隐私政策
最后更新:2026年2月
简介
欢迎来到 ViaConecta。我们致力于保护您的个人数据并尊重您的隐私。本隐私政策解释了当您访问我们的网站 (viaconecta.co)、使用我们的移动应用程序或购买我们的eSIM服务时,我们如何收集、使用、存储和共享您的个人信息。
通过使用我们的服务,您同意按照本政策收集和使用信息。
我们是谁(数据控制者)
负责您个人信息的数据控制者是:
我们收集的信息
我们收集不同类型的信息以提供和改进我们的服务:
A. 您提供给我们的信息
- 账户信息: 当您使用电子邮件或Google (Firebase)注册时,我们收集您的姓名、电子邮件地址和个人资料图片。
- 账单信息: 我们不将您的信用卡详细信息存储在我们的服务器上。支付交易由Stripe和PayPal安全处理。我们只保留交易ID和账单历史。
- 通信数据: 您通过电子邮件或实时聊天(Tawk.to)联系我们的支持团队时提供的信息。
B. 自动收集的信息
- 设备与技术数据: eSIM安装所需的IP地址、浏览器类型、操作系统和设备标识符。
- 使用数据: 关于您如何使用我们的网站和应用程序的详细信息,包括流量数据和日志(通过Google Analytics 4分析)。
C. eSIM 数据
为了激活您的服务,我们要处理与eSIM配置文件(ICCID)及其使用状态(数据消耗、有效期)相关的技术数据。
D. 安全监控
For account security and fraud prevention, we collect:
- IP Addresses: Your real IP address (not server proxy IP) for login monitoring and error reporting
- Device Information: Device model (e.g., iPhone, iPad) and operating system version
- Login Times: Timestamp and geographic location (country) derived from IP address
- Session Data: Active device sessions for security alerts
这些数据基于防止欺诈和改善服务的合法利益而收集。
E. 航班搜索相关数据
在此我们收集和发送您使用本网站所产生的基础的查询相关请求详情数据(例如,目的地,起始地与出发日),仅供给对应的第三方 API。为了更好的保障交易数据资金安全保护及政策独立,我们不会因此获取您的护照信息等隐私。
F. Virtual Telephony & Inbound 2FA SMS Data
When you use ViaConecta Virtual Numbers or OTP verification lines, inbound SMS messages are routed through encrypted telecommunications infrastructure and processed via automated algorithms solely to extract your verification code and display it on your console. Inbound message contents for single OTP activations are automatically purged from active database storage within 24 hours. We strictly never sell, share, or monetize SMS message contents.
G. ViaConecta Digital Wallet Ledger
For account holders utilizing the ViaConecta Digital Wallet, transaction records (deposits, purchases, refunds, and reference IDs) are stored in an encrypted ledger to ensure accounting accuracy and fulfill European Union anti-fraud and tax compliance standards.
我们如何使用您的数据
- 服务交付: 生成并发送您的eSIM二维码并确保互联网连接。
- 支付: 处理交易并通过Stripe和PayPal防止欺诈。
- 支持: 响应您通过我们的聊天或电子邮件系统的咨询。
- 通信: 向您发送交易电子邮件(收据、二维码),如果您选择了加入,还会发送有关新目的地或优惠的新闻通讯。
- 安全:登录监控、欺诈检测和预防。
- 法律合规: 遵守西班牙和全球的税法及电信法规。
商标和品牌声明
ℹ️ 仅供参考:本文提及的商标品牌及产品名称均属于原持有人拥有。
未被关联品牌官方支持
基于商业公平原则引用,不代表官方附属。
所有商标等解释权归属相关主体。
支付方式与商标
我们通过 Stripe 和 PayPal 安全地接受使用主要信用卡、借记卡和数字钱包的付款。
- Visa: Visa® is a registered trademark of Visa International Service Association.
- Mastercard: Mastercard® is a registered trademark of Mastercard International Incorporated.
- American Express: American Express® is a registered trademark of American Express Company.
- PayPal: PayPal® is a registered trademark of PayPal, Inc.
- Apple Pay: Apple Pay is a trademark of Apple Inc., registered in the U.S. and other countries.
- Google Pay: Google Pay is a trademark of Google LLC.
