1. Purpose and scope
This Acceptable Use Policy ("AUP") governs your use of the eSimerge wholesale eSIM platform, the partner portal, the public APIs, the documentation, connectivity products, and every eSIM provisioned through us (collectively, the "Services"). It applies to every partner ("Partner", "you"), every authorised user of a partner account, and — by virtue of your contract with them — every End User who installs an eSIM you have distributed. This AUP is incorporated into our Terms of Service; defined terms used here have the meanings given there.
The Services share critical infrastructure with Tier-1 mobile networks. Misuse directly impacts other Partners, downstream End Users, and our Carrier relationships. We enforce this AUP strictly and reserve the right to act without prior notice where a violation creates immediate risk.
2. Lawful use
You and your End Users must not use the Services for any activity that is unlawful or that violates the rights of others in any applicable jurisdiction, including but not limited to fraud, theft, identity-theft, money-laundering, terrorist financing, harassment, stalking, distribution of child-sexual-abuse material, distribution of other illegal content, defamation, infringement of intellectual-property rights, or breach of telecommunications, broadcasting, export-control, or sanctions law.
3. Prohibited telecom and fraud activity
- SIM-boxing and bypass fraud: using eSIMs to terminate international voice or SMS traffic outside official interconnect routes, including GSM gateways operated without Carrier authorisation.
- Traffic pumping and revenue-share fraud: generating artificial traffic to high-cost destinations, premium-rate numbers, or international revenue-share schemes.
- Wangiri and missed-call fraud.
- OTP harvesting and account-takeover services: using eSIMs to receive one-time passwords or verification SMS for accounts that are not your own or those of your End User, including the operation of OTP-as-a-service marketplaces.
- Spam, smishing, vishing, phishing, or unsolicited bulk messaging.
- Spoofing of caller ID, sender ID, or origination identity in violation of applicable rules.
- Crypto-mining over the cellular link or other workloads that consume Carrier resources disproportionately to their value.
- Use of stolen, forged, or synthetic identity documents to onboard as a Partner or to authenticate an End User.
- Use of stolen, compromised, or unauthorised payment instruments to fund a Wallet or pay invoices.
- Chargeback abuse, including raising disputes for activated and used eSIMs.
- Circumvention of network-side fraud controls, geo-restrictions, blocked-destination lists, or lawful-intercept obligations.
4. Sanctions and restricted jurisdictions
You must not knowingly provision, distribute, sell, or otherwise make available eSimerge eSIMs to any person located in, ordinarily resident in, organised under the laws of, or otherwise subject to comprehensive sanctions imposed by the United Kingdom, the European Union, the United Nations, or the United States Office of Foreign Assets Control ("OFAC"). You must screen End Users against applicable sanctions and denied-party lists where required by law applicable to you.
Certain jurisdictions are blocked at our Platform level due to Carrier policy, regulatory restrictions, or risk profile. We maintain an internal blocked-destination list and reserve the right to update it without prior notice. Attempts to provision eSIMs for blocked jurisdictions, or to disguise the destination of an Order, are a material breach of this AUP.
5. Fair use of unlimited and high-allowance Plans
Plans marketed as "unlimited" or with very high allowances are intended for normal personal travel use by the End User who installed the eSIM. They are not a substitute for a fixed-line broadband connection, a home Wi-Fi router, an enterprise backhaul link, an IoT fleet aggregation point, or always-on streaming infrastructure. Where the underlying Carrier's fair-use policy applies (for example, a soft cap after which speeds are reduced for the remainder of the validity window), that cap is binding on the End User and is documented in the catalogue.
- No sustained extreme consumption (e.g., 24/7 high-bitrate streaming or peer-to-peer seeding).
- No use as a permanent residential or commercial broadband connection.
- No tethering to multiple devices in a way that the Carrier identifies as commercial Wi-Fi resale.
- No use as a backhaul for IoT estates, CCTV networks, vending machines, or fleet telematics unless an explicit IoT contract is in place.
- No bot, scraper, or automated workloads originating from the eSIM connection.
We surface Carrier-imposed caps transparently in our FAQ. Carriers may, in accordance with their own policies, throttle or suspend service on individual eSIMs that exceed their fair-use thresholds. Such throttling is not a defect and is not eligible for refund.
6. End-User identification and consent
In jurisdictions where registration of mobile users is required by law (including but not limited to KSA, the UAE, Türkiye, India, and others), you are responsible for ensuring End Users complete the required identification and registration steps before activating the eSIM, and for retaining the evidence required by the relevant authority. You must obtain all consents required to provide End-User personal data to eSimerge and to the relevant Carriers.
