Data Protection & Privacy

Privacy Policy

Last updated: September 19, 2026 • We never sell your personal data

Our Core Privacy Commitment: Zero Data Selling

We do not sell, rent, monetize, or trade your personal information to any third party or data broker under any circumstances. Your data is strictly used to process your orders, allocate your international travel data plans, and provide direct customer support.

1. Information We Collect

We believe in strict data minimization. We only collect the bare minimum information required to deliver high-speed prepaid travel eSIM connectivity to your device:

  • Contact Information: Your email address, used to dispatch your digital eSIM QR code, installation guides, and order receipts.
  • Transaction Records: Order identification numbers, purchased destination and data package, retail pricing, and transaction status.
  • Payment Token Identifiers: We do not collect or store complete credit card numbers, CVVs, or bank details on our servers. All transactions are securely processed by authorized, PCI-DSS Level 1 certified payment processing gateways. We retain only an encrypted transaction reference token for customer receipts, billing verification, and refunds.
  • Technical Telemetry: Anonymized usage data such as device type, browser type, and diagnostic error logs to maintain service reliability and optimize storefront speed.

2. How We Use and Share Information

Your information is used exclusively to provide, maintain, and support your travel connectivity. Information is shared only with trusted operational infrastructure partners in accordance with applicable privacy laws and strictly as necessary to fulfill your service:

  • Certified Payment Gateways: To authorize and process secure credit card payments, fraud detection, and automated refunds in compliance with PCI-DSS standards.
  • Authorized Telecommunications Operators: To generate and provision unique digital cellular data profiles (ICCID) across foreign destination networks.
  • Secure Transactional Messaging: To deliver instant email notifications containing your QR code, installation instructions, and authentication login codes.
  • Encrypted Database & Hosting: Secure, encrypted cloud database systems utilized strictly to store active order records and referral balances.

All third-party infrastructure providers are contractually bound to confidentiality, data security standards, and are strictly prohibited from using your information for independent advertising or cross-site tracking.

3. Data Security & Encryption

We implement robust administrative, technical, and physical security measures to safeguard your personal data:

  • All website and API communications are encrypted in transit using 256-bit TLS (Transport Layer Security).
  • Authentication codes and customer sessions employ secure, time-bound cryptographic hashing algorithms.
  • Access to administrative records is protected by multi-layered secret slug obfuscation and session authentication.

4. Your Rights & Data Control

Under global data protection regulations (including GDPR, CCPA, and UK-GDPR), you have the right to:

  • Request access to the personal data we maintain associated with your email address.
  • Request correction of any inaccurate or incomplete personal records.
  • Request the complete deletion and erasure of your customer account and order records from our systems.

To exercise any of these rights, simply email our privacy team at support@roamng.com. We respond to all verified data requests promptly and free of charge.

5. Cookies, Analytics & Regional Consent

We believe in minimal data footprint. We categorize cookies and browser storage strictly according to their operational necessity:

Strictly Necessary Cookies & StorageAlways Active

Essential for secure payment tokenization, cryptographic fraud detection, order verification, and remembering your cookie consent choice. These cannot be disabled as the storefront cannot function securely without them.

Analytics & Performance TelemetryOptional / Prior Consent

Used to measure anonymized aggregate site traffic, latency metrics, and checkout funnel friction. Powered by Google Consent Mode v2 with zero cross-site profile tracking.

Regional Opt-In Compliance (GDPR, UK-GDPR, Swiss nFADP):

For visitors located in the European Union, European Economic Area, United Kingdom, and Switzerland, analytics cookies remain disabled by default until affirmative consent is given. Visitors in all jurisdictions may adjust or withdraw their consent at any time.

6. Contact the Privacy Team

If you have questions regarding our data practices, this Privacy Policy, or wish to submit a data deletion request, contact us at:

Email: support@roamng.com
Subject: Privacy & Data Protection Inquiry