隱私政策
最後更新: 2026年5月
目錄
- 1. 前言
- 2. 資料控制者資訊
- 3. 我們收集的個人資料
- 4. 個人資料來源
- 5. 處理的法律依據
- 6. 資料分享與收件方
- 7. 國際資料傳輸
- 8. 你的資料保護權利
- 9. 資料保留
- 10. 兒童個人資料
- 11. Cookie 與追蹤技術
- 12. 聯絡資訊
- 13. 加州隱私權(CCPA/CPRA)
- 14. Brazil Privacy Rights (LGPD)
- 15. Japan Privacy Rights (APPI)
- 16. Canada Privacy Rights (PIPEDA)
- 17. India Privacy Rights (DPDP Act)
- 18. Additional Regional Privacy Rights
- 19. AI and Machine Learning
- 20. Referral Program Privacy
1. Introduction
本隱私政策(「聲明」)說明你的個人資料如何由 Future Syncs Limited(英國)旗下品牌 HelloRoam(「HelloRoam」、「我們」)處理。本聲明涵蓋你在聯絡我們、使用我們的 App、瀏覽本網站或購買服務時,所提供或我們所收集的個人資訊。
依據歐盟《一般資料保護規範》(GDPR)2016/679 及英國 GDPR,我們有義務提供本資訊,包括你的資料保護權利詳情。
HelloRoam 是否符合資料保護法規?
HelloRoam 認真看待資料保護,在沒有適當法律依據的情況下,絕不將你的個人資料分享給第三方。我們遵守 GDPR、英國資料保護法,以及北美、澳洲和拉丁美洲的隱私規範。隱私保護的概念已內建於我們所有服務之中。
We run Data Protection Impact Assessments when we start new services or data processing that may pose a high risk to your rights.
2. Data Controller Information
本聲明的資料控制者為 Future Syncs Limited(英國),旗下品牌為 HelloRoam。HelloRoam 負責你的個人資料之處理。
Company:Future Syncs Limited
Brand:HelloRoam(Future Syncs Limited 旗下品牌)
Address:英國倫敦
Company Registration:15950168
Email:help@helloroam.com
HelloRoam 致力保護你的個人資料。本聲明說明我們處理資料的完整方式。
3. Personal Data We Collect
我們收集並處理下列類別的個人資料:
| 類別 | 範例 |
|---|---|
| 身分資料 | 姓名、用戶名稱或類似識別資訊、稱謂、出生日期 |
| 聯絡資料 | 電子郵件地址、電話號碼、帳單地址、收件地址 |
| 財務資料 | 付款卡資訊(由我們的支付服務商處理)、銀行帳戶資訊 |
| 交易資料 | 你的付款明細,以及你向我們購買的產品與服務資訊 |
| 技術資料 | IP 位址、登入資訊、瀏覽器類型與版本、時區及位置、瀏覽器外掛類型與版本、作業系統與平台、裝置識別碼 |
| 個人檔案資料 | 你的用戶名稱與密碼、購買或訂單紀錄、興趣、偏好設定、意見回饋及問卷回覆 |
| 使用資料 | 你使用我們網站、產品及服務的方式,包含 eSIM 啟用資料及流量使用模式 |
| 行銷資料 | 你接收我們及第三方行銷訊息的偏好設定,以及通訊偏好 |
4. Sources of Your Personal Data
我們從以下來源收集你的個人資料:
直接互動
當你填寫表單或透過電話、電子郵件或其他管道聯絡我們時,你會直接提供身分、聯絡及財務資料。這包括你建立帳戶、購買方案、訂閱電子報、申請行銷、參加活動或提供意見回饋時所分享的資料。
自動化技術
當你使用我們的網站與 App 時,我們可能自動收集你的裝置、瀏覽活動及使用模式等技術資料,這透過 Cookie、伺服器記錄及類似技術進行。
第三方
我們可能從第三方收到個人資料,包括數據分析服務商、廣告網路、搜尋資訊提供商、支付及物流服務,以及身分驗證服務。
5. Legal Basis for Processing
我們只在法律允許的情況下使用你的個人資料。以下是最常見的情況:
履行合約
在我們需要履行與你簽訂或即將簽訂的合約時。
正當利益
在我們有正當利益(或第三方正當利益),且這些利益未被你的基本權利和利益凌駕時。
法律義務
在我們需要遵守法律或監管義務時。
同意
在你已同意針對一個或多個特定目的處理個人資料時。
撤回同意的權利
我們只在法律允許的情況下使用你的個人資料。以下是最常見的情況:
6. Data Sharing & Recipients
我們可能與下列類別的收件方分享你的個人資料:
服務提供商
代表我們提供服務的公司,包括支付處理、數據分析、電子郵件傳遞、主機代管、客戶服務及行銷支援。
網路合作夥伴
