Last updated: 10 September 2026

This Privacy & Cookie Policy explains what personal information blocfone® (“blocfone®”, “we”, “us” or “our”) collects when you use our website and eSIM mobile services (the “Service”), why we collect it, how we use cookies, and the choices you have. It should be read together with our Terms of Service.

When we refer to blocfone®, we mean blocfone LLC, a company headquartered in Atlanta, Georgia 30305, United States. blocfone® is the data controller responsible for the personal information described in this Policy.

The Service is available through our web agent at go.blocfone.com and through our blocfone® bot and mini app on Telegram. Neither requires you to create an account or a password. The wallet you pay from is how we recognise you.

Our approach to privacy

We value privacy and we have designed the Service around a simple principle: we only ask for, and only keep, the information we need to deliver the Service to you. We do not make any special claim to provide more privacy than you would reasonably expect from a responsible provider. Instead, we aim to handle the limited information we hold carefully, to comply with the laws that apply to us, and to be transparent about what we do.

In short:

  • We collect the minimum information needed to sell, deliver, and support your eSIM.
  • We do not sell your personal information, and we do not share it for third-party advertising.
  • We will never share personally identifiable information (“PII”) except as described in this Policy: most narrowly, with the service providers needed to operate the Service, and in response to valid legal or regulatory demands as set out below.
  • We adhere to the laws of the jurisdictions that apply to us and to you.

Information we collect

We collect information in three ways: information you provide, information generated when you use the Service, and information from the providers that help us deliver it.

Information you provide to us. Depending on how you use the Service, this may include:

  • Your Telegram account identifiers, such as your Telegram user ID, username, and the basic profile details Telegram shares with our bot when you interact with it. We use these to operate the bot, deliver your eSIM to your chat, and provide support. In Telegram, your Telegram account is how we identify and reach you, so we generally do not need a separate account.
  • An email address or other contact method, if you choose to provide one (for example, for a receipt or a backup copy of your activation details).
  • In the web agent, we identify you by your Solana wallet address rather than a Telegram account. There is no account or password. To view your past orders, you sign a free message with your wallet to prove you control it, the same kind of signature you give when you buy. It creates a short-lived session and involves no payment.
  • The content of messages you send us, such as support questions and anything you choose to include in them.

Information generated by your use of the Service. To provision and support your eSIM, we process:

  • Technical identifiers for the eSIM itself, such as the ICCID, activation status, assigned plan, and the volume of data remaining or consumed (we use this to deliver the service and to help you with support requests).
  • Your order signature. When you buy, you sign a short message with your wallet. We record that message, your signature, the wallet address that signed it, the version of our Terms you accepted, the language you read them in, and the time. This is our record of what you agreed to. A one-way, salted cryptographic commitment to that record is also written to the blockchain alongside your order. It is indistinguishable from random data and tells anyone reading the blockchain nothing about you or your order.
  • The mobile number assigned to your eSIM. Where the plan you buy includes a mobile number, the network partner assigns one and we store it with your order, so that we can support you and so the number can be released when your plan ends. The number itself is never written to the blockchain. Only a one-way, salted commitment to it is written, and that cannot be turned back into the number.
  • Basic technical and log information, such as IP address, device and browser type, and timestamps, which our systems generate automatically. We use this to operate the Service, keep it secure, and detect and prevent fraud and abuse. We keep this information for no longer than we need it for those purposes.
  • For purchases in the web agent, we record your wallet address, and a label indicating which method you used to reach us and pay (for example, Telegram, a connected web wallet, social sign-in, or a payment QR code). This label records the door you came through, not who you are. Where you paid from a wallet created for you by signing in with Google or Apple, we also record the wallet service’s own internal identifier for that wallet, a random ID that contains no name, no email address, and nothing else about your Google or Apple account. We use it only so that our support team can tell your orders apart if you have bought using more than one sign-in. It is never used to authenticate you, never used for marketing, and never shared.
  • If you choose to share your location in the web agent, your device’s coordinates are sent to our server and to a mapping service only to determine your country; we receive back a two-letter country code and do not store your coordinates. We also record short, non-identifying diagnostic messages if something goes wrong, to help us fix errors.

