Marketing messages are also subject to opt-in and time-of-day restrictions under Korea's Network Act and equivalent local rules.
Roamis (operated by: 주식회사 지모바일 (G-Mobile Co., Ltd.), a company incorporated in the Republic of Korea, Business Registration No. 623-87-02156. "Roamis", "we", "us") respects your privacy and complies with applicable data protection laws, including Korea's Personal Information Protection Act (PIPA), China's Personal Information Protection Law (PIPL), the EU General Data Protection Regulation (GDPR), and Hong Kong's Personal Data (Privacy) Ordinance (PDPO). This Policy explains how we collect, use, share, retain, and delete personal information when you use our travel eSIM products and related services (website and app, the "Services").
1. General
- This Policy applies to personal information we process about our users.
- We do not store full payment card numbers; card payments are processed directly by our payment processor (Toss Payments) under the PCI-DSS standard.
- Consistent with data minimization, we collect only the information necessary to provide the Services.
2. Purposes of use and lawful bases
| Purpose | Lawful basis |
|---|---|
| Providing, provisioning and delivering eSIM products; order processing | Performance of a contract |
| Payment processing and settlement | Performance of a contract |
| Fraud and chargeback prevention; dispute evidence | Legitimate interests / legal obligation |
| Customer support | Performance of a contract / legitimate interests |
| Account, coupon and referral-reward management | Performance of a contract |
| Sending service notifications (transactional) — order and payment confirmations, delivery of eSIM activation details, and activation, expiry and remaining-data notices | Performance of a contract (separate prior consent is required to send advertising information) |
| Verifying the account holder by name and handling payment, refund and fraudulent-transaction disputes (viewable only in the internal administration system) | Performance of a contract / legitimate interests |
| Marketing communications (email, messaging, etc.) | Your prior consent (optional) |
| Service improvement, statistics and analytics | Legitimate interests or consent |
| Legal compliance (tax, accounting, e-commerce record keeping) | Legal obligation |
2-1. Service notifications versus advertising information
Receiving service notifications (transactional) and receiving advertising information (marketing) are two separate matters. We obtain each consent separately and record and keep the timestamp of each consent separately. Declining marketing messages places no restriction whatsoever on signing up or using the Services.
- Service notifications (transactional) — order receipt and payment confirmations, delivery of eSIM activation details (QR code / installation code), activation, expiry and remaining-data notices, and notices of changes to the terms or this Policy. These are necessary to perform our contract with you and are sent without separate advertising consent; because they are essential to the Services you cannot opt out of them (you may change the channel through which you receive them, e.g. email or SMS).
- Advertising information (marketing) — discounts and promotions, news about new products and the like. These are sent only where you have given separate, prior consent, and you may unsubscribe (withdraw that consent) free of charge at any time.
- When we send advertising information we display "(광고)" ("Advertisement") at the beginning of the subject line or of the message body, and we state the sender's name and contact details together with a free means of opting out.
- Advertising information is sent only between 08:00 and 20:50 (Korea Standard Time); we do not send it outside those hours.
- For users who have consented to receive advertising information, we confirm and notify them every two years whether they wish to continue receiving it.
3. Retention and deletion
- We erase personal information without undue delay once the purpose is fulfilled.
- Where retention is required by law, we keep the relevant records for the statutory period: records of contracts and withdrawal of offers — 5 years; records of payment and supply of goods — 5 years; records of consumer complaints or dispute resolution — 3 years; records of labelling and advertising — 6 months (all under the Act on Consumer Protection in Electronic Commerce); tax and accounting books and supporting documents — 5 years (Framework Act on National Taxes); service access logs — 3 months (Protection of Communications Secrets Act).
- Upon account closure, account data is deleted, except data subject to statutory retention or needed for dispute handling, which is stored separately for the required period.
- Erasure method: electronic files are deleted irrecoverably; printouts are shredded.
- In addition, records of electronic financial transactions are retained for five years under the Electronic Financial Transactions Act.
- Deletion procedure: we identify the personal information for which grounds for deletion have arisen and, with the approval of the Personal Information Protection Officer, destroy it so that it cannot be restored or reconstructed.
- Deletion method: information in electronic file form is erased by technical means that make recovery impossible; information printed on paper is shredded or incinerated.
- Separate storage: information that must be retained under statute is moved to a database or storage location separate from other personal information, kept for the required period, and not used for any purpose other than that retention.
- Personal information provided to or entrusted with third parties: once the purpose of the provision or entrustment has been achieved or the contract has ended, we request that the processor or recipient destroy the personal information and we verify that destruction.
