Privacy Policy
Last updated: 16 August 2026
This policy explains what personal data AloAlo collects when you use the AloAlo eSIM mobile app and this website, why we collect it, who we share it with, and the control you have over it.
The service is operated by Amygdal, L.L.C. ("AloAlo", "we", "us"), which is the data controller for the purposes of the GDPR.
1. Data we collect
| Category | What it includes | Why we need it |
|---|---|---|
| Account | First and last name, username, email address, password (stored only as a salted hash) | To create and secure your account and to sign you in |
| Sign-in provider | The identifier your provider gives us when you use Sign in with Google, Apple or LinkedIn, plus the name and email address on that account | To let you sign in without a separate password |
| Profile | Phone number, address, city, postal code, country, preferred language and currency, newsletter preference | To issue invoices and show prices and content that match where you are |
| Purchases | Order records, amounts, currency, invoices and a payment reference from our payment provider | To fulfil your order, provide receipts, handle refunds and meet accounting and tax obligations |
| eSIM | The data plans you buy and the technical identifiers of the eSIM issued to you, such as its ICCID and activation details | To provision the eSIM to your device and support you if it fails |
| Technical | Device and app version, IP address, and log data generated when you use the service | To keep the service secure, diagnose faults and prevent abuse |
Card details
We never receive or store your card number. Payments are processed by Stripe, and your card details are entered directly into Stripe's systems. We only receive a reference to the payment and non-identifying details such as the card brand and last four digits.
2. Legal bases
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to create your account, take payment and deliver the eSIM you bought.
- Legal obligation — to retain transaction and tax records.
- Legitimate interests — to secure the service, prevent fraud and abuse, and improve how the app works.
- Consent — for marketing email, where you have opted in. You can withdraw it at any time.
3. Who we share data with
We do not sell your personal data. We share it only with the providers needed to run the service:
- Stripe — payment processing, fraud prevention and invoicing.
- Airalo — provisioning of eSIM profiles and the connectivity behind them.
- SendGrid — transactional email such as address confirmation and password resets.
- Railway — hosting of our application and database.
- Google, Apple and LinkedIn — only if you choose to sign in with one of them.
We may also disclose data where the law requires it, or to establish or defend legal claims.
4. International transfers
We are based in the United States and our providers may process data in the United States and elsewhere. Where data is transferred out of the European Economic Area or the United Kingdom, it is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
5. How long we keep data
We keep your account data for as long as your account exists. When you delete your account, we immediately remove your personal details as described below.
We retain records of completed transactions — the amount, date, currency and invoice — with your personal details stripped out, because accounting and tax law requires us to keep them, typically for up to seven years. These records can no longer be linked back to you by name or email.
6. Deleting your account
You can delete your account at any time from inside the app, without contacting us: Profile → Privacy & Data → Delete my account.
When you confirm, we immediately and permanently:
- erase your name, email address, username and password;
- erase your phone number, address, city, postal code and country;
- disconnect any Google, Apple or LinkedIn sign-in linked to the account;
- remove the link between you and your payment provider record; and
- revoke every active session, signing you out on all devices.
This cannot be undone, and you will no longer be able to sign in or access eSIMs bought through the account. If you prefer, you can instead email info@amygdal.com and we will action it for you.
7. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, receive it in a portable format, object to or restrict how we use it, and withdraw consent. If you are in California, you have the right to know what we collect and to ask us to delete it, and we do not sell personal information.
To exercise any of these rights, email info@amygdal.com. You also have the right to complain to your local data protection authority.
8. Security
Data is encrypted in transit, passwords are stored only as salted hashes, and access to production systems is restricted. No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority if a breach affects you.
9. Children
AloAlo is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes
If we change this policy we will update the date at the top of this page, and we will tell you directly if the change is significant.
11. Contact
Amygdal, L.L.C. — info@amygdal.com. See our contact page for more ways to reach us.
Questions about this page? Contact us at info@amygdal.com .