Privacy Policy
How we collect, use, retain, and handle personal-data requests.
Version 2026-09-01 · effective September 1, 2026
This is a draft pending legal review and confirmation of contractual details. A new version will be published when finalized.
1. Controller and contact
WhatsRoaming processes the minimum personal data needed to sell, issue, and support global eSIM roaming products. Business information and the support email are displayed in the site footer. Requests to access, correct, erase, or restrict personal data can be made through the support email.
2. Data collected and purposes
For membership, we process email address, optional name and phone number, confirmation that the user is at least 14, and records of terms, privacy, and marketing choices. For orders, we process buyer email, order, product, payment, refund, and agreement records. For guest orders, we process the email and only a hash of the order-access token. For login and security response, we may record email, IP address, user agent, and login success or failure times. To issue an eSIM, we process order data and encrypted eSIM profile and activation information. We do not collect or store raw card numbers, CVCs, or other raw card credentials.
3. Retention
Membership data and marketing consent are erased without delay upon withdrawal or withdrawal of consent. Where required by applicable law, records of contracts, cancellations, payments, and supply may be retained for 5 years; consumer complaints and dispute handling for 3 years; and advertising records for 6 months. General authentication records are retained for a default of 3 months as a data-minimization security policy. Statutory-retention data is segregated from service-use data and erased after the applicable purpose ends.
4. Processors and third-party provision
Within the scope needed to operate the service, we use or provide necessary data to Supabase (authentication and database), Vercel (web hosting and deployment), Resend (email delivery), Toss Payments (card payments), and eSIM suppliers A/B (product provision and profile issuance). Legal entity name, processing country, transferred data, and retention period for each processor or supplier will be stated in the latest document once contracts and service regions are confirmed. Suppliers A/B are not confirmed recipients while their contracts and API documents are pending.
5. International processing
Use of overseas eSIM suppliers or global infrastructure may constitute international transfer or processing. Once supplier contracts and infrastructure regions are confirmed, we will reflect the required notice and consent process for the country, timing, data categories, retention period, and refusal method. Until then, no unconfirmed country or processor is presented as fact.
6. Safeguards and data-subject rights
We apply safeguards including access-control management, encryption, access-log retention, and records of personal-data access. After identity or representative verification, a data subject may request access, correction, erasure, or restriction. Within 10 days of the request, we provide the result or a legally permitted reason for refusal and information on how to object.