共享您的数据(第三方)
我们不会出售您的个人数据。为了提供即时 eSIM 连接、安全支付和可靠的全球基础设施,ViaConecta 依照 GDPR 第 28 条的规定指定值得信赖的第三方数据处理者:
| Subprocessor / Partner Category | Role & Purpose | Processing Location | Transfer Guarantee |
|---|---|---|---|
| Wholesale Mobile Connectivity & eSIM Provisioning Partners | eSIM profile generation (LPA/ICCID), data volume provisioning & local carrier network routing | EU / International | EU Standard Contractual Clauses (SCCs) |
| Cloudflare, Inc. | Global Edge CDN, DNS security, Web Application Firewall (WAF), Cloudflare Workers AI processing | Global / USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Server & Cloud Infrastructure (Hetzner Online GmbH) | Production cloud application server hosting, database backups, file storage & system logs | Germany (EU) | EU Native GDPR Compliance |
| Supabase, Inc. | Managed cloud database infrastructure (PostgreSQL), encrypted user data storage | EU / USA | EU Standard Contractual Clauses (SCCs) |
| Google Ireland Ltd / Firebase | User authentication (Google Sign-In), cloud backend hosting & Google Analytics 4 | EU / USA | EU-US Data Privacy Framework (DPF) & SCCs |
| Apple Inc. | Apple Sign-In authentication & WebAuthn Passkeys validation | USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Stripe Technology Europe, Ltd | PCI-DSS compliant credit/debit card, Apple Pay & Google Pay checkout payment processing | Ireland (EU) / USA | EU-US Data Privacy Framework (DPF) & SCCs |
| PayPal (Europe) S.à r.l. | PayPal digital wallet payment processing & fraud prevention | Luxembourg (EU) | EU Native GDPR Compliance |
| Transactional Email & SMTP Infrastructure | Order confirmation receipt delivery, eSIM QR code transmission, password resets & security alerts | EU / USA | EU Standard Contractual Clauses (SCCs) |
| Tawk.to Ltd | Live customer support chat widget & support ticket resolution | UK / EU | UK/EU GDPR Adequacy Decision & SCCs |
| Microsoft Corporation (Clarity) | Aggregated user interaction heatmaps & performance optimization | USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Ticketmaster / Event Partners | Global event ticket search & discovery integration | USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Public Transport & Transit APIs | European train & transit route schedule aggregation (DB, SBB, ResRobot) | EU | EU Native GDPR Compliance |
| Travel & Airline Affiliate Networks | Flight search result routing and referral booking redirection | EU / USA | EU Standard Contractual Clauses (SCCs) |
您的权利 (GDPR)
要行使这些权利,请通过 [email protected] 联系我们。
You also have the right to lodge a formal complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos — AEPD, www.aepd.es) or your national supervisory authority.
AI旅行助手
✅ 透明的 AI 数据处理:AI 查询通过 Cloudflare Workers AI 动态处理,不会用于训练公共模型。
- Privacy-Focused Processing: AI queries are processed dynamically to assist with destination and eSIM selection. ViaConecta does not retain permanent chat logs in its core application database.
- Cloudflare AI Infrastructure: Processing is performed securely via Cloudflare Workers AI (utilizing open-source LLMs such as Llama). Data is handled in accordance with Cloudflare’s enterprise security policies and is not used to train public AI models.
- Transient Session Context: The assistant maintains context only during your active session to provide relevant answers. Closing the session clears local conversational context.
- No Data Monetization: We do not sell, rent, or share your AI interaction data with third-party advertisers or data brokers for marketing purposes.
AI 助手纯粹用于协助旅行规划和 eSIM 信息提供。它无权访问您的支付卡详情或完整密码。
Cookies
我们使用Cookie 来增强您的体验(例如,保持登录状态、记住您的语言)。有关详细信息,请参阅我们的Cookie政策。
儿童隐私
我们的服务不针对16岁以下的任何人(“儿童”)。我们不会故意收集16岁以下任何人的个人身份信息。如果您是父母或监护人,并且您知道您的孩子向我们提供了个人数据,请联系我们。
数据保留
我们仅在本政策所述目的所需的时间范围内保留您的数据。
- Active Sessions: 30 days from last login
- Error Logs: 90 days for debugging purposes
- Account Data: Until you request deletion or close your account
- AI Chat History: Not stored (deleted immediately after session ends)
- Payment Records: As required by law for tax compliance (typically 7 years)