Rommy.

Rommy / Privacy Policy

Privacy Policy

1. What we collect

To deliver an eSIM we process: your order details (plan, price, timestamps), a delivery contact (e-mail address, if provided), technical data required for eSIM provisioning (ICCID, activation code), and the public transaction data of your crypto payment. We do not collect card numbers or bank details — crypto payments are processed by our payment provider on their systems.

2. What we do not do

No sale of personal data, no advertising trackers on the website, no marketing e-mails without your explicit opt-in, no KYC for standard purchases.

3. Legal bases

Contract performance (Art. 6(1)(b) GDPR) for orders and delivery; legitimate interest (Art. 6(1)(f)) for fraud prevention and service security; legal obligation (Art. 6(1)(c)) for tax and commercial record-keeping.

4. Retention

Order records are kept for the statutory retention periods (up to 10 years under German tax law) and then deleted. Provisioning data is deleted or anonymised once no longer needed for support.

5. Processors & transfers

We use an eSIM connectivity provider to provision profiles and a crypto payment processor to handle payments. Both act as independent controllers or processors under their own privacy terms; data is transferred only as needed to fulfil your order.

6. Your rights

You have the right to access, rectification, erasure, restriction, portability and objection, and to lodge a complaint with a data-protection supervisory authority. Contact: info@rommy.world.