. This is not a theoretical caution; it is simply how eSIM provisioning works.
How is my eSIM data stored?

After payment you receive a link that opens your own order. Many people read it as an ordinary electronic receipt and treat it the way they would treat a paper one: forward it to a friend, drop it in a shared chat, paste it into the trip document everyone in the group can open. The problem is that the link does not only show an amount paid. It shows the installation details too, so anyone holding the link can see what they would need in order to install.

A safer mental model is a hotel room key. You might hand it to the person staying in the same room, but you would not photograph it for social media and you would not leave it where a stranger could pick it up. The same principle applies here. If you genuinely need to share the link, share it with the person the plan belongs to, and send it through a private channel rather than a group one.

What you are holdingHow to treat itWhat a leak means
The order linkKeep it as private as a password; share only with the plan's ownerWhoever holds it may reach that plan's installation details
The installation QR imageNever post it publicly, never drop it in a group, never let someone scan it out of curiosityWhoever installs first takes the plan, and it usually cannot be recovered
The text activation stringTreat it exactly like the QR image — it is the same data in another formThe same outcome as a leaked QR; being text makes it no safer
The order confirmation emailKeep it in a private mailbox; avoid auto-forwarding rules that copy it elsewhereAnyone in that mailbox can follow through to the order link
The order number on its ownFine to quote when you contact usA number alone is not installation data, though there is still no reason to publish it

How sensitive each thing you receive after ordering actually is

Order details travel to you through the email address typed at checkout. One wrong character and they land in a stranger's inbox or nowhere at all. If that address is a shared household or workplace account, everyone who can open the mailbox can see your order too. The security of your plan is therefore bound to the security of that mailbox, and the two cannot be separated.

The simple advice is to reread the address before you pay, especially when typing on a phone in an airport queue. Where possible use a personal mailbox only you can open, rather than a company or tour-group address, because if something goes wrong mid-trip you are the one who will need to open that mailbox from abroad.

If you notice a mistyped address after paying, do not wait for travel day. Message us on LINE at https://lin.ee/skDPoNx (@esimonline) or email esimonline.asia@gmail.com with details that identify the order — the order number, the amount, and roughly when you paid — so we can look into it as quickly as we are able.

What we ask for when you contact us about an order

When a customer writes in because installation failed or asks us to resend a QR, we first need to know we are talking to the order's owner. We do that by asking for details an outsider is unlikely to have: the order number, the email used to buy, the amount paid, or roughly when the transaction went through. That set is proportionate to this kind of product without demanding more than the situation needs.

What we do not ask for matters just as much. We never ask for your email password, never ask for a bank OTP, never ask for a full card number, and never ask you to install a remote-control app so we can drive your phone. If a message using our name asks for any of those, treat it as not from us and do not reply.

  1. 1Gather the order details before you writeOpen your confirmation email or your order link and note the order number, the email used to buy, and the amount paid. Having all of it in the first message cuts the number of back-and-forth rounds, which matters a great deal when you are abroad and only online in short windows.
  2. 2Describe what you actually see, not your conclusionInstead of writing that the plan does not work, say what the screen actually said, which step it stopped at, whether the profile name appears on the device yet, and whether any network signal shows. Those details separate an installation problem from a settings problem from a network problem at the destination.
  3. 3Send only the screenshots that are neededA screenshot of the error message, or of the list of profiles on the device, usually helps a lot. You do not need to send the QR image back to us: once you give the order number we already have the order. Passing a QR through chat adds risk without adding anything useful.
  4. 4Write through a channel that is genuinely oursWe have three channels: LINE at https://lin.ee/skDPoNx (@esimonline), email at esimonline.asia@gmail.com, and the two phone numbers we publish ourselves, 089-942-0818 / 088-521-6848. We do not call customers first, so if a call comes in claiming to be our support desk without you having dialled out to us, that is not us and the conversation should stop there.
  5. 5Wait for a reply instead of retrying the install repeatedlyRepeatedly retrying an install while you wait can change the profile's state and make it harder to diagnose. If a step has already failed, record the message it gave and let us look before you try again — in many cases that turns out to be the faster route.

