Privacy Policy
Last updated: 3 September 2026
SIM SALABIM understands that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of all of our customers and partners and will only collect and use personal data in ways that are described here, in a way that is consistent with our obligations and your rights under the law.
1. Information About Us
1.1 SIM SALABIM is a trading name of PORTABLE DIGITAL LIMITED, a company registered in England and Wales under company number 16974578, whose registered office is at Flat 34 Quested Court, Brett Road, London, England, E8 1JS. PORTABLE DIGITAL LIMITED is the operator of the eSIM reseller service described in this notice and the controller of your personal data. Contact details: support@esim-magic.com.
1.2 We are not a mobile network operator or telecommunications provider. Data services are delivered by third-party network providers in their respective countries. Although we are not the network provider, we provide support to end users who purchase services we resell.
1.3 WE DO NOT ASSUME ANY RESPONSIBILITY AND MAY NOT BE HELD RESPONSIBLE OR LIABLE FOR CONNECTIVITY AS SUCH, ITS QUALITY, QUANTITY, DIVERSITY, COVERAGE, SECURITY OR ANY OTHER FEATURE OR OPTION A CONSUMER MAY EXPECT FROM A MOBILE OPERATOR OR PROVIDER.
1.4 We deliver our services through the Telegram bot @eSIM_MagicBot and through our website. Telegram is not owned or controlled by us. Telegram operates according to its own privacy policy available on https://telegram.org/privacy as may be amended from time to time. IF YOU DISAGREE WITH TELEGRAM'S PRIVACY POLICY, TERMS OF USE OR ANY OTHER POLICY, PLEASE DO NOT USE OUR SERVICES THROUGH TELEGRAM. You can review how to manage your privacy settings with bots here: https://telegram.org/faq#q-are-bots-safe.
1.5 Contact details: support@esim-magic.com.
2. What Does This Notice Cover?
This Privacy Notice explains how we use your personal data: how it is collected, how it is held, and how it is processed. It also explains your rights under the law relating to your personal data. It covers both ways of using our service: the Telegram bot and Mini App, and the website with its own accounts.
3. What Is Personal Data?
Personal data is defined by the General Data Protection Regulation (EU Regulation 2016/679) (the "GDPR") as 'any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier'. In simpler terms, personal data is any information about you that enables you to be identified — obvious information such as your name and contact details, but also less obvious information such as identification numbers, electronic location data, and other online identifiers.
4. What Personal Data Do You Collect and How?
We may collect and hold some or all of the personal data set out below, using the methods listed:
- Telegram account data: numeric user ID, user name, first name, last name and interface language — via the Telegram Bot API, when you open the bot or the Mini App.
- Email address and password — when you create an account on our website. The password is never stored in readable form: we keep only a one-way hash of it.
- Email address for delivery — when you buy without a Telegram account, so that we can send you the eSIM and order notifications.
- Your name — the name you type in the checkout form when you buy on our website, or the first and last name from your Telegram profile when you buy in the Mini App. Payment providers are required to identify the payer, so we pass it on to them.
- Billing address (country, city, street address and postal / ZIP code) — when you pay by card, in the checkout form of the website or of the Mini App. The bank checks it against the address the card is registered to. In the bot, where no address form is shown, we send our own merchant address instead of yours.
- Payment-related information limited to what third-party payment processors return to us (such as transaction reference, status, amount and currency). We do not collect or store full card or wallet credentials — those are entered on the payment provider's own page.
- Order data: the eSIM packages you buy and top up, their status and remaining traffic, your account balance and balance history, referral code and who invited you.
- Product usage events: which screens of the Mini App and the website you open and which steps of the purchase you complete. Stored in our own database — see section 10.
- A technical fingerprint of your request — an irreversible salted hash of your IP address and of your browser's user agent string. The IP address and the user agent themselves are not stored: only the hash is, in your account record. It is written when your account is created and when you sign in, and it is used for one purpose only — protecting the referral programme from abuse. It is removed when you delete your account.
- Support correspondence — directly from you by email or through our Telegram support channel.
PLEASE NOTE that we get access to and may collect your personal data via the Telegram bot @eSIM_MagicBot. This bot operates within Telegram under its own privacy policy available at https://telegram.org/privacy as may be amended from time to time.
5. How Do You Use My Personal Data?
We may use your personal data for the following purposes:
- Administering our business;
- Supplying our services and support to you;
- Managing payments for our services;
- Personalising and tailoring our services for you;
- Communicating with you and supplying you with information on our services.
With your permission and/or where permitted by law, we may also use your personal data for marketing purposes, which may include contacting you with information, news, and offers on our services. You will not be sent any unlawful marketing or spam, and you will always have the opportunity to opt out.