支援我們連線服務的行動網路業者及 eSIM 供應商。
專業顧問
提供法律、財務及顧問服務的律師、銀行、審計師及保險業者。
監管機關
法律要求時,包括政府機關、監管機構、執法機關、法院及其他主管機關。
資料保護標準
我們要求所有第三方尊重你的個人資料安全,並依法處理。我們不允許第三方服務提供商將你的資料用於自身目的,他們只能在我們指定的特定目的下進行處理。
Our Data Processors
We share your data with these trusted service providers. Each one has a data processing agreement with us.
| 处理方 | 用途 |
|---|---|
| Stripe | Payment processing. Card details go directly to Stripe and are never stored on our servers. |
| Supabase | User authentication and account management. |
| Google Analytics (GA4) | Website usage analytics. Only active after you give consent. |
| Google Ads | Conversion tracking for advertising. Only active after you give consent. |
| Google Tag Manager | Tag management for analytics and marketing scripts. |
| Meta (Facebook Pixel) | Marketing analytics and conversion tracking. Only active with marketing consent. |
| Microsoft Clarity | Behavioral analytics and session recordings to improve user experience. Only active with analytics consent. |
| Sentry | Error monitoring and performance tracking. Personal data is automatically redacted. |
| VWO (Visual Website Optimizer) | A/B testing to help us improve the website experience. |
| Vercel | Website hosting, analytics, and performance monitoring. |
| Rewardful | Affiliate referral tracking. Stores a referral token for 90 days when you arrive via an affiliate link. |
We have Data Processing Agreements in place with all processors listed above.
Affiliate Partners
When you arrive through an affiliate link, we share a referral token with Rewardful to attribute your purchase and calculate rewards. This data is kept for 90 days.
7. International Data Transfers
我們可能將你的個人資料傳輸至英國及歐洲經濟區(EEA)以外的國家。每當這樣做時,我們都會採取保護措施,確保你的資料獲得同等程度的保護。
• 傳輸至歐盟委員會或英國政府認定具有充分資料保護水準的國家。
• 使用歐盟委員會或英國政府核准的標準合約條款(SCC)。
• 傳輸至已通過歐美資料隱私框架認證的美國服務提供商。
聯絡我們了解資料傳輸
如需了解我們將個人資料傳輸至英國或歐洲經濟區以外時所採取的具體保障措施,請透過 help@helloroam.com 聯絡我們。
Transfer Mechanisms by Processor
Stripe, Google, Meta, Microsoft, Sentry, VWO, and Vercel transfer data to the United States under Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. Supabase processes data in the US under SCCs. For UK-origin transfers, we use the UK International Data Transfer Agreement (IDTA) alongside SCCs.
