Skip to main content

Privacy Policy

Last updated: May 2026

1. Introduction

This privacy policy ("Notice") informs you how your Personal Data is handled by Future Syncs Limited, UK, operating under the brand name HelloRoam ("HelloRoam", "we", "us", or "our"). It sets out the personal information we collect and process when you contact us or use our application, website, or services.

We provide this information to meet our obligations under the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and the Singapore Personal Data Protection Act 2012 (PDPA).

Does HelloRoam comply with data protection laws?

HelloRoam takes data protection seriously. We will not share your personal data with third parties without a proper legal basis. HelloRoam complies with the Singapore Personal Data Protection Act (PDPA), GDPR, UK data protection laws, and applicable privacy frameworks across North America, Australia, and Asia Pacific. Privacy by design is central to how we build our services.

We run Data Protection Impact Assessments when we start new services or data processing that may pose a high risk to your rights.

2. Data Controller Information

For the purposes of this Notice, the data controller is Future Syncs Limited, UK, trading as HelloRoam. HelloRoam is responsible for the personal data we hold about you.

Company:Future Syncs Limited

Brand:HelloRoam (a brand of Future Syncs Limited)

Address:London, United Kingdom

Company Registration:15950168

Email:help@helloroam.com

HelloRoam is committed to protecting your right to personal data privacy. This Notice explains how we process your Personal Data and what rights you have.

3. Personal Data We Collect

HelloRoam collects and processes the following categories of personal data:

CategoryExamples
Identity DataFirst name, last name, username or similar identifier, title, date of birth
Contact DataEmail address, telephone number, billing address, delivery address
Financial DataPayment card details (processed by our payment provider), bank account details
Transaction DataDetails of payments to and from you, details of products and services you have purchased
Technical DataIP address, login data, browser type and version, time zone setting, browser plug-in types, operating system and platform, device identifiers
Profile DataYour username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses
Usage DataHow you use our website, products and services, including eSIM activation data and data consumption patterns
Marketing DataYour preferences for receiving marketing from us and our partners, and your communication preferences

4. Sources of Your Personal Data

HelloRoam collects personal data from the following sources:

Direct Interactions

You provide us with Identity, Contact and Financial Data when you fill in forms or correspond with us by phone, email or other means. This includes data provided when creating an account, purchasing a plan, subscribing to our services, requesting marketing, or giving feedback.

Automated Technologies

When you use our website and app, we may automatically collect Technical Data about your device, browsing actions and patterns. We collect this data via cookies, server logs and similar technologies.

Third Parties

We may receive personal data from third parties including analytics providers, advertising networks, search information providers, payment and delivery services, and identity verification services.

6. Data Sharing & Recipients

HelloRoam may share your personal data with the following categories of recipients:

Service Providers

Companies that provide services on our behalf, including payment processing, data analysis, email delivery, hosting, customer service, and marketing support.

Network Partners

Mobile network operators and eSIM providers who power our connectivity services in Japan, South Korea, Malaysia, Australia, and other countries in our network.

Professional Advisers

Lawyers, bankers, auditors, and insurers who provide legal, financial, and advisory services.

Regulatory Authorities

Government bodies, regulators, law enforcement agencies, courts, and other authorities when required by law, including the PDPC and IMDA in Singapore.

Data Protection Standards

We require all third parties to respect the security of your personal data and treat it in accordance with the law. We do not permit third-party service providers to use your personal data for their own purposes. They may only process it for specified purposes and in line with our instructions.

Our Data Processors

We share your data with these trusted service providers. Each one has a data processing agreement with us.

ProcessorPurpose
StripePayment processing. Card details go directly to Stripe and are never stored on our servers.
SupabaseUser authentication and account management.
Google Analytics (GA4)Website usage analytics. Only active after you give consent.
Google AdsConversion tracking for advertising. Only active after you give consent.
Google Tag ManagerTag management for analytics and marketing scripts.
Meta (Facebook Pixel)Marketing analytics and conversion tracking. Only active with marketing consent.
Microsoft ClarityBehavioral analytics and session recordings to improve user experience. Only active with analytics consent.
SentryError monitoring and performance tracking. Personal data is automatically redacted.
VWO (Visual Website Optimizer)A/B testing to help us improve the website experience.
VercelWebsite hosting, analytics, and performance monitoring.
RewardfulAffiliate referral tracking. Stores a referral token for 90 days when you arrive via an affiliate link.

We have Data Processing Agreements in place with all processors listed above.

Affiliate Partners

When you arrive through an affiliate link, we share a referral token with Rewardful to attribute your purchase and calculate rewards. This data is kept for 90 days.

