1Introduction
1.1About Us
Thank you for using HaloRoam. This Privacy Policy explains how HaloRoam ("we", "us" or "our") collects, uses, shares and protects your personal data when you access or use the HaloRoam mobile application and related services (the "Services"). Operator: Tapcom Technology Limited (觸通科技有限公司), registered in the Hong Kong Special Administrative Region (Business Registration No. 70308547), contact email [email protected].
1.2Scope
This Policy applies to all personal data collected through the HaloRoam mobile application (both the iOS and Android versions). Accounts are independent and are not shared between the two platforms (the iOS version uses Sign in with Apple; the Android version uses Google Sign-In), and accounts and data are managed separately for each platform. The website is not yet live; once it is, we will supplement this Policy with the website's collection scope (such as cookies). This Policy does not apply to third-party websites or services (for example Stripe's payment pages), whose own privacy policies apply.
1.3Consent
By registering an account, accessing and using the app, and/or ordering and using the Services, you confirm that you have read this Policy and agree to our processing of your personal data as described here. If you do not agree, please do not use the Services.
2Data We Collect
We collect only the data necessary to provide and improve the Services. This version (1.0.0) does not integrate any third-party analytics, advertising or crash-reporting SDK; if a future version introduces one, we will first update this Policy and notify you in the app (see Section 9).
2.1Account Registration Data
When you create an account through a third-party sign-in (iOS: Sign in with Apple; Android: Google Sign-In), we collect your name (if provided on first authorisation) and email address, together with the user identifier returned by the third-party sign-in, in order to create and identify your account.
2.2Order Data
When you order a Data Plan, we process: the selected plan type, duration and currency, order status, order number and purchase history.
2.3Payment Data
(a) For card payments (Apple Pay on iOS, Google Pay on Android), payment is processed by Stripe; where a platform requires settlement through its app store, such payments are processed by that store and we receive only order and settlement result information. Stripe collects and processes your card details (card number, expiry date, etc.) and billing information; we do not store your full card number. (b) We may retain basic billing information (such as purchase date, cardholder name and the last four digits of the card) for customer support, reconciliation and refund handling. (c) When you pay with credit, we process your credit balance and transaction records (including refunds and refunds to the original payment method).
2.4Device & App Data (actual scope)
To serve API requests and localize content, the app sends: bundle identifier (X-Bundle-ID), app version (X-App-Version), time zone (X-Timezone) and language (X-Language). In addition, when you email us from the in-app "Contact Us" sheet, the message includes — at your initiative — the topic, selected order ID(s), app version, OS version and device model. We do not collect advertising identifiers (IDFA on iOS / Advertising ID on Android), cross-app tracking data, contacts, photos or precise location, and this version does not report crash logs or usage analytics.
2.5Service Usage Data
(a) Data and network usage data: to provide, measure and bill the Services, we and our carriers/suppliers record your eSIM data usage, activation time and plan status. (b) eSIM configuration data: to install the eSIM on your device, we process configuration data such as the ICCID, activation code (LPA), QR code/installation link and APN. (c) Support communications: the content of your email exchanges with us.
2.6Data We Do Not Request
We do not ask you to provide identity documents, passports or biometric information. Please do not send such information or full card numbers in support emails.
3Purposes
We process your personal data for the following purposes: (a) Providing the Services — creating and managing accounts, providing eSIM Data Plans and activation, and handling credit and coupons. (b) Payment processing — processing purchases through Stripe, managing credit balances, and handling refunds and refunds to the original payment method. (c) Customer support — responding to your enquiries and requests, troubleshooting, and handling refunds and disputes. (d) Service improvement — monitoring service health, improving the user experience, and developing and optimising features. (e) Legal obligations — complying with applicable laws, preventing fraud and abuse, and protecting our and our users' legitimate interests. Legal bases (where required by applicable law): performance of our contract with you, your consent, our legitimate interests, and compliance with legal obligations.