8. Your Data Protection Rights
依據資料保護法,你享有以下權利:
查閱權
你可以要求取得我們持有的個人資料副本。
更正權
你可以要求我們更正不正確的資訊或補充不完整的紀錄。
刪除權
在符合特定條件的情況下,你可以要求我們刪除你的個人資料。
限制處理權
在符合特定條件的情況下,你可以要求我們限制處理你的個人資料。
異議權
在符合特定條件的情況下,你可以反對我們處理你的個人資料。
資料可攜權
在符合特定條件的情況下,你可以要求我們將你的資料轉移給另一組織或直接交給你。
撤回同意
當我們依賴同意作為處理依據時,你可以隨時撤回同意。
申訴權
你可以向主管機關提出申訴。
We do not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
如何行使你的權利
如需行使上述任何權利,請透過 help@helloroam.com 聯絡我們。查閱資料或行使權利均不收費。僅在你的請求明顯毫無根據、重複提出或過度時,我們才可能收取合理費用。
9. Data Retention
我們只在必要期間保留你的個人資料,包括任何法律、會計或報告要求所需的期間。
決定資料保留期限時,我們會考量資料的數量與敏感程度、未授權使用可能造成的傷害風險、收集目的、是否有其他方式達成同樣目的,以及相關法律規定。
| Category | Retention Period |
|---|---|
| 帳戶資料 | 帳戶存續期間,以及關閉後6年 |
| 交易資料 | 交易日起7年 |
| 行銷偏好 | 直到你取消訂閱,或3年未活動 |
| 技術/使用資料 | 收集後13個月 |
10. Children's Personal Data
我們的服務僅限16歲以上人士使用。我們不會刻意收集16歲以下兒童的個人資料。如果你是家長或監護人,且認為你的小孩已向我們分享資料,請立即與我們聯絡。
如果我們發現已在未取得家長同意的情況下收集兒童個人資料,我們會立即從系統中刪除。
家長通知
如果你認為我們持有16歲以下兒童的相關資料,請立即透過 help@helloroam.com 聯絡我們。
12. Contact Information
如對本隱私政策或我們處理資料的方式有疑問,請透過以下方式聯絡我們:
申訴權利
如對本隱私政策或我們處理資料的方式有疑問,請透過以下方式聯絡我們:
13. 加州隱私權(CCPA/CPRA)
如果你居住在加州,《加州消費者隱私法》(CCPA)及《加州隱私權法》(CPRA)賦予你對個人資訊的特定權利。本節說明這些權利及其行使方式。
HelloRoam不會出售CCPA定義下的個人資訊。
我們收集的個人資訊類別
我們從加州居民收集以下類別的個人資訊:
- 識別資訊:姓名、電子郵件地址及帳號登入資訊
- 裝置資訊:裝置類型、作業系統,以及用於eSIM啟用的裝置識別碼
- 付款資訊:由我們的付款服務商安全處理的帳單詳細資料
- 使用資料:你與我們網站及應用程式的互動方式
- 網際網路或其他網路活動:IP位址、瀏覽器類型及瀏覽頁面
知情權
你可以要求我們說明所收集的個人資訊、資料來源、收集目的,以及與哪些對象共享這些資訊。
刪除權
你可以要求我們刪除已收集的個人資訊。但在某些例外情況下,例如需要資料以完成交易或履行法律義務時,刪除請求可能不適用。
退出權
你可以要求我們不出售或共享你的個人資訊。HelloRoam不出售個人資訊,因此這項權利預設已受保障。
不受歧視權
無論你是否選擇行使任何加州隱私權利,我們都不會因此對你採取差別待遇或拒絕提供服務。
如何提交CCPA請求
如需行使上述任何權利,請發送電子郵件至 help@helloroam.com。請提供你的姓名、電子郵件地址,以及請求說明。若你已取得書面授權或持有委託書,亦可代表他人提交請求。
身份驗證程序
我們在處理你的請求前,需要驗證你的身份。我們將要求你確認與帳號綁定的電子郵件地址,並可能要求提供額外資訊以核實你的身份。我們將在45天內回覆你的請求。如需更多時間,我們會事先通知你。
14. Brazil Privacy Rights (LGPD)
Brazil's Lei Geral de Proteção de Dados (LGPD) applies to HelloRoam when we process personal data from individuals in Brazil. This section explains your rights and how we handle your data under Brazilian law.
