This policy describes what data Roamzy collects and what we do with it. Reading time: ~3 minutes.

1. What we collect

  • Account: email or Telegram ID, display name, optional profile picture (Google/Telegram OAuth).
  • Balance ledger: top-up amounts, transaction history, current balance — stored as integer minor units.
  • eSIM: country, status, consumed MB, install timestamp.
  • Sessions: HttpOnly cookies, IP address, user agent — for security audit and abuse response.
  • Telemetry: route navigations and conversion events via Cloudflare Web Analytics — pseudonymous, no third-party trackers.

2. What we don't collect

  • Your phone number (we don't issue voice or SMS).
  • Browsing history outside Roamzy domains.
  • Location data beyond what your eSIM's network operator already sees.
  • Card numbers (we never see them — NowPayments is the processor).

3. Cookies

We use one functional cookie (the session cookie, HttpOnly + Secure + SameSite=Lax). We do not use third-party advertising cookies. Analytics is Cloudflare Web Analytics' privacy-first model — no IP storage, no cross-site tracking.

4. Sharing

We share data only with: NowPayments (for payment processing), Venta Mobile / vapi.ventamobile.net (for eSIM provisioning — passing only the country code and your internal user id, no PII). We don't sell data. We don't run a third-party ad network.

5. Retention

The balance ledger is kept for 7 years (financial records). Sessions auto-expire after 30 days of inactivity. Account deletion within 30 days, except where law requires retention.

6. Your rights

You can: see all your data (dashboard / Settings) and export it (CSV). To delete your account, use Settings → Danger zone: that files a request with support, who release any active eSIM and settle a remaining balance before erasing the account — normally within 30 days. Payment and invoice records are kept for as long as accounting and anti-money-laundering law requires, which is a legal obligation we cannot waive; everything else is removed. Under GDPR/CCPA you have the right to access, rectify, delete, port, restrict, and object.

7. Security

Money math in integer minor units — no float drift. HttpOnly + Secure session cookies. HMAC verification on all webhook payloads. Rate-limited public endpoints. No PII in logs. Append-only ledger.

8. Contact

Privacy questions: [email protected]. Data subject access requests: same address.