LEGAL
Privacy
Last updated 3 September 2026
This page describes what happens to information about you when you use eSIMradar. It is written from what the site actually does, so it is shorter than most privacy policies: there is not much to describe.
The short version: eSIMradar has no accounts. Google ads pay for the site and Google Analytics counts what gets used, and both start denied: until you say otherwise the ads are picked from the page rather than from you, analytics writes nothing to your device, and you are not recognised between visits. If you click through to a provider you leave us, and from that moment their privacy policy is the one that applies.
Who we are
eSIMradar is operated by Now On Company Limited, a company registered in Thailand. Now On Company Limited is the data controller for the processing described on this page, and the address below is where to write about any of it.
- Now On Company Limited
- 112/246 Moo 8, Bangkaew, Bangplee, 10540 Samut Prakarn, Thailand
- [email protected], for anything on this page, including a request about your data
What we collect when you read the site
Nothing that you type, because there is nothing here to type into. Every public page is a static file served from a content delivery network, and pages are built in advance rather than assembled for you when you ask for one. What does happen is what happens on any website: our hosting provider records the request.
- A server log entry for each request: the IP address it came from, the time, the page, the browser and operating system your device reports, and the response we sent.
- Those logs are used to deliver the site, keep it available, and investigate faults and abuse. They are not used to build a profile of you, and we do not try to work out who you are from them.
- The legal basis is our legitimate interest in running a working, secure website (GDPR Article 6(1)(f)). No consent is asked for because none of this is optional to serving a page.
What we do not do
These are all things a comparison site could reasonably be expected to do. This one does not do them, and this section exists so that is on the record rather than left to be inferred.
- No visitor accounts. There is nothing to sign up for, no password to store, and no email address collected from readers.
- No remarketing pixel, no session recording, no heatmaps and no tag manager. Two Google scripts run here: Analytics, which counts what is used, and AdSense, which fills the banners between the rows on a plan board. Both start with every consent signal denied, and neither is handed anything we know about you, because we know nothing about you.
- No payments, ever. We do not sell eSIMs, so no card details are entered here. A purchase happens on the provider’s own site, under their terms.
- Three third parties receive anything at all from your browser, and all three are named below: Google Analytics, Google AdSense, and Sentry on the occasions our code fails. The first two load a script from Google. Sentry’s is served from our own domain and reaches Sentry only when there is an error to report. Everything else a page loads, including the two typefaces, comes from our own domain, which is the exception people are most often surprised to find in their browser logs.
- We do not sell, rent or trade personal data, and we hand no list of readers to anybody. Showing a Google ad does send Google what any ad request carries: the page you are on, your IP address and what your browser reports. That is what the banner asks about, and your answer decides whether it may be tied to an advertising profile.
Analytics, and the consent it does not assume
We use Google Analytics 4 to see which pages, destinations and plans people actually use, so the site can be built around that rather than around guesses. It is configured to ask first, and to be useful even when the answer is no.
- It loads with every consent signal set to denied. In that state Google Analytics still counts the visit, but it writes nothing to your device, sets no _ga cookie, and cannot connect this visit to any other. The numbers are aggregate and the visitor is not identified.
- The banner asks whether we may store a cookie that recognises you across visits. Saying yes turns on Google’s analytics_storage only. Saying nothing leaves it denied for as long as you keep saying nothing, and there is no second prompt.
- What is recorded is what was done, never what was typed: pages viewed, a plan opened or clicked, a filter or sort used, a currency changed, whether a destination search matched anything. Searches report how many characters were typed and how many results came back, never the words themselves, and the search term is removed from the page address before Google Analytics is told which page you are on.
- Google’s three advertising signals, ad_storage, ad_user_data and ad_personalization, are denied until you say otherwise, and the Analytics property never uses them either way: Google Signals and advertising features are off in it, and IP addresses are anonymised before Google stores them. Those signals are here for the ads, which have their own section below.
