سياسة الخصوصية
آخر تحديث: مايو 2026
المحتويات
- 1. المقدمة
- 2. معلومات المتحكم في البيانات
- 3. البيانات الشخصية التي نجمعها
- 4. مصادر بياناتك الشخصية
- 5. الأساس القانوني للمعالجة
- 6. مشاركة البيانات والمستلمون
- 7. نقل البيانات الدولي
- 8. حقوق حماية البيانات الخاصة بك
- 9. الاحتفاظ بالبيانات
- 10. البيانات الشخصية للأطفال
- 11. ملفات تعريف الارتباط وتقنيات التتبع
- 12. معلومات التواصل
- 13. California Privacy Rights (CCPA/CPRA)
- 14. Brazil Privacy Rights (LGPD)
- 15. Japan Privacy Rights (APPI)
- 16. Canada Privacy Rights (PIPEDA)
- 17. India Privacy Rights (DPDP Act)
- 18. Additional Regional Privacy Rights
- 19. AI and Machine Learning
- 20. Referral Program Privacy
1. Introduction
توضح سياسة الخصوصية هذه («الإشعار») كيفية تعامل Future Syncs Limited في المملكة المتحدة، التي تعمل باسم HelloRoam («HelloRoam» أو «نحن» أو «لنا»)، مع بياناتك الشخصية. تشمل هذه السياسة المعلومات التي تقدمها أو التي نجمعها عند تواصلك معنا، أو استخدامك للتطبيق، أو زيارتك لموقعنا، أو شرائك لخدماتنا.
نلتزم بتزويدك بهذه المعلومات، بما في ذلك تفاصيل حقوق حماية بياناتك، وفقاً للائحة العامة لحماية البيانات (EU) 2016/679 («GDPR») والـ GDPR البريطاني.
هل تلتزم HelloRoam بقوانين حماية البيانات؟
HelloRoam تأخذ حماية البيانات بجدية ولن تشارك بياناتك الشخصية مع أطراف ثالثة دون سند قانوني مناسب. نلتزم بالـ GDPR وقوانين حماية البيانات في المملكة المتحدة وأطر الخصوصية في أمريكا الشمالية وأستراليا وأمريكا اللاتينية. الخصوصية من حيث التصميم مدمجة في جميع خدماتنا.
We run Data Protection Impact Assessments when we start new services or data processing that may pose a high risk to your rights.
2. Data Controller Information
بالنسبة لهذا الإشعار، يُعدّ المتحكم في البيانات هو Future Syncs Limited في المملكة المتحدة، التي تعمل باسم HelloRoam. HelloRoam مسؤولة عن بياناتك الشخصية.
Company:Future Syncs Limited
Brand:HelloRoam (علامة تجارية لـ Future Syncs Limited)
Address:لندن، المملكة المتحدة
Company Registration:15950168
Email:help@helloroam.com
HelloRoam ملتزمة بحماية بياناتك الشخصية. يوضح هذا الإشعار كيفية معالجتنا لها بدقة.