Information from payment and connectivity providers. Payments and network connectivity are handled by third parties:

  • Cryptocurrency payments (USDC) pass through our on-chain escrow smart contract and are recorded on a public blockchain. We receive the wallet address you pay from, the transaction details, and the contract’s record of the payment and its release or refund. Blockchain data is public, permanent, and outside our control, and a wallet address can in some cases be linked to an individual.
  • Connectivity is provided through mobile network partners. Network usage is processed by those carriers under their own terms in order to deliver the data service.
  • In the web agent, you can pay by connecting Phantom, Solflare, Backpack or Base; by signing in with Google or Apple, in which case Phantom creates an embedded wallet for you; or with a Solana Pay QR code. Where you sign in with Google or Apple, Phantom is the provider for that sign-in. We do not receive your Google or Apple account details or login tokens; we receive only your wallet address and the transaction.
  • Reading the blockchain. To show you plans, and to let your own device check them against the record held on the blockchain, our web agent reads from public Solana network endpoints operated by third parties. Those operators can see your device’s IP address and which set of plan offers is being checked. A set of offers is shared by everyone shopping the same provider and country, so this does not reveal which plan you are looking at, or whether you buy anything.

Delivery through Telegram. Where you use the Telegram bot, your interactions with it and the delivery of your eSIM pass through Telegram’s platform, which processes them under Telegram’s own privacy policy. We receive only the account identifiers and messages described above; we do not receive your Telegram phone number unless you choose to share it.

Identity verification. We do not require identity documents to deliver the Service in the ordinary course. Where the law of a relevant jurisdiction requires us to verify identity or perform other regulatory checks for a particular product or location, we will collect only the information that obligation requires, and we will tell you when that applies.

Sanctions screening. We are required by law to check that we are not doing business with a sanctioned person. We screen the wallet address used for every order against published sanctions lists — including the US Treasury (OFAC) blocked-address and Specially Designated Nationals lists, the EU consolidated list, and the UK sanctions list — and we keep a record of each check, which version of each list it was run against, and its result. Where we hold a name because a particular product required it, we screen that too. This checking is a legal obligation and does not depend on your consent; we cannot provide the Service without it.

We do not seek to collect special categories of data (such as data about health, race, religion, or political opinions). Please do not send us this kind of information unless it is necessary, for example to handle an accessibility request.

Why we use your information

We use the information above only to:

  • provide the Service: sell, provision, deliver, and support your eSIM, and process payments and refunds;
  • keep the Service secure: detect and prevent fraud, misuse, and security incidents;
  • comply with the law: meet tax, accounting, sanctions, regulatory, and other legal obligations that apply to us; and
  • send optional communications that you have asked to receive, which you can opt out of at any time.

We do not build advertising or behavioural profiles, we do not use your information for targeted advertising, and we do not make legally significant decisions about you by automated means.

If you are in the EEA or UK, the legal bases we rely on for these purposes are, in order: performance of our contract with you; our legitimate interest in keeping the Service secure and preventing fraud; compliance with a legal obligation; and your consent (which you can withdraw at any time). See EEA, UK, and other regions below for more.

How we share information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising (a category that several US state privacy laws define and restrict). We share information only in these limited situations:

  • Service providers and partners that we need in order to deliver the Service, for example, hosting providers and mobile network/connectivity partners. They may only process your information to provide their service to us, under contractual obligations of confidentiality and security.
  • A mapping service, which we use only to convert a location you choose to share into a country code.
  • The Telegram platform, through which the Service is delivered to you when you use the Telegram bot. Your use of Telegram is also governed by Telegram’s own terms and privacy policy, over which we have no control.
  • The Phantom wallet service, when you choose to connect or create a wallet through it in the web agent; your use of Phantom is governed by Phantom’s own terms and privacy policy. The same applies to any other wallet you choose to connect.
  • Public blockchain network operators, whose endpoints our web agent reads from as described above. They receive your IP address as an unavoidable part of that request, under their own policies.
  • Public blockchains. Crypto payment and escrow transactions are recorded on a public blockchain by design. This information, including wallet addresses and amounts, is visible to anyone and cannot be deleted or controlled by us.
  • Legal and regulatory demands. We will disclose personal information to a government, law-enforcement, or regulatory body only where we receive a valid, legally binding demand from an authority with proper jurisdiction, and where the demand is relevant and applies to us. We assess each request on its own terms, disclose only the information the request actually requires, and decline or challenge requests that are invalid, overbroad, or that do not apply to us. We adhere to the laws of the relevant jurisdictions in doing so.
  • Corporate transactions. If blocfone® is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction; any recipient will remain bound by this Policy or a policy at least as protective.