4. Sharing and processors
To provide the Services, we entrust and share personal information as set out below.
| Recipient / processor | Entrusted work | Data provided | Retention / term |
|---|---|---|---|
| Toss Payments Inc. (토스페이먼츠 주식회사) | Processing of payments in Korean won (KRW) and handling of cancellations and refunds (operation of the integrated card / easy-payment checkout window) | Order number and transaction identifier, payment amount and currency, payment method type, product name, and the email address used to send payment progress notices. Card numbers and other payment credentials are collected and processed directly by the payment provider in its own checkout window and are never stored on our servers. | Until the outsourcing agreement ends. Payment and settlement records are nevertheless kept for the statutory periods set out in Section 3. |
| Tencent Cloud | Server and database hosting and data storage (the servers are located in a data centre in Seoul, Republic of Korea) | All personal information stored in our systems for the operation of the Services | Until the outsourcing agreement ends or the account is closed |
| Upstream mobile supplier (our wholesale supply chain) | eSIM profile provisioning and activation | ICCID and product/provisioning data. The end user’s name, email address and phone number are not passed to the supply chain. | Until provisioning and the product validity period end |
We do not currently entrust the sending of KakaoTalk notification messages, SMS or email, or the operation of online chat support, to any external provider. If we entrust such work in the future, we will update the list above before that work begins and give advance notice in accordance with Section 15.
- We do not sell your personal information.
- We may disclose information where required by law or in response to a lawful request from authorities, following applicable legal procedures.
5. Cross-border transfers
We are incorporated in the Republic of Korea (G-Mobile Co., Ltd.), and the servers and databases used for the Services are operated in a data centre located in the Republic of Korea. However, for payment processing and usage analytics, certain personal information is transferred overseas as set out below.
| Recipient of the transfer | Country · method of transfer | Data transferred and purpose | Retention period |
|---|---|---|---|
| Google LLC (Google Analytics 4) | United States · transmitted over the network on an ongoing basis while you use the website | Cookie-based online identifiers, service usage records such as page views and clicks, approximate location inferred from the connecting IP address, and device/browser information — to compile usage statistics and improve the Services | Until the purpose of the transfer is achieved, or until the data retention period configured in Google Analytics expires |
| Microsoft Corporation (Microsoft Clarity) | United States · transmitted over the network on an ongoing basis while you use the website | Cookie-based online identifiers, records of on-screen interaction such as page views, clicks and scrolling, approximate location inferred from the connecting IP address, and device/browser/screen information — to analyse usability and improve the Services | Until the purpose of the transfer is achieved, or until the data retention period applicable in Microsoft Clarity expires |
| Google LLC (sign-in with Google account) | United States · transmitted only when you choose to sign in with a Google account | Information necessary to process the sign-in request — authentication for sign-up and log-in with a Google account | Limited to the moment the sign-in request is processed |
- Sign-in with a Kakao or Naver account is handled by providers established in the Republic of Korea; no cross-border transfer occurs for that purpose.
- Our servers and databases are operated in a data centre in the Republic of Korea, but the cloud infrastructure provider is a company headquartered outside Korea, and access from outside Korea may occur in the course of infrastructure operation and technical support.
- You have the right to refuse the cross-border transfer of your personal information. If you refuse a transfer that is essential to providing the Services — such as payment processing — your use of that service may be restricted. Transfers for analytics purposes (Google Analytics and Microsoft Clarity) can be refused using the methods described in Section 11.
- When transferring personal information overseas, we secure the safeguards required by the Personal Information Protection Act through contracts with the recipient, and we manage recipients so that they do not use the information for purposes other than those of the transfer.
6. Your rights
You may at any time:
- Request access to your personal information;
- Request correction or deletion;
- Request suspension of processing;
- Withdraw consent (including opting out of marketing);
- Request data portability.
How to exercise: email privacy@roamis.com, or use [My Account > Privacy] in the app/web. We respond within the period required by applicable law. Requests via an authorized agent are permitted.
7. Personal information we collect
7-1. Items collected at sign-up (social login and phone-verification sign-up)
When you sign up (log in) with a social account such as Kakao, Naver or Google, we receive and collect the items below from that platform. The item, collection condition, purpose and retention period are as follows.