3. Personal Data We Collect
نجمع ونعالج الفئات التالية من البيانات الشخصية:
| الفئة | أمثلة |
|---|---|
| بيانات الهوية | الاسم الأول، الاسم الأخير، اسم المستخدم أو معرّف مشابه، اللقب، تاريخ الميلاد |
| بيانات التواصل | البريد الإلكتروني، رقم الهاتف، عنوان الفوترة، عنوان التوصيل |
| البيانات المالية | تفاصيل بطاقة الدفع (تتم المعالجة عبر مزود الدفع لدينا)، تفاصيل الحساب المصرفي |
| بيانات المعاملات | تفاصيل المدفوعات المتبادلة، تفاصيل المنتجات والخدمات التي اشتريتها منا |
| البيانات التقنية | عنوان بروتوكول الإنترنت (IP)، بيانات تسجيل الدخول، نوع المتصفح وإصداره، إعداد المنطقة الزمنية والموقع، أنواع ملحقات المتصفح وإصداراتها، نظام التشغيل والمنصة، معرّفات الجهاز |
| بيانات الملف الشخصي | اسم المستخدم وكلمة المرور، المشتريات أو الطلبات التي أجريتها، اهتماماتك وتفضيلاتك وملاحظاتك وردودك على الاستطلاعات |
| بيانات الاستخدام | معلومات حول كيفية استخدامك لموقعنا ومنتجاتنا وخدماتنا، بما في ذلك بيانات تفعيل eSIM وأنماط استهلاك البيانات |
| بيانات التسويق | تفضيلاتك في تلقي رسائل تسويقية منا ومن أطراف ثالثة، وتفضيلات التواصل الخاصة بك |
4. Sources of Your Personal Data
نجمع بياناتك الشخصية من المصادر التالية:
التفاعل المباشر
تزودنا ببيانات هويتك وتواصلك وبياناتك المالية عند ملء النماذج أو التواصل معنا عبر الهاتف أو البريد الإلكتروني أو قنوات أخرى. يشمل ذلك البيانات التي تشاركها عند إنشاء حساب، أو شراء باقة، أو الاشتراك، أو طلب رسائل تسويقية، أو المشاركة في عرض، أو تقديم ملاحظاتك.
التقنيات الآلية
أثناء استخدامك لموقعنا وتطبيقنا، قد نجمع تلقائياً بيانات تقنية عن جهازك ونشاط التصفح والأنماط. نقوم بذلك عبر ملفات تعريف الارتباط وسجلات الخادم وتقنيات مشابهة.
أطراف ثالثة
قد نتلقى بيانات شخصية من أطراف ثالثة تشمل مزودي خدمات التحليل والشبكات الإعلانية ومزودي معلومات البحث وخدمات الدفع والتوصيل وخدمات التحقق من الهوية.
5. Legal Basis for Processing
نستخدم بياناتك الشخصية فقط عندما يسمح لنا القانون بذلك. فيما يلي أكثر الحالات شيوعاً:
تنفيذ العقد
حين نحتاج إلى تنفيذ العقد الذي أبرمناه أو بصدد إبرامه معك.
المصالح المشروعة
حين يكون ذلك ضرورياً لمصالحنا المشروعة (أو مصالح طرف ثالث) دون أن تطغى مصالحك وحقوقك الأساسية على تلك المصالح.
الالتزام القانوني
حين نحتاج إلى الامتثال لالتزام قانوني أو تنظيمي.
الموافقة
حين تكون قد منحت موافقتك على معالجة بياناتك الشخصية لغرض محدد أو أكثر.
حقك في سحب الموافقة
نستخدم بياناتك الشخصية فقط عندما يسمح لنا القانون بذلك. فيما يلي أكثر الحالات شيوعاً:
6. Data Sharing & Recipients
قد نشارك بياناتك الشخصية مع الفئات التالية من المستلمين:
مزودو الخدمات
شركات تقدم خدمات نيابةً عنا، تشمل معالجة المدفوعات وتحليل البيانات وتوصيل البريد الإلكتروني والاستضافة وخدمة العملاء ودعم التسويق.
شركاء الشبكة
مشغلو شبكات الاتصال المحمول ومزودو eSIM الذين يدعمون خدمات الاتصال لدينا.
المستشارون المتخصصون
محامون ومصرفيون ومدققو حسابات ومؤمّنون يقدمون خدمات قانونية ومالية واستشارية.
السلطات التنظيمية
الجهات الحكومية والجهات التنظيمية وجهات إنفاذ القانون والمحاكم والسلطات الأخرى عند الاقتضاء قانوناً.
معايير حماية البيانات
نشترط على جميع الأطراف الثالثة احترام أمان بياناتك الشخصية والتعامل معها وفق القانون. لا نسمح لمزودي الخدمات الخارجيين باستخدام بياناتك لأغراضهم الخاصة. يجوز لهم معالجتها فقط للأغراض المحددة التي نحددها نحن.
