CHROMIIBack to plans ↗
LEGAL 02 · PRIVACY

Privacy Policy / 隱私政策

A transparent map of the information needed to sell, provision and support an eSIM. Final controller details and local rights notices remain to be completed.

DRAFT · COUNSEL REVIEW REQUIREDThis page is a product-design and compliance-planning draft, not final legal advice or a launched customer contract.
LEGAL HUBTerms of UsePrivacy PolicyRefund PolicyService Disclosures
01

Who controls the data

The final legal entity acting as controller, its address, privacy contact and any required local representative will be named before launch. Different telecommunications partners may act as independent controllers for network and regulatory records.

02

Information collected

Planned categories include contact and account details, order and payment status, device and eSIM identifiers, activation status, network usage metadata, support communications, security events, consent records and basic website analytics. Chromii should not receive full card numbers when Stripe-hosted Checkout is used.

03

Why information is used

Information may be used to process orders, provision connectivity, show usage, prevent fraud, provide support, comply with telecom and tax duties, improve the service and send requested operational messages. Marketing should require the appropriate consent or other lawful basis.

04

Service providers and network partners

Data may be shared with payment processors such as Stripe, connectivity and roaming providers, cloud and support vendors, fraud-prevention services, tax providers, professional advisers and authorities when legally required. The production policy must name or categorize recipients accurately.

05

International transfers

Cross-border service can require data to be processed in multiple countries. Before launch, the company must document transfer locations, applicable safeguards and any local data-residency requirements.

06

Retention

Account, transaction, network and compliance records should be retained only for documented business and legal periods, then deleted or de-identified. Exact schedules remain to be established with providers and counsel.

07

Choices and rights

Depending on location, customers may have rights to access, correct, delete, restrict or port information, object to some uses, withdraw consent, or complain to a regulator. A verified request channel and market-specific response process are required before launch.

08

Security, children and changes

Reasonable technical and organizational safeguards are planned, but no system is risk-free. The service is not designed for children unless a market-specific flow says otherwise. Material policy changes should be dated and communicated as required.

Last draft update: August 3, 2026Localized market versions and the contracting entity remain subject to counsel review.