Skip to content

Privacy policy

Last updated 11 August 2026

The short version

  • We ask for the minimum needed to sell you an eSIM and support it: an email address, an order record, and the identifiers that make the eSIM work.
  • We never see your card number. A payment provider handles that.
  • Our analytics are cookieless and cannot follow you around the internet. There is no advertising pixel on this site, which is why there is no cookie banner.
  • We do not sell or share your personal information. There is no list to be on.

Ordering is not live yet. Until it is, the only personal data this website can collect is whatever you choose to put in an email to us, plus the anonymous measurement described in section 5. Everything below describes how we handle data once ordering opens, so you can read it before you decide to trust us with anything.

1. Who is responsible for your data

TravelNet is a trading name of Xelq Ltd, registered at [REGISTERED ADDRESS — TBC]. That entity is the data controller for the personal data described in this notice.

For any privacy question, correction or request, write to support@travelnet.world with “Privacy” at the start of the subject line. A person reads it — there is no automated privacy inbox.

2. What we collect, and why

Three categories, and nothing beyond them.

Information you give us

  • Your email address, so we can deliver the eSIM and answer you. This is the only field that is genuinely mandatory to buy.
  • A name and billing country, where our payment provider or tax rules require them for the receipt.
  • Whatever you write to us — the contents of support emails, including any screenshots you attach. Please do not send us passwords or card details; we will never ask for either.

Information created by your order

  • Order records: which plan, which destination, when, how much, and the reference number.
  • eSIM identifiers such as the ICCID of the profile issued to you, and activation status. Without these we cannot provision the eSIM, reissue a lost QR code, or tell you why a line is not connecting.
  • Payment metadata: the fact of payment, the amount, the currency, the last four digits and card brand. The card number itself goes directly to the payment provider and never touches our systems.

Information collected automatically

  • Server and security logs held by our hosting provider, including IP address and user agent, used to serve the site and to block abuse.
  • Aggregate page analytics — see section 5. No cookie, no identifier, no profile.

We do not collect location data, contacts, photos or anything from your device. There is no TravelNet app, and the eSIM profile on your phone carries no tracking of ours. What data you consume, and where, is visible to the mobile network you connect to, exactly as it would be with any SIM card.

3. Our legal grounds for using it

Under the GDPR and UK GDPR, we rely on:

  • Performance of a contract — delivering the eSIM you bought, supporting it, and handling refunds.
  • Legitimate interests — keeping the site up, preventing fraud and card testing, understanding in aggregate which pages are useful, and defending legal claims. We have weighed these against your interests and kept the data minimal accordingly.
  • Legal obligation — tax, accounting and record-keeping rules that apply to the sale.
  • Consent — only if you ever explicitly opt in to something, such as being told when ordering opens. You can withdraw it at any time by replying to any email we send, and withdrawal does not affect what happened before.

4. Marketing

We do not run a marketing list. If you email us to be told when ordering opens, we use your address for that one message and then delete it. If we ever start a newsletter it will be a separate, explicit opt-in, and buying an eSIM will not sign you up to it.

5. Cookies and analytics

This site sets no advertising or tracking cookies. There is no Meta pixel, no Google Ads tag, no session recorder and no third-party embed that phones home while you read.

We measure traffic with Cloudflare Web Analytics, which is cookieless: it records page views and referrers in aggregate and does not build a profile of you or follow you to other sites. Because it stores nothing on your device and cannot identify you, no consent banner is required — which is also why you have not been asked to dismiss one.

Strictly necessary cookies may be set at checkout once payments go live, purely to keep your order intact between pages. Those are exempt from consent requirements and will be documented here before they appear.

6. Who else processes your data

We keep the list short on purpose. Each of these is a processor acting on our instructions under a contract:

  • Cloudflare — hosting, content delivery, security filtering and the cookieless analytics above.
  • Proton — our email provider, which carries your correspondence with us and your order emails.
  • Our eSIM supplier — once ordering opens, the wholesale platform that issues the eSIM profile receives the minimum needed to provision it. It is named here before the first order is taken.
  • Our payment provider — processes the card or wallet transaction as an independent controller for fraud and compliance purposes, and is named here before the first order is taken.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not hand it to data brokers. We will disclose data if a valid legal order compels us to, and we will tell you unless we are legally barred from doing so.

7. International transfers

Our customers and our suppliers are spread across the world, so your data will cross borders — a request from Europe may be served from a data centre elsewhere, and support email is read wherever we happen to be. Where data leaves the UK or the European Economic Area, transfers are covered by the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable.

8. How long we keep things

  • Order and payment records — for as long as tax and accounting law requires, typically six to seven years from the transaction.
  • eSIM provisioning records — for the life of the plan plus twelve months, so a reissue or a dispute can still be resolved.
  • Support correspondence — twenty-four months, then deleted.
  • Server logs — retained by our hosting provider on its standard schedule, a matter of days to weeks.

9. Your rights

Wherever you live, you can ask us for a copy of your data, ask us to correct it, or ask us to delete it, and we will do so unless the law requires us to keep it. If you are in the UK, the EEA or Switzerland you also have the right to restrict or object to processing, the right to data portability, and the right to withdraw consent.

If you are a California resident, the CCPA as amended gives you the right to know what we collect and why, to delete it, to correct it, and to opt out of the sale or sharing of personal information. We do not sell or share personal information, so there is nothing to opt out of, and you will never be treated differently for exercising any of these rights.

To exercise anything above, email support@travelnet.world. We reply within thirty days, usually far sooner, and we will only ask you to verify your identity where we genuinely cannot match the request to an order.

You are also entitled to complain to your data protection authority — in the UK the Information Commissioner's Office, in the EEA your national supervisory authority. We would rather you came to us first, but that route is yours regardless.

10. Security

The site is static and served over HTTPS everywhere. Card data never reaches us. Access to order records is limited to the people who need it to do support, and protected by multi-factor authentication. No system is perfect; if a breach ever affects your data we will tell you and the relevant regulator within the deadlines the law sets.

11. Children

This service is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.

12. Changes to this policy

When this notice changes we update the date at the top. If a change is material — a new processor, a new category of data, a new purpose — we will say so plainly here rather than quietly rewording a clause.

Related: terms of service and refund policy.