Version 1.0 · Effective 6 September 2026
The short version. We collect what it takes to sell you an eSIM and keep your account working: how to reach you, what you bought, and which profiles are yours. Your card is entered on Stripe’s page and we never see it. Analytics only start after you accept the banner; error reports run always, and they mask every piece of text on the screen. We do not sell your data and do not train anything on it. You can delete your account yourself, from your account page.
This document is written in English only. See also our Terms of Use.
Boutique eSIM is operated by Nerds Boutique L.L.C., 30 N Gould St Ste N, Sheridan, WY 82801, United States, which is the controller of the personal data described here. Write to service@nerds.boutique about anything in this document.
We do not sell personal data, we do not share it with advertisers, and we do not use it to train machine-learning models.
These companies process data on our behalf, each for one job, under contracts that limit them to it.
| Processor | What it does | What it receives |
|---|---|---|
| Stripe | Takes the payment | Your card details, entered on their page, plus the order amount and your email |
| Our connectivity supplier | Issues and provisions the eSIM profile | The order and the profile it issues; the QR image is served from their domain, so opening the page reaches them directly |
| Google (Firebase) | Signs you in | Your credentials or social profile, your phone number for SMS codes, and a reCAPTCHA check |
| Amazon Web Services | Hosts the site and sends transactional email | Everything above, at rest; email address and message content for order and account email |
| Sentry | Collects error reports (EU region) | Stack traces, the URL, and a masked replay of the moments before a crash |
| Amplitude | Product analytics — only after you accept | Account identifier, locale, currency, sign-in provider, and the events listed below |
| Pusher | Delivers live updates to an open page | The name of your private channel and a connection identifier |
Card details are entered on a page hosted by Stripe, not on ours. We never see, handle or store a card number; we learn from Stripe whether the payment succeeded, the amount, the currency and enough of a reference to match it to your order. Stripe processes your data as a controller in its own right under its own privacy policy.
The insurance and visa blocks are links to partners, and clicking one takes you to them under their own privacy policy.
Be aware of one thing we pass along: the link to iVisa carries the country of the passport you selected as a tracking parameter in the URL, so the referral can be attributed. The link to SafetyWing carries only our affiliate identifier. Your age band and travel dates are not sent to either — they stay with us, and are recorded as an analytics event only if you accepted analytics.
Until you accept the banner, the analytics library is not loaded, sets nothing and sends nothing. If you accept, we record product events — a plan viewed, an item added to the basket, a checkout started, an order placed, an eSIM installed, a partner link clicked — with the identifier of your account and properties such as plan, amount, currency and locale. Declining costs you nothing: sign-in, the basket and your currency all work either way.
Error reports run regardless of your answer. They are how we find out the checkout is broken, and gating them would make exactly the people who decline invisible when it breaks for them. Nothing identifying is attached: the replay masks every piece of text, every input and all media before it leaves your browser.
Account data lives as long as your account does. You can close it yourself, from the account page. When you do, personal data is wiped, you are signed out everywhere and loyalty credits are forfeited; eSIMs already installed keep working but can no longer be managed. Orders and tax records are kept in anonymised form, as the law requires — we cannot delete an invoice. The same email address can sign up again afterwards as a new account.
Error reports and analytics events expire on the retention schedules of Sentry and Amplitude respectively. Server logs are kept for a short period for security and debugging.
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to our use of it, or send it to another provider. If you are in the EU or the UK these are your GDPR rights; in California, the CCPA gives you the right to know, delete, correct and opt out of sale or sharing — and we do neither.
Much of this you can do yourself: your profile, language, currency and account deletion are all in the account page, and the analytics banner can be answered again by clearing the site’s cookies. For anything else, write to service@nerds.boutique. We do not charge for this and will not treat you differently for asking. If we get it wrong, you may complain to your data protection authority.
We are a United States company, and some of the processors above operate outside your country. Where data leaves the European Economic Area or the UK, the transfer relies on the European Commission’s Standard Contractual Clauses or an equivalent safeguard, together with encryption in transit and at rest.
Traffic runs over TLS. Session tokens are stored in cookies that scripts cannot read, which is what keeps a cross-site script from walking away with your account. Card data never touches our systems. No system is perfectly secure, but the account page shows you everywhere you are signed in, and closing the account signs all of them out.
The service is not for children. You must be at least 18 to buy, or 16 with the consent of a parent or guardian. If you believe a child has given us personal data, write to us and we will delete it.
When this policy changes we publish the new version here with a new version number and date. Material changes are announced on the site or by email before they take effect.
Version 1.0 — 6 September 2026. First published.
Nerds Boutique L.L.C.
30 N Gould St Ste N, Sheridan, WY 82801, United States
service@nerds.boutique