Megaroam

Privacy Policy

Megaroam — operated by Brisk Consulting Services LTD

Last updated: 2 September 2026

1. Who we are

Brisk Consulting Services LTD ("we", "us") is the data controller for personal data processed through the Megaroam app. Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Contact: [email protected].

2. Data we collect

That record is sent to our advertising-measurement provider, so that we can tell which of our campaigns brought people to the app. It may also include your device's advertising identifier — Apple's on iPhone and iPad, Google's on Android. On iPhone and iPad that happens only if you allow tracking in the system dialogue the app shows you, and if you decline, the same events are sent without it. Android has no such dialogue, so there the switch described below is the only thing that decides it. On your first launch we also read Apple's install-attribution token — a short-lived code that says which advert an install came from and nothing about you — and exchange it with Apple for that campaign's identifiers. It is governed by the same switch as the usage measurement described below, under Notifications → Privacy, and on iPhone and iPad you can refuse the tracking part separately in that system dialogue or later under Settings → Privacy & Security → Tracking.

We do not collect GPS or precise device location. The app requests no location permission and uses no location API — the approximate location above is derived from your IP address alone, and is no more precise than a city.

The fraud-prevention data is recorded only at the moment you place an order, never continuously in the background. We use it to prevent fraud and abuse (including abuse of the referral programme), to investigate a problem with a specific order, and to protect account security — the legitimate interests described in section 4. It is stored against that order and kept for as long as section 7 describes. Separately, we measure how the app is used, so we can see where it works and where it does not. Those usage events are linked to your account — or, before you sign in, to the anonymous device identifier above — so that one person's journey is not counted as two, and your email address is stored on your profile with our analytics provider so that our support team can find your session when you ask us for help. This is processed in the European Union, we use it only to understand and improve the product, and you can switch it off at any time in the app under Notifications → Privacy; everything else keeps working exactly as before. The copies we keep on our own servers are deleted automatically after 180 days, and our analytics provider keeps them no longer than we need them for this purpose.

We show no adverts inside the app and build no advertising profile of you ourselves; the measurement above tells us which campaign worked, not who you are.

3. How we use your data

We use your data to: create and secure your account; provision, deliver and install your eSIM; process payments and wallet balances; show accurate usage; provide customer support; prevent fraud and abuse; send service messages; send promotional and low-data/expiry notifications only if you have opted in; measure which of our advertising campaigns bring people to the app, if you have allowed it; and meet legal obligations.

4. Legal bases (UK GDPR)

We rely on: performance of our contract with you (providing the eSIM service); your consent (marketing and push/email notifications, and advertising measurement, all of which you can withdraw at any time); our legitimate interests (security, fraud prevention, improving the service); and compliance with legal obligations.

5. Service providers we share data with

We share the minimum data needed with trusted processors, each acting on our behalf under a written contract and only on our instructions: our wholesale eSIM provider (eSIM provisioning and connectivity), our payment provider (payments), our transactional email provider (login codes, receipts and eSIM delivery), our push-notification provider (notifications), our product-analytics provider (understanding how the app is used, hosted in the European Union), Apple (which tells us, from the install-attribution token described in section 2, which advert campaign an install came from) and our cloud infrastructure provider (secure hosting and storage). Where data is transferred outside the UK/EEA, appropriate safeguards are in place. We do not sell your personal data. With one exception, named next, we do not share it with anyone for their own purposes: our advertising-measurement provider — the company whose advertising platform we buy campaigns on — also uses the events described in section 2 for its own advertising optimisation, which is what makes campaign measurement work at all. It is the one recipient in this list that is not acting solely on our instructions, and it only receives anything if you have allowed measurement. If you want to know the identity of a particular processor, ask us at [email protected] and we will tell you.

6. Notifications and marketing

Promotional, product-update and usage (low-data/expiry) notifications are opt-in. You can turn them on or off at any time in the app's notification settings, or by contacting us.

7. Data retention and account deletion

We keep your data for as long as needed to provide the service and to meet legal, accounting and fraud-prevention obligations. You can delete your account from within the app; we then remove or anonymise your personal data, except where we must retain certain records by law.

8. Your rights

Under UK GDPR you have the right to access, correct, delete, restrict or object to the processing of your data, and to data portability. To exercise these rights, email [email protected]. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

9. Security

Data is encrypted in transit. Sensitive credentials (payment, provider keys) are held server-side and never exposed to the app. Card details are processed by our certified payment provider and are not stored by us.

10. Children

Megaroam is not directed at children and is intended for users who can form a binding contract. We do not knowingly collect data from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date above shows the latest version, and significant changes will be highlighted in the app.

12. Contact

For privacy questions or to exercise your rights, contact Brisk Consulting Services LTD at [email protected], 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.