Privacy policy
Last updated: October 4, 2026
Table of Contents
1. Who we are
This policy explains what personal data Andalu collects when you browse or buy, and why. It also says who processes it for us, how long we keep it and what your rights are.
Andalu sells digital game keys and travel eSIM data. Andalu is operated by ZeroOne eCommerce Co., a Delaware company, whose address is 4300 Cliffside Drive, La Crosse, WI 54601, United States. You can buy without an account. An account is optional: it lets you sign in with your email to see your past orders.
2. What we collect and why
When you browse: your IP address, and the country it points to. We use the country to show prices in your currency and to tell you whether a key works in your region. The country is kept in a cookie for 1 day.
When you buy a game key or an eSIM: your name, email address, mobile number and country. We use your email to deliver your order and reply to you. Our order emails record whether they were delivered and opened, and which of their links you clicked. Opening your order page from one is recorded too. This lets us confirm your order reached you and step in when it didn't. We never use this for marketing. We use your name and number to check the order is yours, and your country to price it. These details, what you bought and what you paid are stored with your order by our payment provider.
Text-code verification: before you pay, we text a code to your mobile number to confirm it's yours. Google Firebase sends the code. It keeps this device verified for up to 7 days, so you aren't asked every time.
Phone line check: before the code is sent, a phone-data provider tells us whether the number is a mobile line. Internet and virtual numbers can't be used to buy. We keep the answer for 30 days, stored against a one-way hash of the number, not the number itself.
Your account, if you make one: you sign in with your email address and a 6-digit code we email you, with no password. The account stores your email address, the name you last checked out with, when you signed in, and your sign-in sessions. Each session holds a one-way hash of the device and the country we saw you from. Two cookies keep you signed in on that device for 30 days. The andalu_session cookie can only be read by our server. The andalu_account cookie holds only the first letter of your email, so the menu can show it. A third, andalu_adev, is a random ID that tells us when you sign in on a new device, so we can email you about it. Your account shows the orders sent to your email address, never your keys or eSIM codes. You can delete your account yourself from its settings page. The account and its sessions are deleted at once. Your orders are kept as set out in How long we keep it.
Payment: you pay on Stripe's secure payment page. Your card details go to Stripe, and Andalu never stores them.
Fraud checks: with each payment attempt we record your IP address and a device security ID. The device security ID is a random ID in a cookie on your device. We count attempts using one-way hashes of your email, phone number, IP address and device ID. Cloudflare Turnstile runs an automated bot check on checkout, donations and our forms. Stripe scores each payment for fraud risk.
Location and payment details for fraud checks: to protect you and us, we record the approximate location of your IP address (town, region and network). We also record your billing address, your verified phone number, and the last four digits and expiry of your card. We record your browser's time zone, language and screen size too. We compare how far your IP address is from your billing address. They are kept with the order, for the order's retention period.
Returning buyers: once an order to your phone number has been delivered, you can skip the text code next time. A cookie on the device you verified from makes that work. It holds a one-way hash of your number, of the device and of the country you verified from, never the number itself. It lasts up to 7 days and only works on that device in that country. A larger order than you have bought before asks for a new code.
Remembered details: we keep your email, name, country and phone on this device to fill checkout next time. We keep them from the moment you go to payment, for up to 180 days after your last checkout. "Not you?" at checkout clears it.
Checkout reliability: while you go through checkout, your browser reports which step it reached (for example "code sent" or "payment page opened") and any error. Each report carries a random ID for this browser tab. It never includes your email, number or payment details, and we keep it for 14 days to find and fix problems.
Support messages: when you contact us, we collect your email, your message, any order number you give and any screenshots you add. We also record the page you wrote from, your browser type and a summary of your cart, so we don't have to ask for them.
Product popularity: if analytics is on for you, your browser tells us when you view a product or add one to your cart. See Analytics and consent below. We record the product, the kind of event and the day, and nothing that identifies you. When a payment completes, we count that purchase per product in the same way, without your details.
Donations: you pay on Stripe's page. We don't ask for a phone number.
Site measurement: only if you allow analytics, Cloudflare Web Analytics records the page you opened and the page you came from. It also records how fast the page loaded and your browser type. It sets no cookie and stores nothing on your device.
Tag manager: every visitor's browser loads Google Tag Manager, which sends Google your IP address and browser type, as any script loaded from Google does. In the EU, the UK and Switzerland it starts locked. It sets no analytics cookies and runs none of our analytics tags until you allow analytics. Elsewhere it is on by default, as set out under Analytics and consent below.
Site recordings: where analytics is on for you, Microsoft Clarity records how you use the pages, with clicks, scrolling and anonymized replays and heatmaps. It sets the cookies _clck and _clsk. It masks what you type. It also masks the whole of the checkout, order and account pages, so what is on them is not recorded. It is not loaded on the order confirmation pages at all.
Analytics and consent: Where analytics needs a yes first, and where it is on by default. In the EU, the UK, Switzerland, Iceland, Liechtenstein and Norway, and wherever we cannot tell where you are, analytics runs only after you accept. That covers session replay and product counts too. Everywhere else they run from your first page, unless your browser sends Global Privacy Control, which we honour. You can turn them off at any time from the notice, the Cookie settings link in the footer or the Cookie Policy page. Payment pages are never recorded.