Screenshots of a QR and automatic cloud photo backup

Plenty of people screenshot the QR as a safeguard, which is understandable and genuinely useful when you cannot get online. Be aware of the side effect, though: that image joins your photo library, and if automatic photo backup is switched on, it is uploaded to your cloud account as well. The security of the QR quietly becomes the security of that cloud account.

This is not a rule against screenshots; it is a reason to tidy up afterwards. Once the profile is installed and the device is holding a signal, that QR image is of almost no further use to you. Deleting it from the library and from the recently-deleted album is a small step that shrinks the exposed surface considerably — particularly if you are in the habit of sharing trip albums with travel companions.

Shared albums with travel companions deserve extra care: a screenshot of a QR saved by reflex is synced automatically to everyone in the album. In many cases the plan's owner never meant to share it at all — the shared album was simply set up before the trip began.

Buying for someone else, or travelling as a group

Buying plans for a parent, a child, or a whole tour group is completely normal and perfectly fine. It just needs a system from the start, because the moment one person holds several orders, the odds of sending the wrong QR to the wrong traveller rise sharply — and once the wrong person has installed it, the fix is rarely as simple as resending, since that profile has genuinely been used.

What works is a pairing list written before departure: which order belongs to which traveller, on which device model, for which country. Then send the installation details one to one, never into the group. Sending individually takes slightly longer and removes almost every failure that cannot be reversed, while leaving each person in no doubt about which code is theirs.

Pros

  • Sending installation details one to one leaves no doubt about who received what
  • A pairing list of order to traveller makes it possible to trace back when someone's install fails
  • Having each person install on their own device while still on home Wi-Fi

Cons

  • Dropping every QR into one group chat invites travellers to install each other's codes
  • Letting one person hold every order link with no copy anywhere else
  • Leaving installation until the arrivals hall, where there is often no connection to do it with

Borrowed phones, phones going in for repair, and phones you are about to sell

An eSIM profile lives on the device, not in your account. That makes any change of hands something to think about in advance. If you install a profile on a phone borrowed from a friend, it stays with that phone until it is deleted, and whoever holds the phone next will see the profile listed in settings.

Before a phone goes for repair, before you return a borrowed one, and before you sell one, check the list of profiles and remove the ones that are yours. Where that menu sits varies by manufacturer and OS version; it is generally somewhere under mobile network or SIM settings, but the wording differs between brands. Look for a heading about cellular plans or eSIMs and open the list inside it.

Deleting a profile is usually irreversible, and many plans cannot be reinstalled with the same code afterwards. So do not delete one for the sake of tidiness in the middle of a live trip. Remove it when the trip is over, or when you are certain the plan is finished with.
How is my eSIM data stored?

Installing over public Wi-Fi

Many people install a profile at an airport or a café, because that is where the free Wi-Fi is. In practice this usually goes fine, but two cautions are worth holding. First, some public networks block certain kinds of connection or force a browser sign-in first, which can stall a profile download halfway. Second, you may end up opening your email or your order link on a network you do not control.

The tidier route is to install at home on Wi-Fi you trust, then activate on arrival. If you must install at the airport, pick the network the airport itself operates rather than a similarly named one of unknown origin, and avoid signing into other important accounts in the same session.

What appears on your device once installation is done

After installation you will see a new profile entry in your device settings, carrying either a system-assigned name or one you chose. Some devices also display an identifier for the profile. All of this sits on your own device and is not exposed publicly — but anyone holding your phone can see it if they open that settings screen.

In practice, what is visible on the device after installation does not let anyone install in your place, because the download step has already happened. The genuinely sensitive item is an installation code that has not yet been used. That is why we ask you to guard the QR most carefully in the window before installing, rather than worrying about what shows on screen afterwards.

Scam messages that use an eSIM shop's name

As more buying moves online, so do messages pretending to come from a shop. The common shapes are a warning that your order has a problem and needs urgent verification, or a claim that a refund is waiting if you just enter your card details. The check that always works is to look at what the message asks for. If it wants a password, an OTP, or a full card number, it is not us, however convincing the wording.

