Last updated: 2026-08-10
In short: We collect what we need to sell you an eSIM and keep it working: your account, your orders, and what your eSIM does. Our supplier tells us how much data you used and which country and network you connected to, which is location information and we say so rather than hiding it. From that we build you a travel history of the countries your plans have worked in — private to you, shown to nobody else, and public only if you mint a share link yourself, which you can revoke. We never see what you do over the connection, we never see your card number, and we never sell your data. You can delete your account from the app.
Language. This document is published in English, Azerbaijani, Russian and Turkish. The English version is the authoritative one: in the event of any discrepancy, difference of interpretation or dispute, the English text prevails and is the version that binds both you and MAMMADOFF AGENCY LLC. The other languages are provided for your convenience.
eSimUP sells prepaid mobile data plans that arrive as an eSIM profile. We are a reseller. We are not a mobile network operator and we are not an MVNO. The connection itself comes from local operators in each destination, supplied to us through our wholesale partner, eSIM Go.
This policy covers the website at esimup.io and the eSimUP app for iOS and Android.
eSimUP is operated by MAMMADOFF AGENCY LLC, taxpayer number 7200653321, of Heydar Aliyev ave, Arena Plaza, Block C, Floor 7, Baku, Azerbaijan. That is the company responsible for everything described here, and it is who to write to about it.
This is the complete list. If something is not on it, we do not collect it.
We do not run advertising pixels and we do not sell behavioral data. On the website, Google Analytics runs only if you choose Accept all in the cookie banner. If you choose Essential only, it is not loaded. The app does not use Google Analytics.
Every group above exists for a job. Here is the job.
This deserves to be said plainly, because it is the most sensitive thing we hold.
When your eSIM connects, our supplier tells us how much data it has used and how much is left. It also tells us which country the device attached in, and which local network it attached to there.
That is location information, and we are not going to file it under technical data. It is coarse: a country and an operator name, not coordinates, not an address, not your movements within a country. But it is attached to your eSIM, and your eSIM is attached to your account, so it does tell us which country your device was in and roughly when.
We receive it because it is how a prepaid travel plan works. A plan's validity starts when the eSIM first attaches to a network in its destination, not when you buy it and not when you install it. To start the clock at the right moment, we have to know that it attached and where.
We cannot see anything you do over that connection. See What we do not collect, below.
From the records above we build you a travel history: the countries an eSimUP plan has worked in for you, and a card for each plan showing where it ran, for how long, how much data it used and how many networks it connected through. In the app these are your Travel Passport and your trip cards.
Nothing new is collected to make it. It is the plan history and the network attachments already listed above, counted up. We keep the result as records of its own for two reasons worth saying out loud: the page is then one lookup instead of a sweep through every attachment your account has ever produced, and a trip card goes on saying the same thing after the detailed usage snapshots behind it have been reduced to daily totals.
A country gets onto your passport in one of two ways, and we record which one it was. Either your device attached to a network there and our supplier told us, or you bought a plan sold for that country and that plan actually became active. The second is not proof you were there. It is a plan that worked there, and that is exactly how we describe it — we are not going to call a purchase a sighting. We count it because our supplier's location reporting is patchy, and without it most passports would be blank.
One consequence of giving a plan away. The history follows the eSIM, because the eSIM is what it is a history of. If you hand over a profile that has already been used, the trip it produced moves to the account that receives it, and any share link you had made for that trip is revoked as it moves. So do not give away a used profile whose trip you would rather the other person did not read.
None of this is visible to anyone but you. Signed in, you see your own. There is no other way in: not for another customer, not for someone who knows your email address, not for someone who knows your name. Nothing here starts out shared, so there is no default to go and correct.
Your travel history becomes visible to another person only when you decide it should. Sharing mints a long random link that did not exist until you asked for it.
One trip card at a time is the only thing that can be shared. Your passport as a whole cannot be shared at all — there is no control that would do it and no page that would render it, so the list of every country you have been in stays between you and us. If we ever build that, it will follow the rules in this section, and this section will say so before it ships rather than after.
The link is the whole key. Anyone holding it can open that page without an account and without signing in, which is what makes it shareable and is also the risk: a link that gets posted, forwarded or screenshotted is readable by everyone it reaches. Share it the way you would publish it, because that is what you are doing.
Two practical things about how links behave once they leave your hands. The page carries a picture of the card, so that a link posted in a chat unfurls into something worth looking at — which means the messaging app fetches that picture, and may keep its own copy of it. And the page asks search engines not to index it, which they generally respect, but a request to a crawler is not a lock on a door.
Here is the whole of what such a page contains. What is not on this list is not on the page — never the eSIM's serial number, never the order or what you paid, never your balance, never your email address or phone number, never your name, never your other trips, and never one word about any other customer.
You can revoke any share link at any time, and revoking really does stop the page. It does not mark the page hidden or unlisted: it destroys the link, so there is nothing left in the database to look the page up by and the address simply stops resolving. There is no half-shared state to get wrong later. The picture of the card dies with it, because a revoked link that still served its preview would make revocation only half true.
