✦ Roamledge is launching soon — travel eSIM data in 190+ countries

Privacy Policy

Effective 16 September 2026 · Roamledge LTD

This policy explains what personal data Roamledge collects when you browse our site, buy a travel eSIM or contact support — and what we do with it.

We keep it in plain language. If anything is unclear, ask us and we will explain.

1. Who is responsible for your data

Roamledge LTD ([Company registration number — to be confirmed]), [Registered address — to be confirmed], is the data controller for the personal data described in this policy.

For any privacy question or request, contact [email protected].

We follow Hong Kong's Personal Data (Privacy) Ordinance. Where the GDPR applies to visitors in the European Economic Area or the UK, and where US state privacy laws such as the CCPA apply, we also meet those requirements.

2. Data we collect

Data you give us

  • Account details: name, email address, and a password (stored only as a secure hash) or your Google sign-in.
  • Order details: the plans you buy, destination, prices, promo codes and loyalty points used.
  • Support messages: what you write to us and the contact details you use.
  • Marketing preferences: whether you want travel deals and product news.

Data created when you use the service

  • eSIM records: identifiers such as ICCID, activation codes, plan status, expiry and how much data has been used (reported by the network, usually with a delay of a few hours).
  • Technical data: IP address, browser and device type, pages viewed, and approximate location derived from your IP.
  • Cookies and similar technologies, as described in our Cookie Policy.

What we never see

  • Your full card number — payments are handled by our payment provider.
  • The content of your browsing, messages or calls made over the data connection.

3. How and why we use your data

PurposeLegal basis
Create and manage your accountPerformance of a contract
Sell, deliver and support your eSIM plansPerformance of a contract
Send service messages such as install codes, receipts and expiry remindersPerformance of a contract
Run Roam Points and referral rewardsPerformance of a contract
Prevent fraud, abuse and misuse of promotionsLegitimate interests
Improve the site and understand which pages help travelersConsent (analytics cookies)
Send marketing emails about deals and new featuresConsent, withdrawable at any time
Keep accounting and tax recordsLegal obligation

We do not sell your personal data, and we do not use it for automated decisions with legal effects.

4. Who we share data with

We share only what each partner needs to deliver our service:

eSIM Access (Redtea Mobile)

Provides the eSIM profiles and mobile network access for your plan

Data: Order reference, plan details and eSIM identifiers · Location: Hong Kong SAR and Singapore

Payment provider

Processes your payment securely

Data: Payment details, billing information and transaction records · Location: To be confirmed when the payment provider is appointed

Resend

Delivers transactional email such as eSIM codes and receipts

Data: Email address and message content · Location: United States and European Union

Supabase / hosting provider

Hosts our database and application servers

Data: All account and order data, encrypted in transit and at rest · Location: European Union

Google

Optional sign-in with a Google account

Data: Name, email address and profile picture, only if you choose Google sign-in · Location: United States

We may also disclose data to professional advisers, or to authorities where the law requires it, and to a buyer if the business is sold — in which case this policy continues to apply.

5. International transfers

Because travel data is global, your information may be processed outside your country, including in Hong Kong, the European Union, Singapore and the United States. Where data leaves the EEA or UK, we rely on recognised safeguards such as the European Commission's standard contractual clauses, and we require every partner to protect your data to the standard described here.

6. How long we keep data

  • Account data: while your account is open, then deleted or anonymised after closure.
  • Order and payment records: seven years, to meet accounting and tax obligations.
  • eSIM and usage records: up to 24 months after the plan expires, for support and dispute handling.
  • Support messages: up to 24 months after the conversation ends.
  • Marketing consent records: until you withdraw consent, plus a short period to prove when it was withdrawn.

7. How we protect your data

  • Traffic is encrypted with HTTPS, and data is encrypted at rest by our hosting provider.
  • Passwords are stored only as salted hashes, never in readable form.
  • Access to production data is limited to staff who need it, and admin actions are recorded.
  • Payments run through PCI-compliant providers, so card numbers never reach our systems.
  • If a breach ever affects your rights, we notify you and the relevant regulator as the law requires.

8. Your rights

You can ask us to:

  • give you a copy of the personal data we hold about you
  • correct data that is wrong or incomplete
  • delete your data (you can also close your account yourself in Settings)
  • limit or object to certain processing, including direct marketing
  • provide your data in a portable format, or transfer it to another provider
  • withdraw consent at any time, without affecting processing that already happened

Email [email protected] and we will respond within 30 days. If you are unhappy with our answer, you may complain to the Privacy Commissioner for Personal Data in Hong Kong, or to your local data protection authority.

California residents may also request details of data disclosures and are entitled not to be discriminated against for exercising their rights. We do not sell or share personal information for cross-context behavioural advertising.

9. Cookies

We use strictly necessary cookies to keep you signed in and to run checkout, plus optional preference and analytics cookies with your consent. See our Cookie Policy for the full list and how to change your choices.

10. Marketing messages

We only send marketing email if you opt in, and every message has an unsubscribe link. You can also change this any time in your account under Settings → Notifications. Service messages — order confirmations, eSIM install codes, low-data alerts and expiry reminders — are part of the service and are always sent.

11. Children

The service is not intended for children under 16 (or the local age of digital consent, never under 13 with parental consent). We do not knowingly collect their data; if you believe we have, contact us and we will delete it.

12. Changes to this policy

We update this policy when our service or the law changes. The effective date at the top always shows the current version, and we announce material changes on the website or by email.

13. Contact us

Roamledge LTD, [Registered address — to be confirmed]

Privacy enquiries: [email protected] · General support: [email protected]

Questions about this document? Email [email protected].