How is my eSIM data stored?

Activation codes and QR images are treated as sensitive order data: they are shown only to the order's account or a holder of the order link, and supplier credentials never appear in the frontend. Never post your QR publicly — whoever installs it first gets the plan.
This page explains how your eSIM data — the activation code, the QR image, and the plan detail behind it — is handled within our system, who is entitled to see it, and what you can do to stop it landing in the wrong hands by accident. Unlike a physical SIM, which needs to be physically stolen, eSIM data can leak simply through a screenshot or a link shared in the wrong place.
This is written for anyone wondering exactly who can see their QR, anyone who has read about a QR being shared in public and wants to understand what that actually means, and anyone wanting to know the very first thing to do if they suspect their own data has been exposed.

What counts as sensitive data
The activation code and QR image are treated as the most sensitive order data in our system, because they are the only thing needed to install that plan on any device at all. Unlike a customer name or a destination country, which cannot be acted on by themselves, the code and QR sit in a higher tier of importance than the rest of the order's detail.
Related information such as the email used to buy, the purchase date and the top-up history also counts as personal data, but the risk differs, because none of that can be used to install a profile on someone else's behalf. What we treat with particular care is stopping the activation code itself leaking out by accident.
Who can see this data
We show the activation code and QR only to the account that owns that order, or to whoever holds the order's own link directly. No page on the site displays your code to anyone else without going through one of those two routes. That means anyone holding your order link in their hand can open the QR just as you can, even without ever signing in with your email at all.
Why supplier credentials never appear on the frontend
Behind the scenes, issuing each eSIM involves a connection to the supplier system that provides that profile, and that connection needs its own credentials to function. Those credentials are never surfaced on any page you see. What you see is only the end result — the QR and activation code for the plan you bought.
The separation exists for a straightforward reason: if something goes wrong on the customer-facing side, it does not directly touch the supplier's own backend, and conversely, a supplier-side issue does not require their credentials to ever appear on a page a customer can reach.
The QR behaves like a first-come credential
The single most important point to understand is that a QR not yet installed is not automatically bound to you personally. It binds to whoever scans it or enters the code first, whether or not that happens to be you. Posting a QR image publicly, even just to show off which plan you bought, carries a genuine risk that someone else installs it before you do.
The one point at which the QR stops carrying this risk is once installation has succeeded, since a profile normally cannot be installed a second time. Once installed, the original QR image is no use to anyone else for reactivating that plan. Before that point, treat the QR as being worth exactly as much as cash — whoever picks it up first gets to spend it.
If you have already shared a QR by accident
If you accidentally send the QR or order link to someone who should not have it, the first thing to do is check that profile's status in your order history. If it is not yet installed, install it yourself immediately before anyone else can scan it, or, if you genuinely no longer intend to use that plan, contact us to explain the situation.
Protecting yourself on a shared device
If you open the order page from a work computer, an internet café, or someone else's device, sign out the instant you finish, and check that the browser has not been set to remember the password or to leave the page open in a tab. Whoever uses that device after you will see exactly what you can see.
On your own personal device, the main risk is usually not a stranger but an accidental screenshot share — sending a friend photos from an album that also happens to contain the QR, or uploading that same image to social media without remembering it sat in the same album.

What we ask you to avoid
- Do not post an uninstalled QR image to social media or a public group
- Do not send the order link to anyone other than the actual user of that plan
- Do not let a browser remember the password on a device shared with others
- Do not keep a QR image inside an album that is shared publicly
- Do not delete a profile without being sure no validity or allowance remains, since removal is usually irreversible
Your data once the trip is over
Once a plan has expired or been used up, the order's detail remains in your account so you can look back at it later — for example, when you need the receipt afterwards. The installed eSIM profile on the device, however, cannot be brought back into service again, even though it may still appear listed among the phone's devices.
If you would like us to review or remove any part of your data for personal reasons, contact us directly and explain what you need. We will tell you honestly which parts can be actioned and which must be retained under the requirements of the transaction itself.