Legal Bases Under LGPD
We process your personal data based on your consent, to perform a contract with you, to meet a legal obligation, or to serve our legitimate interests. We tell you the applicable legal basis at the time we collect your data.
Your Rights Under LGPD
- Confirmation that we process your personal data and access to a copy of it.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of unnecessary or excessive data.
- Portability of your personal data to another service provider.
- Deletion of personal data processed with your consent.
- Information about which public and private entities we share your data with.
- Information about your option to deny consent and the consequences of doing so.
- Withdrawal of consent at any time, free of charge.
- Review of decisions made by automated means that affect your interests.
Data Protection Officer
Our Data Protection Officer handles privacy matters for Brazilian residents. Contact them at help@helloroam.com with the subject line "LGPD Request." We will respond within the timeframes required by Brazilian law.
If you believe we have not handled your data correctly, you have the right to file a complaint with Brazil's national data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), at gov.br/anpd.
15. Japan Privacy Rights (APPI)
Japan's Act on Protection of Personal Information (APPI) applies when we process personal data from individuals in Japan. We handle your data in line with APPI requirements and the guidelines issued by Japan's Personal Information Protection Commission (PPC).
Purpose of Data Use
We use your personal data to process eSIM orders, manage your account, provide customer support, send service notifications, and improve our platform. We will not use your data for other purposes without notifying you first.
Cross-Border Transfers
Your personal data is transferred to and stored in the United Kingdom. The UK has been recognized as providing an adequate level of personal data protection by the European Commission. We apply equivalent safeguards for transfers under APPI.
Your Rights Under APPI
- Disclosure of the personal data we hold about you.
- Correction of any inaccurate personal data.
- Cessation of use or deletion of your personal data where it is no longer needed.
- Cessation of provision of your personal data to third parties.
To exercise your rights or to submit a complaint, email us at help@helloroam.com. You may also contact the Personal Information Protection Commission (PPC) at ppc.go.jp.
16. Canada Privacy Rights (PIPEDA)
Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies to HelloRoam's handling of personal information from Canadian residents. We follow the fair information principles that PIPEDA requires.
How We Apply PIPEDA Principles
- Accountability: We are responsible for all personal information under our control and have designated a privacy contact to oversee compliance.
- Consent: We collect, use, or disclose your personal information only with your knowledge and consent, except where the law permits otherwise.
- Limiting Collection: We collect only the information we need for the identified purposes.
- Accuracy: We keep your personal information as accurate, complete, and up to date as necessary.
- Safeguards: We protect your personal information with security appropriate to its sensitivity.
Your Rights Under PIPEDA
- Access to the personal information we hold about you.
- Challenge the accuracy and completeness of your information and request corrections.
- Withdraw consent for non-essential data collection at any time.
To make a privacy request, email us at help@helloroam.com. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
17. India Privacy Rights (DPDP Act)
India's Digital Personal Data Protection Act 2023 (DPDP Act) applies when we process personal data from individuals in India. HelloRoam acts as a Data Fiduciary under this law and processes your data only for clear, lawful purposes.
Your Rights Under the DPDP Act
- Access to a summary of the personal data we process and how we use it.
- Correction and updating of inaccurate or incomplete personal data.
- Erasure of personal data that is no longer necessary for the purpose it was collected.
- Grievance redressal through our dedicated grievance mechanism.
- Nomination of another individual to exercise your rights on your behalf in case of death or incapacity.
As a Data Fiduciary, HelloRoam collects only the personal data needed to provide our eSIM services. We keep it secure, use it only for stated purposes, and delete it when it is no longer needed. We do not process the personal data of children without verifiable parental consent.
