Privacy notice
The design goal is simple: hold the minimum needed to deliver and support an eSIM, and nothing that could identify your travel.
What we collect
- Email address. The only personal detail we ask for. It is stored encrypted and used to send your order confirmation, eSIM activation details, and support replies. We also keep a one-way hash of it so you can find your orders by signing in later.
- Order details. The plan, price, payment status, invoice amounts and addresses, and the time of each state change.
- eSIM technical data. ICCID, activation codes (encrypted), install state and remaining-data figures returned by the connectivity provider. Needed to show your eSIM page and to support you.
- Abuse-prevention signals. Hashed IP address and hashed browser user-agent attached to security events and audit entries, plus the country derived from your IP at checkout. We never store the raw IP.
- Cookies. A session cookie if you sign in, and a per-order cookie so your browser can return to an order without re-entering a link. No advertising or analytics cookies.
What we do not collect
- Your name, address, phone number, passport or ID. We never ask for them.
- Your device identifiers (EID/IMEI). The connectivity provider may see the EID when you install; we do not store it.
- Your location while travelling. Data usage figures are totals, not where or what you browsed.
- Card or bank details. Payments are cryptocurrency; we see only the invoice and the on-chain payment.
Who else sees data
- Connectivity providers / operators receive the plan order and return the eSIM profile. They do not receive your email. They see the eSIM’s network activity in the course of providing service, under their own terms.
- Email delivery provider receives your address and the message content to send it.
- Payment infrastructure we operate ourselves; invoice data stays with us. Blockchain transactions are public by nature.
- Hosting providers process data on our behalf under contract. We do not sell or share data for marketing.
How long we keep it
- Email: deleted from guest orders after the plan has expired plus a support window (default 90 days), unless you created an account.
- Activation secrets: deleted 30 days after the plan expires or the eSIM is revoked.
- Orders and financial records: kept without email for accounting (plan, amounts, dates).
- Security events and audit logs: 12 months, hashed identifiers only.
Your rights
You can ask us to show, correct, or delete the data we hold about an order by emailing support@thecryptodepartment.com from the checkout address with your order id. Deleting your email before the plan expires means we cannot contact you about it; the eSIM keeps working. Depending on where you live you may also have the right to complain to a data-protection authority.
Security
Emails and activation codes are encrypted at rest with per-record keys; raw identifiers are never logged; staff access to any personal data is recorded in an audit log. Payment systems run on infrastructure we control.
This notice may change as the service does; the current version is always at this address. See also the terms and refund policy.