Privacy Policy
Last updated 27 July 2026
This policy explains what personal data travelwithmiru collects, why we collect it, who we share it with, and what you can do about it. It applies to our website and to the eSIM plans we sell.
1. Who is responsible for your data
The data controller is Matteo Jansens, trading as TravelWithMiru, registered in Belgium under enterprise number 1037.772.217, with its registered office at Vremdesteenweg 18, 2160 Wommelgem, Belgium.
For anything in this policy, contact us at support@travelwithmiru.com. We aim to reply within five working days, and we are required to answer formal requests within one month.
2. What we collect
We collect only what we need to sell and support an eSIM.
- Account data, your email address and a securely hashed password. If you sign in with Google, Apple or Facebook, we receive your email address and basic profile information from that provider instead. We never see your password for those services.
- Order data, the plans you buy, the destinations they cover, activation and expiry dates, and your purchase history.
- Payment data, handled entirely by our payment provider, Stripe. We receive a confirmation and the last four digits of the card. We never store full card numbers.
- Technical data, IP address, browser and device type, and pages visited. This is generated automatically when you use the site.
- Support messages, whatever you send us when you ask for help, and our replies.
We do not collect special category data, and we do not ask for your passport, ID or date of birth.
3. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and running your account | Performance of a contract |
| Delivering and activating the eSIM you bought | Performance of a contract |
| Taking payment and issuing receipts | Performance of a contract |
| Keeping invoices and tax records | Legal obligation (Belgian accounting law) |
| Answering support requests | Performance of a contract / legitimate interests |
| Keeping the site secure and preventing fraud | Legitimate interests |
| Marketing emails | Consent, and you can withdraw it at any time |
4. Who we share it with
We do not sell your data. We share it only with the suppliers we need to run the service, each acting as a processor under contract:
- Supabase, accounts, authentication and the database behind them.
- Hostinger, website hosting.
- Stripe, payment processing.
- Resend, transactional email such as confirmations and QR codes.
- Mobile network operators in your destination country, who need the technical identifiers of your eSIM to connect you.
We may also disclose data where the law requires it, or to establish or defend a legal claim.
5. Sending data outside the EEA
Some of our suppliers process data outside the European Economic Area. Where that happens, the transfer is covered by the European Commission’s Standard Contractual Clauses, or by an adequacy decision for that country. You can ask us for a copy of the safeguards that apply.
Because we sell to travellers worldwide, connecting you abroad necessarily involves a local operator in your destination country processing the technical data needed to place you on their network.
6. How long we keep it
- Account data, while your account is open, and for 12 months after you close it.
- Invoices and tax records, 7 years, as Belgian law requires.
- Support messages, 24 months.
- Technical logs, 12 months.
When a period ends we delete the data or anonymise it so it can no longer identify you.
7. Your rights
Under the GDPR you can ask us to:
- give you a copy of the data we hold about you
- correct anything inaccurate
- delete your data, where no legal duty requires us to keep it
- restrict how we use it, or object to us using it
- send your data to another provider in a portable format
- withdraw consent at any time, where consent is the basis
Email support@travelwithmiru.com and we will respond within one month. Exercising these rights is free.
8. Complaints
If you think we have handled your data badly, please tell us first. You also have the right to complain to the Belgian data protection authority:
Gegevensbeschermingsautoriteit / Autorité de protection des données
Drukpersstraat 35 / Rue de la Presse 35, 1000 Brussels
contact@apd-gba.be · dataprotectionauthority.be
If you live outside Belgium, you may instead complain to the supervisory authority where you live or work.
9. Cookies and similar technology
We use the minimum necessary. A cookie or local storage entry keeps you signed in, and another remembers whether you chose light or dark mode. Neither is used for advertising or tracking across other websites.
If we later add analytics or marketing cookies, we will ask for your consent first and you will be able to refuse without losing access to the site.
10. Security
Traffic to this site is encrypted with HTTPS. Passwords are stored only as salted hashes and cannot be read by us or anyone else. Access to customer data is limited to people who need it to do their job.
No system is perfectly secure. If a breach ever affects your rights, we will notify the authority within 72 hours and tell you directly where the law requires it.
11. Children
Our service is not aimed at children under 16. We do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
12. Changes to this policy
If we change this policy we will update the date at the top. If the change materially affects your rights, we will tell account holders by email before it takes effect.