Skip to content

Privacy Policy

Last updated 2026-07-06

This policy explains what personal data Roamlu collects when you visit roamlu.com or buy a travel eSIM from us, how we use it, and the choices and rights you have. We keep the language plain so you can see exactly what happens with your information — including the analytics our own site records every time a page loads.

  1. 1. Who we are and what this policy covers

    Roamlu provides travel eSIMs, in-app calling, an optional VPN, and an AI travel advisor, with a focus on travellers in and around the Gulf region. In this policy, "Roamlu", "we", "us", and "our" refer to the operator of roamlu.com and the Roamlu service. Roamlu is the controller of the personal data described here.

    This policy covers the Roamlu website, our purchase and delivery flow, our newsletter, and our customer support. It does not cover third-party websites, app stores, or services we link to, which run under their own privacy policies. If any local law gives you stronger protections than this policy, that law applies.

  2. 2. Information you give us

    You share some information with us directly, and we only ask for what we need:

    • Email address — so we can deliver your eSIM and QR code, send purchase and delivery confirmations, and, if you opt in, send our newsletter.
    • Account and order details — the destination and plan you choose, your order reference, and the device details you provide so we can confirm eSIM compatibility.
    • Support messages — anything you send us by email or chat when you ask for help, including the contents of your message and any screenshots or details you attach.

    We do not ask for more than the service requires, and you can choose not to provide optional information, though that may limit features such as the newsletter.

  3. 3. Information we collect automatically (site analytics)

    Roamlu runs its own first-party visitor analytics. We do not rely on a third-party tracking product for this — the measurement happens on our own servers. Each time a page loads, we record:

    • Your IP address, together with a pseudonymized (hashed) version of it that lets us count unique visitors without storing the raw address alongside every event.
    • Your browser, operating system, and device type, parsed from the User-Agent your browser sends.
    • Approximate location — country, region, and city — derived from network and content-delivery signals, not from precise GPS.
    • The pages you view, the page you arrived from (the referrer), and the order in which you move through the site.
    • Your screen and viewport size, preferred language, and timezone.
    • UTM campaign parameters in the link you followed, so we can understand which campaign or referral brought you here.

    This information is tied to a first-party visitor id and a session id (see cookies below) so we can distinguish a returning visitor from a new one and group a single visit together. We use it to understand how the site is used, not to build advertising profiles about you.

  4. 4. Cookies and local storage

    We store a small amount of information in your browser using cookies and local storage. We use it to remember your preferences and to make the analytics above work. The main items are:

    • Locale, currency, and theme preferences — so the site shows the language, prices, and appearance you chose.
    • A first-party visitor id and session id — random identifiers that let us count visits and sessions.
    • An admin session cookie — set only for Roamlu staff who sign in to our internal tools; ordinary visitors never receive it.

    You can clear or block these through your browser settings. Preference and analytics identifiers are not required to browse, but blocking them may reset your language, currency, and theme each time you visit.

  5. 5. How we use your information

    We use the data described above to:

    • Deliver your eSIM, QR code, and order confirmations, and provide the calling, VPN, and AI advisor features you buy.
    • Run, secure, and troubleshoot the service, including keeping it available and diagnosing technical problems.
    • Understand how the site is used and improve it — which destinations and pages are popular, where visitors drop off, and which campaigns bring the right travellers.
    • Detect and prevent fraud, abuse, and other activity that threatens the service or our users.
    • Respond to your support requests and, where you have opted in, send you our newsletter.

    We do not sell your personal data, and we do not use it to make decisions with legal effects about you by automated means alone.

  6. 6. Legal bases for processing

    Where data-protection laws such as the GDPR apply, we rely on one or more of these legal bases:

    • Consent — for the newsletter and, in the EU and EEA, for non-essential analytics. In those regions our analytics are consent-gated: we ask before recording the analytics described above, and a Do-Not-Track signal from your browser is itself recorded and respected as a request not to be tracked.
    • Performance of a contract — to deliver the eSIM and service you purchased and to provide support related to your order.
    • Legitimate interests — to keep the service secure, prevent fraud and abuse, and understand aggregate site usage so we can improve Roamlu, balanced against your rights and expectations.

    Where we rely on consent, you can withdraw it at any time without affecting processing that already took place.

  7. 7. How we share information

    We share personal data only with the providers we need to run Roamlu, and only for the purposes in this policy:

    • Connectivity partners — our eSIM network partner and roaming providers, so your plan can be provisioned and work abroad.
    • Payment providers — to process your purchase securely; we do not store full card numbers ourselves.
    • Hosting and infrastructure providers — who run the servers and content-delivery network that serve roamlu.com and store our data.
    • Email and messaging providers — to send order confirmations, delivery emails, and, if you opted in, the newsletter.

    These providers act on our instructions under contracts that require them to protect your data. We may also disclose information if the law requires it, to enforce our terms, or to protect the rights and safety of our users and Roamlu. We never sell your personal data.

  8. 8. International data transfers

    Roamlu serves travellers across many countries, so your information may be processed in a country other than the one you live in, including where our providers operate. When we transfer personal data across borders, we use appropriate safeguards — such as standard contractual clauses or transfers to countries recognized as providing adequate protection — so your data keeps a comparable level of protection wherever it is handled.

  9. 9. How long we keep your data

    We keep personal data only as long as we need it for the purposes above, then delete or anonymize it.

    • Order and delivery records are kept for as long as needed to support your eSIM and to meet tax, accounting, and legal obligations.
    • Support messages are kept long enough to resolve your issue and handle any follow-up.
    • Analytics events are retained in identifiable form for a limited period and then aggregated or discarded so they no longer identify you.
    • Newsletter signup data is kept until you ask us to remove it.
  10. 10. Your rights and choices

    Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, object to or restrict certain processing, receive a copy in a portable format, and withdraw any consent you gave. You can also leave the newsletter at any time by emailing hello@roamlu.com — and once our emails start arriving, each one will include an unsubscribe link.

    To exercise any of these rights, email us at hello@roamlu.com and tell us what you would like to do. We will respond within the time required by applicable law and may need to verify your identity first. If you believe we have not handled your data properly, you also have the right to complain to your local data-protection authority.

  11. 11. Children

    Roamlu is intended for adults and is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has given us personal data, contact us and we will delete it.

  12. 12. Changes to this policy

    We may update this policy as Roamlu, our providers, or the law changes. When we make material changes, we will update the "Last updated" date above and, where appropriate, tell you in another way. Please review this page from time to time so you stay informed about how we handle your information.

  13. 13. Contact us

    If you have questions about this policy or how Roamlu handles your personal data, email us at hello@roamlu.com. We are happy to help and will point you to the right person if your request needs specialist handling.