Privacy Policy
Effective 16 September 2026 · Roamledge LTD
This policy explains what personal data Roamledge collects when you browse our site, buy a travel eSIM or contact support — and what we do with it.
We keep it in plain language. If anything is unclear, ask us and we will explain.
1. Who is responsible for your data
Roamledge LTD ([Company registration number — to be confirmed]), [Registered address — to be confirmed], is the data controller for the personal data described in this policy.
For any privacy question or request, contact [email protected].
We follow Hong Kong's Personal Data (Privacy) Ordinance. Where the GDPR applies to visitors in the European Economic Area or the UK, and where US state privacy laws such as the CCPA apply, we also meet those requirements.
2. Data we collect
Data you give us
- Account details: name, email address, and a password (stored only as a secure hash) or your Google sign-in.
- Order details: the plans you buy, destination, prices, promo codes and loyalty points used.
- Support messages: what you write to us and the contact details you use.
- Marketing preferences: whether you want travel deals and product news.
Data created when you use the service
- eSIM records: identifiers such as ICCID, activation codes, plan status, expiry and how much data has been used (reported by the network, usually with a delay of a few hours).
- Technical data: IP address, browser and device type, pages viewed, and approximate location derived from your IP.
- Cookies and similar technologies, as described in our Cookie Policy.
What we never see
- Your full card number — payments are handled by our payment provider.
- The content of your browsing, messages or calls made over the data connection.
3. How and why we use your data
| Purpose | Legal basis |
|---|---|
| Create and manage your account | Performance of a contract |
| Sell, deliver and support your eSIM plans | Performance of a contract |
| Send service messages such as install codes, receipts and expiry reminders | Performance of a contract |
| Run Roam Points and referral rewards | Performance of a contract |
| Prevent fraud, abuse and misuse of promotions | Legitimate interests |
| Improve the site and understand which pages help travelers | Consent (analytics cookies) |
| Send marketing emails about deals and new features | Consent, withdrawable at any time |
| Keep accounting and tax records | Legal obligation |
We do not sell your personal data, and we do not use it for automated decisions with legal effects.
5. International transfers
Because travel data is global, your information may be processed outside your country, including in Hong Kong, the European Union, Singapore and the United States. Where data leaves the EEA or UK, we rely on recognised safeguards such as the European Commission's standard contractual clauses, and we require every partner to protect your data to the standard described here.
6. How long we keep data
- Account data: while your account is open, then deleted or anonymised after closure.
- Order and payment records: seven years, to meet accounting and tax obligations.
- eSIM and usage records: up to 24 months after the plan expires, for support and dispute handling.
- Support messages: up to 24 months after the conversation ends.
- Marketing consent records: until you withdraw consent, plus a short period to prove when it was withdrawn.
7. How we protect your data
- Traffic is encrypted with HTTPS, and data is encrypted at rest by our hosting provider.
- Passwords are stored only as salted hashes, never in readable form.
- Access to production data is limited to staff who need it, and admin actions are recorded.
- Payments run through PCI-compliant providers, so card numbers never reach our systems.
- If a breach ever affects your rights, we notify you and the relevant regulator as the law requires.
8. Your rights
You can ask us to:
- give you a copy of the personal data we hold about you
- correct data that is wrong or incomplete
- delete your data (you can also close your account yourself in Settings)
- limit or object to certain processing, including direct marketing
- provide your data in a portable format, or transfer it to another provider
- withdraw consent at any time, without affecting processing that already happened
Email [email protected] and we will respond within 30 days. If you are unhappy with our answer, you may complain to the Privacy Commissioner for Personal Data in Hong Kong, or to your local data protection authority.
California residents may also request details of data disclosures and are entitled not to be discriminated against for exercising their rights. We do not sell or share personal information for cross-context behavioural advertising.
10. Marketing messages
We only send marketing email if you opt in, and every message has an unsubscribe link. You can also change this any time in your account under Settings → Notifications. Service messages — order confirmations, eSIM install codes, low-data alerts and expiry reminders — are part of the service and are always sent.
11. Children
The service is not intended for children under 16 (or the local age of digital consent, never under 13 with parental consent). We do not knowingly collect their data; if you believe we have, contact us and we will delete it.
12. Changes to this policy
We update this policy when our service or the law changes. The effective date at the top always shows the current version, and we announce material changes on the website or by email.
13. Contact us
Roamledge LTD, [Registered address — to be confirmed]
Privacy enquiries: [email protected] · General support: [email protected]
Questions about this document? Email [email protected].
