Skip to content

Privacy policy

Last updated 15 August 2026

The short version

  • We ask for the minimum needed to sell you an eSIM and support it: an email address, an order record, and the identifiers that make the eSIM work.
  • We never see your card number. A payment provider handles that.
  • Our analytics are cookieless and cannot follow you around the internet. There is no advertising pixel on this site, which is why there is no cookie banner.
  • There are no accounts and no passwords. Nothing to sign up for, nothing to be logged into, nothing of yours to be breached out of a login table.
  • We do not sell or share your personal information. There is no list to be on.

Ordering is live, so this site now collects order data. That is the order record described in section 2, plus whatever you choose to put in an email to us and the anonymous measurement described in section 5. Everything below sets out how we handle it, so you can read it before you decide to trust us with anything.

1. Who is responsible for your data

TravelNet is a trading name of Xelq Ltd, a company registered in Kenya under number PVT-5JUED9LZ, at 14 Ring Road, Parklands, Nairobi 00100, Kenya. That entity is the data controller for the personal data described in this notice.

For any privacy question, correction or request, write to support@travelnet.world with “Privacy” at the start of the subject line. A person reads it — there is no automated privacy inbox.

2. What we collect, and why

Three categories, and nothing beyond them.

Information you give us

  • Your email address, so we can deliver the eSIM and answer you. This is the only field that is genuinely mandatory to buy.
  • Your confirmation of the withdrawal-right waiver — the tick you give at checkout, recorded with the order because the law asks us to be able to show it.
  • Whatever you write to us — the contents of support emails, including any screenshots you attach. Please do not send us passwords or card details; we will never ask for either.

Information created by your order

One row in one database, and this is the whole of it — there is no second table and no profile built alongside it:

  • The email address you gave us, which is how the eSIM and your order link reach you.
  • Which product you bought — the plan, and therefore the destination — and the price you paid, in US dollars.
  • A payment reference from our payment provider, so a payment can be matched to an order and verified. It identifies the transaction, not your card.
  • The state of the order: awaiting payment, paid, delivered, or failed.
  • The eSIM credentials issued to you — the QR code, SM-DP+ address and activation code. These are the product, so we hold them in order to deliver them and to show them to you again on your order page if the delivery email goes astray.

We never receive your card number, and we do not store one. Payment happens on a page hosted by our payment provider; the card details go to them and never pass through our servers. There are also no accounts and no passwords — you cannot register with TravelNet, so there is no credential of yours for us to hold or lose. Your order page is reached by an unguessable link we email you, which is why that link is worth keeping to yourself.

Information collected automatically

  • Server and security logs held by our hosting provider, including IP address and user agent, used to serve the site and to block abuse.
  • Aggregate page analytics — see section 5. No cookie, no identifier, no profile.
  • The anti-bot check at checkout — Cloudflare Turnstile, which reads browser and device signals to tell a person from a script before an order is placed. It runs on the checkout page and nowhere else.

We do not collect location data, contacts, photos or anything from your device. There is no TravelNet app, and the eSIM profile on your phone carries no tracking of ours. What data you consume, and where, is visible to the mobile network you connect to, exactly as it would be with any SIM card.

3. Our legal grounds for using it

Under the GDPR and UK GDPR, we rely on:

  • Performance of a contract — delivering the eSIM you bought, showing it to you again when you need it, and supporting it when it does not work.
  • Legitimate interests — keeping the site up, preventing fraud and card testing, understanding in aggregate which pages are useful, and defending legal claims. We have weighed these against your interests and kept the data minimal accordingly.
  • Legal obligation — tax, accounting and record-keeping rules that apply to the sale, including keeping the record that you consented to immediate delivery.
  • Consent — only if you ever explicitly opt in to something, such as a future newsletter. You can withdraw it at any time by replying to any email we send, and withdrawal does not affect what happened before.

4. Accounts and marketing

There is no account to create. You buy with an email address and nothing else; there is no profile, no saved payment method, no purchase history to log into, and no password of yours anywhere in our systems.

There is no newsletter. The only emails we send about an order are the one carrying your eSIM and the one carrying your order link — both are part of the thing you bought, not marketing. If we ever start a newsletter it will be a separate, explicit opt-in, and buying an eSIM will not sign you up to it.