Telling our part apart from what is beyond our control
| Area | Whose responsibility |
|---|---|
| Showing the activation code and QR on the site | Us, controlling who can see it via the account or the order link |
| Security of the network the profile connects to | The mobile network operator at the destination |
| Protecting your own browser and password | You, such as signing out on a shared device |
| The supplier system that issues the profile | The supplier, whose own credentials we never expose on the site |
Reporting something you suspect
- 1Stop using the old link at onceIf you suspect the order link or QR has leaked, do not forward or reopen that same link again until you have checked its status first
- 2Check the status in order historySee whether the profile has already been installed, to judge how real the risk actually is
- 3Contact us with the order numberExplain whatever detail you have through phone, LINE or email, describing what you believe happened
- 4Wait for our reply and follow the guidanceWe check with the supplier as far as we are able and tell you honestly what options are available
سؤالات متداول
Security has a side you control, not just a side we do
When people think about the security of eSIM data, they picture what a provider does behind the scenes. That part matters. But in practice, the events that actually cost a customer their plan rarely start in the system. They start when a QR image is forwarded into a group chat, when an order link is parked in a note shared with someone else, or when a phone is handed over and somebody scans the code out of curiosity and taps install. This page is about the side you control, alongside the side we look after.
The distinction to grasp early is that an eSIM profile does not behave like a password you can rotate after a leak. It behaves much closer to a single-use ticket. Once the profile has been downloaded onto one device, the same code usually cannot be used again. So a leak does not mean "someone might be able to read your data" — it means "your plan may already have been consumed". That is far harder to undo after the fact, and it is why we press this point harder than the technical-sounding question usually invites.

The order link works like a key, not just a receipt
After payment you receive a link that opens your own order. Many people read it as an ordinary electronic receipt and treat it the way they would treat a paper one: forward it to a friend, drop it in a shared chat, paste it into the trip document everyone in the group can open. The problem is that the link does not only show an amount paid. It shows the installation details too, so anyone holding the link can see what they would need in order to install.
A safer mental model is a hotel room key. You might hand it to the person staying in the same room, but you would not photograph it for social media and you would not leave it where a stranger could pick it up. The same principle applies here. If you genuinely need to share the link, share it with the person the plan belongs to, and send it through a private channel rather than a group one.
| What you are holding | How to treat it | What a leak means |
|---|---|---|
| The order link | Keep it as private as a password; share only with the plan's owner | Whoever holds it may reach that plan's installation details |
| The installation QR image | Never post it publicly, never drop it in a group, never let someone scan it out of curiosity | Whoever installs first takes the plan, and it usually cannot be recovered |
| The text activation string | Treat it exactly like the QR image — it is the same data in another form | The same outcome as a leaked QR; being text makes it no safer |
| The order confirmation email | Keep it in a private mailbox; avoid auto-forwarding rules that copy it elsewhere | Anyone in that mailbox can follow through to the order link |
| The order number on its own | Fine to quote when you contact us | A number alone is not installation data, though there is still no reason to publish it |
How sensitive each thing you receive after ordering actually is
The email you type at checkout is the most overlooked link
Order details travel to you through the email address typed at checkout. One wrong character and they land in a stranger's inbox or nowhere at all. If that address is a shared household or workplace account, everyone who can open the mailbox can see your order too. The security of your plan is therefore bound to the security of that mailbox, and the two cannot be separated.
The simple advice is to reread the address before you pay, especially when typing on a phone in an airport queue. Where possible use a personal mailbox only you can open, rather than a company or tour-group address, because if something goes wrong mid-trip you are the one who will need to open that mailbox from abroad.
What we ask for when you contact us about an order
When a customer writes in because installation failed or asks us to resend a QR, we first need to know we are talking to the order's owner. We do that by asking for details an outsider is unlikely to have: the order number, the email used to buy, the amount paid, or roughly when the transaction went through. That set is proportionate to this kind of product without demanding more than the situation needs.
What we do not ask for matters just as much. We never ask for your email password, never ask for a bank OTP, never ask for a full card number, and never ask you to install a remote-control app so we can drive your phone. If a message using our name asks for any of those, treat it as not from us and do not reply.
- 1Gather the order details before you writeOpen your confirmation email or your order link and note the order number, the email used to buy, and the amount paid. Having all of it in the first message cuts the number of back-and-forth rounds, which matters a great deal when you are abroad and only online in short windows.
