Data & Compliance
Last reviewed: September 2026
Telovigo sells prepaid travel data. That means we hold very little about you — and we have built the app so that it stays that way. This page explains, in plain language, what we do with your data, who we work with, how payments are protected, and which laws we operate under. The legally binding texts are the Privacy Policy and the Terms of Service.
GDPR & CCPA
German business, EU data protection law. GDPR for everyone, CCPA/CPRA rights honoured worldwide, your rights answered from one address.
No card data on our servers
Payments are handled by PCI DSS Level 1 providers. We only ever see a payment reference and the outcome.
No tracking
No advertising SDKs, no analytics trackers, no session replay, no cookies on this site. Nothing is sold or shared for marketing.
GDPR · CCPA / CPRA · Security · Payments
1. Who is responsible
| Controller | Amoverse, owner Amad Amjad Khedir — a sole proprietorship registered in Germany (see Impressum) |
| Applicable law | EU General Data Protection Regulation (GDPR), German Federal Data Protection Act (BDSG), German Telecommunications Act (TKG), German Telecommunications-Digital-Services Data Protection Act (TDDDG) |
| Supervisory authority | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW); for telecom-specific matters the Bundesnetzagentur |
| Contact | support@telovigo.com — for privacy requests, security reports and everything else |
2. What we hold about you
Only what is needed to sell you a plan and keep it working:
| Data | Why | How long |
|---|---|---|
| Email, hashed password, display name | Your account and sign-in | Until you delete your account |
| Orders: plan, destination, price, currency, date, payment reference | Issuing the eSIM, receipts, refunds, bookkeeping | 10 years (§ 147 AO, German tax law) |
| eSIM data: ICCID, activation code, status, data used | Provisioning and showing your usage | 12 months after the plan ends |
| Device model & OS version | Checking your phone supports eSIM before you pay | Session only |
| Country / currency from device region | Showing the right prices and payment methods | Session only |
| T-Wallet balance and ledger | Prepaid balance, gift codes | Until you delete your account (ledger kept with orders) |
| Support conversations | Answering you | 2 years |
| Crash reports (app version, screen, error text) | Fixing bugs — never contains your messages or payment details | 90 days |
We never collect your location, contacts, photos, browsing history or advertising identifiers. The eSIM carries data traffic; we do not see or log what you do with it.
3. Payments
Card, Apple Pay, Google Pay and other European payment methods are processed by Stripe Payments Europe Ltd. (Dublin), certified PCI DSS Level 1. Card numbers are entered into Stripe's own fields inside the app and go straight to Stripe. Our servers receive only the payment reference, last four digits, amount and result — and we verify every payment with Stripe server-side before an eSIM is issued.
In Iraq we are integrating a licensed local payment partner for FIB, ZainCash and Qi Card. Until it is live, Iraqi customers pay by card through Stripe; the T-Wallet can be funded with gift codes. We will name the partner on this page and in the Privacy Policy on the day it goes live.
PCI DSS via Stripe3-D Secure / SCA (PSD2)Server-side payment verificationIraqi wallets — in preparation
4. Who we share data with
Only the providers needed to run the service, each under a data-processing agreement (Art. 28 GDPR). Where data leaves the EU/EEA it is covered by the EU Standard Contractual Clauses or an adequacy decision.
| Provider | Role | What they see |
|---|---|---|
| Supabase Inc. | Database, authentication, server functions | Account, orders, eSIM records, support chat |
| Stripe Payments Europe Ltd. | Payment processing | Payment details, email for receipts |
| eSIMfly and its partner carriers | eSIM supply and mobile data in the destination | Order and eSIM profile; network traffic in the destination country |
| Resend Inc. | Transactional email (receipts, sign-in links) | Email address and message content |
| Cloudflare Inc. | Hosting of telovigo.com, DNS, DDoS protection | IP address and request logs for this website |
| Apple Inc. / Google LLC | Optional "Sign in with Apple / Google", app distribution | Only what you approve in the sign-in dialog |
We do not sell personal data and do not share it with advertisers or data brokers — ever.
5. Security
- Encryption in transit: TLS 1.2+ everywhere (app ↔ server, this website, all providers). HTTPS is enforced on telovigo.com.
- Encryption at rest: database and backups are encrypted by our hosting provider.
- Passwords: stored only as salted hashes (bcrypt); we cannot read them. Passkeys and Sign in with Apple / Google are available so you need not use a password at all.
- Least privilege: every database table is protected with row-level security — your account can only read its own rows; admin functions require a separately verified admin role.
- Server-side checks: prices, promo codes, wallet balances and payment status are decided on the server, never trusted from the app.
- Rate limiting: sign-in, purchase and support endpoints are rate-limited to blunt abuse.
- Secrets: API keys live only in the server's secret store, never in the app bundle or source code.
- Logging: server logs contain status codes and references, not personal data.
Found a vulnerability? Please email support@telovigo.com with "Security report" in the subject. We reply within 3 working days and will not take legal action against good-faith research.
