Data & Compliance

Last reviewed: September 2026

Telovigo sells prepaid travel data. That means we hold very little about you — and we have built the app so that it stays that way. This page explains, in plain language, what we do with your data, who we work with, how payments are protected, and which laws we operate under. The legally binding texts are the Privacy Policy and the Terms of Service.

GDPR & CCPA

German business, EU data protection law. GDPR for everyone, CCPA/CPRA rights honoured worldwide, your rights answered from one address.

No card data on our servers

Payments are handled by PCI DSS Level 1 providers. We only ever see a payment reference and the outcome.

No tracking

No advertising SDKs, no analytics trackers, no session replay, no cookies on this site. Nothing is sold or shared for marketing.

GDPR · CCPA / CPRA · Security · Payments

1. Who is responsible

ControllerAmoverse, owner Amad Amjad Khedir — a sole proprietorship registered in Germany (see Impressum)
Applicable lawEU General Data Protection Regulation (GDPR), German Federal Data Protection Act (BDSG), German Telecommunications Act (TKG), German Telecommunications-Digital-Services Data Protection Act (TDDDG)
Supervisory authorityLandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW); for telecom-specific matters the Bundesnetzagentur
Contactsupport@telovigo.com — for privacy requests, security reports and everything else

2. What we hold about you

Only what is needed to sell you a plan and keep it working:

DataWhyHow long
Email, hashed password, display nameYour account and sign-inUntil you delete your account
Orders: plan, destination, price, currency, date, payment referenceIssuing the eSIM, receipts, refunds, bookkeeping10 years (§ 147 AO, German tax law)
eSIM data: ICCID, activation code, status, data usedProvisioning and showing your usage12 months after the plan ends
Device model & OS versionChecking your phone supports eSIM before you paySession only
Country / currency from device regionShowing the right prices and payment methodsSession only
T-Wallet balance and ledgerPrepaid balance, gift codesUntil you delete your account (ledger kept with orders)
Support conversationsAnswering you2 years
Crash reports (app version, screen, error text)Fixing bugs — never contains your messages or payment details90 days

We never collect your location, contacts, photos, browsing history or advertising identifiers. The eSIM carries data traffic; we do not see or log what you do with it.

3. Payments

Card, Apple Pay, Google Pay and other European payment methods are processed by Stripe Payments Europe Ltd. (Dublin), certified PCI DSS Level 1. Card numbers are entered into Stripe's own fields inside the app and go straight to Stripe. Our servers receive only the payment reference, last four digits, amount and result — and we verify every payment with Stripe server-side before an eSIM is issued.

In Iraq we are integrating a licensed local payment partner for FIB, ZainCash and Qi Card. Until it is live, Iraqi customers pay by card through Stripe; the T-Wallet can be funded with gift codes. We will name the partner on this page and in the Privacy Policy on the day it goes live.

PCI DSS via Stripe3-D Secure / SCA (PSD2)Server-side payment verificationIraqi wallets — in preparation

4. Who we share data with

Only the providers needed to run the service, each under a data-processing agreement (Art. 28 GDPR). Where data leaves the EU/EEA it is covered by the EU Standard Contractual Clauses or an adequacy decision.

ProviderRoleWhat they see
Supabase Inc.Database, authentication, server functionsAccount, orders, eSIM records, support chat
Stripe Payments Europe Ltd.Payment processingPayment details, email for receipts
eSIMfly and its partner carrierseSIM supply and mobile data in the destinationOrder and eSIM profile; network traffic in the destination country
Resend Inc.Transactional email (receipts, sign-in links)Email address and message content
Cloudflare Inc.Hosting of telovigo.com, DNS, DDoS protectionIP address and request logs for this website
Apple Inc. / Google LLCOptional "Sign in with Apple / Google", app distributionOnly what you approve in the sign-in dialog

We do not sell personal data and do not share it with advertisers or data brokers — ever.

5. Security

Found a vulnerability? Please email support@telovigo.com with "Security report" in the subject. We reply within 3 working days and will not take legal action against good-faith research.

6. Your rights and how to use them

Access / exportEmail us; you receive a copy of your data as JSON within 30 days (usually much faster)
Delete your accountIn the app: Account → Delete account. Account and eSIM records are removed immediately; invoices are kept for the legally required 10 years, then deleted
Correct / restrict / objectEmail support@telovigo.com
ComplainTo the LDI NRW or any EU data protection authority

7. GDPR (EU / EEA / UK)

Telovigo is established in Germany, so the GDPR applies to everything we do — regardless of where you are. What that means in practice:

Your GDPR rights (Art. 15–21) and how to use them are in section 6. Requests are free and answered within one month.

8. CCPA / CPRA (California)

If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you specific rights. Telovigo honours them for every user, not only Californians:

Right to knowThe categories we collect are listed in section 2 (identifiers, commercial information, device information). Sources: you, your device, and our payment and eSIM providers. Purposes: providing the service, security, legal compliance.
Right to deleteAccount → Delete account in the app, or email us. Exceptions: invoices kept under German tax law and records needed to complete a transaction or defend legal claims.
Right to correctChange your name and email in the app; anything else by email.
Right to opt out of sale or sharingWe do not sell or share personal information as defined by the CCPA/CPRA, and have not done so in the preceding 12 months. There is nothing to opt out of; we honour Global Privacy Control signals on this website regardless.
Sensitive personal informationWe do not collect sensitive personal information (no precise geolocation, no government IDs, no financial account numbers — card data goes directly to Stripe).
Non-discriminationExercising your rights never changes the price or quality of the service.
Authorised agentAn agent may submit a request on your behalf with written permission; we will verify the request with you by email.
VerificationRequests are verified by confirming control of the account email. We respond within 45 days.
MinorsWe have no actual knowledge of selling or sharing the personal information of anyone under 16.
How to submitsupport@telovigo.com with "CCPA request" in the subject, or from the app under Account → Support.

The same standards apply to residents of other US states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others).

9. Telecommunications law

Telovigo resells mobile data plans and is therefore a provider of telecommunications services under the German Telecommunications Act (TKG). The business is notified to the Bundesnetzagentur under § 5 TKG. We operate no network of our own, issue no phone numbers and offer no voice or SMS services; the data connection is provided by the partner carrier in the destination country. Telecommunications secrecy (§ 3 TDDDG) applies: we do not inspect or log the content of your traffic.

10. Consumer protection

11. Children

Telovigo is for people aged 13 and over (COPPA / Art. 8 GDPR). Creating an account requires confirming your age; the server refuses accounts that do not. We do not knowingly hold data of anyone younger and delete it on notice.

12. Sanctions and export control

As a German business we follow EU sanctions regulations and, because our payment provider is subject to them, US (OFAC) sanctions programs. We do not offer plans for, or accept payments from, destinations and persons under comprehensive sanctions, and our catalog is reviewed against the current lists.

13. Email

We send only transactional email: order receipts, sign-in and password links, and replies to your support requests. No newsletters, no promotions, no third-party mailings (CAN-SPAM, § 7 UWG). Every message comes from an @telovigo.com address — treat anything else claiming to be us as phishing and forward it to support.

14. Keeping this page honest

This page is updated whenever a provider, a process or the law changes. Material changes are announced in the app. If you think anything here is out of date, tell us at support@telovigo.com.