- 2Describe what you actually see, not your conclusionInstead of writing that the plan does not work, say what the screen actually said, which step it stopped at, whether the profile name appears on the device yet, and whether any network signal shows. Those details separate an installation problem from a settings problem from a network problem at the destination.
- 3Send only the screenshots that are neededA screenshot of the error message, or of the list of profiles on the device, usually helps a lot. You do not need to send the QR image back to us: once you give the order number we already have the order. Passing a QR through chat adds risk without adding anything useful.
- 4Write through a channel that is genuinely oursWe have three channels: LINE at https://lin.ee/skDPoNx (@esimonline), email at esimonline.asia@gmail.com, and the two phone numbers we publish ourselves, 089-942-0818 / 088-521-6848. We do not call customers first, so if a call comes in claiming to be our support desk without you having dialled out to us, that is not us and the conversation should stop there.
- 5Wait for a reply instead of retrying the install repeatedlyRepeatedly retrying an install while you wait can change the profile's state and make it harder to diagnose. If a step has already failed, record the message it gave and let us look before you try again — in many cases that turns out to be the faster route.
Screenshots of a QR and automatic cloud photo backup
Plenty of people screenshot the QR as a safeguard, which is understandable and genuinely useful when you cannot get online. Be aware of the side effect, though: that image joins your photo library, and if automatic photo backup is switched on, it is uploaded to your cloud account as well. The security of the QR quietly becomes the security of that cloud account.
This is not a rule against screenshots; it is a reason to tidy up afterwards. Once the profile is installed and the device is holding a signal, that QR image is of almost no further use to you. Deleting it from the library and from the recently-deleted album is a small step that shrinks the exposed surface considerably — particularly if you are in the habit of sharing trip albums with travel companions.
Buying for someone else, or travelling as a group
Buying plans for a parent, a child, or a whole tour group is completely normal and perfectly fine. It just needs a system from the start, because the moment one person holds several orders, the odds of sending the wrong QR to the wrong traveller rise sharply — and once the wrong person has installed it, the fix is rarely as simple as resending, since that profile has genuinely been used.
What works is a pairing list written before departure: which order belongs to which traveller, on which device model, for which country. Then send the installation details one to one, never into the group. Sending individually takes slightly longer and removes almost every failure that cannot be reversed, while leaving each person in no doubt about which code is theirs.
Pros
- Sending installation details one to one leaves no doubt about who received what
- A pairing list of order to traveller makes it possible to trace back when someone's install fails
- Having each person install on their own device while still on home Wi-Fi
Cons
- Dropping every QR into one group chat invites travellers to install each other's codes
- Letting one person hold every order link with no copy anywhere else
- Leaving installation until the arrivals hall, where there is often no connection to do it with
Borrowed phones, phones going in for repair, and phones you are about to sell
An eSIM profile lives on the device, not in your account. That makes any change of hands something to think about in advance. If you install a profile on a phone borrowed from a friend, it stays with that phone until it is deleted, and whoever holds the phone next will see the profile listed in settings.
Before a phone goes for repair, before you return a borrowed one, and before you sell one, check the list of profiles and remove the ones that are yours. Where that menu sits varies by manufacturer and OS version; it is generally somewhere under mobile network or SIM settings, but the wording differs between brands. Look for a heading about cellular plans or eSIMs and open the list inside it.

Installing over public Wi-Fi
Many people install a profile at an airport or a café, because that is where the free Wi-Fi is. In practice this usually goes fine, but two cautions are worth holding. First, some public networks block certain kinds of connection or force a browser sign-in first, which can stall a profile download halfway. Second, you may end up opening your email or your order link on a network you do not control.
The tidier route is to install at home on Wi-Fi you trust, then activate on arrival. If you must install at the airport, pick the network the airport itself operates rather than a similarly named one of unknown origin, and avoid signing into other important accounts in the same session.
What appears on your device once installation is done
After installation you will see a new profile entry in your device settings, carrying either a system-assigned name or one you chose. Some devices also display an identifier for the profile. All of this sits on your own device and is not exposed publicly — but anyone holding your phone can see it if they open that settings screen.