4Data Sharing
We do not sell your personal data. We share it only where necessary: (a) Payment processors — Stripe Inc. (which processes payment transactions under its own privacy policy). (b) Carriers and eSIM suppliers — to provide the eSIM data service we share necessary information with carriers/eSIM suppliers, including the eSIM identifier (ICCID), device-related identifiers and data usage. (c) Infrastructure providers — cloud servers, object storage and email delivery services (used to send receipts and support emails). (d) Sign-in providers — Apple (iOS) / Google (Android) (for authentication). (e) Legal requirements — disclosure to law enforcement, regulators or courts where required by law. Note: we do not use third-party advertising or behavioural analytics services and do not share data with them.
4.6Cross-Border Transfers
Your personal data may be stored and processed outside your country/region of residence. We will take appropriate measures to protect it and rely on appropriate transfer mechanisms under applicable law (e.g. an adequacy decision for the receiving country, or standard contractual clauses).
5Storage & Security
5.1Security Measures
We implement appropriate technical and organisational measures to protect your personal data: encryption in transit and at rest, secure servers and firewalls, least-privilege access control, and regular security assessments and updates.
5.2Payment Security
Payments are processed by Stripe in accordance with PCI-DSS; Stripe is a certified PCI service provider. We do not store full card numbers.
5.3Risk Notice
Although we take reasonable security measures, no method of internet transmission or electronic storage is 100% secure, and you use the Services at your own risk.
6Retention
We retain your personal data only for as long as necessary to provide the Services or as required by law, as set out in the table above. When we no longer have a lawful reason to retain your data, we will securely delete or anonymise it.
7Your Rights
Under applicable data protection law you have the following rights: (a) Access — to request access to the personal data we hold about you. (b) Rectification — to request correction or updating of inaccurate or incomplete data. (c) Erasure — to request deletion of your personal data. Accounts are independent per platform: deleting your account in the app deletes only the account on the platform you are using; if you also have an account on the other platform, please delete it there separately. You can do this yourself in the app via "Account → Delete Account"; if the in-app option is unavailable (for example if you have uninstalled the app), you may email [email protected] (subject "Account Deletion") and we will act after verifying your identity. (d) Withdraw consent — at any time for processing based on consent, without affecting the lawfulness of prior processing. (e) Data portability — to request a copy of your personal data in a structured, commonly used format. (f) Complaint — to lodge a complaint with the data protection authority in your place of residence; if you are in Hong Kong, you may complain to the Office of the Privacy Commissioner for Personal Data (PCPD).
7.7How to Exercise Your Rights
Please contact us at [email protected]. We will handle your request as soon as possible after verifying your identity; where applicable law prescribes a deadline, we will complete it within that deadline. If you are in Hong Kong, the access and correction requests above are also handled under the Personal Data (Privacy) Ordinance (Cap. 486).
7.8Consequences of Account Deletion
After your account is deleted (this concerns only the account on the platform you acted on): you will not be able to sign in, nor view or manage orders and Data Plans in the app; an installed eSIM may still be usable on the original device until the Data Plan's validity period expires (such use does not depend on signing in to the app and is subject to our supplier's rules), but unused portions are not separately refunded; we process your personal data in accordance with Section 6; and financial and transaction records that must be retained by law are deleted once the retention period ends.
8Children's Privacy
HaloRoam does not knowingly collect personal data from anyone under 18. The Services are intended only for users aged 18 or over. If you are under 18, please do not use the Services or provide us with any personal data. If we become aware that we have collected personal data from someone under 18, we will delete it as soon as possible.
9Policy Updates
We may update this Policy from time to time. If there are material changes, we will notify you in advance through an in-app notice or email, and will update the effective date and version number at the top. Your continued use of the Services constitutes acceptance of the updated Policy.
10Contact
If you have any questions, requests or complaints about this Policy or our processing of your personal data, please contact us: Tapcom Technology Limited (觸通科技有限公司), Hong Kong Special Administrative Region, Business Registration No. 70308547 · [email protected] (please mark personal-data requests as "Privacy Request") · https://haloroam.net · Unit 1140B, 11/F, Eastcore, 398 Kwun Tong Road, Kwun Tong, Kowloon, Hong Kong.