7. API, Platform, and infrastructure integrity
- No reverse engineering, decompilation, disassembly, or extraction of source from any part of the Platform, except to the extent expressly permitted by mandatory law.
- No probing, scanning, fuzzing, stress-testing, load-testing, or penetration-testing the Platform without our prior written consent and a coordinated test window.
- No attempts to bypass authentication, authorisation, rate limits, quotas, or signing requirements.
- No introduction of malware, ransomware, trojans, worms, logic bombs, or other malicious code.
- Respect documented rate limits, idempotency keys, pagination contracts, and webhook delivery semantics. Repeated polling of resources at a frequency far exceeding documented guidance is a violation.
- Keep API keys, webhook signing secrets, OAuth credentials, and any other authentication material confidential. Rotate them immediately on suspected exposure and notify us at contact us.
- Do not share authentication material across legal entities; each Partner must use its own credentials.
- Do not crawl, mirror, or republish the catalogue, documentation, or any other Platform content beyond what is necessary to operate your integration.
8. Data and privacy
Do not upload personal data you have no lawful basis to process, special category data the Platform is not designed to handle, or data of children under the age applicable in their jurisdiction without verifiable parental consent. Do not use the Services to enrich, build, or sell datasets about individuals without their consent. Do not exfiltrate data about other Partners, other Partners' End Users, or our internal operations.
9. Branding and communications
Partners may resell eSimerge connectivity under their own brand. You may not:
- Imply official endorsement, certification, sponsorship, or formal partnership beyond what your contract explicitly permits.
- Use eSimerge trademarks, logos, service marks, or trade dress without our prior written consent and adherence to our brand guidelines.
- Use Carrier trademarks, network names, or coverage maps in a way that breaches the Carrier's own usage rules.
- Make claims about coverage, speed, or service quality that go beyond what is documented in the catalogue.
- Use eSimerge branding in any campaign that targets prohibited activities or sanctioned jurisdictions.
10. End-User responsibilities owned by you
As the Partner, you are responsible for:
- Communicating accurate activation instructions, device-compatibility guidance, and supported countries to your End Users.
- Communicating the fair-use, refund, and support expectations applicable to the Plan they purchase.
- Handling first-line support, including triage of activation issues, basic troubleshooting, and refund decisions consistent with the Refund Policy.
- Receiving, recording, and where appropriate escalating End-User complaints, including any complaints relating to lawful intercept, content, or local regulatory matters.
11. Reporting abuse and security issues
Report suspected fraud, abuse, security vulnerabilities, intellectual-property infringement, or any other AUP violation to contact us. Where possible, include the order ID, the ICCID, timestamps, log excerpts, and a clear description of the issue. Responsible-disclosure reports for security vulnerabilities should be sent to the same address, allowing reasonable time for remediation before any public disclosure. We do not pursue good-faith security researchers who follow responsible-disclosure norms.
12. Enforcement
Our typical enforcement ladder is: (1) informal notice with an opportunity to remediate; (2) formal written warning; (3) temporary suspension of affected capabilities (for example, throttled provisioning or restricted catalogue access); (4) full suspension; (5) termination. For violations that put the Platform, other Partners, Carriers, End Users, or eSimerge at material risk — including suspected fraud, sanctions violations, security incidents, or widespread spam — we may proceed directly to suspension or termination without prior notice.
Where we suspend or terminate as a result of a violation, you remain liable for: (a) all amounts owed to eSimerge; (b) any costs imposed on us by Carriers, payment networks, or regulators as a direct or indirect consequence of the violation; and (c) any third-party claims arising from the violation. Wallet balances tied to fraudulent or AUP-violating activity may be forfeited. We may report the violation to Carriers, payment networks, fraud-prevention consortia, and competent authorities where appropriate.
13. Cooperation with investigations
You will cooperate in good faith with any reasonable investigation we conduct into a suspected violation, including by providing logs, identification documents, End-User records (subject to your own privacy obligations), and evidence of remedial measures. Failure to cooperate is itself a material breach of this AUP.
14. Changes to this Policy
We may update this AUP from time to time to address new risks, regulatory requirements, or Carrier rules. Material changes will be communicated through the partner portal or by email at least fifteen (15) days before they take effect, except where a shorter notice period is required for legal, regulatory, or security reasons. The "Effective" date at the top of this page reflects the latest revision. Continued use of the Services after the effective date constitutes acceptance.
15. Contact
Questions about this AUP, requests for clarification, and abuse reports: contact us.
This document is provided as a plain-language template and does not constitute legal advice. Please have qualified counsel review before relying on it in production. Questions? Contact us.