onesim

Datenschutzrichtlinie

Last updated: April 21, 2026 · Effective date: April 21, 2026

At Onesim our mission is to help you use the best eSIM plans around the world in the easiest and simplest way. To do that, we need to collect, use, and share some of your personal information.

This Privacy Policy ("Policy") explains how Onesim LLC ("Onesim", "we", "our", "us") collects, uses, discloses and protects your personal information when you interact with us through any of our services:

  • our website at https://onesim.co;
  • our Telegram Mini App and bot at https://t.me/myesim_bot/onesim;
  • our mobile applications "Onesim" for Android (Google Play) and iOS (App Store);
  • any related API, customer support channels, marketing pages or communications

(together, the "Services"). This Policy is a single, unified document that governs all of the above Services — where a provision applies only to a specific platform (for example, a mobile-only permission), we say so explicitly.

1. Data Controller

The data controller responsible for your personal information under the EU/UK GDPR and similar laws is:

Onesim LLC

530-B Harkle Road, Suite 100

Santa Fe, NM 87505, USA

Email: hello [at] onesim [dot] co

For any questions about this Policy or to exercise your privacy rights, please contact us using the details above.

2. Scope of this Policy

This Policy covers the personal information we collect about you when you use our Services or otherwise interact with us. It also explains the choices and rights you have in your information, including how you can object to certain uses of it and how you can access, correct, export or delete it.

Our Services are intended for a worldwide audience; this Policy is written to comply with the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), the Google Play Developer Program Policies, the Apple App Store Review Guidelines, and the Telegram Mini App Terms.

3. What Personal Information We Collect

A. Information You Provide to Us

Account Registration

When you create an account with Onesim, we collect the information you provide us, such as your name, email address, and password (hashed — we never store passwords in clear text). Authentication is powered by Supabase; if you sign in with Google, your Google email, display name and profile picture may also be provided to us by Google. Accounts created on any platform (web, Mini App, mobile app) share the same identity, so the Services can recognize you across platforms.

Order Information

When you place an order for an eSIM plan, we collect the information you provide us, such as your name, email address, nationality (for regulatory KYC/KYT purposes), device model and operating system (to verify eSIM compatibility), destination country or region, plan details, promo codes and order history.

Payment Information

We do not store your full payment card details on our servers. Payments are processed by Stripe, Inc. via Stripe Payment Intents (on web, Mini App and mobile). When you pay, Stripe collects your card number, CVC, expiration date and billing address directly; we only receive a payment token, the last 4 digits, card brand, the billing country and the transaction status. On Android, Stripe may also support Google Pay (Google Wallet); on iOS, Apple Pay. Please see Stripe's privacy policy at stripe.com/privacy.

Your Communications with Us

When you contact us or we contact you — by email, via our support bot @onesim_app_bot on Telegram, or through the in-app support form — we collect any information you provide, such as your name, email address, Telegram username, and the contents of the messages and any attachments.

Ratings and Feedback

When you rate an order or provide feedback about our Services, we collect the content of your feedback, a pseudonym if you provide one, and the associated order or bundle.

eSIM Issue Reports

If you report a problem with your eSIM, we collect a description of the issue, optional screenshots you attach, and the corresponding eSIM identifiers (ICCID, order ID). This data is used solely to diagnose and resolve the issue.

B. Information We Receive from Telegram (Mini App only)

When you use Onesim inside Telegram (as a Mini App or bot), Telegram passes us the data described in sections 4.1 and 4.2 of the Telegram Mini App Terms. In practice this includes:

  • your Telegram user ID, first name, last name, username (if set) and language code;
  • whether your Telegram account is a Premium account;
  • your profile photo URL if your privacy settings make it available;
  • a signed initialization hash that we use to verify the request came from Telegram;
  • launch parameters, such as the startapp or start value you used to open the app (e.g., referral or invoice identifiers).

We use Telegram Cloud Storage only to store non-sensitive UI preferences (for example, your selected language). We do not read your Telegram chats, contacts, or files.

C. Information We Collect from Mobile Devices (mobile apps only)

Our Android and iOS apps request only the minimum permissions required for their features:

  • Internet / Network State (INTERNET, ACCESS_NETWORK_STATE): to communicate with Onesim servers, Supabase and Stripe.
  • Device information (read via device_info_plus): non-personal information such as device model (e.g., "iPhone 15 Pro"), manufacturer, OS version, and whether the device supports eSIM. This is used to show you eSIM compatibility and to help diagnose technical issues. We do not collect hardware serial numbers, IMEI, IMSI, advertising identifiers (IDFA/AAID), contacts, SMS, location, microphone input, or installed-app lists.
  • Secure on-device storage (flutter_secure_storage, iOS Keychain / Android Keystore): we store your authentication token and a small number of preferences on your device in encrypted storage.

Onesim does not request access to the device camera, microphone or photo library. eSIM QR codes and activation details are shown in the app; any scanning during installation is handled by your device’s own system settings or apps, outside the Onesim app.

