HelloRoam is a global eSIM provider offering instant mobile data in 185+ countries. Buy prepaid travel eSIM plans with no extra fees, no contracts, and instant activation on any eSIM-compatible device.
Last updated: May 2026
This privacy policy ("Notice") informs you about how your Personal Data is handled by Future Syncs Limited, UK, operating under the brand name HelloRoam ("HelloRoam", "we", "us", or "our"). It sets out the personal information detailed below that relates to you or which you provide to us ("Personal Data"). This Personal Data is collected and processed by HelloRoam or on its behalf by third party service providers when you use our application, website, or contracted services.
We are required to provide you this information, including details of your data protection rights, under the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and India's Digital Personal Data Protection Act 2023 (DPDP Act) where applicable.
HelloRoam takes data protection obligations seriously and will not share personal data with third parties without a proper legal basis. We follow global data protection standards, including GDPR, UK data protection laws, and India's Digital Personal Data Protection Act 2023 (DPDP Act), with privacy built into all our services from the ground up.
We run Data Protection Impact Assessments when we start new services or data processing that may pose a high risk to your rights.
For the purposes of this Notice, the controller of your personal data is Future Syncs Limited, UK, operating under the brand name HelloRoam. HelloRoam is fully responsible for your Personal Data.
Company:Future Syncs Limited
Brand:HelloRoam (a brand of Future Syncs Limited)
Address:London, United Kingdom
Company Registration:15950168
Email:admin@helloroam.com
HelloRoam is committed to protecting your fundamental right to personal data privacy. This Notice is intended to inform you clearly about how we process your Personal Data.
HelloRoam collects and processes the following categories of personal data:
| Category | Examples |
|---|---|
| Identity Data | First name, last name, username or similar identifier, title, date of birth |
| Contact Data | Email address, phone number, billing address, delivery address |
| Financial Data | Payment card details (processed by our payment provider), bank account details |
| Transaction Data | Details of payments to and from you, details of products and services purchased |
| Technical Data | Internet Protocol (IP) address, login data, browser type and version, time zone, browser plug-in types, operating system, device identifiers |
| Profile Data | Your username and password, purchases or orders placed by you, your interests, preferences, feedback, and survey responses |
| Usage Data | Information about how you use our website, products and services, including eSIM activation data and data consumption patterns |
| Marketing Data | Your preferences for receiving marketing from us and third parties, and your communication preferences |
We collect personal data from the following sources:
You provide your Identity, Contact, and Financial Data when filling in forms or corresponding with us by phone, email, or other means. This includes data provided when creating an account, purchasing an eSIM plan, subscribing to services, requesting marketing, entering a promotion or survey, or sending us feedback.
As you use our website and app, we may automatically collect Technical Data about your device, browsing behaviour, and usage patterns. We collect this data using cookies, server logs, and similar technologies.
We may receive personal data from third parties including analytics providers, advertising networks, search information providers, payment and delivery services, and identity verification services.
We will use your personal data only when the law permits us to do so. The most common circumstances in which we process your data are:
Where we must perform the contract we are entering into or have entered into with you.
Where it is necessary for our legitimate interests, provided your interests and fundamental rights do not override those interests.
Where we must comply with a legal or regulatory obligation.
Where you have provided consent for us to process your personal data for one or more specific purposes.
We will use your personal data only when the law permits us to do so. The most common circumstances in which we process your data are:
We may share your personal data with the following categories of recipients:
Companies providing services on our behalf, such as payment processing, data analysis, email delivery, hosting, customer service, and marketing support.
Mobile network operators and eSIM providers who make our connectivity services possible, including networks in the UAE, UK, USA, Thailand, and Singapore.
Lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services.
Government bodies, regulators, law enforcement agencies, courts, and other authorities where required by law.
We require all third parties to protect the security of your personal data and to treat it in accordance with applicable law. We do not permit third-party service providers to use your personal data for their own purposes. They may only process your data for specified purposes and strictly according to our instructions.
We share your data with these trusted service providers. Each one has a data processing agreement with us.
| Processor | Purpose |
|---|---|
| Stripe | Payment processing. Card details go directly to Stripe and are never stored on our servers. |
| Supabase | User authentication and account management. |
| Google Analytics (GA4) | Website usage analytics. Only active after you give consent. |
| Google Ads | Conversion tracking for advertising. Only active after you give consent. |
| Google Tag Manager | Tag management for analytics and marketing scripts. |
| Meta (Facebook Pixel) | Marketing analytics and conversion tracking. Only active with marketing consent. |
| Microsoft Clarity | Behavioral analytics and session recordings to improve user experience. Only active with analytics consent. |
| Sentry | Error monitoring and performance tracking. Personal data is automatically redacted. |
| VWO (Visual Website Optimizer) | A/B testing to help us improve the website experience. |
| Vercel | Website hosting, analytics, and performance monitoring. |
| Rewardful | Affiliate referral tracking. Stores a referral token for 90 days when you arrive via an affiliate link. |
We have Data Processing Agreements in place with all processors listed above.
