Rommy / Privacy Policy
Privacy Policy
Controller: Rommy · info@rommy.world
1. What we collect
To deliver an eSIM we process: your order details (plan, price, timestamps), a delivery contact (e-mail address, if provided), technical data required for eSIM provisioning (ICCID, activation code), and the public transaction data of your crypto payment. We do not collect card numbers or bank details — crypto payments are processed by our payment provider on their systems.
2. What we do not do
No sale of personal data, no advertising trackers on the website, no marketing e-mails without your explicit opt-in, no KYC for standard purchases.
3. Legal bases
Contract performance (Art. 6(1)(b) GDPR) for orders and delivery; legitimate interest (Art. 6(1)(f)) for fraud prevention and service security; legal obligation (Art. 6(1)(c)) for tax and commercial record-keeping.
4. Retention
Order records are kept for the statutory retention periods (up to 10 years under German tax law) and then deleted. Provisioning data is deleted or anonymised once no longer needed for support.
5. Processors & transfers
We use an eSIM connectivity provider to provision profiles and a crypto payment processor to handle payments. Both act as independent controllers or processors under their own privacy terms; data is transferred only as needed to fulfil your order.
6. Your rights
You have the right to access, rectification, erasure, restriction, portability and objection, and to lodge a complaint with a data-protection supervisory authority. Contact: info@rommy.world.