Privacy Policy
Last updated: June 2026
1. Who We Are
Wanderly ("we", "us", "our") operates the global eSIM marketplace at getwanderly.com. For the purposes of applicable data protection law, Wanderly is the data controller of your personal information. Contact: privacy@getwanderly.com.
2. What Information We Collect
We collect the following categories of personal data:
- Account information: name, email address, password (hashed)
- Purchase information: email address, order details, plan type, country selected
- Payment information: payment is processed by our merchant of record, Zotlo (Z3P LLP, London, UK). We do not store full card numbers. We may receive a transaction reference and billing country from Zotlo.
- Device and technical data: IP address, device type, operating system, browser type, eSIM EID (if provided for compatibility checks)
- Usage data: pages visited, search queries on our site, referral source, session duration
- Communications: emails or messages you send to our support team
- Cookies and tracking technologies: see Section 8 below
3. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)): to deliver your eSIM, manage your account, and provide support
- Legal obligation (Art. 6(1)(c)): to comply with tax, fraud prevention, and financial regulations
- Legitimate interests (Art. 6(1)(f)): to improve our services, prevent fraud, send transactional communications, and analyse usage patterns — where these interests are not overridden by your rights
- Consent (Art. 6(1)(a)): for marketing emails (where required by law) and non-essential cookies. You may withdraw consent at any time.
4. How We Use Your Information
We use your personal data to:
- Process and deliver eSIM purchases
- Create and manage your account
- Send order confirmations, QR codes, and support responses
- Send marketing emails (only with your consent, and you may unsubscribe at any time)
- Detect and prevent fraud and abuse
- Improve our website, products, and customer experience
- Comply with applicable legal obligations
- Respond to legal requests from competent authorities
5. Information Sharing and Third-Party Processors
We do not sell your personal data. We share data only with trusted third-party processors who are contractually bound to protect it:
- Zotlo (Z3P LLP) — payment processing and merchant of record. Their privacy policy governs payment data.
- Supabase — database and authentication infrastructure (data hosted on servers within the EU or US; see Section 6)
- eSIM network providers — we share minimal data (email, plan details) with our upstream eSIM suppliers to provision your plan
- Email service providers — to send transactional and marketing emails
- Analytics providers — for anonymised website analytics (see Section 8)
We may also disclose data to law enforcement or regulators where required by law.
6. International Data Transfers
Some of our third-party processors (including Supabase) may process your data outside the European Economic Area (EEA) or United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on adequacy decisions where applicable.
7. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes outlined in this policy:
- Account data: retained for the duration of your account, plus 2 years after closure
- Purchase and transaction records: 7 years (legal and tax compliance)
- Support communications: 3 years
- Marketing preferences and consent records: 5 years from last interaction
- Cookies and analytics data: see Section 8
- Sign-in security logs (IP address, approximate location, device/browser): 90 days, kept to protect your account from unauthorised access (GDPR Art. 6(1)(f) legitimate interest; CCPA security exception)
You may request earlier deletion subject to our legal retention obligations.
8. Cookies and Tracking Technologies
We use cookies and similar technologies on our website. These include:
- Strictly necessary cookies: required for the site to function (e.g. authentication tokens, session management). These cannot be disabled.
- Analytics cookies: help us understand how visitors use our site (e.g. pages visited, traffic sources). These are only placed with your consent where required by law.
- Preference cookies: remember your settings (e.g. theme, recently viewed destinations).
You can manage cookie preferences through your browser settings or our cookie consent tool. Note that disabling certain cookies may affect site functionality.
9. Your Rights
If you are located in the EEA, UK, or another jurisdiction with similar laws, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you
- Right to rectification: request correction of inaccurate or incomplete data
- Right to erasure: request deletion of your data ("right to be forgotten"), subject to legal retention obligations
- Right to restriction: request that we limit how we process your data in certain circumstances
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent: withdraw marketing or cookie consent at any time without affecting prior processing
- Right to lodge a complaint: if you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. In the EU, contact your national data protection authority.
To exercise any of these rights, email privacy@getwanderly.com. We will respond within 30 days.
10. Data Security
We implement appropriate technical and organisational security measures to protect your personal data, including encryption in transit (TLS/HTTPS), hashed passwords, access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
11. Children's Privacy
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@getwanderly.com and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email (if you have an account) or by posting a notice on our website. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of our services after changes constitutes acceptance of the updated policy.
13. Contact Us
For any privacy-related questions or to exercise your rights:
Email: privacy@getwanderly.com
Postal:
Wanderly Technologies LLC
4464 Lone Tree Way #3093
Antioch, CA 94531
United States
Entity No. 202253719897 (California LLC)