7. International Data Transfers

HelloRoam may transfer your personal data to countries outside Singapore, the UK, and the European Economic Area (EEA). When we do so, we put in place safeguards to ensure your data receives an equivalent level of protection.

Transfers to countries that the European Commission, UK government, or Singapore PDPC has determined provide adequate data protection.

Use of Standard Contractual Clauses approved by the European Commission or UK government.

Transfers to US-based providers certified under the EU-US Data Privacy Framework.

Contact Us About Transfers

Please contact us at help@helloroam.com if you want further information on the safeguards we use when transferring your personal data outside Singapore, the UK, or the EEA.

Transfer Mechanisms by Processor

Stripe, Google, Meta, Microsoft, Sentry, VWO, and Vercel transfer data to the United States under Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. Supabase processes data in the US under SCCs. For UK-origin transfers, we use the UK International Data Transfer Agreement (IDTA) alongside SCCs.

8. Your Data Protection Rights

You hold the following rights under applicable data protection laws, including PDPA (Singapore), GDPR, and UK GDPR:

Right to Access

Request a copy of the personal data HelloRoam holds about you.

Right to Rectification

Ask us to correct any inaccurate data or complete any incomplete records.

Right to Erasure

Request that we delete your personal data, subject to applicable conditions.

Right to Restrict Processing

Ask us to restrict how we process your personal data, under certain conditions.

Right to Object

Object to our processing of your personal data, under certain conditions.

Right to Data Portability

Ask us to transfer data we hold to another organisation, or directly to you, under certain conditions.

Withdraw Consent

Withdraw consent at any time where we rely on consent to process your data.

Complaint

File a complaint with a supervisory authority, including the PDPC in Singapore.

We do not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.

How to Exercise Your Rights

To exercise any of the rights listed above, contact us at help@helloroam.com. There is no fee for most requests. We may charge a reasonable fee only if your request is clearly unfounded, repetitive, or excessive.

9. Data Retention

HelloRoam keeps your personal data only as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements.

When determining how long to keep your data, we consider the amount, nature, and sensitivity of the data, the risk of harm from unauthorised access or disclosure, the purposes for which we collected it, whether those purposes can be achieved another way, and the legal requirements that apply.

CategoryRetention Period
Account DataFor the duration of your account plus 6 years after closure
Transaction Data7 years from the date of the transaction
Marketing PreferencesUntil you unsubscribe or 3 years of inactivity
Technical/Usage Data13 months from collection

10. Children's Personal Data

Our services are intended for users aged 16 and above. HelloRoam does not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has given us personal data, please contact us straight away.

If we find that we have collected personal data from a child without verified parental consent, we will remove that information from our systems promptly.

Parental Notice

If you believe we hold data from or about a child under 16, please contact us immediately at help@helloroam.com.

11. Cookies & Tracking Technologies

HelloRoam uses cookies and similar tracking technologies on our service to store information and monitor activity. These include beacons, tags, and scripts that help us collect data and improve our platform.

Managing Your Cookie Preferences

HelloRoam uses cookies and similar tracking technologies on our service to store information and monitor activity. These include beacons, tags, and scripts that help us collect data and improve our platform.

Essential Cookies

Required for the website to function correctly. These cannot be disabled.

Analytics Cookies

Help us understand how visitors use our website by collecting anonymous usage data.

Marketing Cookies

Used to track visitors across websites and show relevant advertisements.

Functional Cookies

Remember your preferences and allow personalised features on our platform.

We use VWO (Visual Website Optimizer) to test website changes and improve user experience. VWO may set cookies to track which version of a page you see.

We use Vercel Analytics and Speed Insights to measure page performance. These tools collect anonymous usage data without setting cookies.

12. Contact Information

For questions about this privacy policy or how HelloRoam handles your personal data, please contact us via the details below:

Email Privacy Team

For questions about how HelloRoam handles your personal data

help@helloroam.com

Contact Support

For general questions about our eSIM services

help@helloroam.com

Legal Department

For legal matters and formal requests

help@helloroam.com

Right to Complain

For questions about this privacy policy or how HelloRoam handles your personal data, please contact us via the details below:

13. California Privacy Rights (CCPA/CPRA)

If you live in California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give you specific rights over your personal information. This section explains those rights and how to use them.

HelloRoam does not sell personal information as defined under the CCPA.

Personal Information We Collect

We collect the following categories of personal information from California residents:

  • Identifiers: name, email address, and account credentials
  • Device information: device type, operating system, and identifiers used for eSIM activation
  • Payment information: billing details processed securely by our payment provider
  • Usage data: how you interact with our website and app
  • Internet or other network activity: IP address, browser type, and pages visited

Right to Know

You can ask us what personal information we have collected about you, where it came from, why we collected it, and who we share it with.

