Legal review required
Marketing messages are also subject to opt-in and time-of-day restrictions under Korea's Network Act and equivalent local rules.
Roamis
How Roamis collects, uses, shares, retains, and deletes your personal information when you use our travel eSIM services.
Effective date 〔2026-__-__〕 · Operator Roamis 〔company incorporated in Hong Kong〕 · Contact privacy@roamis.com · Last updated 2026-07-18 (DRAFT — pending final legal review)
Roamis 〔legal name of the company incorporated in Hong Kong, registration details to be inserted; "Roamis", "we", "us"〕 respects your privacy and complies with applicable data protection laws, including Korea's Personal Information Protection Act (PIPA), China's Personal Information Protection Law (PIPL), the EU General Data Protection Regulation (GDPR), and Hong Kong's Personal Data (Privacy) Ordinance (PDPO). This Policy explains how we collect, use, share, retain, and delete personal information when you use our travel eSIM products and related services (website and app, the "Services").
| Category | Items |
|---|---|
| Account / identity | Email, mobile number, social login identifiers (Kakao/Naver/Google/Apple/WeChat), password (stored encrypted), membership tier, referral code |
| Order / transaction | Order history, purchase and payment records, coupon/reward usage, payment method type (card/KakaoPay/NaverPay/Alipay/WeChat Pay, etc.), currency and language preferences |
| Payment | Processor-issued transaction identifiers, amount and currency, payment status. Full card numbers are not stored by us. |
| eSIM usage data | ICCID, data usage (daily/cumulative), plan validity, activation/expiry times, first-access time of the QR/activation code |
| Automatically collected / technical | IP address, device and browser information, order-time device identifiers (for fraud and dispute handling), cookies and similar technologies |
| Guest (non-member) | Delivery email, order look-up token |
| Customer support | Inquiry content and support history |
We do not, as a rule, collect sensitive data (e.g., health, beliefs).
| Purpose | Lawful basis |
|---|---|
| Providing, provisioning and delivering eSIM products; order processing | Performance of a contract |
| Payment processing and settlement | Performance of a contract |
| Fraud and chargeback prevention; dispute evidence | Legitimate interests / legal obligation |
| Customer support | Performance of a contract / legitimate interests |
| Account, coupon and referral-reward management | Performance of a contract |
| Marketing communications (email, messaging, etc.) | Your prior consent (optional) |
| Service improvement, statistics and analytics | Legitimate interests or consent |
| Legal compliance (tax, accounting, e-commerce record keeping) | Legal obligation |
Legal review required
Marketing messages are also subject to opt-in and time-of-day restrictions under Korea's Network Act and equivalent local rules.
To provide the Services, we entrust and share personal information as set out below.
| Recipient / processor | Purpose | Data |
|---|---|---|
| Stripe (payment processor) | Payment processing and fraud prevention | Payment method and transaction data; minimal identifiers |
| Upstream mobile supplier (via our wholesale supply chain, e.g., CMLink / China Mobile HK) | eSIM profile provisioning and activation | ICCID, product/provisioning data (the end customer's name and contact details are not passed upstream; the supply chain recognizes us only as a "merchant wholesale customer") |
| Cloud infrastructure providers | Hosting and storage | Data necessary to operate the Services |
| Notification and support tools | Order/provisioning notices, support | Email/contact and order data |
We are incorporated in Hong Kong. In operating the Services, personal information may be transferred to and processed in Hong Kong and in countries where our cloud, payment, and telecom suppliers are located.
Legal review required
The specific notice/consent requirements for cross-border transfer under PIPA, the PIPL requirements for transfers of Chinese users' data (separate consent, standard contract/security assessment, PIPIA), and the GDPR transfer mechanism for EU users (e.g., SCCs) must be finalized by qualified counsel in each jurisdiction.
Legal review required
Item-by-item statutory retention periods to be confirmed.
You may at any time:
How to exercise: email privacy@roamis.com, or use [My Account > Privacy] in the app/web. We respond within the period required by applicable law. Requests via an authorized agent are permitted.
We use cookies and similar technologies for service delivery, convenience, statistics, and analytics.
Legal review required
Region-specific requirements for a prior-consent banner (CMP) for non-essential cookies to be confirmed.
We apply technical and organizational safeguards: encryption in transit and at rest, access controls and access logging, non-storage of card data (delegated to Stripe), data-boundary separation (end-customer identifiers are not passed to the supply chain), and an internal management plan.
Our Services are not directed to children under 14. We do not collect personal information from children under 14 without verifiable guardian consent, and we delete such information promptly if we learn it was collected without consent.
Legal review required
The applicable age threshold and consent-verification method must be finalized per jurisdiction (Korea 14 / EU 13–16 / China 14, etc.).
We may amend this Policy in light of legal or service changes; we will post the effective date and changes within the Services. Material changes take effect after prior notice.