1. Introduction
Your privacy matters to RORO. This Privacy Policy describes how we handle personal data when you use roroesim.com, the RORO app, and our eSIM and physical SIM services. We follow the EU General Data Protection Regulation (GDPR) and applicable Swedish law.
2. Data controller
The controller of your personal data is DDUP Business Service AB ("RORO"), reg. no. 556883-0672, EU VAT SE556883067201, registered at Transportgatan 2, 254 64 Helsingborg, Sweden. You can reach us about any data matter at team@roroesim.com.
3. What data we collect
RORO is built to need as little about you as possible. We do not collect, require or store identity documents or personal profiles. To buy, you only give us a way to reach you — an eSIM needs just an email address; a physical SIM also needs a delivery address. Across the 190+ countries and regions we cover, only Hong Kong (China) and Taiwan (China) require first-time users to register identity details with the local operator; that exchange is strictly between you and the operator — it never passes through RORO, and we have no access to it. The only other data we handle is what's generated when you use the Services:
- Contact data — only what you provide: an email address, plus a delivery address for physical SIM orders. We don't require your name, phone number or ID;
- Order & payment data — products bought, amounts, and payment confirmation (card numbers are handled by our payment providers, not stored by us);
- Service data — which eSIM/plan you use, activation status, and high-level usage needed to provide and support the service;
- Device & technical data — device type, eSIM compatibility, IP address, app/diagnostic logs;
- Support data — messages you send us;
- Website data — cookies and similar technologies (see our Cookie Notice).
4. How we use your data
- Provide, activate and support your eSIM/SIM and process orders;
- Communicate about your orders, account and service;
- Provide customer support in your language;
- Improve and secure our Services and prevent fraud or abuse;
- Send marketing where you have agreed, or as permitted by law;
- Comply with legal, tax and regulatory obligations.
5. Legal bases (GDPR)
We rely on the following legal bases:
- Contract — to provide the Services you buy;
- Legitimate interests — to secure, improve and support the Services;
- Consent — for optional analytics/marketing cookies and marketing emails (you can withdraw anytime);
- Legal obligation — for accounting, tax and lawful requests.
6. How we share data
We share data only as needed to run the Services:
- Mobile-network partners (including operators such as China Mobile International) to provision connectivity;
- Payment providers to process your payment;
- Service providers (hosting, analytics, customer support, logistics for physical SIMs) acting as our processors under contract;
- Authorities where required by law.
We do not sell your personal data.
7. International transfers
Because RORO operates globally, limited service data may be processed outside the EEA — for example by the network partner in the country you are traveling in. What is transferred is restricted to your data plan and the connection/usage information needed to deliver connectivity; it does not include identity documents or personal profiles. Where any personal data is transferred outside the EEA, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
8. Data retention
We don't keep personal profiles. For newsletter subscribers, registered accounts and customers with a purchase history, the only personal detail we retain is the email address needed to provide the service. Order and accounting records are kept for the period required by Swedish law, after which data is deleted or anonymized.
9. Your rights
Subject to the GDPR, you have the right to:
- Access the personal data we hold about you;
- Have inaccurate data corrected;
- Have your data erased ("right to be forgotten");
- Restrict or object to certain processing;
- Data portability;
- Withdraw consent at any time;
- Lodge a complaint with a supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (IMY).
To exercise any right, email team@roroesim.com.
10. Cookies
We use cookies and similar technologies as described in our Cookie Notice. You can manage your choices anytime via "Cookie settings" in the footer.
11. Security
We use technical and organizational measures to protect your data, including encryption in transit and access controls. No method of transmission is completely secure, but we work to protect your information and review our measures regularly.
12. Children
The Services are not directed to children under 16, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this policy
We may update this policy. The "Last updated" date shows the current version, and material changes will be communicated through the Services.
14. Contact us
For any privacy question or request, contact team@roroesim.com, or write to DDUP Business Service AB, Transportgatan 2, 254 64 Helsingborg, Sweden.
Privacy questions or requests?
Contact us at team@roroesim.com to exercise your rights or ask anything about your data.