The short answer
For most travellers, a travel eSIM from a legitimate provider is a safe way to get mobile data abroad. An eSIM is a standard mobile line delivered digitally instead of on a plastic card. It connects to licensed mobile networks in the countries it covers, in the same way a roaming SIM or a local SIM does. Using mobile data from your own line is also generally safer than relying on public Wi-Fi in airports, cafés and hotels.
That said, safe depends on what you are worried about. Some people are concerned about the phone itself, others about personal data, others about scams or being overcharged. The sections below take each concern in turn and are honest about where the risks actually lie.
What an eSIM can and cannot do on your phone
An eSIM profile is not an app. It does not have access to your photos, contacts, messages or files. It is a set of credentials that lets your phone identify itself to a mobile network, the same job a physical SIM card does.
Installing an eSIM does not change your phone's software, does not replace your existing SIM and does not affect your normal phone number. Your own SIM continues to handle calls and texts if you keep it switched on. You can turn the travel line off in your settings at any time, and remove it after the trip if you want to.
How eSIM profiles are protected
eSIM profiles are installed through a process defined by industry standards, built into your phone's operating system by the phone maker. The profile is downloaded over an encrypted connection and stored in a secure chip on the phone. Your phone also asks you to confirm before adding a new line, so an eSIM cannot be installed silently.
eSIM versus a physical SIM
Because an eSIM cannot be popped out of the phone, a thief cannot simply remove it and put it in another device. That is a modest security advantage over a plastic SIM. As with any SIM, you should still protect your phone with a screen lock.
What a travel eSIM provider can see
Any mobile service involves some data. It is reasonable to ask what that is.
- Order details. To sell you an eSIM, Spidot needs your email address, your plan and payment status. Payments are handled by a payment processor; according to our privacy policy, we never receive your full card number. We do not need your phone number, home address or date of birth.
- Line information. The eSIM has an identifier, and the provider sees how much data has been used and how much is left, so you can check how much data is left.
- Network-level data. The mobile networks that carry your traffic see technical data about the connection, as for any mobile service.
What about the content of your browsing?
Most apps and websites now use encryption, shown in browsers as https. With encrypted connections, the content of what you send and receive, such as messages, passwords and card numbers, is not readable by the networks in between. Messaging apps with end-to-end encryption protect content even from the app provider. That holds whether you are on a travel eSIM, your home operator or a local SIM.
If you want an additional layer, you can use a reputable VPN over your eSIM data. It adds a little overhead to data use, and some streaming or banking services behave differently with a VPN switched on.
Mobile data versus public Wi-Fi
For many travellers, the most practical security improvement a travel eSIM brings is that it reduces the need for public Wi-Fi. Public networks in airports, hotels, cafés and stations are shared with strangers, may be poorly configured and can be imitated by look-alike networks with similar names. Some ask for personal details before you can connect.
Mobile data runs on a connection between your phone and the network that other users nearby cannot easily join. It is not a guarantee against every risk, but it removes several common ones.
If you do use public Wi-Fi
Turn off automatic joining of open networks, check the exact network name with staff, prefer encrypted apps and websites, avoid entering card details or logging in to banking on public networks if mobile data is available, and forget the network when you leave.
Avoiding eSIM scams and mistakes
Most problems with travel eSIMs are not about the technology but about where the eSIM came from or how its QR code is handled.
- Buy directly from the provider's own website or app. Be wary of links in unsolicited messages offering cheap travel data.
- Only scan QR codes from your own order email. An eSIM QR code is effectively a key to a mobile line. Do not scan codes sent by strangers or found on posters.
- Do not share your QR code. Anyone with the code may be able to install your eSIM on their phone before you do. Treat it like a ticket.
- Check the website address before paying. Look-alike sites copying well-known brands exist in every industry.
- Contact support through the official address. For Spidot, that is support@spidot.com. Be wary of any message asking you to send card numbers or passwords by email.
SIM swap fraud and your home number
SIM swap fraud is when a criminal convinces your home operator to move your phone number to a SIM they control, so they can receive your security codes. It targets your home number, not your travel eSIM.
A data-only travel eSIM does not have a phone number, so it does not take part in the text-message codes used by banks and other services. Your home SIM stays responsible for those. To protect it, set a PIN or password with your home operator if they offer one, keep your home SIM switched on while you travel so you notice if it suddenly loses service, and move to authenticator apps where services allow it.
Location, IP addresses and websites abroad
When you use mobile data abroad, your internet traffic may be routed through a different country from the one you are standing in. This is normal for roaming services, including many home operators. It means some websites may show content or prices for another country, or ask you to confirm a login because it looks unusual.
This does not mean anyone is tracking you. Your phone's GPS location is separate and is controlled by your phone's location settings, not by the eSIM. Spidot does not collect GPS location; the details are in our privacy policy.
Billing: no surprises by design
Another kind of safety is financial. Travel eSIMs are prepaid. You pay for a plan before you travel, and when the data or validity runs out, the line stops working rather than adding charges. Topping up is something you choose to do, as described in our add more data guide.
The main risk of unexpected charges is on your home SIM. If data roaming is left on for your home line, it can use data abroad and your operator may bill you. Turn data roaming off for your home SIM and on for the travel eSIM only, as shown in our data roaming guide.
Simple habits that keep you safe abroad
These apply whichever way you connect.
- Use a screen lock and turn on your phone's find-and-erase feature before you travel.
- Update your phone's software before you leave.
- Keep data roaming off for your home SIM.
- Prefer mobile data over unknown Wi-Fi for logins and payments.
- Keep your eSIM QR code private and delete the email once the eSIM is installed, if you prefer.
- Back up your phone before the trip in case it is lost or stolen.
- Check your phone is compatible before you buy, so you are not tempted by workarounds.
Frequently asked questions
Can a travel eSIM read my messages or photos?
Is a travel eSIM safer than hotel Wi-Fi?
Can someone else use my eSIM if they get my QR code?
Does using a travel eSIM affect my WhatsApp or iMessage account?
Will I be charged if I use up my eSIM data?
Should I remove the eSIM after my trip?
Plans for this trip
Check the plans and live prices before you go. You receive the QR code by email right after payment.