1. Summary
The short version
- BlingSIM does not use advertising, analytics or tracking cookies, and does not track you across other websites.
- We set no cookies of our own. We use a few browser storage items (localStorage and sessionStorage) that are needed for the things you ask us to do: signing in, returning from a payment page and the free-eSIM limit.
- A service worker caches public pages and static files so the site opens when you are offline. It never caches payment, order or account pages.
- Because everything we store is strictly necessary or a simple convenience you trigger yourself, we do not show a consent banner (ePrivacy Directive Article 5(3) exemption; UK PECR regulation 6(4)). We will ask for your consent before adding anything else.
This notice explains each item in detail. Our Privacy Policy explains how we use the personal data behind them.
2. Storage items we set
These are the only items our website writes to your browser. None of them is a cookie, so none of them is sent automatically with every request; our code reads them only when needed.
| Name | Type | Purpose | When it is set | How long it lasts | Category |
|---|---|---|---|---|---|
blingsim_session | localStorage | Keeps you signed in to My eSIMs. Holds a random session token that is checked on our server. | When you sign in to My eSIMs with your email code. | Up to 14 days (the server session expires then). Removed when you sign out. | Strictly necessary |
blingsim_email | localStorage | Remembers your email address so the checkout and sign-in forms are pre-filled next time. | When you pay, sign in to My eSIMs, or claim the free eSIM. | Until you sign out of My eSIMs or clear site data. | Convenience (functional) |
blingsim_device | localStorage | A random device ID used to enforce the one-free-eSIM-per-device limit of the free eSIM promotion. It is not used for anything else. | Only when you ask for the free eSIM (when you request the code). | Until you clear site data. | Strictly necessary for the promotion you requested (abuse prevention) |
aurexio_oid | sessionStorage | Matches your payment to your order when you come back from the Aurexio payment page. | When you choose Aurexio at checkout. | Removed when the payment completes, or when the browser tab is closed. | Strictly necessary |
admin_token | sessionStorage | Staff-only sign-in for the admin panel. Never set for customers. | When a staff member signs in to the admin panel. | Until the browser tab is closed. | Strictly necessary (staff only) |
bs_install_hint_dismissed | localStorage | Remembers that you closed the “Add to Home Screen” hint so we do not show it again. | When you dismiss the install hint. | Until you clear site data. | Convenience (functional) |
The eSIM QR code and activation code themselves are not stored in your browser: they are shown from our server when you open My eSIMs, and they are in your delivery email.
3. Offline cache (service worker)
- When you visit the site, your browser may install a small service worker (a script that runs in the background). It keeps a copy of public pages you have viewed, our design files and app icons, so the site still opens without a connection and loads faster.
- It never caches or intercepts API calls, payment pages (
/pay), order pages (/order), the My eSIMs dashboard or the admin panel, and it never stores non-GET requests. Checkout and account data always come straight from our server. - It stores nothing that identifies you and sends nothing to us. You can remove it under section 8.
4. Payment pages and third-party scripts
You pay on pages run by the payment provider you choose. Those pages set their own cookies and identifiers for payment security and fraud prevention, which are strictly necessary for the payment you requested. They are governed by the providers' own notices:
- Stripe (cards, Apple Pay, Google Pay and Link) — Stripe Checkout on stripe.com. Stripe privacy policy.
- PayPal — paypal.com. PayPal privacy statement.
- Aurexio — on our
/pay/aurexiopage we load Aurexio's hosted checkout widget, which may in turn load PayPal, Stripe or Airwallex scripts to process the card payment. Those scripts may set cookies or identifiers in your browser for payment security. Please see Aurexio's own privacy notice and those of Stripe, PayPal and Airwallex. - OxaPay(cryptocurrency) — the invoice page is on OxaPay's site. Crypto transactions are recorded on the public blockchain. OxaPay privacy policy.
We never receive your full card number; the payment provider collects it directly.
5. Other third-party content
- Country flags currently load from flagcdn.com. Like any image request, this sends your IP address and browser details to that server. As far as we know it sets no cookies. We plan to host these images ourselves.
- QR code imagesin our delivery emails and in My eSIMs load from our eSIM provisioning partner's servers (eSIM Access).
- Blog cover images may load from images.unsplash.com, and some blog posts embed links to other websites.
6. Fonts
Our fonts are bundled with the website and served from our own hosting. Your browser makes no request to Google Fonts or any other font service.
7. Server logs
Our hosting and database providers (Vercel and Supabase) record the IP address, browser type and requested page in security and request logs. Our own application logs record order numbers and events (not your email address in full). These logs are not cookies and are not used to profile you. Retention periods are in the Privacy Policy.
8. How to clear or control storage
- Sign out of My eSIMs to remove
blingsim_sessionandblingsim_email. - Clear site data for blingsim.com to remove everything, including the offline cache:
- Safari (iPhone/iPad): Settings → Apps → Safari → Advanced → Website Data → find blingsim.com → swipe left → Delete. On a Mac: Safari → Settings → Privacy → Manage Website Data.
- Chrome: open the site, tap or click the icon left of the address (the tune or lock icon) → Cookies and site data → Manage on-device site data → remove blingsim.com. Or Settings → Privacy and security → Delete browsing data.
- Firefox: Settings → Privacy & Security → Cookies and Site Data → Manage Data → search blingsim.com → Remove Selected.
- Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data → See all cookies and site data → remove blingsim.com.
- Clearing
blingsim_devicedoes not reset your free-eSIM eligibility. The offer is limited per person, per email address and per internet connection as well, and those limits are checked on our server (see the Promotion Terms). - Blocking storage entirely in your browser is possible, but you will not be able to stay signed in to My eSIMs or complete an Aurexio payment.
9. Global Privacy Control and Do Not Track
We do not sell or share personal information and do not use cross-site tracking, so there is nothing to opt out of. Global Privacy Control (GPC) and Do Not Track signals are honoured automatically, because we treat every visitor as if they had sent one.
10. Future changes
Before we add any analytics, advertising or tracking tools, we will update this notice, ask for your consent where required (in the EU, the UK and other places with similar rules), and offer an opt-out, including GPC, elsewhere. The version number and effective date at the top of this page change whenever the notice changes.
11. Contact and version history
Questions about this notice: privacy@blingsim.com, or write to BlingSIM, Registered address available on request from support@blingsim.com.
| Version | Effective | Change |
|---|---|---|
| 2026-09-23 | 23 September 2026 | First published version. |