The channel is another tell. We have only LINE at https://lin.ee/skDPoNx (@esimonline), email at esimonline.asia@gmail.com, and the phone numbers we publish ourselves, 089-942-0818 / 088-521-6848. We run no call centre and we do not call customers first. If a call comes in claiming to be our eSIM support desk without you having dialled out to us, hang up and check through a channel you opened yourself from our site rather than a link inside the message you received.

  • Check whether the message asks for something we never ask for — a password, an OTP, or a full card number
  • Do not tap links in a message you were not expecting; open our site yourself and reach the contact page from there
  • Match the LINE account name against @esimonline before sending anything
  • Be wary of messages pushing you to decide within minutes; urgency is the main tool of a scam
  • When unsure, ask us directly through a channel you opened yourself before acting on the message
  • Keep a screenshot of anything suspicious; it makes it easier for us to look into it

If the phone is lost mid-trip

If a phone is lost, the eSIM profiles installed on it go with it. They do not follow your account onto a replacement device. In the general case the same plan cannot be installed on a new phone because its code has already been used — though this does depend on the supplier behind the plan, so it is a case-by-case question.

What you can do straight away is write in with the order number so we can check the state of that plan and tell you honestly what options exist. In the meantime, deal with the accounts tied to the device — remote-locking it, changing passwords on important accounts — which is a much larger matter than the data plan itself.

Keeping your order data, and asking for it to be removed

Order data has to be kept for a period so that after-sales support remains possible — when you come back with an installation question, or ask us to check a plan's status. If everything were erased the moment a plan was delivered, we could not help you at all when something went wrong mid-trip. That is the practical reason behind keeping it, rather than keeping it for its own sake.

If you want your data removed, send the request to esimonline.asia@gmail.com along with enough detail to show the order is yours. We will tell you plainly what can and cannot be removed, since some records — those held by the payment provider, for example — sit outside our systems, and removing an order record necessarily means we can no longer provide after-sales support on that order.

SituationDo this firstAvoid this
A friend asks to see your QR out of curiosityDescribe it, or show an example image from our installation guide insteadSending your real QR image, even to a close friend
You want someone to help you install because devices are not your strengthLet them help with the phone in your hands, where you can see every stepSending the QR for them to install on their own phone and sorting it out later
Buying for several family members at onceWrite down which order belongs to whom before sending anythingDropping every QR into the family chat and letting each person pick
The trip is over and the plan is finished withDelete QR screenshots from the library and the recently-deleted albumLeaving the image sitting in an album shared with other people
A message using our name asks for extra detailsOpen our site yourself and write through the channel you reach from thereReplying to that message directly or tapping the link it carries

Common situations and the safer path through each

Separating what we handle from what lies outside our reach

We look after how order data is shown on the site, how installation details reach the buyer, and answering questions after the sale. Outside our reach are the security of the mailbox you use, the security of the phone in your hand, and the choices you make about sharing. We cannot pull a profile back off the device of whoever installed it, and there is no button that makes a leaked QR usable again.

Saying this plainly is more useful than a broad reassurance, because it tells you where the effort actually pays. The highest-return window is the one before installation, while the code is still unused. Get through that cleanly and the remaining risk drops sharply.

Small habits that genuinely help across a trip

Durable security does not come from one big gesture; it comes from small habits repeated. Install at home on a network you trust. Name the profile clearly on day one. Keep the order link in one place you can find. Delete the screenshot once it has done its job. Together these take a few minutes and remove most of the failures that are hard to undo.

If you travel often, turning these into a routine helps even more: when you are not reinventing the process each time, mistakes made in a hurry become less likely. And most of the errors we see come from hurry rather than from not knowing.

Časté dotazy

Can support staff see my full activation code when I ask for help?+

To help investigate your order, staff need to be able to access the order detail, including the installation data, through internal systems. That information is never published publicly and is not shown on any page to anyone else.