Our Data Processors
We share your data with these trusted service providers. Each one has a data processing agreement with us.
| المعالج | الغرض |
|---|---|
| Stripe | Payment processing. Card details go directly to Stripe and are never stored on our servers. |
| Supabase | User authentication and account management. |
| Google Analytics (GA4) | Website usage analytics. Only active after you give consent. |
| Google Ads | Conversion tracking for advertising. Only active after you give consent. |
| Google Tag Manager | Tag management for analytics and marketing scripts. |
| Meta (Facebook Pixel) | Marketing analytics and conversion tracking. Only active with marketing consent. |
| Microsoft Clarity | Behavioral analytics and session recordings to improve user experience. Only active with analytics consent. |
| Sentry | Error monitoring and performance tracking. Personal data is automatically redacted. |
| VWO (Visual Website Optimizer) | A/B testing to help us improve the website experience. |
| Vercel | Website hosting, analytics, and performance monitoring. |
| Rewardful | Affiliate referral tracking. Stores a referral token for 90 days when you arrive via an affiliate link. |
We have Data Processing Agreements in place with all processors listed above.
Affiliate Partners
When you arrive through an affiliate link, we share a referral token with Rewardful to attribute your purchase and calculate rewards. This data is kept for 90 days.
7. International Data Transfers
قد ننقل بياناتك الشخصية إلى دول خارج المملكة المتحدة والمنطقة الاقتصادية الأوروبية (EEA). عند القيام بذلك، نضع ضمانات لضمان حصول بياناتك على المستوى ذاته من الحماية.
• النقل إلى دول تعتبرها المفوضية الأوروبية أو الحكومة البريطانية ذات مستوى كافٍ من حماية البيانات.
• استخدام عقود محددة معتمدة من المفوضية الأوروبية أو الحكومة البريطانية (البنود التعاقدية القياسية).
• النقل إلى مزودين مقيمين في الولايات المتحدة معتمدين وفق إطار خصوصية البيانات بين الاتحاد الأوروبي والولايات المتحدة (EU-US Data Privacy Framework).
تواصل معنا بشأن عمليات النقل
يرجى التواصل معنا على help@helloroam.com إذا أردت معلومات إضافية عن الضمانات المحددة التي نستخدمها عند نقل بياناتك الشخصية خارج المملكة المتحدة أو المنطقة الاقتصادية الأوروبية.
Transfer Mechanisms by Processor
Stripe, Google, Meta, Microsoft, Sentry, VWO, and Vercel transfer data to the United States under Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. Supabase processes data in the US under SCCs. For UK-origin transfers, we use the UK International Data Transfer Agreement (IDTA) alongside SCCs.
8. Your Data Protection Rights
تتمتع بالحقوق التالية بموجب قوانين حماية البيانات:
حق الوصول
يمكنك طلب نسخة من البيانات الشخصية التي نحتفظ بها عنك.
حق التصحيح
يمكنك طلب تصحيح المعلومات غير الدقيقة أو استكمال السجلات الناقصة.
حق المحو
يمكنك طلب حذف بياناتك الشخصية وفق شروط معينة.
حق تقييد المعالجة
يمكنك طلب تقييد معالجتنا لبياناتك الشخصية وفق شروط معينة.
حق الاعتراض
يمكنك الاعتراض على معالجتنا لبياناتك الشخصية وفق شروط معينة.
حق نقل البيانات
يمكنك طلب نقل البيانات التي نحتفظ بها إلى جهة أخرى أو مباشرةً إليك وفق شروط معينة.
سحب الموافقة
يمكنك سحب موافقتك في أي وقت حين نستند إلى موافقتك لمعالجة بياناتك.
تقديم شكوى
يمكنك تقديم شكوى إلى هيئة رقابية.
