Cookies

Updated 2 September 2026.

There is one cookie, and you only get it after you sign in. That is the whole story. No banner asks you for consent because there is nothing here that needs it.

The cookie

NameWhat it isLifetimeSet when
esim_session Your sign-in session. It holds a random token and nothing else — no email, no name, nothing readable. Flags: HttpOnly (scripts on the page cannot read it), Secure (HTTPS only), SameSite=Lax (not sent from other sites). 30 days, or until you log out. Logging out invalidates the token on the server as well, not just in your browser. Only after you enter a sign-in code. Browsing and buying as a guest sets no cookie at all.

Things kept in your browser, not sent to us

The shop remembers your language and currency so it does not ask twice. These live in your browser's local storage, never leave your device, and are not cookies:

Clearing your site data removes them and nothing breaks.

What is not here

One clarification, because it would otherwise look like a contradiction: we do use an error reporting service (Sentry, see Privacy & data). It runs on our server only. Nothing of it is loaded in your browser, it sets no cookie, and it never sees what you do on the page — only that something broke on our side.

Why there is no consent banner

Spanish law (art. 22.2 LSSI-CE, which implements the ePrivacy directive) requires consent for storage that is not strictly necessary for a service the user asked for. A session cookie that exists only because you asked to sign in, and a language preference you set yourself, are exactly the exceptions. A banner here would be theatre — it would ask you to approve something that does not happen.

On the payment page

When you pay, you leave our site for Stripe (or, on KRAHS eSIM, for our own BTCPay Server). Those pages set their own cookies under their own rules — Stripe uses them for fraud prevention on the payment itself. We do not control them and they are not set on our domain. Stripe's cookie policy is on stripe.com.

Turning it off

You can block cookies in your browser. Everything except signing in keeps working: you can browse, pick a plan, pay and receive an eSIM by email as a guest. Only the account page needs the cookie, because that is what proves it is you.