In practice, what is visible on the device after installation does not let anyone install in your place, because the download step has already happened. The genuinely sensitive item is an installation code that has not yet been used. That is why we ask you to guard the QR most carefully in the window before installing, rather than worrying about what shows on screen afterwards.
Scam messages that use an eSIM shop's name
As more buying moves online, so do messages pretending to come from a shop. The common shapes are a warning that your order has a problem and needs urgent verification, or a claim that a refund is waiting if you just enter your card details. The check that always works is to look at what the message asks for. If it wants a password, an OTP, or a full card number, it is not us, however convincing the wording.
The channel is another tell. We have only LINE at https://lin.ee/skDPoNx (@esimonline), email at esimonline.asia@gmail.com, and the phone numbers we publish ourselves, 089-942-0818 / 088-521-6848. We run no call centre and we do not call customers first. If a call comes in claiming to be our eSIM support desk without you having dialled out to us, hang up and check through a channel you opened yourself from our site rather than a link inside the message you received.
- Check whether the message asks for something we never ask for — a password, an OTP, or a full card number
- Do not tap links in a message you were not expecting; open our site yourself and reach the contact page from there
- Match the LINE account name against @esimonline before sending anything
- Be wary of messages pushing you to decide within minutes; urgency is the main tool of a scam
- When unsure, ask us directly through a channel you opened yourself before acting on the message
- Keep a screenshot of anything suspicious; it makes it easier for us to look into it
If the phone is lost mid-trip
If a phone is lost, the eSIM profiles installed on it go with it. They do not follow your account onto a replacement device. In the general case the same plan cannot be installed on a new phone because its code has already been used — though this does depend on the supplier behind the plan, so it is a case-by-case question.
What you can do straight away is write in with the order number so we can check the state of that plan and tell you honestly what options exist. In the meantime, deal with the accounts tied to the device — remote-locking it, changing passwords on important accounts — which is a much larger matter than the data plan itself.
Keeping your order data, and asking for it to be removed
Order data has to be kept for a period so that after-sales support remains possible — when you come back with an installation question, or ask us to check a plan's status. If everything were erased the moment a plan was delivered, we could not help you at all when something went wrong mid-trip. That is the practical reason behind keeping it, rather than keeping it for its own sake.
If you want your data removed, send the request to esimonline.asia@gmail.com along with enough detail to show the order is yours. We will tell you plainly what can and cannot be removed, since some records — those held by the payment provider, for example — sit outside our systems, and removing an order record necessarily means we can no longer provide after-sales support on that order.
| Situation | Do this first | Avoid this |
|---|---|---|
| A friend asks to see your QR out of curiosity | Describe it, or show an example image from our installation guide instead | Sending your real QR image, even to a close friend |
| You want someone to help you install because devices are not your strength | Let them help with the phone in your hands, where you can see every step | Sending the QR for them to install on their own phone and sorting it out later |
| Buying for several family members at once | Write down which order belongs to whom before sending anything | Dropping every QR into the family chat and letting each person pick |
| The trip is over and the plan is finished with | Delete QR screenshots from the library and the recently-deleted album | Leaving the image sitting in an album shared with other people |
| A message using our name asks for extra details | Open our site yourself and write through the channel you reach from there | Replying to that message directly or tapping the link it carries |
Common situations and the safer path through each
Separating what we handle from what lies outside our reach
We look after how order data is shown on the site, how installation details reach the buyer, and answering questions after the sale. Outside our reach are the security of the mailbox you use, the security of the phone in your hand, and the choices you make about sharing. We cannot pull a profile back off the device of whoever installed it, and there is no button that makes a leaked QR usable again.
Saying this plainly is more useful than a broad reassurance, because it tells you where the effort actually pays. The highest-return window is the one before installation, while the code is still unused. Get through that cleanly and the remaining risk drops sharply.
Small habits that genuinely help across a trip
Durable security does not come from one big gesture; it comes from small habits repeated. Install at home on a network you trust. Name the profile clearly on day one. Keep the order link in one place you can find. Delete the screenshot once it has done its job. Together these take a few minutes and remove most of the failures that are hard to undo.
If you travel often, turning these into a routine helps even more: when you are not reinventing the process each time, mistakes made in a hurry become less likely. And most of the errors we see come from hurry rather than from not knowing.