What revoking cannot do is reach into somebody's memory, screenshots or messages. A person who already opened the page has already seen it. A chat app that already drew a preview of it may still be holding that picture in its own cache, on its own servers, where we have no power at all. Revoking closes the door going forward; it does not undo the past. We would rather say that here than let you find it out.
The other half of this is what we are not doing. There is no directory of eSimUP customers, no leaderboard, no map of travellers near you, no way to search for a person, and no way to ask which customers have been to a country. This is not a promise about our intentions, it is a fact about the database: there is no lookup in it that could answer those questions, and the only reads that cross between accounts are share links you minted yourself. If we ever wanted to build such a thing, we would have to say so here first, and we do not want to.
Deleting a trip's history is not something the app can do on its own yet. If you want a trip or a country taken off your passport, write to [email protected] and we will remove it.
These are not things we collect and keep quiet about. They are things we never receive.
We do not sell personal data, to anyone, ever.
A short list, and nobody outside it.
We may also have to disclose data if the law requires it. If that happens, we will tell you unless we are forbidden from telling you.
Different records have different lives.
One honest caveat: these are the limits we hold ourselves to and they are how the database is designed, but the automatic clean-up that enforces them is not built yet. Until it is, ask us at [email protected] and we will delete on request.
You can do all of the following by writing to [email protected], and some of it without asking us at all.
We are not going to quote a specific law or name a regulator you could complain to. MAMMADOFF AGENCY LLC is registered in Azerbaijan and sells to people in a great many other countries, and which data protection regime formally covers you is a question we would rather have answered properly than guess at. The rights below are ones we honour for every customer, wherever you live, regardless of which regime formally applies to you.
Deletion is in the app, under your account. It is not a request that sits in a queue. This is what happens the moment you confirm it.
It cannot be undone. You will not be able to sign back in to a deleted account, though you can register again later with the same email address.
An eSIM you already installed keeps working until its plan runs out, because the profile lives on your device rather than in your account. You will no longer be able to see it or its remaining data in the app.
The section above is the whole of what deletion clears, and we would rather set out the remainder than let you assume it went too.
The most important one: your orders keep the email address they were placed with, along with the IP address and the browser or app that placed them. It would be easy to write here that your records are anonymous afterwards. They are not. The account is emptied, but an order still carries the address you bought with, and someone reading the orders table could still tell it was you.
The same is true of a few smaller things: login attempts record the email address that was tried and are kept for 90 days; password-reset and verification links are stored against the email they were issued for until they expire; and if you were ever given or gave an eSIM, the recipient details and companion entries hold an email address too.
Also left in place on the emptied account: your language, country and currency, your support ID, your referral code and the referrals attached to it, your balance ledger, your registered devices and their push tokens, and the eSIMs you were issued.
Your travel history is in that list too, and it deserves its own line because of what it is. Deleting the account does not delete your trips or your visited countries — they stay on the emptied account, and if you want them gone, ask us. But every share link you had made is revoked as part of the deletion, so no trip card of yours is left readable by a stranger after you have gone. That one is not left for you to remember: deleting the account also revokes every session you could have signed back in with, so a link outliving the account would be a page nobody was able to take down. Anything already screenshotted or cached by a chat app is of course beyond our reach.
If you want any of that removed as well, write to [email protected] and ask. Some of it we can delete on request; some of it is a financial record we will keep and tell you we are keeping.
A travel eSIM is international by its nature. When you use a plan abroad, a local operator in that country carries your connection and knows that a SIM is attached to its network. We cannot change that, and no privacy policy can. It is what makes the product work at all.
eSIM Go operates across many countries, so the details we send them to issue and manage your eSIM may be handled outside the country you live in.
MAMMADOFF AGENCY LLC is registered in Azerbaijan, so that is the country your data sits in when it is with us. Our suppliers operate internationally, so it is also handled outside Azerbaijan. The specific safeguards for each of those transfers are still being documented, and this section will be completed rather than quietly dropped.
eSimUP is not intended for anyone under 16, and we do not knowingly collect anything from a child under 16.
If you believe a child has created an account, write to [email protected] and we will delete it.
When this changes, the date at the top changes with it.
Two changes are already coming. Payments and email delivery are not connected yet, and both add a company that receives your data. This policy will be updated before either goes live, not afterwards.
Write to [email protected] about anything in this document, including a request to see, correct or delete your data.
If you have a support ID, include it. It lets us find your account without asking you for more personal details than we already have.
For a formal privacy request in writing, the company behind eSimUP is MAMMADOFF AGENCY LLC, Heydar Aliyev ave, Arena Plaza, Block C, Floor 7, Baku, Azerbaijan, taxpayer number 7200653321.
Not legal advice. This document describes honestly how eSimUP works, but it has not been reviewed by a qualified lawyer and is not drafted for any particular jurisdiction. Before eSimUP takes money from customers it should be reviewed by a solicitor in the country the business is registered in — particularly the sections on liability, refunds and governing law.
Questions: [email protected]