We do not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
كيفية ممارسة حقوقك
لممارسة أي من الحقوق المذكورة أعلاه، تواصل معنا على help@helloroam.com. لا توجد رسوم للاطلاع على بياناتك أو ممارسة حقوقك. قد نفرض رسوماً معقولة فقط إذا كان طلبك بلا مسوّغ واضح أو متكرراً أو مفرطاً.
9. Data Retention
نحتفظ ببياناتك الشخصية فقط للمدة التي نحتاج إليها، بما في ذلك أي متطلبات قانونية أو محاسبية أو إعداد تقارير.
لتحديد مدة الاحتفاظ ببياناتك، نأخذ في الاعتبار حجم البيانات وحساسيتها، وخطر الضرر من الاستخدام غير المصرح به، وسبب جمعها، وما إذا كان بمقدورنا تحقيق ذلك الغرض بطريقة أخرى، والمتطلبات القانونية المعمول بها.
| Category | Retention Period |
|---|---|
| Account Data | طوال مدة حسابك بالإضافة إلى 6 سنوات بعد إغلاقه |
| Transaction Data | 7 سنوات من تاريخ المعاملة |
| Marketing Preferences | حتى إلغاء الاشتراك أو 3 سنوات من عدم النشاط |
| Technical/Usage Data | 13 شهراً من تاريخ الجمع |
10. Children's Personal Data
خدماتنا مخصصة للأشخاص الذين تبلغ أعمارهم 16 عاماً فما فوق. لا نجمع بيانات شخصية من الأطفال دون سن 16 عاماً عن قصد. إذا كنت والداً أو وصياً وتعتقد أن طفلك شارك بيانات معنا، يرجى التواصل معنا فوراً.
إذا اكتشفنا أننا جمعنا بيانات شخصية من طفل دون موافقة أحد والديه، سنحذفها من أنظمتنا على الفور.
إشعار للوالدين
إذا كنت تعتقد أن لدينا بيانات من طفل أو تتعلق بطفل دون سن 16، يرجى التواصل معنا فوراً على help@helloroam.com.
12. Contact Information
إذا كان لديك أسئلة حول سياسة الخصوصية هذه أو كيفية تعاملنا مع بياناتك، تواصل معنا:
حق تقديم شكوى
إذا كان لديك أسئلة حول سياسة الخصوصية هذه أو كيفية تعاملنا مع بياناتك، تواصل معنا:
13. California Privacy Rights (CCPA/CPRA)
If you live in California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give you specific rights over your personal information. This section explains those rights and how to use them.
HelloRoam does not sell personal information as defined under the CCPA.
Personal Information We Collect
We collect the following categories of personal information from California residents:
- Identifiers: name, email address, and account credentials
- Device information: device type, operating system, and identifiers used for eSIM activation
- Payment information: billing details processed securely by our payment provider
- Usage data: how you interact with our website and app
- Internet or other network activity: IP address, browser type, and pages visited
Right to Know
You can ask us what personal information we have collected about you, where it came from, why we collected it, and who we share it with.
Right to Delete
You can ask us to delete the personal information we have collected from you. Some exceptions apply, such as when we need the data to complete a transaction or meet a legal obligation.
Right to Opt Out
You can ask us not to sell or share your personal information. HelloRoam does not sell personal information, so this right is already honored by default.
Right to Non-Discrimination
We will not treat you differently or deny you services because you chose to exercise any of your California privacy rights.
How to Submit a CCPA Request
To exercise any of the rights above, email us at help@helloroam.com. Include your name, email address, and a description of your request. You may also submit a request on behalf of another person if you have written authorization or hold power of attorney.
Verification Process
We need to verify your identity before we can process your request. We will ask you to confirm the email address linked to your account and may request additional information to confirm your identity. We will respond to your request within 45 days. If we need more time, we will let you know.
14. Brazil Privacy Rights (LGPD)
Brazil's Lei Geral de Proteção de Dados (LGPD) applies to HelloRoam when we process personal data from individuals in Brazil. This section explains your rights and how we handle your data under Brazilian law.