سؤالات متداول
Can support staff see my full activation code when I ask for help?+
To help investigate your order, staff need to be able to access the order detail, including the installation data, through internal systems. That information is never published publicly and is not shown on any page to anyone else.
Once I have installed it, do I still need to worry about someone seeing the old QR?+
The main risk drops considerably, since a profile normally cannot be reinstalled. It is still worth not publishing the QR image publicly without reason, since other order detail can sit in the same image.
Where is my card information kept when I pay?+
This page covers eSIM data specifically — the activation code and QR. For any question about payment information itself, please contact us directly to ask.
My phone was lost — will the installed profile move itself to a new device?+
No, since the profile is bound only to the device it was installed on. If the phone is lost, contact us with the order number so we can check what is possible, without promising in advance that a replacement can always be issued.
Can I ask for my account and all my data to be removed?+
Contact us to explain what you would like. We will check which parts can be removed and which must be kept under the requirements of the transaction, and reply with the outcome.
Does the order link expire by itself after a while?+
The exact behaviour can vary by order. If you are unsure whether your original link still opens, sign in with the account instead, or contact us for a fresh one.
If a travel companion asks to see my QR, how do I do that safely?+
Let them look at your own screen directly rather than sending the image or link for them to keep on their device. This cuts the chance of it being saved, forwarded or posted later by accident.
Why is the QR not shown directly in the confirmation email without clicking a link?+
Opening it through a link rather than embedding the image directly limits who can reach the code, since an email can be forwarded or opened on another device more easily than a link tied directly to that specific order.
I have already sent my QR to someone else — what do I do first?+
Contact the recipient immediately and ask them to delete the image and not tap install — as long as nobody has installed it, your plan is still intact. Then install it on your own device if you are in a position to, because a profile is usually single-use and whoever installs first keeps it. After that, tell us the order number so we can check the plan's state and give you a straight answer about what options remain. We will not promise in advance that a fresh code can always be issued: that depends on the supplier behind the plan and on the profile's state at that moment.
Can I keep the QR image on my phone, or should I delete it right after installing?+
Keeping it is reasonable before installation and while you are still unsure the install completed, since a dropped connection sometimes means restarting the process. Once the profile is in place and the device is holding a signal at the destination, the image is of almost no further use to you. Deleting it from the library and the recently-deleted album removes the risk of accidental sharing — worth doing especially if automatic photo backup is on or you share albums with travel companions.
Why does the site not show the supplier's credentials when I am the one who paid?+
Because supplier credentials are a different thing from your installation details. What you actually need is the code that provisions the profile on your device, and that is delivered to you in full. The credentials that connect our systems to a supplier would not make your plan work any better, yet a leak of them would affect other customers' orders as well. Keeping them off the frontend protects every order at once, rather than withholding something you are entitled to.
If I change to a new phone mid-trip, can the plan move with me?+
Generally it cannot. The profile is tied to the device it was installed on, and the original code usually cannot be reused. Whether anything is possible depends on the supplier behind that particular plan. If you know in advance that you will switch devices, install on the phone you intend to carry for the whole trip. If the switch is forced by a lost or broken handset, tell us the order number so we can check the state and describe the options that genuinely exist in your case.
How can I tell whether a message claiming to be from you is genuine?+
Look at two things: the channel and the request. Our channels are LINE at https://lin.ee/skDPoNx (@esimonline), email at esimonline.asia@gmail.com, and the phone numbers we publish ourselves, 089-942-0818 / 088-521-6848 — we do not call customers first. As for the request, we will never ask for an email password, an OTP, a full card number, or for you to install a remote-control app. Anything outside that is not us. The safest check is to open our site yourself and reach the contact page from there, rather than tapping a link inside the message.
I bought a plan for someone else — what is the safest way to send the installation details?+
Send it one to one, in a private chat with the person the plan belongs to. Do not put it in a group, even a family or tour group where everyone knows each other — the main risk is not a stranger, it is two members installing each other's codes by accident. Before sending, write down which order belongs to whom and for which country, and have each traveller do the install themselves on their own device while still on home Wi-Fi. That removes most of the trouble that would otherwise surface on arrival.
Instagram and TikTok have no web share button, so we open your phone's share sheet or copy the link instead.