Privacy Policy
Last updated: 7 July 2026
This Privacy Policy explains what information NordSecure collects, why, and what choices you have. We designed our business so we handle as little of your personal data as possible.
Information we collect
- Card orders — checkout is handled by Shopify. We receive the details needed to fulfil and support your order (name, shipping address, contact details, items).
- Crypto orders — when you pay for a phone in cryptocurrency, checkout happens on this site rather than Shopify, so we collect and store your email, delivery address and phone number ourselves in order to post the parcel. We ask for nothing else, and you are not asked to create an account.
- Payment information — handled entirely by our payment providers. We never see or store your card details. For crypto, we store the payment reference and amount, not your wallet.
- eSIM orders — bought with an Order ID and PIN only. No name, address or ID is required or collected.
- Phone-number & verification-code (SMS) orders — like eSIMs, bought with an Order ID and PIN only, with no name, address or ID required or collected. The service and country you choose are passed to the number supplier to fulfil the order; your identity is not.
- Messages — if you contact us, we keep your message and contact details to reply and provide support.
- A cart cookie — a single httpOnly cookie stores your cart ID so your basket persists between visits. It contains no personal data.
- Analytics cookies, only if you accept them— we use Google Analytics to see which pages people find useful. It sets cookies, so we ask first and load nothing until you say yes. Declining is remembered, changes nothing about the site, and we still count the visit using our hosting provider’s cookieless analytics, which records no identifiers and cannot follow you between sites. Your IP address is anonymised before Google receives it.
How we use it
- To process, ship, and support your orders.
- To answer your questions.
- To meet legal and accounting obligations.
We do not sell your data, and we do not build advertising profiles.
Processors we rely on
- Shopify (Canada/EU) — store, card checkout, and payment processing for card orders.
- Vercel (EU/US) — hosts this website, runs the code that serves it, and provides the cookieless visit counts described above.
- Google (US) — Google Analytics, and only for visitors who accept analytics cookies. Nothing is sent to Google if you decline. This is website measurement only: it has no connection to the phones we sell, which ship with no Google account and no Google services running privileged.
- Upstash (EU) — the database holding crypto phone orders, including the delivery address you give us at checkout.
- NOWPayments (EU) — processes cryptocurrency payments and tells us when one has cleared.
- Shopify (EU/US) — runs the checkout for phone orders paid by card, and processes those payments. Card details are handled entirely by Shopify; they never reach us.
- Resend (EU/US) — sends order confirmations, shipping notices, and replies to your messages.
- Our connectivity supplier— provisions eSIM data plans and phone numbers. Receives the plan ordered; it is not given your name or address, because we don't have them.
- Our verification-number supplier — routes one-time numbers for SMS verification. Receives the service and country requested; it is not given your identity.
- WordPress — hosts our blog content.
Newsletter
If you subscribe to our newsletter we store your email address, the exact consent wording you agreed to and its version, and the time you agreed — so we can always show what you consented to and when. We also store a salted hash of your IP address and browser user agent to detect abuse of the signup form. The raw IP address is never written to storage, and a salted hash cannot be reversed back to it.
Confirmation is required: we send one email asking you to confirm, and nothing further unless you do. That email, and every message after it, carries a working one-click unsubscribe link and the standard unsubscribe headers your mail app uses for its own button.
If we issue you a discount code, we store the code, its status and — once used — which order it applied to and how much it took off. We keep subscriber records until you unsubscribe or ask us to erase them, then delete them. Redeemed codes stay attached to the order they paid for, because that order is an accounting record we must keep, but the link back to your email address is removed.
We do not use tracking pixels, remote images or click tracking in our emails, and your address is not shared with an email marketing platform — our sending provider handles delivery only.
How long we keep it
We keep order records — including delivery addresses for crypto phone orders — for as long as we need them to support the order and to meet Danish accounting and tax obligations, then delete them. eSIM purchases carry no personal data to retain. You can ask us to delete anything we hold that we are not legally required to keep.
Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, and you can object to certain processing. To exercise these rights, contact us at support@nordsecure.eu.
Contact
Questions about this policy? Email support@nordsecure.eu.