Privacy Policy

Last updated 23 September 2026

1. Who is responsible

Relai Solutions (202603138146), of Kuala Lumpur, is the data controller for personal data collected through Averoam. For any privacy question or request, contact support@averoam.com.

2. The records we keep

You do not need a customer account to buy or manage an eSIM. We do keep order, delivery and review records so we can fulfil purchases, provide support and verify reviews.

Stripe handles payment information, and MobiMatter, our connectivity supplier, holds the eSIM and activation details. Our own order database stores references to those records and delivery status, but does not store raw email addresses, full card numbers, eSIM QR codes or activation credentials.

We process your email address when handling payments, sending it to our supplier for delivery and checking an order lookup. We store a salted hash of the address to match orders and reviews. This remains data linked to your purchase; it is not anonymous.

3. What is collected, and by whom

Stripe collects your email address, payment details and billing country in order to take payment and send you a receipt. We can see the email address and the amount, but never your full card number.

Our supplier receives your email address so it can send your eSIM QR code and setup guide, and it generates the eSIM record including its ICCID.

Our order records include the payment session and order references, products and quantities purchased, supplier order references, pricing and currency information, delivery status, timestamps and the salted email hash. We also keep records of fulfilment attempts to prevent duplicate purchases and investigate failures.

If you submit a rating or review, we store the rating, any title, review text and display name you provide, the associated product or destination, order reference, email hash, timestamps and moderation status.

If you contact support, we receive the information you include in your message and use it to respond.

Cloudflare hosts the site and our order and review databases. It processes technical data such as IP address and user agent to deliver the site. Operational logs can include order or payment references, delivery errors and diagnostic information.

4. Why we process it

To perform the contract with you: taking payment, issuing your eSIM, delivering it and providing support.

To keep transaction records for accounting, handle disputes and meet applicable legal obligations.

To prevent fraud, duplicate fulfilment and abuse, investigate errors, and collect and display verified customer feedback.

5. Who we share it with

We use Stripe for payments, MobiMatter for eSIM provisioning and delivery, and Cloudflare for hosting, database storage and technical operations. These providers process the information needed for their services under the applicable service agreements and privacy terms.

Product reviews may be published with your chosen display name, rating, review text, destination and review date. Service ratings contribute to summary scores. Do not include private information in a public review.

We do not sell personal data, and we do not share it with advertisers or data brokers.

Because these providers operate internationally, your data may be processed outside Malaysia.

6. Cookies and tracking

We use Google Analytics on public pages of our production site to understand visits, destination searches, plan selections and checkout activity. Google Analytics uses cookies and processes browser and device information. Our search events contain result counts and matched destinations, not the text you enter. We do not load the analytics tag on order lookup, private order, eSIM management or review pages.

When analytics is available, we associate its browser and session identifiers with your checkout and send Google a confirmed purchase event containing an opaque transaction identifier, purchased plan, quantity, currency and amount. We do not send your email address, order access links, eSIM credentials or payment card details in these events. Pending purchase analytics payloads are removed after delivery or expiry within approximately three days; the identifiers associated with checkout remain subject to our payment provider's retention policies. Google processes analytics information under its own privacy terms.

If you select a currency, we save a preference cookie for up to one year. We may use the country supplied by our hosting provider to choose an initial currency. Recent destination selections are saved in your browser so you can revisit them; they remain until replaced or you clear the site’s browser storage. You can clear cookies and local storage through your browser settings.

When you pay, Stripe sets cookies needed to process the payment and to detect fraud. That happens on Stripe's own checkout page under Stripe's privacy terms.

7. How long it is kept

Our order, fulfilment and review records remain stored after an eSIM expires. We have not yet set fixed retention periods or an automatic deletion schedule for these records. You can contact us to request deletion; we will assess what can be removed and what needs to be retained for outstanding service, disputes or applicable legal obligations.

Removing a review from public display does not automatically erase its stored record. Stripe, MobiMatter and Cloudflare also retain information under their own applicable retention policies.

8. Your rights

Under the Malaysian Personal Data Protection Act 2010, and under other laws that may apply to you, you may request access to your personal data, ask for it to be corrected, withdraw consent, or limit how it is processed.

Write to support@averoam.com with your payment reference to make a request, including a request to remove a review or delete data. We may need to verify your identity. We will explain any limits that apply and coordinate with our providers where needed.

9. Security

Full card details are handled by Stripe. Our systems process payment references and transaction information. Access links to your eSIM are cryptographically signed and expire, and the Manage my eSIM form requires both an order reference and the matching email address.

Anyone holding a valid eSIM access link may be able to view its details. Keep these links private. We limit the data stored in our order database, but no system is perfectly secure.

10. Changes

We may update this policy. The date below shows when it last changed. Material changes will be reflected here before they take effect.