International transfers

blocfone® is based in the United States, and we process personal information there. If you use the Service from outside the United States, your information will be transferred to and processed in the US, and may also be processed by our providers in other countries. US privacy laws may differ from those where you live. Where we transfer personal information across borders, we take steps to protect it in line with applicable law, including appropriate contractual safeguards where required (such as the EU/UK Standard Contractual Clauses for transfers out of the EEA or UK).

How long we keep information

We keep personal information only for as long as we need it to deliver and support the Service, and for any period we are legally required to retain it. For example, we keep records relating to your orders and payments for as long as we need them to support you and to meet our tax and accounting obligations (generally up to seven years in the United States) and we keep basic technical logs for only a short period, for security and fraud-prevention purposes. When we no longer have a reason to keep information, we delete it or anonymise it so that it no longer identifies you.

We also keep the records we rely on when reviewing a refund request (your acceptance of the plan terms, our record of delivery, and activation and usage records provided by the mobile provider) for as long as applicable law and regulation require. Section 5 of our Terms of Service explains how we use them.

Where we are required to keep records to meet anti-money-laundering obligations, we keep them for the period the applicable law requires: in the European Union, five years from the end of the relationship or the transaction, which member states may extend to ten. Records we are required to preserve as evidence are kept unaltered for that period and then deleted.

How we protect information

We use reasonable technical and organisational measures designed to protect personal information against loss, misuse, and unauthorised access, and we limit access to those who need it to do their work. As part of this, we pseudonymise the Telegram identifiers we store (we keep a one-way cryptographic hash rather than your raw account ID) and we encrypt sensitive delivery information, such as your eSIM activation details, at rest. No method of transmission or storage is completely secure, so while we work to protect your information we cannot guarantee absolute security.

Reporting a security issue

We welcome reports of security vulnerabilities in the blocfone® service, including our on-chain programs. If you believe you have found a vulnerability, please email hello@blocfone.io with enough detail for us to reproduce and assess it. We aim to acknowledge your report within 10 working days.

We ask that you give us a reasonable opportunity to investigate and resolve the issue before disclosing it publicly, and that while testing you avoid privacy violations, loss or destruction of data, and any disruption to the service or to other users. We will not pursue action against researchers who report in good faith and follow this guidance.

Your rights

Depending on where you live, you may have some or all of the following rights over your personal information:

  • to know and access the information we hold about you;
  • to have inaccurate information corrected;
  • to have your information deleted, where there is no overriding legal reason for us to keep it;
  • to receive your information in a portable format;
  • to opt out of the sale of personal information or its use for targeted advertising (note that blocfone® does neither); and
  • (EEA/UK) to restrict or object to certain processing, and to withdraw consent where we rely on it.

Several US states (including California, Virginia, Colorado, and Connecticut) grant residents rights along these lines, and we extend them regardless of your state of residence. We will not discriminate against you for exercising a privacy right.

Please note that information recorded on a public blockchain (including wallet addresses, transaction amounts, and the cryptographic commitments described above) cannot be altered or deleted by us or by anyone else. Where you ask us to delete information, we will delete what we hold in our own systems, subject to any legal obligation to retain it.

To exercise a right, contact us at hello@blocfone.io. We will verify your request and respond within the time required by applicable law. If you are in the EEA or UK and are unhappy with our response, you may also lodge a complaint with your local data protection authority.