We may use automated systems to deliver and operate our services. The Telegram bot @eSIM_MagicBot is the primary automated system through which we provide our services. If at any point you wish to query an automated action or request human intervention, please contact us using the details in section 11.
We will only use your personal data for the purpose(s) for which it was originally collected unless we reasonably believe that another purpose is compatible with that or those original purpose(s) and need to use your personal data for that purpose. In some circumstances, where permitted or required by law, we may process your personal data without your knowledge or consent. This will only be done within the bounds of applicable data protection legislation and your legal rights.
6. How Long Will You Keep My Personal Data?
We will not keep your personal data for any longer than is necessary in light of the reason(s) for which it was first collected. We will keep your personal data to comply with our legal obligations, resolve disputes, and enforce our agreements unless a longer retention period is required or permitted by law.
Records of orders, payments and balance movements are kept for accounting and tax purposes even after you delete your account, but in a form that no longer identifies you. Section 9 describes exactly what is removed and what is kept.
7. How and Where Do You Store or Transfer My Personal Data?
We store your personal data in our own database, on our own servers. Data we receive through the Telegram bot @eSIM_MagicBot — your numeric Telegram user ID, user name, first name and last name — is copied into that database and kept there, because your orders, eSIM profiles, balance and referral records are attached to it. Separately from us, Telegram stores your messages with the bot under its own privacy policy at https://telegram.org/privacy.
Website accounts exist independently of Telegram: registering with an email address and a password creates a record in our database that contains that email address and a one-way hash of the password, with no involvement of Telegram at all. The same applies to an email address you give at checkout when buying on the website without an account.
Our application servers and our managed PostgreSQL database are located in Amsterdam, the Netherlands — that is, within the European Economic Area (the "EEA" — all EU member states, Norway, Iceland, and Liechtenstein). Backup copies are made daily. A local copy is kept on the same hosting provider's infrastructure, and one encrypted copy is shipped daily to an S3-compatible object storage provider (currently Cloudflare R2). That copy is encrypted on our own server before it leaves it, and the encryption key is kept separately, so the storage provider cannot read its contents.
Some of the service providers listed in section 8 operate outside the EEA — including our upstream eSIM supplier, some payment providers and the object storage provider that holds our off-site backups. These are known as "third countries" and may not have data protection laws that are as strong as those in the EEA. Where this happens, we take additional steps to ensure that your personal data is treated just as safely and securely as it would be within the EEA, and we share only the minimum data needed for that provider to do its job.
8. Do You Share My Personal Data?
We do not sell your personal data and we do not share it with advertising networks or data brokers. We share it only with the service providers we need in order to run the service, and only to the extent each of them needs:
- Telegram — the platform through which the bot and the Mini App are delivered.
- eSIM Access — our upstream eSIM supplier. It receives the package code, the quantity or duration ordered and our internal transaction reference, and returns the eSIM profile. We do not pass your name, Telegram profile or email address to it.
- Payment providers, depending on the method you choose: Crypto Bot for cryptocurrency payments, and card / SBP acquirers (Overpay, Platega, Paycot) for card and fast-payment-system payments. They receive the amount, the currency and an order reference; card acquirers additionally receive your name and the email address given at checkout, and — when you pay by card on the website or in the Mini App — the billing country, city, street address and postal / ZIP code you entered, because they are required to identify the payer and the bank verifies the billing address. Card and wallet credentials are entered on the provider's side and never reach us.
- ZeptoMail (Zoho) — the service that sends our outgoing email to website customers: confirmation and password reset codes, eSIM delivery, gift links and order notifications. It receives the recipient's email address and the content of the message.
- Our hosting provider — it operates the virtual server and the managed PostgreSQL database described in section 7, and holds the local backup copies.
- Our object storage provider (currently Cloudflare R2) — it holds our encrypted off-site backups. It receives only encrypted archives and cannot read their contents.
- Sentry — error monitoring, where enabled. It receives technical details of software errors. We have deliberately turned off the sending of personal data to it, so IP addresses, cookies and request bodies are not sent.
- Google Sheets — where enabled, an accounting export of payments for our own bookkeeping: date and time, the identifier of the buyer (your Telegram ID for purchases in the bot or the Mini App, or the email address you gave at checkout for purchases on the website), order reference, amounts and payment method.
- Public authorities, courts and professional advisers — where we are required to disclose data by law, or need to establish, exercise or defend legal claims.
Each of these providers acts under data-processing terms and may use the data only to provide their service to us. If any personal data is transferred outside of the EEA, we will take suitable steps to ensure that it is treated just as safely and securely as it would be within the EEA.
