1. PingRoam
  2. /Privacy Policy

Privacy Policy

Table of contents

  • 1. Introduction
  • 2. Data Controller
  • 3. Information We Collect
  • 4. How We Use Your Information
  • 5. Third-Party Service Providers
  • 6. Legal Basis for Processing (GDPR)
  • 7. Your Rights Under GDPR
  • 8. Data Retention
  • 9. International Data Transfers
  • 10. Security
  • 11. Children's Privacy
  • 12. How to Delete Your Account
  • 13. Contact Us
  • 14. Data Subject Requests
  • 15. CCPA / CPRA (California)
  • 16. Data Retention

Privacy Policy

Last updated: July 11, 2026

1. Introduction

PingRoam ("we," "us," or "our") operates a travel eSIM platform that enables customers to purchase and manage digital data plans for use in 179+ countries. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website, mobile application, and related services.

2. Data Controller

TechHealth, LLC (PingRoam) is the data controller responsible for your personal information. PingRoam operates as a software platform, not a telecommunications operator; eSIM connectivity is provided by licensed third-party telecom partners (see our eSIM Provider Disclosure). For privacy-related inquiries, contact us at [email protected].

3. Information We Collect

We collect the following categories of personal data:

  • Account information: Email address provided during authentication via Firebase Auth (Google or Apple sign-in).
  • eSIM identifiers: ICCID (Integrated Circuit Card Identifier) associated with your purchased eSIM profiles.
  • Device notifications: Firebase Cloud Messaging (FCM) token to deliver order updates, activation alerts, and service notifications.
  • Transaction data: Purchase history, payment method type, and order status (payment details are processed by Whop and are not stored on our servers).
  • Technical data: IP address, browser type, device information, and language preferences.

4. How We Use Your Information

We use your personal data to:

  • Authenticate your account and provide access to your eSIM dashboard.
  • Provision and deliver eSIM profiles through our provider, eSIM Access.
  • Process payments via Whop.
  • Send transactional emails (order confirmations, activation instructions, support replies) via Resend.
  • Deliver push notifications related to your eSIM status.
  • Comply with legal obligations and prevent fraud.

5. Third-Party Service Providers

We share limited data with trusted processors:

| Provider | Purpose | |----------|---------| | Firebase Auth | User authentication and session management | | Whop | Payment processing (Merchant of Record) | | eSIM Access | eSIM provisioning, activation, and network connectivity | | Resend | Transactional email delivery | | Firebase Cloud Messaging | Push notification delivery | | z.ai (GLM) | AI-generated auto-replies in the support chat |

Each provider processes data under their own privacy policies and applicable data processing agreements.

6. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), UK, or Switzerland, we process your data based on:

  • Contract performance: To deliver eSIM services you purchase.
  • Legitimate interests: Fraud prevention, service improvement, and security.
  • Legal obligation: Tax, accounting, and regulatory compliance.
  • Consent: Marketing communications and non-essential cookies (where applicable).

7. Your Rights Under GDPR

You have the right to:

  • Access your personal data and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten"), subject to legal retention requirements.
  • Restrict processing in certain circumstances.
  • Port your data to another service in a structured format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time for consent-based processing.
  • Lodge a complaint with your local data protection authority.

To exercise these rights, email [email protected]. We will respond within 30 days.

8. Data Retention

We retain your data for as long as your account is active or as needed to provide services. Transaction records are kept for up to 7 years for tax and legal compliance. FCM tokens are deleted when you uninstall the app or disable notifications. You may request account deletion at any time.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your jurisdiction, including the United States. We ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) where required by applicable law.

10. Security

We implement industry-standard security measures including encryption in transit (TLS), access controls, and secure authentication. No method of transmission over the Internet is 100% secure; we cannot guarantee absolute security.

11. Children's Privacy

PingRoam is not intended for users under 16 years of age. We do not knowingly collect data from children. If you believe a child has provided us data, contact us immediately.

12. How to Delete Your Account

You can delete your PingRoam account and request erasure of personal data at any time:

  1. In the mobile app or website: Open Settings → Privacy & Data, choose Erase / Delete my account, and confirm.
  2. By email: Write to [email protected] with subject “Account deletion” from the email address on your account.

We will anonymize or delete personal data as described in this policy. Order and payment records may be retained where required by tax or accounting law (typically up to 7 years), with personal identifiers removed where legally permitted.

13. Contact Us

For questions about this Privacy Policy or your personal data:

Email: [email protected]
Subject line: Privacy Request

You may also submit GDPR requests via Settings → Privacy & Data in the PingRoam app or website.

14. Data Subject Requests

We support access, rectification, erasure, portability, and objection requests. Submit via Settings or email [email protected]. We respond within 30 days.

15. CCPA / CPRA (California)

California residents have the right to know, delete, and opt out of the sale of personal information. We do not sell personal information.

16. Data Retention

| Data type | Retention period | |-----------|------------------| | Account data | While account is active | | Orders & eSIM records | Up to 7 years (legal/tax) | | Support tickets | 3 years after closure | | Server logs | 90 days | | FCM tokens | Until uninstall or opt-out |