Privacy policy

Last updated: 5 October 2026

We collect the minimum needed to sell you an eSIM and deliver it. Nothing more.

What we collect

  • Contact details — your name and email address, so we can deliver your eSIM QR code and reach you about your order.
  • Order details — which plan you bought, when, and for how much, so we can provision the eSIM and handle refunds or support.
  • Technical data — basic, anonymized analytics (pages visited, device type) to keep the site fast and fix broken pages.

What we never collect

  • No passport or ID scans. Travel eSIMs don't require identity registration, so we never ask for — and never want — your ID documents.
  • No payment card numbers. Payments are processed by our payment provider (Stripe); your card details go directly to them and are never stored on our servers.
  • No precise location tracking beyond what your carrier sees when you use mobile data (that's between you and the network).

Cookies

We use only minimal, functional cookies (e.g. remembering your cart). No advertising trackers, no cross-site profiling. If we ever add analytics cookies, we'll ask first.

How we use your data

  • Deliver your eSIM and order confirmations.
  • Provide customer support and process refunds.
  • Improve the website (aggregated, anonymized statistics only).

We do not sell your personal data, and we do not share it with advertisers. Your email is used to deliver your order and support replies — marketing emails only if you explicitly opt in, with an unsubscribe link in every one.

Data retention

Order records are kept for as long as needed for accounting, tax, and refund obligations, then deleted or anonymized. Support emails are kept for up to 2 years. You can ask us to delete your data sooner (see below) unless the law requires us to keep it.

Your rights

Under Thailand's PDPA and the EU GDPR, you can request a copy of your data, corrections, or deletion. Email hello@roamthai.com with the subject "Data request" — we respond within 30 days.

Data security

The site runs over HTTPS, access to order data is restricted, and payment processing is handled by PCI-DSS-compliant providers. If we ever discover a breach affecting your data, we'll notify you promptly as the law requires.

Changes to this policy

We'll update the "last updated" date above and note material changes here. Continued use of the site after changes means you accept the updated policy.