When you arrive through an affiliate link, we share a referral token with Rewardful to attribute your purchase and calculate rewards. This data is kept for 90 days.
We may transfer your personal data to countries outside the UK and the European Economic Area (EEA). Whenever such a transfer takes place, we put appropriate safeguards in place to protect your data to the same standard.
• Transfers to countries the European Commission or UK government has recognised as providing adequate data protection.
• Use of specific contracts approved by the European Commission or UK government (Standard Contractual Clauses).
• Transfers to US-based providers certified under the EU-US Data Privacy Framework.
Please write to us at privacy@helloroam.com if you require further information about the specific safeguards we use when transferring your personal data outside the UK or EEA.
Stripe, Google, Meta, Microsoft, Sentry, VWO, and Vercel transfer data to the United States under Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. Supabase processes data in the US under SCCs. For UK-origin transfers, we use the UK International Data Transfer Agreement (IDTA) alongside SCCs.
Under data protection laws, you have the following rights in relation to your personal data:
You have the right to request a copy of the personal data HelloRoam holds about you.
You have the right to request that we correct information you believe is inaccurate or complete information that is incomplete.
You have the right to request that we erase your personal data, subject to certain conditions.
You have the right to request that we restrict how we process your personal data, subject to certain conditions.
You have the right to object to our processing of your personal data, subject to certain conditions.
You have the right to request that we transfer data we hold about you to another organisation, or directly to you, subject to certain conditions.
Withdraw consent at any time where we rely on consent to process your data.
Lodge a complaint with a supervisory authority if you are unsatisfied with our response.
We do not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
To exercise any of the rights listed above, please write to us at privacy@helloroam.com. You will not be charged a fee for accessing your personal data or exercising your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
HelloRoam retains your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements.
When deciding the appropriate retention period, we consider the volume, nature, and sensitivity of the personal data; the potential risk of harm from unauthorised use or disclosure; the purposes for which we process the data and whether those purposes can be achieved by other means; and the applicable legal requirements.
| Category | Retention Period |
|---|---|
| Account Data | For the duration of your account plus 6 years after closure |
| Transaction Data | 7 years from the date of the transaction |
| Marketing Preferences | Until you unsubscribe or 3 years of inactivity |
| Technical/Usage Data | 13 months from collection |
HelloRoam services are not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us without delay.
If we discover that we have collected personal data from a child without verified parental consent, we will take steps to remove that information from our systems promptly.
If you believe we may hold any information from or about a child under 16, please contact us immediately at admin@helloroam.com.
If you have any questions about this privacy policy or our data practices, you are welcome to contact us through the following channels:
If you have any questions about this privacy policy or our data practices, you are welcome to contact us through the following channels:
If you live in California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give you specific rights over your personal information. This section explains those rights and how to use them.
HelloRoam does not sell personal information as defined under the CCPA.
We collect the following categories of personal information from California residents:
You can ask us what personal information we have collected about you, where it came from, why we collected it, and who we share it with.
You can ask us to delete the personal information we have collected from you. Some exceptions apply, such as when we need the data to complete a transaction or meet a legal obligation.
You can ask us not to sell or share your personal information. HelloRoam does not sell personal information, so this right is already honored by default.
We will not treat you differently or deny you services because you chose to exercise any of your California privacy rights.
To exercise any of the rights above, email us at privacy@helloroam.com. Include your name, email address, and a description of your request. You may also submit a request on behalf of another person if you have written authorization or hold power of attorney.
We need to verify your identity before we can process your request. We will ask you to confirm the email address linked to your account and may request additional information to confirm your identity. We will respond to your request within 45 days. If we need more time, we will let you know.
Brazil's Lei Geral de Proteção de Dados (LGPD) applies to HelloRoam when we process personal data from individuals in Brazil. This section explains your rights and how we handle your data under Brazilian law.
We process your personal data based on your consent, to perform a contract with you, to meet a legal obligation, or to serve our legitimate interests. We tell you the applicable legal basis at the time we collect your data.
Our Data Protection Officer handles privacy matters for Brazilian residents. Contact them at admin@helloroam.com with the subject line "LGPD Request." We will respond within the timeframes required by Brazilian law.
If you believe we have not handled your data correctly, you have the right to file a complaint with Brazil's national data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), at gov.br/anpd.
