Skip to content

Roamis

Privacy Policy

How Roamis collects, uses, shares, retains, and deletes your personal information when you use our travel eSIM services.

Effective date 〔2026-__-__〕 · Operator Roamis 〔company incorporated in Hong Kong〕 · Contact privacy@roamis.com · Last updated 2026-07-18 (DRAFT — pending final legal review)

Roamis 〔legal name of the company incorporated in Hong Kong, registration details to be inserted; "Roamis", "we", "us"〕 respects your privacy and complies with applicable data protection laws, including Korea's Personal Information Protection Act (PIPA), China's Personal Information Protection Law (PIPL), the EU General Data Protection Regulation (GDPR), and Hong Kong's Personal Data (Privacy) Ordinance (PDPO). This Policy explains how we collect, use, share, retain, and delete personal information when you use our travel eSIM products and related services (website and app, the "Services").

1. General

  • This Policy applies to personal information we process about our users.
  • We do not store full payment card numbers; card payments are processed directly by our payment processor (Stripe) under the PCI-DSS standard.
  • Consistent with data minimization, we collect only the information necessary to provide the Services.

2. Personal information we collect

CategoryItems
Account / identityEmail, mobile number, social login identifiers (Kakao/Naver/Google/Apple/WeChat), password (stored encrypted), membership tier, referral code
Order / transactionOrder history, purchase and payment records, coupon/reward usage, payment method type (card/KakaoPay/NaverPay/Alipay/WeChat Pay, etc.), currency and language preferences
PaymentProcessor-issued transaction identifiers, amount and currency, payment status. Full card numbers are not stored by us.
eSIM usage dataICCID, data usage (daily/cumulative), plan validity, activation/expiry times, first-access time of the QR/activation code
Automatically collected / technicalIP address, device and browser information, order-time device identifiers (for fraud and dispute handling), cookies and similar technologies
Guest (non-member)Delivery email, order look-up token
Customer supportInquiry content and support history

We do not, as a rule, collect sensitive data (e.g., health, beliefs).

3. Purposes of use and lawful bases

PurposeLawful basis
Providing, provisioning and delivering eSIM products; order processingPerformance of a contract
Payment processing and settlementPerformance of a contract
Fraud and chargeback prevention; dispute evidenceLegitimate interests / legal obligation
Customer supportPerformance of a contract / legitimate interests
Account, coupon and referral-reward managementPerformance of a contract
Marketing communications (email, messaging, etc.)Your prior consent (optional)
Service improvement, statistics and analyticsLegitimate interests or consent
Legal compliance (tax, accounting, e-commerce record keeping)Legal obligation

Legal review required

Marketing messages are also subject to opt-in and time-of-day restrictions under Korea's Network Act and equivalent local rules.

4. Sharing and processors

To provide the Services, we entrust and share personal information as set out below.

Recipient / processorPurposeData
Stripe (payment processor)Payment processing and fraud preventionPayment method and transaction data; minimal identifiers
Upstream mobile supplier (via our wholesale supply chain, e.g., CMLink / China Mobile HK)eSIM profile provisioning and activationICCID, product/provisioning data (the end customer's name and contact details are not passed upstream; the supply chain recognizes us only as a "merchant wholesale customer")
Cloud infrastructure providersHosting and storageData necessary to operate the Services
Notification and support toolsOrder/provisioning notices, supportEmail/contact and order data
  • We do not sell your personal information.
  • We may disclose information where required by law or in response to a lawful request from authorities, following applicable legal procedures.

5. Cross-border transfers

We are incorporated in Hong Kong. In operating the Services, personal information may be transferred to and processed in Hong Kong and in countries where our cloud, payment, and telecom suppliers are located.

  • Recipients: Stripe, cloud providers, upstream telecom supplier, etc.
  • Countries: Hong Kong and the data-center locations of the above providers.
  • Data, purpose and retention: as set out in Sections 2, 3 and 6.
  • You may object to cross-border transfer; however, this may limit our ability to provide the Services.

Legal review required

The specific notice/consent requirements for cross-border transfer under PIPA, the PIPL requirements for transfers of Chinese users' data (separate consent, standard contract/security assessment, PIPIA), and the GDPR transfer mechanism for EU users (e.g., SCCs) must be finalized by qualified counsel in each jurisdiction.

6. Retention and deletion

  • We erase personal information without undue delay once the purpose is fulfilled.
  • Where retention is required by law, we retain the relevant data for the required period — e.g., contract, payment and e-commerce records, and tax/accounting evidence are kept for the period required by applicable law 〔statutory retention periods to be confirmed〕.
  • Upon account closure, account data is deleted, except data subject to statutory retention or needed for dispute handling, which is stored separately for the required period.
  • Erasure method: electronic files are deleted irrecoverably; printouts are shredded.

Legal review required

Item-by-item statutory retention periods to be confirmed.

7. Your rights

You may at any time:

  • Request access to your personal information;
  • Request correction or deletion;
  • Request suspension of processing;
  • Withdraw consent (including opting out of marketing);
  • Request data portability.

How to exercise: email privacy@roamis.com, or use [My Account > Privacy] in the app/web. We respond within the period required by applicable law. Requests via an authorized agent are permitted.

8. Account and data deletion

  • You may request account deletion directly via [My Account > Delete Account] in the app and on the web, in compliance with App Store policy.
  • On deletion, personal information is erased per Section 6; data under statutory retention is erased after the required period.
  • Deletion requests may also be sent to privacy@roamis.com.

9. Cookies and similar technologies

We use cookies and similar technologies for service delivery, convenience, statistics, and analytics.

  • Essential cookies: strictly necessary (login, payment, security) — used without consent.
  • Functional/analytics/advertising cookies: used with your consent; you may refuse or change them via browser settings or our cookie banner.

Legal review required

Region-specific requirements for a prior-consent banner (CMP) for non-essential cookies to be confirmed.

10. Security measures

We apply technical and organizational safeguards: encryption in transit and at rest, access controls and access logging, non-storage of card data (delegated to Stripe), data-boundary separation (end-customer identifiers are not passed to the supply chain), and an internal management plan.

11. Children and minors

Our Services are not directed to children under 14. We do not collect personal information from children under 14 without verifiable guardian consent, and we delete such information promptly if we learn it was collected without consent.

Legal review required

The applicable age threshold and consent-verification method must be finalized per jurisdiction (Korea 14 / EU 13–16 / China 14, etc.).

12. Data Protection Officer and contact

  • Data Protection Officer (DPO): 〔name/title〕, privacy@roamis.com
  • Korea domestic representative: 〔to be inserted if required under PIPA〕 【Legal review required】
  • You may lodge a complaint with a supervisory authority — e.g., Korea's PIPC, the EU data protection authorities, the Hong Kong PCPD, or China's CAC.

13. Changes to this Policy

We may amend this Policy in light of legal or service changes; we will post the effective date and changes within the Services. Material changes take effect after prior notice.