Privacy Policy
Last updated: 16 August 2026
This policy describes what personal data VamosData collects, the purposes for which we process it and the rights you have over it. For any query you can write to admin@vamosdata.com.
1. Data controller
The controller of your personal data is:
- Owner: Mariano Alberto Lopez Lomas (trading as VamosData)
- Email: admin@vamosdata.com
Given the volume and nature of our processing activities, appointing a Data Protection Officer is not mandatory. You can raise any question about your data at the address above.
2. Data we collect
We collect the following data depending on how you interact with our platform:
- Account and contact data: email address, language and preferred currency; name when you provide it (for example, when you sign in with Google).
- Order data: plan purchased, destination country, order date and time, amount paid, currency, payment-related identifiers.
- Payment data: processed directly by Stripe; we receive a transaction identifier and, where applicable, the last four digits of the card, but never the full card number or CVV.
- Email delivery logs: delivery status of transactional email (sent, delivered, bounced). Addresses are stored as SHA-256 hashes so the address is never kept in the clear.
- Support assistant conversations: we keep an anonymised transcript of conversations held while signed out, identified by a random per-conversation code, with no IP address or user identifier, and with email addresses and phone numbers automatically redacted. Conversations from signed-in users are not stored.
- Minimal technical site logs: records needed to maintain security and diagnose errors.
3. Purposes of processing
We process your data in order to:
- Process orders, issue eSIMs and deliver them by email.
- Manage activation with the local operator.
- Handle your queries and provide support.
- Comply with legal obligations (tax, accounting and consumer protection).
- Improve the platform through aggregate analysis and internal metrics.
4. Legal bases
The bases that legitimise the processing are:
- Performance of the contract (purchase and delivery of the eSIM).
- Compliance with legal obligations (tax, accounting).
- Legitimate interest in service security and fraud prevention.
- Consent, where we expressly ask for it (for example, analytics cookies or promotional communications).
5. Named recipients
We share data only with the providers strictly necessary to deliver the service. We name those you interact with directly or whose processing you expressly consent to:
- Stripe — payment processor. Payment takes place on its own platform.
- Google — only when you choose to sign in with your Google account.
- Resend — transactional email provider used to send your QR code and order notifications.
- PostHog — site usage analytics, with servers in the European Union. Only involved if you accept analytics cookies.
6. Other categories of recipient
The remaining providers form part of the technical infrastructure needed to run the service and have no direct relationship with you. For security reasons we do not publish their specific names, and we disclose them by category:
- Hosting and content delivery provider, with infrastructure in the European Union: hosts and serves the website.
- Database and authentication provider, with infrastructure in the European Union: stores your account and order information and handles sign-in.
- Conversational artificial intelligence provider, located outside the European Economic Area: powers the site’s support assistant.
- Security and abuse-prevention providers: cap the number of requests per user to protect us against attacks and automated abuse.
- Operators and connectivity providers that issue the eSIM profile and deliver the data service in each destination country.
Because we do not publish the name of the support-assistant provider, we describe that processing precisely: it receives the messages you type and, if you are signed in, a minimal summary of your order (status, data used, expiry date, plan and destination country). It never receives your identifying details, the activation code, the QR code, the provisioning server address, the full eSIM identifier or the price. Under the commercial terms of its programming interface, the content sent is not used to train models.
If you wish to know the specific identity of any of these recipients, write to admin@vamosdata.com and we will provide it.
7. International transfers
Most processing takes place within the European Union. Specifically, website hosting, the account and order database, and usage analytics all run on infrastructure located in the European Union.
The following categories of recipient do involve processing outside the European Economic Area:
- Payment processing.
- The artificial-intelligence support assistant.
- The operators and connectivity providers delivering the data service in the destination country, where that country lies outside the European Economic Area.
These transfers rely on the safeguards set out in Chapter V of the General Data Protection Regulation: an adequacy decision of the European Commission where one exists for the country or the applicable certification framework, and, failing that, standard contractual clauses approved by the European Commission together with any supplementary measures required.
You can request a copy of the safeguards applied by writing to admin@vamosdata.com.
8. Retention periods
- Account data: for as long as the account remains active.
- Order data: for the period required to comply with tax, commercial and consumer protection law (in many jurisdictions, up to 6 years).
- Email delivery logs: 12 months, unless longer retention is required for security reasons.
- Anonymised support assistant transcripts: 90 days, after which they are deleted automatically.
9. Your rights
You may exercise the following rights at any time:
- Access to your data.
- Rectification of inaccurate data.
- Erasure when the data is no longer necessary.
- Restriction of or objection to processing.
- Portability.
- Withdrawal of consent, where applicable.
10. How to exercise your rights
To exercise these rights, write to admin@vamosdata.com. We will respond within one month of receiving your request, extendable by a further two months where the request is particularly complex, in which case we will tell you about the extension.
If you believe your rights have not been properly addressed, you may lodge a complaint with the competent supervisory authority. In Spain this is the Agencia Española de Protección de Datos (C/ Jorge Juan 6, 28001 Madrid — www.aepd.es).
11. Automated decision-making and profiling
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, nor do we carry out profiling for that purpose.
The usage analytics we perform, when you consent to it, is aggregate and aimed at improving the website, not at making individual decisions about you.
12. Cookies
We use strictly necessary cookies, required for the site to work (session, language and currency), and analytics cookies that are only set if you expressly accept them. You can change your decision at any time from the "Cookie preferences" link in the footer.
Details of each cookie, its purpose and its lifetime are in our Cookie Policy, linked at the bottom of this page.
13. Contact
For any privacy query or to exercise your rights: admin@vamosdata.com.