| Item collected | Condition | Purpose of collection | Retention and use period |
|---|---|---|---|
| Nickname (the profile nickname of your social account, used for on-screen display) | Required | Member identification · displaying the user within the Services | Until account deletion |
| Email address (e.g., Kakao Account email or another social account email) | Required | Identity verification · member identification · service notices (delivering eSIM activation details and order and payment records) | Until account deletion |
| Name, Gender, Birthday (month and day), Phone number (mobile number), Connecting Information (CI) | Required | Identity verification · member identification · checking for duplicate registrations | Until account deletion |
| Gender | Optional — provided by Naver or Kakao with your consent at login; declining does not restrict sign-up or use | Service usage statistics and product planning (analysing the age-band and gender distribution). Never used for identity verification, member identification or account merging | Until account deletion |
| Age band (e.g. 20s) — we receive only the band; birthdays and dates of birth are not collected | Optional — provided by Naver or Kakao with your consent at login; declining does not restrict sign-up or use | Service usage statistics and product planning (analysing the age-band and gender distribution). Never used for identity verification, member identification or account merging | Until account deletion |
Gender and age band are items that Naver or Kakao provides, with your consent, when you log in with that account. They are not provided by Google or Apple sign-in or by e-mail sign-up, and on Kakao they are optional-consent items, so declining places no restriction whatsoever on logging in or using the service. Where an item is not provided we leave it blank; we never estimate it or fill it in.
We keep the age band only as a range such as "20s"; birthdays and dates of birth are not collected. Gender and age band are used solely for customer-mix statistics (the age-band and gender distribution) and for product planning, and are never used as a basis for identity verification, member identification or account merging. Even in our internal administration screens they appear only as head-count distributions, never as an individual user value, and they are not transmitted to your device.
Your name is viewable only in our internal administration system; it is not displayed anywhere on the website or in the app and is not transmitted to your device. The name shown on screen is the nickname of your social account.
7-2. Items collected when you purchase (order and payment)
- Email address — required: to deliver the eSIM activation details (QR / installation code) and the order and payment record. Retention: 5 years for contract, withdrawal-of-offer and payment records under the Act on Consumer Protection in Electronic Commerce.
- Phone number — required: to send eSIM activation details and activation/expiry notices by KakaoTalk alert or SMS, and to verify identity for order look-ups (last four digits). Retention: as above.
- Payment information — required: the processor-issued transaction identifier, amount and currency, and payment method type. We do not store full card numbers; card payments are handled directly by our payment processor (Toss Payments) under PCI-DSS. Retention: as above.
- Guest order look-up token — required: to look up orders placed without an account and re-display the eSIM. Retention: as above.
7-3. Overall summary of the personal information we process
| Category | Items |
|---|---|
| Account / identity | Nickname, email, name, gender, birthday, mobile phone number, Connecting Information (CI), password (stored encrypted), membership tier, referral code |
| Order / transaction | Order history, purchase and payment records, coupon/reward usage, payment method type (card/KakaoPay/NaverPay/Alipay/WeChat Pay, etc.), currency and language preferences |
| Payment | Processor-issued transaction identifiers, amount and currency, payment status. Full card numbers are not stored by us. |
| eSIM usage data | ICCID, data usage (daily/cumulative), plan validity, activation/expiry times, first-access time of the QR/activation code |
| Automatically collected / technical | IP address, device and browser information, order-time device identifiers (for fraud and dispute handling), cookies and similar technologies |
| Guest (non-member) | Delivery email, order look-up token |
| Customer support | Inquiry content and support history |
We do not, as a rule, collect sensitive data (e.g., health, beliefs).
8. Account and data deletion
- You may request account deletion directly via [My Account > Delete Account] in the app and on the web, in compliance with App Store policy.
- On deletion, personal information is erased per Section 3; data under statutory retention is erased after the required period.
- Deletion requests may also be sent to privacy@roamis.com.
9. Security measures
We implement the following administrative, technical and physical measures to keep personal information secure.
- Administrative measures: establishing and implementing an internal management plan, minimising the number of staff who handle personal information and managing their access rights, and providing regular privacy training to employees
- Technical measures: managing and controlling access rights to systems that process personal information, storing passwords and other credentials in encrypted form, encrypting data in transit (HTTPS/TLS), retaining access logs and protecting them against tampering, and installing and regularly updating security software
- Physical measures: physical access controls for the systems where personal information is stored, including data-centre access control
- Minimisation of payment data: card numbers and other payment credentials are handled directly by the payment providers and are not stored on our servers.
- Data boundary separation: end users’ names, email addresses and phone numbers are not passed to the eSIM supply chain.
10. Cookies and similar technologies
We use cookies and similar technologies for service delivery, convenience, statistics, and analytics.
- Essential cookies: strictly necessary (login, payment, security) — used without consent.
- Functional/analytics/advertising cookies: used with your consent; you may refuse or change them via browser settings or our cookie banner.
- How to refuse: you can refuse the storage of cookies or delete cookies already stored in your browser settings — Chrome: [Settings > Privacy and security]; Safari: [Preferences > Privacy]; Microsoft Edge: [Settings > Cookies and site permissions].