9. What Are My Rights and How Do I Use Them?
Under data protection law you have the following rights in relation to your personal data:
- Access — to be told whether we hold personal data about you and to receive a copy of it.
- Rectification — to have inaccurate personal data corrected and incomplete data completed.
- Erasure — to have your personal data deleted. You can do this yourself at any time, see below.
- Restriction — to ask us to limit how we use your personal data while a dispute about it is being resolved.
- Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time, with no reason required.
- Portability — to receive the personal data you gave us in a structured, commonly used and machine-readable format.
- Withdrawal of consent — where processing is based on your consent, you can withdraw it at any time; this does not affect processing carried out before the withdrawal.
- Complaint — to lodge a complaint with a data protection supervisory authority.
Deleting your account. In the Mini App, open Account → Privacy Policy and use the account deletion button; on the website, the same button is at the bottom of your account page. Deletion runs immediately and cannot be undone.
What is deleted: your Telegram identifiers, user name, first and last name, your referral code and your notification preferences; the anti-abuse fingerprint of your IP address and user agent described in section 4; your product usage events; the login record of your website account, including the email address and the password hash. Any unpaid orders are cancelled, any part of them already paid from your balance is returned to that balance, and the remaining balance is then written down to zero. The email address stored on your past orders is replaced with a technical placeholder, and personal data in our internal audit records about you is redacted.
What is kept: records of orders, payments and balance movements remain, in a form that no longer identifies you, because we are required to keep records of transactions for accounting and tax purposes. eSIM profiles that have already been issued remain with the upstream supplier under its own retention rules, and messages you exchanged with the bot remain in Telegram. If any of your data is legitimately outside the scope of automated deletion, you can ask us about it using the contact details in section 11.
To exercise any of the other rights, or to make a subject access request, write to us at the email address in section 11. There is normally no charge. If your request is 'manifestly unfounded or excessive' (for example, if you make repetitive requests) a fee may be charged to cover our administrative costs in responding.
We will do our best to respond to your request within 20 calendar days and, in any case, not more than one month of receiving it. In some cases, particularly if your request is more complex, more time may be required up to a maximum of three months from the date we receive your request. You will be kept fully informed of our progress.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the data protection supervisory authority in the country where you live, where you work, where the alleged infringement took place, or in the jurisdiction in which the operator named in section 1 is established. We would appreciate the chance to address your concern first, but you do not have to contact us before complaining.
10. Cookies, Local Storage and Analytics
We use a small number of our own cookies. There are no third-party advertising or analytics trackers on our website or in the Mini App, and no cookie we set is used for profiling or ad targeting.
- viewer_telegram_id — strictly necessary. A signed token that keeps you signed in to the Telegram Mini App. Lifetime 30 days. Removed when you delete your account.
- web_session — strictly necessary. A signed token that keeps you signed in to your website account. Lifetime 30 days, HttpOnly.
- web_registration_proof — strictly necessary. A short-lived token that carries a registration in progress from the form to the email confirmation step. Lifetime 30 minutes, HttpOnly.
- web_lang — functional. The interface language you chose on the website. Lifetime one year.
- web_ref — attribution. The invitation code from a referral link (?ref=...), so that the person who invited you is credited when you register or buy. Only letters and digits are stored, up to 32 characters. Lifetime 90 days.
- admin_session — strictly necessary, used only by our staff in the admin area. It is never set for customers.
Your browser also keeps a few settings in local storage: the light or dark theme you selected, a cached interface language, and whether you dismissed the referral welcome banner. These stay on your device, are never sent to us, and disappear when you clear the site data.
Analytics are our own and stay in our own database: we record product events such as opening the Mini App, opening a destination, viewing or selecting a plan, tapping to pay, and the payment and issue steps that follow. An event stores its type, the time, your account identifier if you are signed in, and a couple of short technical fields such as a country code or a plan identifier. We do not store your IP address or your browser's user agent alongside these events. We never write an IP address or a user agent string to the database in readable form: the address is used in the server's memory to limit how often public endpoints can be called, and the only thing that reaches the database is the irreversible salted fingerprint described in section 4, which protects the referral programme from abuse. Deleting your account deletes these events.
You can block or delete cookies through your browser settings. If you block the strictly necessary ones, signing in and completing a purchase will not work.
11. How Do I Contact You?
To contact us about anything to do with your personal data and data protection, including to make a subject access request, please use the following email: support@esim-magic.com.
12. Changes to this Privacy Notice
We may change this Privacy Notice from time to time. This may be necessary, for example, if the law changes, or if we change our business in a way that affects personal data protection. Any changes will be made available in this section of the application.
This Privacy Policy was last updated on 2026-09-03.