- The legal basis is your consent (GDPR Article 6(1)(a)) for the cookie, and our legitimate interest in knowing whether the site works (Article 6(1)(f)) for the cookieless counting. Withdraw consent by clearing site data for esimradar.com, which removes the record of your answer and lets you give a different one.
Google acts as our processor for the analytics and is listed with our other processors below. Their own terms govern what they may do with it, and they are not permitted to use it for their own advertising. The ads are a different arrangement, described in the next section.
Advertising
The site carries Google AdSense banners, spaced far apart between the rows on a plan board. They pay for the catalogue alongside the affiliate commissions described below, and they are the only advertising here: no interstitials, no video, no remarketing pixel, and nothing that follows you off the site.
- Until you answer the banner, every ad is requested as non-personalised. Google is told so explicitly on the request, and it picks the ad from the page you are reading rather than from anything about you.
- Saying yes turns on Google’s ad_storage, ad_user_data and ad_personalization, which lets Google use what it already knows about your browser to choose the ad. Saying no, or saying nothing, leaves all three denied for as long as you keep saying nothing, and there is no second prompt.
- Non-personalised does not mean nothing is stored. Google may still keep enough to stop you seeing the same banner ten times and to catch click fraud. Those cookies sit under Google’s domains rather than ours, and the cookie page says what that means for clearing them.
- An ad is not a plan and never changes the order plans are listed in. Each one is labelled where it sits, and no advertiser can buy a top pick, a place on the picks shelf or a place on the Recommended tab by buying a banner: that is a separate relationship, described under affiliate links below.
- The legal basis is your consent (GDPR Article 6(1)(a)) for personalised ads and the storage they use, and our legitimate interest in funding a free site (Article 6(1)(f)) for serving a non-personalised one. Withdraw consent by clearing site data for esimradar.com, which removes the record of your answer and lets you give a different one.
For the ads Google is not merely our processor: it decides for itself how the advertising it serves works, and its own privacy policy governs that. What comes back to us is money and aggregate reporting, never a record of who saw what.
What is stored in your browser
Two entries, both written only in response to something you did. If you change the display currency, your choice is saved under the name esimradar.currency; if you answer the banner, your answer is saved under esimradar.consent. Both are local storage rather than cookies, which means neither is ever attached to a request and neither reaches our servers. Clearing site data for esimradar.com removes both. Google writes cookies of its own for the analytics and for the ads; the cookie page lists them and says which depend on your answer.
The cookie page lists this in full, along with what a browser stores on its own.
When you click through to a provider
Deal links are affiliate links. Following one takes you off eSIMradar to the provider or to the affiliate network they use, and their privacy policy applies from that point. Typically they set a cookie to record that the visit came from us.
- What comes back to us is commercial reporting: that a click led to a purchase, and what commission is due. Those reports do not tell us who you are, and we do not receive your name, your email address or your order details.
- A commission never changes the order plans are ranked in. What it can decide is which plans a promoted surface carries: the "top pick" marker, the "Our picks" shelf, the paid partner row and the "Recommended" tab of a board. All four are labelled where they appear, and the method is written out on our ranking page.
- Blocking third-party cookies does not break anything here. At most it means a provider does not credit us for the visit.
When an assistant asks on your behalf
eSIMradar publishes a small interface that AI assistants can call: an MCP server at esimradar.com/mcp, which is what the ChatGPT app and the Claude Code plugin use. It answers four read-only questions about the catalogue. If you have never asked an assistant about eSIMs, nothing in this section has happened to you.
- What reaches us is the query, not the conversation: a destination, and whichever filters the assistant chose to pass, such as how much data, how many days, a budget, or whether the plan has to allow hotspot sharing. None of the four tools has an input field for a name, an account, a device identifier or your own location, so none of those can be sent.
- Nothing is written. Answering means reading files we prepared in advance and returning them: no database row, no counter, no analytics event. Google Analytics never sees these calls at all, because it runs in a browser and this is not one.
- Our host still records the request, exactly as described above. Where the assistant runs on its provider’s servers, the address in that log is theirs rather than yours. Where it runs on your own machine, as a command line tool does, it is yours.