Legal Bases Under LGPD
We process your personal data based on your consent, to perform a contract with you, to meet a legal obligation, or to serve our legitimate interests. We tell you the applicable legal basis at the time we collect your data.
Your Rights Under LGPD
- Confirmation that we process your personal data and access to a copy of it.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of unnecessary or excessive data.
- Portability of your personal data to another service provider.
- Deletion of personal data processed with your consent.
- Information about which public and private entities we share your data with.
- Information about your option to deny consent and the consequences of doing so.
- Withdrawal of consent at any time, free of charge.
- Review of decisions made by automated means that affect your interests.
Data Protection Officer
Our Data Protection Officer handles privacy matters for Brazilian residents. Contact them at help@helloroam.com with the subject line "LGPD Request." We will respond within the timeframes required by Brazilian law.
If you believe we have not handled your data correctly, you have the right to file a complaint with Brazil's national data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), at gov.br/anpd.
15. Japan Privacy Rights (APPI)
Japan's Act on Protection of Personal Information (APPI) applies when we process personal data from individuals in Japan. We handle your data in line with APPI requirements and the guidelines issued by Japan's Personal Information Protection Commission (PPC).
Purpose of Data Use
We use your personal data to process eSIM orders, manage your account, provide customer support, send service notifications, and improve our platform. We will not use your data for other purposes without notifying you first.
Cross-Border Transfers
Your personal data is transferred to and stored in the United Kingdom. The UK has been recognized as providing an adequate level of personal data protection by the European Commission. We apply equivalent safeguards for transfers under APPI.
Your Rights Under APPI
- Disclosure of the personal data we hold about you.
- Correction of any inaccurate personal data.
- Cessation of use or deletion of your personal data where it is no longer needed.
- Cessation of provision of your personal data to third parties.
To exercise your rights or to submit a complaint, email us at help@helloroam.com. You may also contact the Personal Information Protection Commission (PPC) at ppc.go.jp.
16. Canada Privacy Rights (PIPEDA)
Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies to HelloRoam's handling of personal information from Canadian residents. We follow the fair information principles that PIPEDA requires.
How We Apply PIPEDA Principles
- Accountability: We are responsible for all personal information under our control and have designated a privacy contact to oversee compliance.
- Consent: We collect, use, or disclose your personal information only with your knowledge and consent, except where the law permits otherwise.
- Limiting Collection: We collect only the information we need for the identified purposes.
- Accuracy: We keep your personal information as accurate, complete, and up to date as necessary.
- Safeguards: We protect your personal information with security appropriate to its sensitivity.
Your Rights Under PIPEDA
- Access to the personal information we hold about you.
- Challenge the accuracy and completeness of your information and request corrections.
- Withdraw consent for non-essential data collection at any time.
To make a privacy request, email us at help@helloroam.com. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
17. India Privacy Rights (DPDP Act)
India's Digital Personal Data Protection Act 2023 (DPDP Act) applies when we process personal data from individuals in India. HelloRoam acts as a Data Fiduciary under this law and processes your data only for clear, lawful purposes.
Your Rights Under the DPDP Act
- Access to a summary of the personal data we process and how we use it.
- Correction and updating of inaccurate or incomplete personal data.
- Erasure of personal data that is no longer necessary for the purpose it was collected.
- Grievance redressal through our dedicated grievance mechanism.
- Nomination of another individual to exercise your rights on your behalf in case of death or incapacity.
As a Data Fiduciary, HelloRoam collects only the personal data needed to provide our eSIM services. We keep it secure, use it only for stated purposes, and delete it when it is no longer needed. We do not process the personal data of children without verifiable parental consent.
To raise a grievance or exercise any DPDP right, email us at help@helloroam.com with the subject line "DPDP Request." We will acknowledge your request within 48 hours and resolve it within the timeframe required by law.
