Legal / Privacy

Privacy

Last updated: 2026-08-24

What we store about you, why, and for how long. In plain words — if a sentence here needs a lawyer to decode, it is our failure, not yours.

Where you were when you bought

When you buy, we record up to three things about your location: the country you choose at checkout, the country that issued the card you paid with (Stripe tells us this — we never see the card number itself), and the IP address the order came from.

We record it because the tax on a digital purchase is decided by where the buyer is, and we are required to hold two pieces of evidence for that which do not contradict each other. That is the whole purpose. None of it is used to build a profile of you, to advertise, or to guess anything else about you.

Today we do not translate that IP address into a country — the other two signals already give us the two we need. We keep it in case a tax authority ever asks us to show a third, which is the only thing it would be used for.

The two-letter country codes are part of the accounting record behind your receipt, so we keep them for 10 years. The IP address itself is different: it is far more identifying than a country code and tells us nothing extra once the country is recorded, so we erase it after 12 months.

The erasure is done by a scheduled job, not by hand. It overwrites the address and records the date it did so — so if you ever ask, we can tell you the difference between “we destroyed it on this date” and “we never had one”.

If the three signals disagree with each other, that is flagged for a person to look at. It usually means nothing — people travel, and cards follow them — but it is also how card fraud looks, so we would rather check.

The payment page

The checkout page is the only page on this site that contacts anyone but us. The card fields are supplied directly by Stripe, our payment processor, so your card number reaches them and never us.

Stripe also loads hCaptcha, a bot-detection service, to protect the payment form from automated card testing. We did not choose to add it and we cannot switch it off without giving up card payments altogether — so we are telling you it is there instead.

Stripe’s fraud checks can also bring in further services of their own when something about a payment attempt looks unusual. That happens inside Stripe’s code rather than ours, and we would rather tell you the payment page is a surface where that can happen than publish a list of exactly two and be wrong on the days it is three.

What reaches them is your IP address and basic information about your browser. None of it is used to advertise to you, and we ask none of them anything about you.

Your order and your eSIM

The email address you give at checkout; what you bought and what you paid; the device-compatibility answer you were shown before paying; and, for each eSIM we issue you, its ICCID and activation code — the QR.

The email is how we deliver your eSIM and how you get back into your order later; there is no password on this site. The ICCID and activation code are the eSIM — without them we cannot re-send it or help when it will not install. The device answer is kept so that, if there is ever a disagreement, it is clear what you were told before you paid.

Order records, including the ICCID and activation code, are kept for 10 years, because they are the accounting record behind a receipt and we are required to hold them.

We never see or hold your card number — payment is handled by Stripe. We do not store your phone’s IMEI or EID, we do not track you across other websites, and we do not sell or share your data with advertisers.

Our own support staff can read it, in an admin area that records who looked at what. Our network partner necessarily receives the request to issue your eSIM, but not your name and not your email — only an anonymous reference.

Sign-in links

When you ask for a link to reopen your order, we store your email address, a one-way hash of the link’s token — never the link itself — when it expires, and the IP address the request came from.

The hash lets us check your link without our database ever containing a working key to your orders. The IP address is kept only so we can investigate if somebody floods an inbox with sign-in requests.

Kept for 30 days, then deleted by a scheduled job — the same kind of job, on the same schedule, as the erasures described above.

We do not store your browser, your device, or any identifier that would let us recognise you somewhere else.

How you found us

When you first arrive, we record which website or search engine sent you, which of our pages you landed on, and any campaign tag in the link you followed. If you buy something, a copy of that is stored on the order.

We keep the name of the site — “google.com”, “chatgpt.com” — and nothing else from it. Not the address of the page, and not what you typed into a search box to get here. If you searched for us, we do not know what you searched for.

It is the only way to tell which of our pages actually help people find what they came for. That is the whole use. It is not linked to anything you do elsewhere, it is not sold, and it is not shared with an advertiser.

We do not set a tracking cookie to do this. It is held in the ordinary session your browser already keeps for security while you are on the site (“fivebars-session”), and it disappears when that session does.

On an order, we keep it for 24 months, and then a scheduled job erases it. That is deliberately shorter than the 10 years we hold the accounting record behind your receipt: we are required to keep that, and there is no such reason to remember how you arrived. The order stays; how you found us is deleted from it.

SIA "Ragnarok Solutions" · Reg. No. 50203000401 · VAT LV50203000401 · Lejasdores iela 10, Alderi, Ādažu pag., Ādažu nov., LV-2164 Latvia