Once I have installed it, do I still need to worry about someone seeing the old QR?+

The main risk drops considerably, since a profile normally cannot be reinstalled. It is still worth not publishing the QR image publicly without reason, since other order detail can sit in the same image.

Where is my card information kept when I pay?+

This page covers eSIM data specifically — the activation code and QR. For any question about payment information itself, please contact us directly to ask.

My phone was lost — will the installed profile move itself to a new device?+

No, since the profile is bound only to the device it was installed on. If the phone is lost, contact us with the order number so we can check what is possible, without promising in advance that a replacement can always be issued.

Can I ask for my account and all my data to be removed?+

Contact us to explain what you would like. We will check which parts can be removed and which must be kept under the requirements of the transaction, and reply with the outcome.

Does the order link expire by itself after a while?+

The exact behaviour can vary by order. If you are unsure whether your original link still opens, sign in with the account instead, or contact us for a fresh one.

If a travel companion asks to see my QR, how do I do that safely?+

Let them look at your own screen directly rather than sending the image or link for them to keep on their device. This cuts the chance of it being saved, forwarded or posted later by accident.

Why is the QR not shown directly in the confirmation email without clicking a link?+

Opening it through a link rather than embedding the image directly limits who can reach the code, since an email can be forwarded or opened on another device more easily than a link tied directly to that specific order.

I have already sent my QR to someone else — what do I do first?+

Contact the recipient immediately and ask them to delete the image and not tap install — as long as nobody has installed it, your plan is still intact. Then install it on your own device if you are in a position to, because a profile is usually single-use and whoever installs first keeps it. After that, tell us the order number so we can check the plan's state and give you a straight answer about what options remain. We will not promise in advance that a fresh code can always be issued: that depends on the supplier behind the plan and on the profile's state at that moment.

Can I keep the QR image on my phone, or should I delete it right after installing?+

Keeping it is reasonable before installation and while you are still unsure the install completed, since a dropped connection sometimes means restarting the process. Once the profile is in place and the device is holding a signal at the destination, the image is of almost no further use to you. Deleting it from the library and the recently-deleted album removes the risk of accidental sharing — worth doing especially if automatic photo backup is on or you share albums with travel companions.

Why does the site not show the supplier's credentials when I am the one who paid?+

Because supplier credentials are a different thing from your installation details. What you actually need is the code that provisions the profile on your device, and that is delivered to you in full. The credentials that connect our systems to a supplier would not make your plan work any better, yet a leak of them would affect other customers' orders as well. Keeping them off the frontend protects every order at once, rather than withholding something you are entitled to.

If I change to a new phone mid-trip, can the plan move with me?+

Generally it cannot. The profile is tied to the device it was installed on, and the original code usually cannot be reused. Whether anything is possible depends on the supplier behind that particular plan. If you know in advance that you will switch devices, install on the phone you intend to carry for the whole trip. If the switch is forced by a lost or broken handset, tell us the order number so we can check the state and describe the options that genuinely exist in your case.

How can I tell whether a message claiming to be from you is genuine?+

Look at two things: the channel and the request. Our channels are LINE at https://lin.ee/skDPoNx (@esimonline), email at esimonline.asia@gmail.com, and the phone numbers we publish ourselves, 089-942-0818 / 088-521-6848 — we do not call customers first. As for the request, we will never ask for an email password, an OTP, a full card number, or for you to install a remote-control app. Anything outside that is not us. The safest check is to open our site yourself and reach the contact page from there, rather than tapping a link inside the message.

I bought a plan for someone else — what is the safest way to send the installation details?+

Send it one to one, in a private chat with the person the plan belongs to. Do not put it in a group, even a family or tour group where everyone knows each other — the main risk is not a stranger, it is two members installing each other's codes by accident. Before sending, write down which order belongs to whom and for which country, and have each traveller do the install themselves on their own device while still on home Wi-Fi. That removes most of the trouble that would otherwise surface on arrival.

Share this page

Instagram and TikTok have no web share button, so we open your phone's share sheet or copy the link instead.

Related