The mobile apps do not include any third-party advertising SDKs, do not track you across other companies' apps or websites, and do not collect precise location.

D. Information We Collect Automatically

Usage and Device Data

When you visit or use the Services, we automatically collect certain information, including your Internet protocol (IP) address, approximate location inferred from your IP (country/region only), user-agent string, operating system, browser or mobile app version, screen size and language, referring URL, the pages and screens you visit, features you use, the links you click, timestamps, and error/crash diagnostics. This information may be associated with your account.

Cookies and Similar Technologies (website only)

On onesim.co we use cookies, local storage and similar technologies to:

  • keep you signed in (Supabase Auth session cookies — strictly necessary);
  • remember your language and UI preferences (functional);
  • secure checkout and prevent payment fraud (Stripe.js — strictly necessary);
  • measure how the website is used via Google Analytics 4 (analytics — only with your consent where required by law).

You can manage cookies in your browser settings, and where a consent banner is shown you can withdraw consent at any time. Blocking strictly necessary cookies may break login or checkout. The Telegram Mini App and the native mobile apps do not use browser cookies.

Analytics

On the website only, we use Google Analytics 4 (provided by Google LLC / Google Ireland Ltd.) to understand aggregate product usage and measure the effectiveness of marketing campaigns. IP addresses are truncated by Google before storage. You can opt out by installing the Google Analytics Opt-out Browser Add-on or by rejecting analytics cookies in our consent banner. The Telegram Mini App and the mobile apps do not use Google Analytics or any other cross-company analytics SDK.

E. Information We Collect from Third Parties

We may receive information about you from third parties:

  • Google — if you use Google Sign-In, we receive your Google email, name and profile image (as permitted by the OAuth scopes you approve).
  • Telegram — as described in section 3.B above.
  • Stripe — payment status, last 4 digits of the card, billing country, and anti-fraud signals.
  • eSIM providers — status updates about your eSIM (activation, data usage summary, expiration) from the underlying mobile-network operator or aggregator that provisions the eSIM.

4. How We Use Your Information and Legal Bases

We process your personal information for the purposes described below. Where the EU/UK GDPR applies, we rely on the legal bases indicated in brackets (performance of a contract, legitimate interests, consent or legal obligation).

  • Provide the Services — create and manage your account, sell and deliver eSIMs, process payments, show you eSIM compatibility, display your orders and usage [contract].
  • Customer support — answer your questions, investigate and resolve eSIM issues, process refunds [contract, legitimate interests].
  • Security and fraud prevention — verify the authenticity of requests (including the Telegram signed hash), prevent abuse and payment fraud, protect our users and our Services [legitimate interests, legal obligation].
  • Communications — send you transactional emails and in-app messages (order confirmations, delivery of the eSIM QR code, policy changes) [contract, legal obligation].
  • Product improvement — analyse aggregated usage trends, crash and error reports, and A/B test new features [legitimate interests, consent where required].
  • Marketing — send you promotional emails or show relevant content; you can opt out at any time [consent or legitimate interests, depending on jurisdiction].
  • Compliance — keep records required by tax, accounting or consumer-protection laws; respond to lawful requests from authorities [legal obligation].

We do not sell your personal information, and we do not use it for automated decision-making that produces legal or similarly significant effects about you.

5. How We Share Your Information

We share personal information only with the categories of recipients listed below, and only to the minimum extent necessary for the stated purpose.

Service Providers (processors)

We use trusted third-party service providers. Each of them acts as our processor under a data-processing agreement and is only allowed to use your data for the purposes we instruct.

  • Supabase (Supabase Inc., USA) — authentication and primary database.
  • Stripe (Stripe, Inc., USA / Stripe Payments Europe, Ireland) — payment processing.
  • Google (Google LLC / Google Ireland Ltd.) — Google Sign-In, and on the website Google Analytics 4 and Google Cloud hosting for certain services.
  • Telegram (Telegram Messenger Inc.) — the platform on which our Mini App and bot run.
  • Apple (Apple Inc.) — App Store distribution and, if you use Apple Pay, payment tokenization.
  • eSIM partners and mobile network operators / aggregators — to provision and activate the eSIM you purchase. We only share the data strictly required to issue and operate the eSIM (e.g., a unique order reference and destination).
  • Hosting and infrastructure providers — Vercel, Google Cloud or equivalent providers used to host the website and API.
  • Email and messaging providers — to deliver transactional emails and in-app notifications.

Business Partners

We may share information with partners with whom we jointly offer products or services, strictly to deliver what you requested.

Legal and Safety

We may disclose information where we reasonably believe disclosure is required by applicable law, regulation or legal process, or is necessary to protect the rights, property or safety of Onesim, our users or the public.

Corporate Transactions

If Onesim is involved in a merger, acquisition, financing, restructuring or sale of all or part of its assets, personal information may be transferred to the acquiring party; we will notify you of any such change and of any resulting change to this Policy.

If you post a public rating, review or feedback, the content may be visible to other users along with any name or identifier you chose to display. We do not sell personal information and we do not "share" personal information for cross-context behavioral advertising within the meaning of the CCPA/CPRA.

