Privacy policy
What we collect, why, and your rights under Thailand's PDPA.
Last updated September 5, 2026

What we collect
- Email and order details, so we can deliver the eSIM and support you afterwards.
- Payment data is handled by the payment provider; we do not store full card numbers.
- Site usage statistics through Google Tag Manager and Google Analytics, to improve the site.

Your rights
- Request access to, correction of, or deletion of your data.
- Withdraw consent for marketing email.
- Contact us about personal data at esimonline.asia@gmail.com
Who this policy applies to, and when
This policy applies to everyone who visits this site, whether you only came to check a price without buying anything, or you bought a plan and later contacted support about it. It covers data collected automatically when you open a page, through to data you type in yourself when ordering or reaching out to us. Every plan on this site is sold by us directly, through suppliers we connect to ourselves, so there is no other seller collecting your order data outside this policy.
Data collected while you are just browsing
While you are browsing without having ordered anything, we collect anonymous usage data, such as which pages get opened often, or where most people drop off before completing a purchase. This helps us see which parts of the site are hard to read or awkward to use, without needing to know who any particular visitor is. The specific cookies used to collect this data are described separately in our cookie policy.
Data collected when you place an order
When you place an order, we collect your email and order details, so the eSIM reaches the right person and so support can look up your order history if you contact us later. If you contact support and describe your handset — brand, model, OS version — we keep that information only to help resolve the issue you reported, not for any other purpose.
Data your payment provider handles, not us
During checkout, your card or payment-method details are handled by the payment provider you chose, not by us directly. We do not keep full card numbers in our own systems. What we see is only the outcome — whether the transaction succeeded. If you have a question about card data your payment provider holds, you would contact that provider directly, since we cannot access that part of it.
Why we collect each type of data
| Data | Collected for | Example use |
|---|---|---|
| Email and order details | Delivering the eSIM and supporting you afterwards | Sending the QR code to the email used to order |
| Handset details you tell support | Resolving the specific installation issue you reported | Checking which steps your handset model supports |
| Site usage data collected through Google Tag Manager and Google Analytics | Improving how clear a page reads | Seeing where readers drop off before completing a purchase |
The bases we rely on to process your data
Data needed to deliver an eSIM and support it afterwards is collected because it is necessary to fulfil the order you asked for, not because we ask for separate consent every time. Marketing email unrelated to an order you already hold is sent only where you have agreed to it, and you can withdraw that agreement at any time without affecting your right to the eSIM you already bought. Site usage data collected through Google Tag Manager and Google Analytics rests on the basis that it is needed to maintain and improve a working site. We do not identify you from it ourselves, but Google receives the data those services normally receive, including an IP address and cookie identifiers.

How long we keep your data
We keep data only for as long as the purpose it was collected for actually requires, not indefinitely for no reason. Order data is kept long enough to support after-sales care and any related accounting requirement. If you ask us to delete your data and there is no legal reason to keep it further, we act on that request.
Who else may see your data
Beyond our own team, some data is processed by the providers we actually use to run the business: Stripe for taking payment, Resend for sending order email, eSIM Access as the supplier that issues the eSIM profiles, Vercel for hosting this site, and Google Tag Manager with Google Analytics for site usage statistics. Each sees only what its job needs — Stripe sees the payment, eSIM Access sees only what issuing a profile requires — not the full picture of your account, and none is entitled to use the data for any purpose beyond what is agreed with us.
Your rights over your personal data
| Right | What it means |
|---|---|
| Access | Ask what data we hold about you |
| Correction | Ask us to fix inaccurate data, such as an email mistyped at checkout |
| Deletion | Ask us to delete data where there is no legal reason to keep it |
| Withdraw consent | Stop marketing email at any time without affecting an existing order |
| Object to certain processing | Tell us not to use certain data beyond what an order strictly requires |
How to exercise these rights
- 1Send us your requestMessage us via LINE at https://lin.ee/skDPoNx (@esimonline) or email at esimonline.asia@gmail.com, stating which right you want to exercise and the email you ordered with.
- 2We verify it is really youSo nobody else can request access to or deletion of your data on your behalf, we may ask for extra order details to confirm it is you.
- 3We act on the requestIf the request is clear and nothing legally limits it, we carry it out. If something does limit it, we explain exactly what.
- 4We confirm back to youWe do not let a request go unanswered. Even where the answer is that it cannot be done in full, we say why.
Data from children
This site is intended for people who buy and set up an eSIM themselves. We do not knowingly collect data specifically from children. If you are a parent and believe your child provided us with personal data without your knowledge, contact us through the channels below, and we will look into it and remove the data if that turns out to be the case.
How we keep data secure
We limit who on the team can access order data to those who genuinely need it for their work, not everyone equally. We use measures appropriate to this kind of data both in transit and in storage. Even with our best effort, no system is completely secure. If you suspect your account or data has been accessed without authorisation, tell us right away through the channels below.
Marketing email and how to opt out
If you previously agreed to receive newsletters or promotions, you can withdraw that agreement at any time without affecting your right to receive or use an eSIM you already bought. Withdrawing consent does not stop emails necessary to fulfil an order, such as the QR code or a payment issue notice, since those belong to fulfilling the order, not to marketing.

