Effective date: 4 August 2026 Version: 2026-08-04
This policy describes global processing practices and recognizes that users may have additional rights under the laws of their location, including EEA/UK and US state privacy laws.
1. Who controls your data
Didugo operates didugo.net and determines how customer data is used to provide travel eSIM services. Contact info@didugo.net for privacy requests. We may request reasonable verification before acting on a request.
2. Data we collect
| Category | Examples |
|---|---|
| Identity and contact | Name, email, international mobile number, account identifiers, language, country. |
| Account and authentication | Firebase user ID, verification status, login and security events. |
| Orders and eSIM | Destination, package, price, order reference, payment status, supplier order ID, ICCID, activation and QR-related data, usage and lifecycle status. |
| Payment | PayPal order, capture, refund, dispute, currency and amount. Didugo does not intentionally store full card details. |
| Technical | IP address, device, browser, operating system, timestamps, logs, cookies, security signals. |
| Engagement | Points, referrals, wishlist, travel map, promotions, notifications and support communications. |
3. Why we use data
We process data to create and secure accounts; provide quotes and packages; take payment; order, deliver, support, and manage eSIMs; send transactional communications; detect fraud and abuse; meet legal, tax, accounting, sanctions, and regulatory obligations; improve performance and customer experience; handle support, refunds, disputes, and complaints; and send marketing where permitted.
4. Legal bases
Depending on your location, processing may rely on contract performance, legal obligations, legitimate interests such as fraud prevention and service improvement, consent, or other lawful bases. You can withdraw consent where processing relies on consent, without affecting earlier lawful processing.
5. Service providers and sharing
We share only what is reasonably required with providers such as Firebase for authentication, Render and database infrastructure for hosting, PayPal for payments, Resend for email, eSIM Access and mobile operators for fulfillment and lifecycle management, security and analytics providers, professional advisers, authorities where legally required, and a successor in a legitimate corporate transaction. We do not sell customer personal data for money.
6. International transfers
Didugo and its providers may process data in countries different from yours. Where required, we use recognized safeguards such as adequacy decisions, contractual clauses, transfer assessments, or provider commitments. No transfer mechanism eliminates all risk, but we apply proportionate contractual, organizational, and technical protections.
7. Retention
We retain data only as long as needed for service, security, legal, tax, accounting, dispute, and fraud-prevention purposes. Account and order records may be kept for legally required periods. QR and activation data are protected and retained while needed to provide customer access, support, and auditability. We may anonymize data for longer-term statistics.
8. Security
We use access controls, encrypted transport, role-based access, restricted QR retrieval, secrets management, logging, backups, and monitoring. No internet service is completely secure. Keep credentials private and contact us immediately if you suspect unauthorized access.
9. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or information about disclosure. You may opt out of direct marketing at any time and may lodge a complaint with a competent privacy authority. Some data cannot be deleted immediately where retention is legally required or necessary for fraud, disputes, security, or contract records.
10. Children
Didugo is not directed to children who cannot legally consent in their country. A parent or guardian should manage purchases for minors. Contact us if you believe a child provided data without proper authorization.
11. Cookies and local storage
We use strictly necessary cookies or browser storage for authentication, security, shopping, preferences, and core functionality. We may use optional analytics or advertising technologies only where configured and permitted. Where consent is required, optional technologies should not activate until consent is obtained. Browser settings may block cookies, but core functions may stop working.
12. Marketing
Service messages about orders, security, eSIM delivery, usage, support, and policy updates are transactional. Promotional messages are sent only where permitted and can be stopped using unsubscribe controls or by contacting us.
13. Public travel maps
A shared travel-map link is public to anyone who receives it. We limit displayed information and do not intentionally publish email, phone, payment, ICCID, QR code, or exact travel dates. You should avoid sharing a link where public destination information creates personal risk.
14. Changes and contact
We may update this policy and publish a new effective date and version. Send privacy requests to info@didugo.net.
