Born to Roam
Buy

Privacy policy

We collect only what we need to deliver your eSIM and support you. This page sets out what that is, the lawful basis for each purpose, and how to exercise your rights.

Last updated:

  • We use your email address to send the eSIM, the receipt and support replies.
  • We never see or store card details - the payment processor handles them.
  • We only send offers if you explicitly opted in, and unsubscribing is one click.
  • You can ask for access, correction, deletion or a copy of your data at any time.

Who the controller is

The controller is the legal entity listed in the seller details section. For any question about data processing, write to the contact address shown there with "data protection" in the subject.

If our processing ever requires a data protection officer, their contact details will be published on this page.

What data we collect

Data you enter: email address, optionally your name, optionally an order number, and the content of the messages you send us.

Purchase data: the plans you bought, the amount, the currency, the order status, the issued eSIM profile and the usage records our partner returns.

Technical data: IP address, basic browser and device information, the pages you visited and the visitor identifier from a cookie.

We do not ask for and do not want special categories of data such as health or beliefs. Please do not include them in support messages.

Why we process it and on what basis

The table below lists every purpose, the data it needs, the lawful basis under the General Data Protection Regulation and the retention period.

Purposes, bases and retention

Overview of processing by purpose
PurposeDataLawful basisRetention
Fulfilling the order and delivering the eSIM profileEmail, name (if given), plan details, eSIM profile identifierPerformance of a contract, Art. 6(1)(b)For the duration of the service, then within accounting records
Taking payment and issuing receiptsAmount, currency, payment status, transaction identifierLegal obligation, Art. 6(1)(c)Ten years, as required by accounting law
Customer support and complaint handlingEmail, name, order number, message contentContract and legitimate interest, Art. 6(1)(b) and (f)Two years after the request is closed
Site security and abuse preventionIP address, browser data, access logsLegitimate interest, Art. 6(1)(f)Up to twelve months
Visit measurement and improving the siteVisitor identifier, pages visited, traffic sourceConsent, Art. 6(1)(a)Up to fourteen months
Sending the newsletter and offersEmail address, language, consent dateConsent, Art. 6(1)(a)Until consent is withdrawn
Calculating partner commissionVisitor identifier, partner code, order amountPartner contract and legitimate interest, Art. 6(1)(b) and (f)Until the partner settlement period ends, at most five years

Payment data

Payments are handled by an external payment processor which is an independent controller for transaction data. Card number, expiry date and security code never reach us and are never stored on our servers.

We store only the amount, currency, payment status and a transaction identifier, because we need them for the receipt, for complaints and for refunds.

Who we share data with

We share data only with processors that help us deliver the service, and only to the minimum extent needed. We have a data processing agreement with each of them.

We do not sell data and we do not pass it to third parties for their own marketing.

Processors we entrust data to

Categories of processors
RoleWhat it processesProcessing location
Payment processorCard payments and refundsEuropean Economic Area, with possible transfer under standard contractual clauses
eSIM supplierProfile issuing, activation and usage dataEuropean Economic Area or a third country with appropriate safeguards
Email delivery providerDelivery of transactional email and the newsletterEuropean Economic Area
Hosting and database providerRunning the application and storing dataEuropean Economic Area

The current list of named processors is available on request at the contact email address.

Transfers outside the European Economic Area

We aim to keep data inside the European Economic Area. Where a transfer to a third country is necessary, for example because a partner runs infrastructure outside it, the transfer happens only with appropriate safeguards: an adequacy decision or the European Commission standard contractual clauses.

You can request a copy of the safeguards in place at the contact address.

How long we keep data

The periods are listed per purpose in the table above. In short:

  • order data and receipts are kept for as long as accounting law requires,
  • account data is kept while the account exists,
  • support correspondence is kept for two years after the request is closed,
  • technical visit records are kept for at most fourteen months,
  • newsletter consent is kept until you withdraw it, and proof of withdrawal for a further year.

After the period ends we delete or irreversibly anonymise the data.

Cookies and measurement

We use cookies that are strictly necessary for the site to work and, with your consent, cookies for visit measurement and partner attribution. Every cookie, its purpose and its lifetime is listed in the cookie policy.

Visit measurement runs primarily on our own system, on our own infrastructure, and we look at aggregate figures rather than individual profiles.

Automated decision-making

We do not make decisions based solely on automated processing that would produce legal effects for you, and we do not profile you in that sense.

Your rights

Send your request to the contact email address. We answer within thirty days at the latest, and if the request is complex we will tell you about the extension.

We may ask for additional confirmation of identity before acting, so that data never ends up with the wrong person.

The rights you have

Right of access
To confirm whether we process your data and to receive a copy of it.
Right to rectification
To have inaccurate data corrected and incomplete data completed.
Right to erasure
To have data deleted when it is no longer needed for the purpose it was collected for, except where law requires us to keep it.
Right to restriction
To have processing paused, for example while we verify the accuracy of the data.
Right to portability
To receive your data in a structured, commonly used and machine-readable format.
Right to object
To object to processing based on legitimate interest, and to direct marketing at any time without giving a reason.
Right to withdraw consent
To withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal.
Right to complain
To lodge a complaint with the data protection supervisory authority in your country of residence. In Serbia this is the Commissioner for Information of Public Importance and Personal Data Protection.

Children

The service is not intended for people under sixteen and we do not knowingly collect their data. If we learn that we have, without parental consent, we delete it.

Security

Traffic is encrypted in transit, passwords are stored only as a cryptographic hash, access to data is limited to staff who need it, and administrative changes are written to an audit log.

In case of a personal data breach likely to create a risk to your rights, we notify the supervisory authority within 72 hours and, where the risk is high, we notify you as well.

Changes to this policy

We may update this policy when the service or the law changes. The date of the last change is shown at the top. We email account holders about significant changes.

Seller details

Legal name
Stratoventures LLC
Address
Albuquerque, NM 87101, United States
Activity
Sale of digital mobile connectivity services

We are not a mobile network operator. The service is provided together with authorised partners and local networks.

Questions about this document

If something is unclear, write to us. We answer in plain language.

Contact us