5. Cookies and analytics

This site sets no advertising or tracking cookies. There is no Meta pixel, no Google Ads tag and no session recorder. The one third-party embed anywhere on the site is Cloudflare's anti-bot challenge on the checkout page, which is there to keep scripts and stolen cards out; on every page you read before that, nothing phones home.

We measure traffic with Cloudflare Web Analytics, which is cookieless: it records page views and referrers in aggregate and does not build a profile of you or follow you to other sites. Because it stores nothing on your device and cannot identify you, no consent banner is required — which is also why you have not been asked to dismiss one.

Checkout sets no cookies of ours either. Nothing needs keeping between pages, because your order page opens from the link we email you. The anti-bot challenge above may use storage on Cloudflare's own domain; travelnet.world sets nothing.

6. Who else processes your data

We keep the list short on purpose. Each of these is a processor acting on our instructions under a contract:

  • Cloudflare — hosts the site, serves it, filters abuse, runs the cookieless analytics above, and holds the order database in which the record described in section 2 lives. Effectively everything we operate runs on Cloudflare.
  • Pesapal (Pesapal Limited, Kenya) — takes the payment, on a payment page hosted by them. They receive your card or wallet details and your email address, because they cannot charge a card without them; we receive back only whether the payment succeeded, for how much, and a reference. Pesapal acts as an independent controller for its own fraud, anti-money-laundering and regulatory obligations.
  • MobiMatter — the wholesale eSIM platform that actually issues your profile. It receives your email address and the product you bought, because it both provisions the eSIM and sends you the email carrying it. It gets nothing else, because nothing else is needed to issue an eSIM.
  • Resend — carries our internal alerts when an order needs a human. It never emails you. It receives your email address only when it appears in one of those alerts, which happens when something has gone wrong with your order and we need to find it.
  • Proton — our email provider, which carries your correspondence with us.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not hand it to data brokers. We will disclose data if a valid legal order compels us to, and we will tell you unless we are legally barred from doing so.

7. International transfers

Our customers and our suppliers are spread across the world, so your data will cross borders — a request from Europe may be served from a data centre elsewhere, and support email is read wherever we happen to be. We are a Kenyan company and our payment provider is a Kenyan company, so an order placed from Europe is handled in part in Kenya. Where data leaves the UK or the European Economic Area, transfers are covered by the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable.

8. How long we keep things

  • Order and payment records — for as long as tax and accounting law requires, typically six to seven years from the transaction.
  • eSIM credentials — for the life of the plan plus twelve months, so we can show them to you again, reissue them, or settle a dispute about whether they were delivered. After that they are of no use to anyone, including us.
  • Support correspondence — twenty-four months, then deleted.
  • Server logs — retained by our hosting provider on its standard schedule, a matter of days to weeks.

9. Your rights

Wherever you live, you can ask us for a copy of your data, ask us to correct it, or ask us to delete it, and we will do so unless the law requires us to keep it. If you are in the UK, the EEA or Switzerland you also have the right to restrict or object to processing, the right to data portability, and the right to withdraw consent.

If you are a California resident, the CCPA as amended gives you the right to know what we collect and why, to delete it, to correct it, and to opt out of the sale or sharing of personal information. We do not sell or share personal information, so there is nothing to opt out of, and you will never be treated differently for exercising any of these rights.

To exercise anything above, email support@travelnet.world. We reply within thirty days, usually far sooner, and we will only ask you to verify your identity where we genuinely cannot match the request to an order.

You are also entitled to complain to your data protection authority — in the UK the Information Commissioner's Office, in the EEA your national supervisory authority. We would rather you came to us first, but that route is yours regardless.

10. Security

Every page is served over HTTPS, and almost all of them are prerendered files with no database behind them at all. The order record lives in a Cloudflare database reachable only by our own code. Card data never reaches us, and there are no accounts, so there is no password of yours to steal. Access to order records is limited to the people who need it to do support, and protected by multi-factor authentication. No system is perfect; if a breach ever affects your data we will tell you and the relevant regulator within the deadlines the law sets.

11. Children

This service is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.

12. Changes to this policy

When this notice changes we update the date at the top. If a change is material — a new processor, a new category of data, a new purpose — we will say so plainly here rather than quietly rewording a clause.

Related: terms of service and refund policy.