EEA, UK, and other regions

Because we offer the Service to customers around the world, more than one data protection law may apply to how we handle your information. We aim to meet the requirements of whichever applies to you.

EEA and UK (GDPR / UK GDPR). blocfone® acts as the data controller for your personal information. We process it on the legal bases described under Why we use your information; we transfer it to the US and other countries only with appropriate safeguards such as the EU/UK Standard Contractual Clauses (see International transfers); and we keep it only as long as needed (see How long we keep information). In addition to the rights listed under Your rights, you may object to processing based on our legitimate interests, object at any time to any use of your data for direct marketing, and ask not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects (we do not make such decisions). You may also lodge a complaint with your local supervisory authority. EEA authorities are listed by the European Data Protection Board, and in the UK by the Information Commissioner’s Office (ICO).

  • Privacy contact (including EEA/UK enquiries): hello@blocfone.io. If you are in the EEA or UK, you can use this address to contact us about your personal information, to exercise your rights, or to reach us about any data protection matter.

Other regions. Where other data protection laws apply to you (for example Brazil’s LGPD, Canada’s PIPEDA, or Australia’s Privacy Act), we handle your information in line with those laws and honour the rights they give you. Contact us at hello@blocfone.io to exercise them.

Children

The Service is not directed to children, and we do not knowingly collect personal information from anyone under the age of 13 (consistent with the US Children’s Online Privacy Protection Act). Where local law sets a higher minimum age for consent (in parts of the EEA, the age of digital consent is up to 16), we apply that higher age. If you believe a child has provided us with personal information, please contact us so we can delete it.

Cookies and similar technologies

The web agent at go.blocfone.com uses a small number of strictly necessary cookies and on-device storage to work. It also uses on-device storage in the Telegram mini app, which runs in a webview; your use of Telegram is governed by Telegram’s own policies, which we do not control. This section covers the cookies and similar technologies used across the blocfone® website and web agent.

What cookies are. Cookies are small text files placed on your device when you visit a website. “Similar technologies” include things like local storage and pixels that perform comparable functions. They let a site work properly, remember your choices, and understand, in aggregate, how the site is used.

How we use them. We keep our use of cookies to a strict minimum. The web agent uses a short-lived session cookie (about 35 minutes) to keep you signed in after you prove control of your wallet, and a short-lived cookie that carries your pending order through the sign-in step so your purchase isn’t lost. It also uses your browser’s local storage to remember your in-progress order, which wallet or sign-in method you last used, an identifier for the wallet account last used on that device (so we can ask you to confirm if you come back with a different one) and basic diagnostic flags. These are all strictly necessary to provide the Service and to keep it secure and working; we do not use analytics or advertising cookies, we do not build advertising profiles, and we do not sell or share information collected through cookies for cross-context behavioural advertising.

If we add website analytics in the future, we will use a privacy-respecting, cookieless analytics tool that measures usage only in aggregate, does not identify you, and is never used for advertising, and we will update this Policy before doing so.

Your choices and consent. Because we set no analytics or advertising cookies and only strictly necessary cookies, there is no non-essential cookie consent to manage today. If we introduce any non-essential cookies or similar technologies in the future:

  • EEA, UK, and other regions that require it. We will ask for your consent before setting them, through a cookie banner you can accept or reject and change at any time. Strictly necessary cookies do not require consent.
  • United States. Where required, we will honour browser-based opt-out signals such as Global Privacy Control (GPC) for the categories US state laws cover. As noted elsewhere in this Policy, we do not sell your information or use it for targeted advertising in any case.
  • Browser controls. You can also block or delete cookies through your browser settings at any time; blocking strictly necessary cookies may stop parts of the website from working.

Third-party cookies. Any cookies on the site would be limited to those set by the providers that help us run it securely (such as our hosting or security provider), under their own policies. We do not permit third parties to use cookies on our site for their own advertising.

Changes to this Policy

We may update this Policy from time to time. When we do, we will change the “Last updated” date above and, where the change is significant, take reasonable steps to bring it to your attention. The version in effect at the time you use the Service applies to that use.

Contact us

If you have any questions about this Policy or how we handle your information, contact us at hello@blocfone.io.