Last updated: October 1, 2026
Short answer
Island eSIM doesn’t use analytics, advertising trackers or cookies of its own. When you click through to an eSIM provider we count the click without storing your IP address. If you send us a message, we keep your name, email and message to reply to you and delete them after 12 months. We never sell personal information.
Who we are
Island eSIM (islandesim.com) is an independent website that compares travel eSIM plans. In this policy, “we” and “us” mean Island eSIM.
Questions about your data go to [email protected] or through our contact form.
What we collect and why
When you browse the site
We don’t run Google Analytics or any other analytics service, we don’t show ads, and we don’t set cookies of our own.
Like every website, our hosting provider and content delivery network receive your IP address and basic request details (page, browser type, time) when you load a page. They use this to deliver the page and to block attacks. Cloudflare may set a strictly necessary security cookie to tell people from bots.
When you click a link to a provider
Links to eSIM providers go through an address on our site starting with /go/. Each click records:
- which provider and plan you clicked, and on which of our pages
- the date and time
- a one-way code made from your IP address and browser type, which changes every day
We never store your IP address itself, and the code can’t be turned back into it. We use these records to count clicks per page and provider. When you use the “Copy” button on a discount code, we record the copy in the same way. The button only writes the code to your clipboard; we never read what’s on it.
After the redirect you’re on the provider’s website. The provider, or the affiliate network it uses, may set its own cookies so the sale can be credited to us. Their privacy policy applies from that point.
When you buy an eSIM
You buy from the provider, not from us. We never see your payment details, your order or your phone number. Read the provider’s privacy policy for how it handles them.
When you contact us
Our contact form asks for your name, email address, a topic and your message. We also note which page you sent it from. We use this only to reply to you and, if you reported a mistake, to fix it.
To stop spam, the form keeps a one-way code of your IP address and browser for one hour, so the same visitor can’t send more than a few messages an hour.
The form also uses Cloudflare Turnstile to check that you’re a person and not a bot. The check runs in your browser and sends technical signals, including your IP address and browser details, to Cloudflare. Cloudflare uses them to run the check and to improve its bot detection. See the Turnstile privacy notice.
If you email [email protected] directly, Cloudflare forwards the message to our inbox.
How long we keep it
- Contact form messages: 12 months, then deleted automatically. Sooner if you ask.
- Emails: as long as needed to deal with your question, then deleted.
- Click and discount-code records: kept for our statistics. They don’t identify you.
- Hosting and Cloudflare logs: kept by those providers under their own policies.
Who we share it with
We don’t sell, rent or trade personal information, and we don’t share it for advertising.
Two services process data for us:
- Hostinger hosts the website and its database. Hostinger privacy policy
- Cloudflare delivers and protects the site, runs the spam check on our contact form and forwards email sent to our domain. Cloudflare privacy policy
These services may process data outside the country you’re in. We may also disclose information if the law requires it, or to protect our rights or someone’s safety.
We don’t embed videos, maps, social media widgets or ads, so apart from these two services no other company receives data from you while you’re on our pages.
Your rights
You can ask us to:
- send you a copy of the personal information we hold about you
- correct it
- delete it
- stop using it for a particular purpose
Email [email protected] or use the contact form. We’ll reply within 30 days. We can’t find click records for you, because they contain nothing that identifies you.
If you’re unhappy with how we’ve handled your information, you can also complain to the data protection authority where you live. In Bermuda that’s the Office of the Privacy Commissioner.
Security
The site is served only over HTTPS. Access to the database and to messages is restricted and protected by strong passwords, and the software is kept up to date. No website can promise perfect security, but we keep as little personal information as we can, so there’s little to lose.
Children
This site isn’t aimed at children under 16, and we don’t knowingly collect their information. If you think a child has sent us personal information, contact us and we’ll delete it.
Changes to this policy
If we change what we collect, for example by adding analytics or a newsletter, we’ll update this page and the date at the top before the change goes live.
Laws this policy follows
This policy is written to meet Bermuda’s Personal Information Protection Act 2016 (PIPA) and the principles of the EU and UK General Data Protection Regulation (GDPR).
See also our terms of use and affiliate disclosure.