To raise a grievance or exercise any DPDP right, email us at help@helloroam.com with the subject line "DPDP Request." We will acknowledge your request within 48 hours and resolve it within the timeframe required by law.
18. Additional Regional Privacy Rights
HelloRoam operates in 185+ countries. In addition to GDPR, CCPA, LGPD, APPI, PIPEDA, and the DPDP Act, the following regional laws may apply to you depending on where you live.
South Africa (POPIA)
South Africa's Protection of Personal Information Act (POPIA) gives you rights to access, correct, and delete your personal data. Cross-border transfers require adequate protection. To exercise your rights or file a complaint, contact us at help@helloroam.com or reach the Information Regulator at inforegulator.org.za.
Thailand (PDPA)
Thailand's Personal Data Protection Act (PDPA) requires your consent for most processing. You have the right to access, correct, delete, and port your data, and to object to processing. To exercise your rights or complain to the Personal Data Protection Committee (PDPC), contact us at help@helloroam.com.
Singapore (PDPA)
Singapore's Personal Data Protection Act (PDPA) requires your consent before we collect, use, or disclose your personal data. You can withdraw consent at any time. We notify affected individuals promptly in the event of a data breach. Contact help@helloroam.com for any PDPA-related request.
Turkey (KVKK)
Turkey's Personal Data Protection Law (KVKK) requires explicit consent for cross-border data transfers. You have the right to know whether your data is processed, access it, request correction or deletion, and object to automated decisions. To submit a request or file a complaint with the KVKK Board, contact us at help@helloroam.com.
Switzerland (nFADP)
Switzerland's revised Federal Act on Data Protection (nFADP) applies to both natural and legal persons. You have the right to access your data, correct inaccuracies, and object to certain processing. We notify the Federal Data Protection and Information Commissioner (FDPIC) of significant data breaches. Contact help@helloroam.com with any nFADP request.
Indonesia (UU PDP)
Indonesia's Personal Data Protection Law (UU PDP) requires your consent for data collection and cross-border transfers. We maintain a designated Data Protection Officer to oversee compliance. To exercise your rights or raise a concern, email help@helloroam.com.
China (PIPL)
China's Personal Information Protection Law (PIPL) requires us to notify you and obtain separate consent before transferring your personal data outside China. We process data from Chinese residents only for the purposes clearly stated at the time of collection. Contact help@helloroam.com for any PIPL-related request.
19. AI and Machine Learning
HelloRoam uses AI tools carefully and only where they improve our service without compromising your privacy. We do not use AI in ways that produce automated decisions with legal or similarly significant effects on individual users.
AI Crawler Access
Our public website content, including eSIM pricing, coverage information, and FAQs, is accessible to AI crawlers. Your account data, personal information, and order history are never exposed to or shared with AI crawlers. We protect all personal data from AI training pipelines.
How We Use AI Internally
We use AI tools to support content research and review customer support quality. These tools process anonymized or aggregated data only. They are not used to make automated decisions about individual users.
HelloRoam does not sell user data to AI companies, data brokers, or any third parties for AI model training purposes.
20. Referral Program Privacy
When you participate in the HelloRoam referral program, we collect limited technical data to attribute referrals accurately and prevent fraud.
Data Collected
- IP address (anonymized after attribution)
- Browser user-agent string
- Device fingerprint (hashed, non-reversible)
Purpose
This data is used solely to attribute referral purchases to the correct referrer, prevent duplicate or fraudulent claims, and calculate referral rewards. We do not use this data for advertising or sell it to third parties.
Data Retention
Referral attribution data is retained for 90 days after the referred purchase. After this period, the data is automatically deleted. Aggregated, non-personal statistics (total referrals, reward amounts) are kept for accounting purposes.
Your Privacy Matters
We care about your data rights. Our practices are transparent, and you can exercise your rights anytime by contacting us at help@helloroam.com.
Related Policies
Questions About This Policy?
Have questions about this Privacy Policy or how we handle your data? We're happy to help.