6. International Data Transfers

We are based in the United States, and many of our providers (Supabase, Stripe, Google, Telegram) are also based in the United States or operate globally. When we transfer personal data outside the European Economic Area, the United Kingdom, Switzerland or other jurisdictions with similar rules, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and additional technical and organisational measures.

You can request a copy of the relevant safeguards by contacting us.

7. Data Retention

We keep your personal information only for as long as needed for the purposes set out in this Policy:

  • Account data — for the lifetime of your account, and up to 30 days after account deletion (for backups and fraud prevention).
  • Order and transaction data — up to 7 years from the order date, as required by tax and accounting laws.
  • Support correspondence — up to 3 years from the last interaction.
  • Diagnostic / usage logs — typically up to 12 months, then aggregated or deleted.

When we no longer need your data, we delete or anonymise it.

8. Security

We use industry-standard technical and organisational measures to protect your information, including TLS 1.2+ in transit, encryption at rest for passwords (hashed) and secrets, OAuth 2.0 for authentication, signed Telegram init-data verification, role-based access controls, regular backups, audit logging, and a documented incident-response process. No system is 100% secure; we encourage you to use a strong, unique password and to protect access to your email and Telegram accounts.

If we become aware of a security breach affecting your personal information, we will notify you and the relevant authorities in accordance with applicable law.

9. Your Rights and Choices

Depending on where you live, you may have the following rights in respect of your personal data:

  • Access — ask for a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Deletion ("right to be forgotten") — ask us to delete your data; you can also delete your account yourself from the Account screen on any of our platforms, subject to data we must retain by law.
  • Restriction or Objection — ask us to stop or limit certain processing, including processing based on legitimate interests.
  • Data Portability — receive your data in a structured, commonly used, machine-readable format.
  • Withdraw Consent — where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
  • Lodge a Complaint — with a supervisory authority in your country of residence.
  • CCPA / CPRA rights (California residents) — right to know, right to delete, right to correct, right to opt out of sale/sharing (we do not sell or share), and the right to non-discrimination for exercising these rights.

To exercise any of these rights, email us at hello [at] onesim [dot] co or use the in-app "Delete Account" option. We will respond within the time frame required by applicable law (typically 30 days). We may ask you to verify your identity before we act on a request.

Marketing Communications

You can unsubscribe from promotional emails at any time by clicking the "unsubscribe" link in each message. We will continue to send you non-promotional transactional messages (order confirmations, eSIM QR delivery, service notices) that are necessary to operate the Services.

Do Not Track

Our website does not respond to "Do Not Track" signals, because no industry standard currently exists. We honour other opt-out mechanisms such as the Global Privacy Control (GPC) signal.

10. Children's Data

Our Services are not directed to children and we do not knowingly collect personal information from anyone under the age of 18. The mobile apps are rated accordingly on the App Store and Google Play. If you believe that a child has provided us with personal information, please contact us at hello [at] onesim [dot] co and we will promptly delete it.

11. Platform-Specific Notices

Google Play (Android)

Our Android app complies with the Google Play Developer Program Policies, including the Data safety and User Data sections. The Data safety form in our Google Play listing reflects the practices described in this Policy. We do not use sensitive permissions such as SMS, Call Log, or background location.

Apple App Store (iOS)

Our iOS app complies with the Apple App Store Review Guidelines and the App Privacy ("Privacy Nutrition Label") requirements. We do not perform any tracking within the meaning of Apple's App Tracking Transparency framework and therefore do not display an ATT prompt. Data collected is used only to operate the Services described above.

Telegram Mini App

Onesim is an independent third-party service that operates on Telegram and is not endorsed by, nor affiliated with, Telegram. This Policy does not supersede the Telegram Privacy Policy, the Bot Terms, or the Mini App Terms, which continue to govern your relationship with Telegram itself.

12. Links to Third-Party Websites

The Services may contain links to other websites and applications, and other websites/applications may reference or link to the Services. These third-party services are not controlled by us. We encourage you to read the privacy policies of each website or application you interact with. We are not responsible for the privacy practices or content of such third parties.

13. Changes to This Privacy Policy

We may update this Policy from time to time. If we make material changes, we will notify you by posting the updated Policy on this page, updating the "Last updated" date above, and, where appropriate, sending you an email or an in-app notification. Your continued use of the Services after the effective date constitutes your acceptance of the revised Policy.

14. Contact Us

If you have any questions, comments or complaints about this Policy or our privacy practices, please contact us at hello [at] onesim [dot] co or at the postal address below:

Onesim LLC

530-B Harkle Road, Suite 100

Santa Fe, NM 87505, USA

Support on Telegram: @myesim_bot

onesim
Onesim LLC
530-B Harkle Road, Suite 100, Santa Fe, NM 87505, USA
KUNDENSUPPORT
HilfezentrumKontakt
© 2025 Onesim. Alle Rechte vorbehalten.
stripe
visa
mastercard
amex
discover
o
jcb
unionpay
applepay