Japan's Act on Protection of Personal Information (APPI) applies when we process personal data from individuals in Japan. We handle your data in line with APPI requirements and the guidelines issued by Japan's Personal Information Protection Commission (PPC).
We use your personal data to process eSIM orders, manage your account, provide customer support, send service notifications, and improve our platform. We will not use your data for other purposes without notifying you first.
Your personal data is transferred to and stored in the United Kingdom. The UK has been recognized as providing an adequate level of personal data protection by the European Commission. We apply equivalent safeguards for transfers under APPI.
To exercise your rights or to submit a complaint, email us at admin@helloroam.com. You may also contact the Personal Information Protection Commission (PPC) at ppc.go.jp.
Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies to HelloRoam's handling of personal information from Canadian residents. We follow the fair information principles that PIPEDA requires.
To make a privacy request, email us at admin@helloroam.com. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
India's Digital Personal Data Protection Act 2023 (DPDP Act) applies when we process personal data from individuals in India. HelloRoam acts as a Data Fiduciary under this law and processes your data only for clear, lawful purposes.
As a Data Fiduciary, HelloRoam collects only the personal data needed to provide our eSIM services. We keep it secure, use it only for stated purposes, and delete it when it is no longer needed. We do not process the personal data of children without verifiable parental consent.
To raise a grievance or exercise any DPDP right, email us at admin@helloroam.com with the subject line "DPDP Request." We will acknowledge your request within 48 hours and resolve it within the timeframe required by law.
HelloRoam operates in 185+ countries. In addition to GDPR, CCPA, LGPD, APPI, PIPEDA, and the DPDP Act, the following regional laws may apply to you depending on where you live.
South Africa's Protection of Personal Information Act (POPIA) gives you rights to access, correct, and delete your personal data. Cross-border transfers require adequate protection. To exercise your rights or file a complaint, contact us at admin@helloroam.com or reach the Information Regulator at inforegulator.org.za.
Thailand's Personal Data Protection Act (PDPA) requires your consent for most processing. You have the right to access, correct, delete, and port your data, and to object to processing. To exercise your rights or complain to the Personal Data Protection Committee (PDPC), contact us at admin@helloroam.com.
Singapore's Personal Data Protection Act (PDPA) requires your consent before we collect, use, or disclose your personal data. You can withdraw consent at any time. We notify affected individuals promptly in the event of a data breach. Contact admin@helloroam.com for any PDPA-related request.
Turkey's Personal Data Protection Law (KVKK) requires explicit consent for cross-border data transfers. You have the right to know whether your data is processed, access it, request correction or deletion, and object to automated decisions. To submit a request or file a complaint with the KVKK Board, contact us at admin@helloroam.com.
Switzerland's revised Federal Act on Data Protection (nFADP) applies to both natural and legal persons. You have the right to access your data, correct inaccuracies, and object to certain processing. We notify the Federal Data Protection and Information Commissioner (FDPIC) of significant data breaches. Contact admin@helloroam.com with any nFADP request.
Indonesia's Personal Data Protection Law (UU PDP) requires your consent for data collection and cross-border transfers. We maintain a designated Data Protection Officer to oversee compliance. To exercise your rights or raise a concern, email admin@helloroam.com.
China's Personal Information Protection Law (PIPL) requires us to notify you and obtain separate consent before transferring your personal data outside China. We process data from Chinese residents only for the purposes clearly stated at the time of collection. Contact admin@helloroam.com for any PIPL-related request.
HelloRoam uses AI tools carefully and only where they improve our service without compromising your privacy. We do not use AI in ways that produce automated decisions with legal or similarly significant effects on individual users.
Our public website content, including eSIM pricing, coverage information, and FAQs, is accessible to AI crawlers. Your account data, personal information, and order history are never exposed to or shared with AI crawlers. We protect all personal data from AI training pipelines.
We use AI tools to support content research and review customer support quality. These tools process anonymized or aggregated data only. They are not used to make automated decisions about individual users.
HelloRoam does not sell user data to AI companies, data brokers, or any third parties for AI model training purposes.
When you participate in the HelloRoam referral program, we collect limited technical data to attribute referrals accurately and prevent fraud.
This data is used solely to attribute referral purchases to the correct referrer, prevent duplicate or fraudulent claims, and calculate referral rewards. We do not use this data for advertising or sell it to third parties.
Referral attribution data is retained for 90 days after the referred purchase. After this period, the data is automatically deleted. Aggregated, non-personal statistics (total referrals, reward amounts) are kept for accounting purposes.
We care about your data rights. Our practices are transparent, and you can exercise your rights anytime by contacting us at admin@helloroam.com.
Have questions about this Privacy Policy or how we handle your data? We're happy to help.
Get the app. Travel smarter.
Manage your eSIMs from anywhere, at any time.