Changes to this policy
We update this policy when how we collect or use data genuinely changes, not on a fixed schedule. A change affecting your rights moves the updated date shown at the top of this page. Where a change is material — bringing on a new service provider with access to order data, for instance — we try to let you know through a channel you have previously used to reach us.
Cookies and related policies
Details of every cookie category this site uses — necessary, analytics, and the ones set by a payment provider — are explained separately in our cookie policy. Purchase and refund terms sit in our terms of service and refund policy respectively. Reading these together gives the fuller picture of how your data is handled across the whole journey of using the site.
Data from the contact form and general questions
If you message us a general question before ordering anything — whether a certain model supports eSIM, say — we keep only what you typed and the channel you used, so we can reply through the right one. We do not automatically link this to a future order history. If you later buy using a different email from the one you first asked with, the two are not connected unless you tell us yourself.
Using data to guard against fraud and abuse
Some order data is used to watch for unusual patterns — repeated attempts to place many orders in a short time using a payment method that keeps failing, which can signal fraud. This use is limited to protecting the system and other buyers from harm; it is not used to build a personal behavioural profile of you for marketing, and it is not shared with any outside party unrelated to preventing this specific kind of problem.
Your right to receive your data in a portable form
Beyond the access, correction and deletion rights listed above, you can also ask for a copy of your order data in a format you can read and reuse elsewhere — a file that opens in an ordinary spreadsheet program, for instance. This is useful if you want to keep your own purchase history beyond what we hold, or want to carry it over to a different service. A request like this uses the same channel as a general access request.
What happens to your data if you never come back
If you order once and never come back to buy again or contact us further, that order data still sits with us for as long as the original purpose requires — supporting you if you return about that same order later, or meeting a related accounting requirement. We do not automatically delete data the moment it goes quiet, but we do not keep it forever without reason either. If you want it deleted sooner than that, you can send a request through the channels stated on this page.
Using your own data across several devices or browsers
If you open this site from a phone to place an order, then later open it from a computer to contact support about that same order, the two visits only connect once you provide a shared reference — your email or order number. The system does not automatically link data across devices simply because it happens to be the same person, since linking across devices without a reference you provided yourself risks guessing wrong about whether it is the same person or someone else entirely.
- Check that the email you order with is typed correctly, since the QR code is sent there
- Do not share your QR or activation code with anyone, even while asking for help
- If you want to withdraw consent for marketing email, you can do so any time without affecting an existing order
- If you want to request access, correction or deletion, have the email you ordered with ready before you contact us
FAQ
Can I ask what data you hold about me?+
Yes. Send the request via LINE at https://lin.ee/skDPoNx (@esimonline) or email at esimonline.asia@gmail.com with the email you ordered with, so we can verify it is you before responding.
If I ask you to delete my data, does my past order disappear too?+
Data that accounting requirements say must be kept for a period stays in place under that requirement. The rest, with no reason to keep it further, is deleted as requested.
Does this site store my card details?+
No, not the full card number. Card data is handled by the payment provider you choose. We only see the outcome — whether the transaction succeeded.
I changed my mind about marketing email. What do I do?+
Tell us via LINE or email any time. We stop marketing email immediately, without affecting your right to receive or use an eSIM you already bought.
If I am unhappy with how you handled my request, what can I do?+
Tell us through the same channel first, so we can put it right. If you remain unhappy, you retain the right to complain to Thailand's personal data protection authority.
Instagram and TikTok have no web share button, so we open your phone's share sheet or copy the link instead.