Right to Delete

You can ask us to delete the personal information we have collected from you. Some exceptions apply, such as when we need the data to complete a transaction or meet a legal obligation.

Right to Opt Out

You can ask us not to sell or share your personal information. HelloRoam does not sell personal information, so this right is already honored by default.

Right to Non-Discrimination

We will not treat you differently or deny you services because you chose to exercise any of your California privacy rights.

How to Submit a CCPA Request

To exercise any of the rights above, email us at help@helloroam.com. Include your name, email address, and a description of your request. You may also submit a request on behalf of another person if you have written authorization or hold power of attorney.

Verification Process

We need to verify your identity before we can process your request. We will ask you to confirm the email address linked to your account and may request additional information to confirm your identity. We will respond to your request within 45 days. If we need more time, we will let you know.

14. Brazil Privacy Rights (LGPD)

Brazil's Lei Geral de Proteção de Dados (LGPD) applies to HelloRoam when we process personal data from individuals in Brazil. This section explains your rights and how we handle your data under Brazilian law.

Legal Bases Under LGPD

We process your personal data based on your consent, to perform a contract with you, to meet a legal obligation, or to serve our legitimate interests. We tell you the applicable legal basis at the time we collect your data.

Your Rights Under LGPD

  • Confirmation that we process your personal data and access to a copy of it.
  • Correction of incomplete, inaccurate, or outdated data.
  • Anonymization, blocking, or deletion of unnecessary or excessive data.
  • Portability of your personal data to another service provider.
  • Deletion of personal data processed with your consent.
  • Information about which public and private entities we share your data with.
  • Information about your option to deny consent and the consequences of doing so.
  • Withdrawal of consent at any time, free of charge.
  • Review of decisions made by automated means that affect your interests.

Data Protection Officer

Our Data Protection Officer handles privacy matters for Brazilian residents. Contact them at help@helloroam.com with the subject line "LGPD Request." We will respond within the timeframes required by Brazilian law.

If you believe we have not handled your data correctly, you have the right to file a complaint with Brazil's national data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), at gov.br/anpd.

15. Japan Privacy Rights (APPI)

Japan's Act on Protection of Personal Information (APPI) applies when we process personal data from individuals in Japan. We handle your data in line with APPI requirements and the guidelines issued by Japan's Personal Information Protection Commission (PPC).

Purpose of Data Use

We use your personal data to process eSIM orders, manage your account, provide customer support, send service notifications, and improve our platform. We will not use your data for other purposes without notifying you first.

Cross-Border Transfers

Your personal data is transferred to and stored in the United Kingdom. The UK has been recognized as providing an adequate level of personal data protection by the European Commission. We apply equivalent safeguards for transfers under APPI.

Your Rights Under APPI

  • Disclosure of the personal data we hold about you.
  • Correction of any inaccurate personal data.
  • Cessation of use or deletion of your personal data where it is no longer needed.
  • Cessation of provision of your personal data to third parties.

To exercise your rights or to submit a complaint, email us at help@helloroam.com. You may also contact the Personal Information Protection Commission (PPC) at ppc.go.jp.

16. Canada Privacy Rights (PIPEDA)

Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies to HelloRoam's handling of personal information from Canadian residents. We follow the fair information principles that PIPEDA requires.

How We Apply PIPEDA Principles

  • Accountability: We are responsible for all personal information under our control and have designated a privacy contact to oversee compliance.
  • Consent: We collect, use, or disclose your personal information only with your knowledge and consent, except where the law permits otherwise.
  • Limiting Collection: We collect only the information we need for the identified purposes.
  • Accuracy: We keep your personal information as accurate, complete, and up to date as necessary.
  • Safeguards: We protect your personal information with security appropriate to its sensitivity.

Your Rights Under PIPEDA

  • Access to the personal information we hold about you.
  • Challenge the accuracy and completeness of your information and request corrections.
  • Withdraw consent for non-essential data collection at any time.

To make a privacy request, email us at help@helloroam.com. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.

17. India Privacy Rights (DPDP Act)

India's Digital Personal Data Protection Act 2023 (DPDP Act) applies when we process personal data from individuals in India. HelloRoam acts as a Data Fiduciary under this law and processes your data only for clear, lawful purposes.