- The conversation belongs to the assistant, not to us. What you typed, and what the assistant decided to pass on from it, are governed by that provider’s privacy policy. We receive the question it chose to ask us and nothing around it.
- The legal basis is our legitimate interest in publishing a working public interface (GDPR Article 6(1)(f)). No consent is asked for because no cookie is set, nothing is stored on your device, and nothing that arrives identifies you.
The endpoint needs no key and no sign in. That is a limit as much as a convenience: with nothing to authenticate, we cannot tell one caller from another, and we cannot link two questions to the same person.
Providers who list with us
A provider that lists on eSIMradar, through our API or by arrangement, gives us business contact details. This is the only place the site holds an account of any kind.
- A contact email address and company details, plus an API key that is stored only as a one-way hash: we cannot read back a key that has been issued.
- Used to operate the listing: to tell a provider when their catalogue fails validation, to enforce fair use of the API, and to reach them about their listing.
- The rest of that relationship is covered by the provider terms, which are a separate document.
Reviews shown on provider pages
Provider pages show ratings and written reviews. Most of them come from our own dataset, gathered before this version of the site existed. The rest are written here, through the form on the write-a-review page or on a provider's own reviews page. Nothing written there is published automatically: a person reads it first. We keep the rating, the text, the display name, the country if you name one, and the time it was sent. We do not ask for an email address and we do not store one. Where a review is published with a display name, that name is what the reviewer gave. Write to us if you want a review of yours removed.
Who else processes data for us
Three companies, all acting on our instructions, plus the affiliate networks that only see anything after you choose to click a deal link.
- Vercel: hosting and the content delivery network that serves every page, and therefore the request logs described above.
- Google: Google Analytics 4 and Google AdSense, both described above. Analytics receives page and event data from your browser, with a cookie identifier only if you consented. For the ads Google acts as its own controller rather than as our processor, and what it receives is what serving an ad on a page requires.
- Sentry: error monitoring, on European servers. When our code fails, the error, its stack trace, the page it happened on and the browser reporting it are sent there so we can fix it. Tracing and session replay are both switched off, and we do not turn on its setting for attaching personal data, so it receives faults rather than a record of your visit.
- Supabase: the database holding the plan catalogue, provider records and reviews. No visitor data is written to it while you browse; public pages read prepared documents and never query it for you personally.
- Both operate internationally, so data may be processed outside the country you are in. Where transfer safeguards are required we rely on the standard contractual clauses and equivalent mechanisms those providers publish.
How long anything is kept
There is no visitor profile to keep, so the question mostly answers itself.
- Request logs are held by our hosting provider for the limited operational period their platform applies, and are not copied into any store of ours.
- Error reports are held by Sentry for the limited period their platform applies, and are not copied into any store of ours.
- The currency preference stays on your device until you clear it. We never receive it, so we cannot delete it for you.
- Provider account records are kept while a listing is active, and after it ends for as long as we need them for accounting and dispute-handling.
Your rights
Under the GDPR, the UK GDPR and Thailand’s Personal Data Protection Act, you can ask us to give you a copy of the personal data we hold about you, correct it, delete it, restrict or object to what we do with it, or provide it in a portable format. Where we ever rely on consent, you can withdraw it at any time. Write to [email protected] and we will answer within one month.
The honest caveat: for an ordinary reader we hold nothing that identifies you, so a request will usually be answered by telling you that, since we cannot find records we never made. You also have the right to complain to your national data protection authority, and in Thailand to the Personal Data Protection Committee.
Children
This site is aimed at people buying mobile data for travel and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, through the provider API or by writing to us, tell us and we will delete it.
Changes to this policy
If what the site does changes, this page changes with it and the date at the top moves. Anything material, such as a new processor or a different measurement tool, will be described here before it starts, not after.
Questions about any of this?
Write to [email protected] and a person will answer. If your question is about how we rank plans or what a featured placement is, the method is written out in full on our ranking page.