18. Additional Regional Privacy Rights
HelloRoam operates in 185+ countries. In addition to GDPR, CCPA, LGPD, APPI, PIPEDA, and the DPDP Act, the following regional laws may apply to you depending on where you live.
South Africa (POPIA)
South Africa's Protection of Personal Information Act (POPIA) gives you rights to access, correct, and delete your personal data. Cross-border transfers require adequate protection. To exercise your rights or file a complaint, contact us at help@helloroam.com or reach the Information Regulator at inforegulator.org.za.
Thailand (PDPA)
Thailand's Personal Data Protection Act (PDPA) requires your consent for most processing. You have the right to access, correct, delete, and port your data, and to object to processing. To exercise your rights or complain to the Personal Data Protection Committee (PDPC), contact us at help@helloroam.com.
Singapore (PDPA)
Singapore's Personal Data Protection Act (PDPA) requires your consent before we collect, use, or disclose your personal data. You can withdraw consent at any time. We notify affected individuals promptly in the event of a data breach. Contact help@helloroam.com for any PDPA-related request.
Turkey (KVKK)
Turkey's Personal Data Protection Law (KVKK) requires explicit consent for cross-border data transfers. You have the right to know whether your data is processed, access it, request correction or deletion, and object to automated decisions. To submit a request or file a complaint with the KVKK Board, contact us at help@helloroam.com.
Switzerland (nFADP)
Switzerland's revised Federal Act on Data Protection (nFADP) applies to both natural and legal persons. You have the right to access your data, correct inaccuracies, and object to certain processing. We notify the Federal Data Protection and Information Commissioner (FDPIC) of significant data breaches. Contact help@helloroam.com with any nFADP request.
Indonesia (UU PDP)
Indonesia's Personal Data Protection Law (UU PDP) requires your consent for data collection and cross-border transfers. We maintain a designated Data Protection Officer to oversee compliance. To exercise your rights or raise a concern, email help@helloroam.com.
China (PIPL)
China's Personal Information Protection Law (PIPL) requires us to notify you and obtain separate consent before transferring your personal data outside China. We process data from Chinese residents only for the purposes clearly stated at the time of collection. Contact help@helloroam.com for any PIPL-related request.
19. AI and Machine Learning
HelloRoam uses AI tools carefully and only where they improve our service without compromising your privacy. We do not use AI in ways that produce automated decisions with legal or similarly significant effects on individual users.
AI Crawler Access
Our public website content, including eSIM pricing, coverage information, and FAQs, is accessible to AI crawlers. Your account data, personal information, and order history are never exposed to or shared with AI crawlers. We protect all personal data from AI training pipelines.
How We Use AI Internally
We use AI tools to support content research and review customer support quality. These tools process anonymized or aggregated data only. They are not used to make automated decisions about individual users.
HelloRoam does not sell user data to AI companies, data brokers, or any third parties for AI model training purposes.
20. Referral Program Privacy
When you participate in the HelloRoam referral program, we collect limited technical data to attribute referrals accurately and prevent fraud.
Data Collected
- IP address (anonymized after attribution)
- Browser user-agent string
- Device fingerprint (hashed, non-reversible)
Purpose
This data is used solely to attribute referral purchases to the correct referrer, prevent duplicate or fraudulent claims, and calculate referral rewards. We do not use this data for advertising or sell it to third parties.
Data Retention
Referral attribution data is retained for 90 days after the referred purchase. After this period, the data is automatically deleted. Aggregated, non-personal statistics (total referrals, reward amounts) are kept for accounting purposes.
Your Privacy Matters
We care about your data rights. Our practices are transparent, and you can exercise your rights anytime by contacting us at help@helloroam.com.
Related Policies
Questions About This Policy?
Have questions about this Privacy Policy or how we handle your data? We're happy to help.
حمّل التطبيق. سافر بذكاء.
أدر بطاقات eSIM الخاصة بك في أي وقت ومن أي مكان.
