Privacy
Privacy policy
Last updated August 10, 2026
This policy explains what personal data Haxobit collects, why we collect it, and the choices you have. It is written to be read — not to hide.
What we collect
- Account data — email address, name (optional), password hash.
- Order data — plans purchased, destinations, purchase timestamps.
- Payment metadata — card brand, last four digits, transaction reference. Full card numbers never touch our servers; they go directly from your device to our payment processor (Stripe).
- eSIM data — technical identifiers (ICCID), activation status, data usage totals reported to us by the underlying carrier.
- Device data — the type of device you used to visit our website (for responsive layout choices) and your approximate country (for currency defaults).
What we do not collect
- Your browsing history outside of Haxobit.
- Contents of your messages, calls, or the sites you visit while using the eSIM.
- Your precise location.
Why we collect it
- To deliver the eSIM you purchased.
- To send order confirmations, install guides, and receipts.
- To provide customer support.
- To meet legal obligations (e.g. tax records, fraud prevention).
Who we share it with
We share the minimum necessary with the underlying eSIM providers (to provision your plan), our payment processor (to charge you), and our email sender (to deliver confirmations). Every provider is bound by data-processing terms that limit their use of your data to the service they provide us.
Your rights
- Access — request a copy of your data.
- Correction — update anything that is wrong.
- Deletion — close your account and remove your data.
- Portability — receive your data in a machine-readable format.
Send requests to privacy@haxobit.com. We reply within 30 days.
Retention
Order records are kept for the length required by tax law (typically 7 years). Account data is kept until you delete your account, then removed within 30 days. Backups roll off within 90 days.
Security
All traffic is served over HTTPS. Passwords are hashed with Argon2id. Payment card data is never stored on our servers. We follow the OWASP Top 10 and undergo periodic security review.
Changes to this policy
If we change this policy, we'll email active-account holders and post the updated version here with a new "last updated" date.
Contact
Questions? privacy@haxobit.com.