Privacy Policy
Effective date: September 2026
This policy explains what personal data Telovigo ("we", "us") processes when you use the Telovigo app and telovigo.com, why, and what rights you have. It is written to meet the EU General Data Protection Regulation (GDPR) and the German BDSG.
1. Controller
The controller is the business named in our Impressum. Contact for all privacy matters: support@telovigo.com.
2. What we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, password (hashed) | Your account, sign-in, order confirmations | Contract (Art. 6(1)(b) GDPR) |
| Orders: plan, destination, price, date | Delivering the eSIM, receipts, refunds, accounting | Contract; legal obligation (§147 AO, 10 years) |
| eSIM technical data: ICCID, activation code, status, data used | Provisioning the eSIM and showing your usage | Contract |
| Device model and OS version | eSIM compatibility check | Contract |
| Country / currency (from device region) | Showing prices and payment methods available to you | Legitimate interest (Art. 6(1)(f)) |
| Wallet balance and top-ups (Iraq only) | Prepaid balance | Contract |
| Support emails | Answering you | Contract / legitimate interest |
We do not collect your location, contacts, browsing history or advertising identifiers, and we do not use advertising or tracking SDKs.
3. Payments
Card, Apple Pay, Google Pay, PayPal and Klarna payments are processed by Stripe Payments Europe, Ltd. (Ireland). Your card details go directly to Stripe and never reach our servers; we receive only a payment reference, the last four digits and the outcome. Stripe privacy policy: stripe.com/privacy. Klarna and PayPal apply their own policies when you choose them.
4. Who receives your data (processors)
- Supabase Inc. - database, authentication and server functions (hosting of your account and orders).
- eSIMfly - our eSIM supplier; receives the plan ordered so the profile can be issued. The profile is provisioned by partner carriers in the destination country.
- Stripe - payments (see above).
- Resend - sending order confirmation emails to the address on your account.
- Apple / Google - app distribution; they receive crash and purchase data under their own terms.
All processors are bound by data processing agreements under Art. 28 GDPR. Where data leaves the EU/EEA, transfers rely on Standard Contractual Clauses or an adequacy decision.
5. Retention
- Account data: until you delete your account.
- Orders and receipts: 10 years (German tax law), then deleted.
- eSIM technical data: 12 months after the plan expires.
- Support emails: 2 years.
6. Your rights
You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest (Art. 15-21 GDPR). Email support@telovigo.com. You can delete your account yourself in the app under Account → Settings → Delete account. You also have the right to lodge a complaint with a data protection supervisory authority.
7. Children
Telovigo is not directed at people under 16 and we do not knowingly collect their data.
8. Security
All traffic is encrypted (TLS). Passwords are stored hashed. Access to production data is restricted to the account owner.
9. Changes
We will post any changes here and update the effective date. Material changes are announced in the app.