Privacy Policy
Last Updated: February 2026
Introduction
Welcome to ViaConecta. We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you visit our website (viaconecta.co), use our mobile application, or purchase our eSIM services.
By using our services, you agree to the collection and use of information in accordance with this policy.
Who We Are (Data Controller)
The data controller responsible for your personal information is:
Information We Collect
We collect different types of information to provide and improve our service:
A. Information You Provide
- Account Information: Name, email, profile picture (via Google/Firebase).
- Billing Information: Transaction IDs (Card details are handled securely by Stripe).
- Communication: Chat logs (Tawk.to) and email correspondence.
B. Automated Collection
- Technical Data: IP address, device ID, browser type (for eSIM compatibility).
- Usage Data: Traffic logs and app interaction metrics.
C. eSIM Data
To activate your service, we process technical data related to the eSIM profile (ICCID) and its usage status (data consumed, validity period).
D. Security Monitoring
For account security and fraud prevention, we collect:
- IP Addresses: Your real IP address (not server proxy IP) for login monitoring and error reporting
- Device Information: Device model (e.g., iPhone, iPad) and operating system version
- Login Times: Timestamp and geographic location (country) derived from IP address
- Session Data: Active device sessions for security alerts
This data is collected based on our legitimate interest in protecting your account from unauthorized access. You receive email notifications for all login attempts showing the device and location.
E. Flight Search Data
When you use our Flight Search tool, your search queries (such as origin, destination, and dates) are transmitted to third-party affiliate APIs to fetch flight results. We do not collect or store any passenger details, passport information, or payment data related to flight bookings, as all transactions are securely handled on the third-party provider's website.
How We Use Your Data
- Service Delivery: Activation & Connectivity
- Payments: Secure Processing via Stripe
- Support: Customer Service Resolution
- Communication: Receipts & QR Codes
- Security: Login monitoring, fraud prevention, and unauthorized access detection
- Compliance: Legal & Tax Obligations
Trademark & Brand Names Disclaimer
Informational Use Only: Brand and product names such as Apple®, iPhone®, Samsung®, Google Pixel®, OnePlus®, Xiaomi®, Sony®, Motorola®, and Huawei® are the registered or unregistered trademarks of their respective owners.
ViaConecta is not affiliated with, endorsed by, or sponsored by any of the brands mentioned on this website. These names are used solely for informational and compatibility reference purposes — to help users identify whether their device supports eSIM technology.
The use of brand names, logos, and product names on this site constitutes nominative fair use under applicable trademark law (EU Directive 2015/2436, U.S. Lanham Act). We make no claim of ownership over these marks and do not imply any commercial relationship with the respective trademark owners. Additionally, airline and travel agency names, logos, and trademarks displayed in our Flight Search tool are the property of their respective owners. They are used strictly for identification purposes, to accurately display available flight routes and providers.
All trademarks, service marks, trade names, product names, logos, and trade dress mentioned are the property of their respective owners.
Payment Methods & Trademarks
We accept payments securely via Stripe and PayPal using major credit and debit cards and digital wallets.
- Visa: Visa® is a registered trademark of Visa International Service Association.
- Mastercard: Mastercard® is a registered trademark of Mastercard International Incorporated.
- American Express: American Express® is a registered trademark of American Express Company.
- PayPal: PayPal® is a registered trademark of PayPal, Inc.
- Apple Pay: Apple Pay is a trademark of Apple Inc., registered in the U.S. and other countries.
- Google Pay: Google Pay is a trademark of Google LLC.
Sharing Your Data & Subprocessors
We do not sell your personal data. To deliver instant eSIM connectivity, secure payments, and reliable global infrastructure, ViaConecta engages trusted third-party subprocessors in compliance with GDPR Article 28:
| Subprocessor / Partner Category | Role & Purpose | Processing Location | Transfer Guarantee |
|---|---|---|---|
| Wholesale Mobile Connectivity & eSIM Provisioning Partners | eSIM profile generation (LPA/ICCID), data volume provisioning & local carrier network routing | EU / International | EU Standard Contractual Clauses (SCCs) |
| Cloudflare, Inc. | Global Edge CDN, DNS security, Web Application Firewall (WAF), Cloudflare Workers AI processing | Global / USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Server & Cloud Infrastructure (Hetzner Online GmbH) | Production cloud application server hosting, database backups, file storage & system logs | Germany (EU) | EU Native GDPR Compliance |
| Supabase, Inc. | Managed cloud database infrastructure (PostgreSQL), encrypted user data storage | EU / USA | EU Standard Contractual Clauses (SCCs) |
| Google Ireland Ltd / Firebase | User authentication (Google Sign-In), cloud backend hosting & Google Analytics 4 | EU / USA | EU-US Data Privacy Framework (DPF) & SCCs |
| Apple Inc. | Apple Sign-In authentication & WebAuthn Passkeys validation | USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Stripe Technology Europe, Ltd | PCI-DSS compliant credit/debit card, Apple Pay & Google Pay checkout payment processing | Ireland (EU) / USA | EU-US Data Privacy Framework (DPF) & SCCs |
| PayPal (Europe) S.à r.l. | PayPal digital wallet payment processing & fraud prevention | Luxembourg (EU) | EU Native GDPR Compliance |
| Transactional Email & SMTP Infrastructure | Order confirmation receipt delivery, eSIM QR code transmission, password resets & security alerts | EU / USA | EU Standard Contractual Clauses (SCCs) |
| Tawk.to Ltd | Live customer support chat widget & support ticket resolution | UK / EU | UK/EU GDPR Adequacy Decision & SCCs |
| Microsoft Corporation (Clarity) | Aggregated user interaction heatmaps & performance optimization | USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Ticketmaster / Event Partners | Global event ticket search & discovery integration | USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Public Transport & Transit APIs | European train & transit route schedule aggregation (DB, SBB, ResRobot) | EU | EU Native GDPR Compliance |
| Travel & Airline Affiliate Networks | Flight search result routing and referral booking redirection | EU / USA | EU Standard Contractual Clauses (SCCs) |
Your Rights (GDPR)
Contact us: [email protected]
AI Travel Assistant
Transparent AI Data Handling:
- Privacy-Focused Processing: AI queries are processed dynamically to assist with destination and eSIM selection. ViaConecta does not retain permanent chat logs in its core application database.
- Cloudflare AI Infrastructure: Processing is performed securely via Cloudflare Workers AI (utilizing open-source LLMs such as Llama). Data is handled in accordance with Cloudflare’s enterprise security policies and is not used to train public AI models.
- Transient Session Context: The assistant maintains context only during your active session to provide relevant answers. Closing the session clears local conversational context.
- No Data Monetization: We do not sell, rent, or share your AI interaction data with third-party advertisers or data brokers for marketing purposes.
The AI assistant exists purely to assist with travel planning, destination advice, and eSIM connectivity. It has no access to your payment card details, full passwords, or financial credentials.
Cookies
We use cookies to enhance your experience. See our Cookie Policy.
Children's Privacy
Our Service does not address anyone under the age of 16 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 16. If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us.
Data Retention
We retain your data only as long as necessary:
- Active Sessions: 30 days from last login
- Error Logs: 90 days for debugging purposes
- Account Data: Until you request deletion or close your account
- AI Chat History: Not stored (deleted immediately after session ends)
- Payment Records: As required by law for tax compliance (typically 7 years)
Contact Us
Email: [email protected]