6. Your rights and how to use them
| Access / export | Email us; you receive a copy of your data as JSON within 30 days (usually much faster) |
| Delete your account | In the app: Account → Delete account. Account and eSIM records are removed immediately; invoices are kept for the legally required 10 years, then deleted |
| Correct / restrict / object | Email support@telovigo.com |
| Complain | To the LDI NRW or any EU data protection authority |
7. GDPR (EU / EEA / UK)
Telovigo is established in Germany, so the GDPR applies to everything we do — regardless of where you are. What that means in practice:
- Legal basis for every processing: your contract with us (account, orders, eSIM), our legal obligations (tax records), or a narrowly defined legitimate interest (fraud prevention, showing prices in your currency). We do not rely on consent for anything essential, and we never bundle consent into terms.
- Data minimisation and purpose limitation: we collect only what section 2 lists, use it only for the stated purpose, and delete it on the schedule shown.
- Records of processing (Art. 30) and processor agreements (Art. 28) are in place for every provider in section 4.
- International transfers (Art. 44–49): providers outside the EU/EEA are bound by the EU Standard Contractual Clauses or covered by an adequacy decision (e.g. the EU–US Data Privacy Framework where certified).
- Breach notification (Art. 33/34): a personal-data breach is reported to the LDI NRW within 72 hours and to affected users without undue delay if it is likely to put them at high risk.
- No automated decision-making with legal effect and no profiling (Art. 22).
- UK users: the UK GDPR applies alongside; the same rights and the same contact address apply. Complaints may also go to the ICO.
Your GDPR rights (Art. 15–21) and how to use them are in section 6. Requests are free and answered within one month.
8. CCPA / CPRA (California)
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you specific rights. Telovigo honours them for every user, not only Californians:
| Right to know | The categories we collect are listed in section 2 (identifiers, commercial information, device information). Sources: you, your device, and our payment and eSIM providers. Purposes: providing the service, security, legal compliance. |
| Right to delete | Account → Delete account in the app, or email us. Exceptions: invoices kept under German tax law and records needed to complete a transaction or defend legal claims. |
| Right to correct | Change your name and email in the app; anything else by email. |
| Right to opt out of sale or sharing | We do not sell or share personal information as defined by the CCPA/CPRA, and have not done so in the preceding 12 months. There is nothing to opt out of; we honour Global Privacy Control signals on this website regardless. |
| Sensitive personal information | We do not collect sensitive personal information (no precise geolocation, no government IDs, no financial account numbers — card data goes directly to Stripe). |
| Non-discrimination | Exercising your rights never changes the price or quality of the service. |
| Authorised agent | An agent may submit a request on your behalf with written permission; we will verify the request with you by email. |
| Verification | Requests are verified by confirming control of the account email. We respond within 45 days. |
| Minors | We have no actual knowledge of selling or sharing the personal information of anyone under 16. |
| How to submit | support@telovigo.com with "CCPA request" in the subject, or from the app under Account → Support. |
The same standards apply to residents of other US states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others).
9. Telecommunications law
Telovigo resells mobile data plans and is therefore a provider of telecommunications services under the German Telecommunications Act (TKG). The business is notified to the Bundesnetzagentur under § 5 TKG. We operate no network of our own, issue no phone numbers and offer no voice or SMS services; the data connection is provided by the partner carrier in the destination country. Telecommunications secrecy (§ 3 TDDDG) applies: we do not inspect or log the content of your traffic.
10. Consumer protection
- Prices are shown in full, in your currency, including VAT where applicable, before you pay. No hidden fees, no auto-renewal — every plan is prepaid and ends when its data or days run out.
- Right of withdrawal: you agree at checkout that the eSIM is issued immediately; once delivered, the 14-day withdrawal right ends as permitted by § 356(5) BGB. Plans that never activated are refunded — see the Refund Policy.
- Compatibility check runs before payment so you cannot buy a plan your phone cannot use.
- Dispute resolution: EU online dispute resolution platform at ec.europa.eu/consumers/odr. We are not obliged and not willing to take part in dispute resolution before a consumer arbitration board.
11. Children
Telovigo is for people aged 13 and over (COPPA / Art. 8 GDPR). Creating an account requires confirming your age; the server refuses accounts that do not. We do not knowingly hold data of anyone younger and delete it on notice.
12. Sanctions and export control
As a German business we follow EU sanctions regulations and, because our payment provider is subject to them, US (OFAC) sanctions programs. We do not offer plans for, or accept payments from, destinations and persons under comprehensive sanctions, and our catalog is reviewed against the current lists.
13. Email
We send only transactional email: order receipts, sign-in and password links, and replies to your support requests. No newsletters, no promotions, no third-party mailings (CAN-SPAM, § 7 UWG). Every message comes from an @telovigo.com address — treat anything else claiming to be us as phishing and forward it to support.
14. Keeping this page honest
This page is updated whenever a provider, a process or the law changes. Material changes are announced in the app. If you think anything here is out of date, tell us at support@telovigo.com.