Your Rights Under the DPDP Act

  • Access to a summary of the personal data we process and how we use it.
  • Correction and updating of inaccurate or incomplete personal data.
  • Erasure of personal data that is no longer necessary for the purpose it was collected.
  • Grievance redressal through our dedicated grievance mechanism.
  • Nomination of another individual to exercise your rights on your behalf in case of death or incapacity.

As a Data Fiduciary, HelloRoam collects only the personal data needed to provide our eSIM services. We keep it secure, use it only for stated purposes, and delete it when it is no longer needed. We do not process the personal data of children without verifiable parental consent.

To raise a grievance or exercise any DPDP right, email us at help@helloroam.com with the subject line "DPDP Request." We will acknowledge your request within 48 hours and resolve it within the timeframe required by law.

18. Additional Regional Privacy Rights

HelloRoam operates in 185+ countries. In addition to GDPR, CCPA, LGPD, APPI, PIPEDA, and the DPDP Act, the following regional laws may apply to you depending on where you live.

South Africa (POPIA)

South Africa's Protection of Personal Information Act (POPIA) gives you rights to access, correct, and delete your personal data. Cross-border transfers require adequate protection. To exercise your rights or file a complaint, contact us at help@helloroam.com or reach the Information Regulator at inforegulator.org.za.

Thailand (PDPA)

Thailand's Personal Data Protection Act (PDPA) requires your consent for most processing. You have the right to access, correct, delete, and port your data, and to object to processing. To exercise your rights or complain to the Personal Data Protection Committee (PDPC), contact us at help@helloroam.com.

Singapore (PDPA)

Singapore's Personal Data Protection Act (PDPA) requires your consent before we collect, use, or disclose your personal data. You can withdraw consent at any time. We notify affected individuals promptly in the event of a data breach. Contact help@helloroam.com for any PDPA-related request.

Turkey (KVKK)

Turkey's Personal Data Protection Law (KVKK) requires explicit consent for cross-border data transfers. You have the right to know whether your data is processed, access it, request correction or deletion, and object to automated decisions. To submit a request or file a complaint with the KVKK Board, contact us at help@helloroam.com.

Switzerland (nFADP)

Switzerland's revised Federal Act on Data Protection (nFADP) applies to both natural and legal persons. You have the right to access your data, correct inaccuracies, and object to certain processing. We notify the Federal Data Protection and Information Commissioner (FDPIC) of significant data breaches. Contact help@helloroam.com with any nFADP request.

Indonesia (UU PDP)

Indonesia's Personal Data Protection Law (UU PDP) requires your consent for data collection and cross-border transfers. We maintain a designated Data Protection Officer to oversee compliance. To exercise your rights or raise a concern, email help@helloroam.com.

China (PIPL)

China's Personal Information Protection Law (PIPL) requires us to notify you and obtain separate consent before transferring your personal data outside China. We process data from Chinese residents only for the purposes clearly stated at the time of collection. Contact help@helloroam.com for any PIPL-related request.

19. AI and Machine Learning

HelloRoam uses AI tools carefully and only where they improve our service without compromising your privacy. We do not use AI in ways that produce automated decisions with legal or similarly significant effects on individual users.

AI Crawler Access

Our public website content, including eSIM pricing, coverage information, and FAQs, is accessible to AI crawlers. Your account data, personal information, and order history are never exposed to or shared with AI crawlers. We protect all personal data from AI training pipelines.

How We Use AI Internally

We use AI tools to support content research and review customer support quality. These tools process anonymized or aggregated data only. They are not used to make automated decisions about individual users.

HelloRoam does not sell user data to AI companies, data brokers, or any third parties for AI model training purposes.

20. Referral Program Privacy

When you participate in the HelloRoam referral program, we collect limited technical data to attribute referrals accurately and prevent fraud.

Data Collected

  • IP address (anonymized after attribution)
  • Browser user-agent string
  • Device fingerprint (hashed, non-reversible)

Purpose

This data is used solely to attribute referral purchases to the correct referrer, prevent duplicate or fraudulent claims, and calculate referral rewards. We do not use this data for advertising or sell it to third parties.

Data Retention

Referral attribution data is retained for 90 days after the referred purchase. After this period, the data is automatically deleted. Aggregated, non-personal statistics (total referrals, reward amounts) are kept for accounting purposes.

Your Privacy Matters

We care about your data rights. Our practices are transparent, and you can exercise your rights anytime by contacting us at help@helloroam.com.

Questions About This Policy?

Have questions about this Privacy Policy or how we handle your data? We're happy to help.

Excellent
Trustpilot

Get the app. Travel smarter.

Manage your eSIMs on the go, anytime.

5.0
App Store rating
4.3
Trustpilot
Scan to download HelloRoam eSIM app - QR code for mobile app installation