- Effect of refusal: refusing functional and analytics cookies does not restrict your use of the Services. However, if you also block essential cookies, some features such as staying signed in and completing payment may not work correctly.
11. Collection and use of behavioural data, and how to refuse
To compile usage statistics and improve the usability of our screens, we automatically collect and analyse information about how you use the Services, as set out below.
| Data collected | Method of collection | Purpose | Retention period |
|---|---|---|---|
| Cookie-based online identifiers, usage records such as page views, clicks and scrolling, approximate location inferred from the connecting IP address, device/browser/screen information | Collected automatically through Google Analytics 4 and Microsoft Clarity when you visit and use the website | Compiling usage statistics, analysing screen usability and improving the Services | Until the retention period configured in each analytics tool expires, or the purpose is achieved |
- We do not currently collect or use behavioural data for online targeted advertising, nor do we provide behavioural data to advertising businesses. If we introduce targeted advertising in the future, we will set out the data collected, the purpose, the retention period and how to refuse in this Policy, and give advance notice in accordance with Section 15.
- Our mobile app does not collect advertising identifiers (Android Advertising ID or iOS IDFA).
- How to refuse in a web browser: blocking or deleting cookies in your browser settings prevents the analytics tools above from collecting behavioural data. You can also install the Google Analytics Opt-out Browser Add-on provided by Google to refuse collection by Google Analytics.
- Managing advertising identifiers on a smartphone (for reference): on Android you can delete the advertising ID at [Settings > Privacy > Ads]; on iOS you can turn off “Allow Apps to Request to Track” at [Settings > Privacy & Security > Tracking].
- Refusing the collection of behavioural data does not restrict your use of the Services.
12. Mobile app permissions
Our mobile app requests only the minimum device permissions necessary to provide the Services. All permissions below are optional; if you do not grant them you can still use the app’s core features such as browsing products, purchasing and viewing your eSIM.
- Notifications (push) — optional: used to send service notifications such as order and payment confirmations, eSIM activation guidance and reminders that your data plan is about to expire. You can turn this off at any time in your device settings.
- Our app does not request access to the camera, location, contacts, photos, microphone or call logs.
- On Android 6.0 and above and on iOS, each permission can be granted or withdrawn individually at any time under [Settings > Apps > Roamis > Permissions] on your device.
13. Children and minors
Our Services are not directed to children under 14. We do not collect personal information from children under 14 without verifiable guardian consent, and we delete such information promptly if we learn it was collected without consent.
14. Personal Information Protection Officer and where to submit access requests
- Personal Information Protection Officer: Tae Sae-min · Email smtae9@gmobile.co.kr · Tel 1555-1850
- Where to submit access and other requests: email privacy@roamis.com · tel 1555-1850. You may exercise the rights in Section 6 (access, correction, deletion, suspension of processing, withdrawal of consent, etc.) through this contact point or via [My Account > Privacy] in the app or on the web.
- The Personal Information Protection Officer oversees all enquiries, complaints and remedies relating to the processing of personal information, and we respond without undue delay after receipt.
- If you need to report or seek advice on a privacy infringement, you may contact the following Korean bodies — Privacy Infringement Report Centre (privacy.kisa.or.kr, 118) · Personal Information Dispute Mediation Committee (www.kopico.go.kr, 1833-6972) · Supreme Prosecutors’ Office Cyber Investigation Division (www.spo.go.kr, 1301) · National Police Agency Cyber Bureau (ecrm.police.go.kr, 182).
- Users outside the Republic of Korea may also lodge a complaint with the supervisory authority in their place of residence (for example an EU member-state authority or the Hong Kong PCPD).
15. Changes to this Policy and our duty to notify
- This Policy may be amended in line with changes to legislation, policy or the Services.
- When we amend the Policy, we announce the effective date and the changes at least seven days before the effective date, through the website notice board and in-app notifications.
- For changes that materially affect your rights — such as adding data items, changing the purposes of use, or adding recipients for third-party provision, entrustment or cross-border transfer — we give notice at least 30 days before the effective date and, where necessary, obtain your consent again.
- Previous versions of this Policy are retained so that users can review them.
16. Addendum
- This Policy was established and took effect on 1 August 2026, and was partially amended on 5 August 2026.
- Main changes in the amendment of 5 August 2026: identification of processors and cross-border transfers in detail; new sections on behavioural data, mobile app permissions and security measures; designation and publication of the Personal Information Protection Officer; and express statement of the notice periods (7 and 30 days).
- If you wish to review an earlier version of this Policy, please request it at privacy@roamis.com and we will provide it.