Site statistics: only if you allow analytics, Google Analytics counts visits, the pages and products viewed and what was added to carts. It sets the cookies _ga and _ga_ followed by an ID. If you allowed it when you bought, we tell Google Analytics about the purchase once the payment is taken. We send the order reference, the products, the amount and the currency, with the random ID from its cookie. Never your name, email address, phone number or payment details. Its advertising features are off.
3. Why we are allowed to use it
We use your details to take, deliver and support your order, because we can't sell to you without them.
We run the fraud checks because of our legitimate interest in keeping stolen payment cards off Andalu. They also protect buyers whose cards could be misused.
We keep order records to meet our tax and accounting duties.
In the EU, the UK and Switzerland, we record product popularity, and run any analytics that sets cookies or records sessions, only with your consent. You can withdraw it at any time on our Cookie Policy page. Elsewhere we run them by default, because of our legitimate interest in improving the site. You can turn them off at any time on the same page, and we honour Global Privacy Control.
4. Who processes it for us
We share personal data only with the providers that run each part of the service, and only what each one needs:
Payments: Stripe processes your payment and keeps the order record.
Bot check: Cloudflare Turnstile.
Phone verification: Google Firebase sends the text code, with a Google reCAPTCHA check on the request.
Phone line check: a phone-data provider receives your number to tell us its line type.
Hosting: Cloudflare serves the site.
Error monitoring: for every visitor, Sentry (United States) receives technical error reports and a count of page loads. It gets no cookies, no personal details and no page address beyond the path.
Site measurement: Cloudflare Web Analytics, only if you allow analytics and without cookies.
Tag management: Google Tag Manager loads for every visitor.
Site recordings: Microsoft Clarity, only if you allow analytics.
Site statistics: Google Analytics, only if you allow analytics.
Product analytics: PostHog counts which steps of the site and checkout are used, only if you allow analytics. It never receives your name, email address, phone number or payment details, and records no sessions.
Email delivery: Resend sends our order and support emails, and tells us whether each order email was delivered, opened or clicked.
Delivery partner: delivers your key and emails it to you. It receives your email address and what you ordered, and tells us whether that email arrived and whether you opened your order.
Map lookups: OpenStreetMap receives the country, postcode and town of your billing address (never your name or street) to find its approximate location.
eSIM provider: your eSIM plan is issued without sending the provider your name, email address or phone number.
Support desk: Atlassian Jira Service Management stores the messages and screenshots you send us.
Internal alerts: when an order fails or is flagged as possible fraud, its order number and email address go to our team's internal chat. That way a person can act on it.
We don't sell your personal data, and we don't share it for advertising. We share data with others only when the law requires it, or to stop fraud.
Some of these providers process data in the United States and other countries outside yours.
5. How long we keep it
Country cookie: 1 day.
Device security ID cookie: 1 year.
Phone line check answer: 30 days, as a one-way hash of the number.
Fraud attempt counters: from 10 minutes to 30 days, depending on the check.
Records of held, refunded, disputed or fraudulent orders: 400 days.
Product popularity records: 37 days. They contain no personal data.
Support messages and the screenshots you send: 2 years after your request is resolved.
Your account: until you delete it. Deleting it removes the account and its sessions straight away; it does not delete your orders, which follow the order period below. A sign-in code expires after 10 minutes and a sign-in session after 30 days without a visit.
Orders: 2 years. An order record holds your email address, what you bought, what you paid, and the country and approximate location we saw you from. It also holds your billing address, your verified phone number and the last four digits and expiry of your card. It records the risk checks that ran on it too. We keep it that long to deliver and support your order and to handle a claim or a dispute. It also meets our tax and legal duties. An order that has been disputed with your card issuer is kept past that period, for as long as the dispute needs it.
Our staff's actions on an order (who released, canceled or refunded it, and when): 3 years. This log names our staff, not you, but it points at your order.
Card risk history: 1 year, as a one-way hash of the card, never the card number itself. It records that a card has been used here before and from which countries. That is how we tell a returning customer from a stolen card being tried out.
Support messages and screenshots: for as long as we need them to answer you and to handle any claim that follows.
6. Your rights
You can ask us to:
- give you a copy of the personal data we hold about you
- correct it if it's wrong
- delete it
- send it to you in a format another service can read
- stop using it for a purpose you object to
If you're in the EU, the EEA or the UK, you can also ask us to limit how we use it. You can complain to your data protection authority too.
If you're in California, you have the right to know what we collect, to correct it and to delete it. We won't treat you differently for using these rights. We don't sell or share personal data for advertising.
To use any of these rights, send us a request through the contact form. Include the email address you used with us, and your order number (like #42101) if you have one. We answer within one month.
Send a privacy request8. Children
Andalu is not for children under 13, and we don't knowingly collect their data. If you think a child has given us personal data, contact us and we will delete it.
9. Security
Every page is served over an encrypted connection. Your card details go straight to Stripe, never to us. The email addresses, phone numbers, IP addresses and device IDs we use to count fraud attempts are stored as salted one-way hashes.
No system is completely secure. If a breach affects your data, we will tell you and the authorities as the law requires.
10. Changes to this policy
When we change this policy, we update the date at the top of this page.
11. Contact us
For any privacy question or request, use the contact form. Our contact address of record is support@andalu.com.
Andalu is operated by ZeroOne eCommerce Co., a Delaware company, whose address is 4300 Cliffside Drive, La Crosse, WI 54601, United States.
Ask a privacy questionRead this policy with our Terms of Service and our Cookie Policy.