Legal
Privacy policy.
A short, specific description of what we hold and why. We collect what running a mobile service requires, and nothing extra.
Updated 8 Aug 2026
What we collect
Three categories, and no more:
- Account data — your email address, and a name and country if you give them. Email is how we deliver your eSIM, so we cannot operate without it.
- Service data — the technical identifiers of the eSIM issued to you (such as ICCID and IMSI), which term is active, and how much data has been used. This is what lets us show your usage and support you when something breaks.
- Payment data — handled entirely by Stripe. We receive a confirmation, the amount, and a reference. We never see or store your card number.
What we deliberately do not collect
We do not log the websites you visit, the apps you use, your browsing history, or the content of anything you send. Our supplier reports us aggregate data volume only.
We do not sell personal data, and we do not share it with advertisers.
Why we hold it
- To deliver the service you bought — the lawful basis is performance of a contract.
- To bill you and prevent fraud — contract, and our legitimate interests.
- To meet accounting and regulatory obligations — legal obligation.
- To send you service messages such as install details and usage notices — contract.
Marketing email, if we ever send it, is separate and opt-in, with a working unsubscribe link.
Who else is involved
We keep the list of processors deliberately short:
- Our connectivity supplier — issues and operates the eSIM profile.
- Stripe — payments.
- Supabase — database and authentication hosting.
- Vercel — website hosting.
- Resend — transactional email delivery.
Some of these operate outside your country. Where data moves internationally we rely on appropriate safeguards such as standard contractual clauses.
How long we keep it
Account and order records are kept while your account is active and afterwards for as long as tax and accounting rules require. Detailed usage records are kept for a limited operational period and then aggregated or deleted — we do not need a long-term history of your data consumption, so we do not keep one.
Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, or ask for it in a portable format. You can also complain to your local data protection authority.
To exercise any of these, email privacy@romiomobile.com. We will respond within the period the law allows, and sooner where we can.
[Data controller entity, registered address, and EU/UK representative where required, to be inserted before launch.]
Security
Data is encrypted in transit and at rest. Access to the credentials that could install an eSIM profile is restricted to server-side systems: those fields are not readable by any browser-facing role, and they are never written to logs.