Legal

Privacy Policy

Version 2026-09-19 · Effective 19 September 2026

1. Who is responsible for your information

Merofly is a travel eSIM service operated by SPACE AI TECHNOLOGY UK LTD, company number 15446027, registered office 142-143 Parrock Street, Gravesend, Kent, DA12 1EY, United Kingdom. We are the controller for the personal information described here. Contact us at privacy@merofly.com, or support@merofly.com for help with an order. We will tell you here if we appoint a data protection officer or a representative.

2. Where your information comes from

We receive personal information from four sources, and it matters which one applies to you.

  • Directly from you — when you create an account, search destinations, buy an eSIM, contact support or use Travel Assist.
  • From a purchaser — someone who buys an eSIM for you gives us your email address and your device model so the eSIM can be checked for compatibility and issued to you.
  • From an approved Merofly professional partner — a partner who sells or arranges an eSIM for you passes us the same limited delivery details.
  • From our service providers — our eSIM supplier Airalo and participating mobile networks send installation, activation, usage and status information; Stripe sends payment outcome, fraud signals, refund and dispute information.
  • From your use of the service — device and browser information, approximate location derived from your network address, security and diagnostic events, and, where you have consented, analytics and advertising identifiers.

3. Categories of information we hold

We keep the information needed to sell, deliver and support a travel eSIM, and nothing collected for its own sake.

  • Account and contact — email address, name where given, password credentials held in hashed form by our authentication provider, account state and verification events.
  • Order and product — destination, package, allowance, validity, order reference, price, currency, order and fulfilment status.
  • Device and compatibility — the device model you select and your confirmation that the device supports eSIM and is not network-locked.
  • eSIM service — installation status, activation status, remaining allowance, expiry, top-up history and supplier reference identifiers.
  • Payment — Stripe payment, charge, refund and dispute references, the last four digits and card brand where Stripe provides them, and billing country. We never hold your full card number.
  • Support — messages, attachments and the outcome of your enquiry.
  • Travel Assist — the trip details you choose to enter, such as destination, arrival date and the assistance you ask for.
  • Rewards and attribution — your Merofly invitation code, the invitation code used on an order, attribution timestamps, Merofly Credit balance and reward state.
  • Security and fraud — request metadata, network address, consent records, rate-limit and abuse signals, and the outcome of automated checks.

4. Why we use it, and our lawful basis

Each purpose below has its own lawful basis under UK GDPR. Where we rely on legitimate interests, our assessment is summarised in section 5.

  • Sell and deliver your eSIM, check device compatibility, issue it and support installation — performance of a contract with you.
  • Deliver an eSIM to a traveller whose details a purchaser or partner gave us — legitimate interests in fulfilling the purchaser's order, and performance of our contract with the purchaser.
  • Operate your account, sign-in, email verification and password recovery — performance of a contract, and legitimate interests in account security.
  • Take payment, handle refunds, chargebacks and disputes — performance of a contract, and legal obligation for tax and accounting records.
  • Send transactional messages such as order confirmation, delivery, installation and expiry notices — performance of a contract. These are not marketing and you cannot be enrolled in marketing by buying.
  • Prevent fraud, payment abuse and misuse of the network, and keep the service secure — legitimate interests, and legal obligation where fraud reporting applies.
  • Operate Traveller Rewards attribution, credit and reversal — performance of the Traveller Rewards terms you take part in, and legitimate interests in preventing reward abuse.
  • Record attribution for an approved professional partner — legitimate interests in administering our partner arrangements correctly.
  • Provide Travel Assist information and arrival help you request — performance of a contract, or consent where you give us optional trip details.
  • Understand how the website is used, and advertising measurement — consent, given through the cookie banner, withdrawable at any time.
  • Send optional marketing about Merofly — consent, withdrawable in every message.
  • Meet legal, tax, accounting and regulatory duties, and handle legal claims — legal obligation, and legitimate interests in defending claims.

5. Our legitimate interests

Where we rely on legitimate interests we have balanced our interest against your rights. Fulfilling a purchase made for another traveller uses the minimum information needed to deliver a product that person is expecting, with no marketing use. Fraud prevention and network security protect travellers, suppliers and Merofly from loss. Attribution and reward integrity keep rewards honest for everyone. In each case we limit the data, restrict access, keep it only as long as needed, and you can object at any time using the contact details in section 11.

6. Who receives your information

We share only what each recipient needs, and we do not sell personal information. Merofly names its service providers here for transparency, while the customer-facing Merofly product identity, pricing and package naming remain ours; commercial arrangements with our suppliers stay confidential.

  • Airalo and participating mobile-network suppliers — to create, issue, activate, top up and support the eSIM. The traveller's email address is not required for, and is not passed to, eSIM creation; suppliers receive the package and eSIM identifiers needed to provision service.
  • Stripe — to take payment and handle refunds, chargebacks, disputes and payment fraud checks. Stripe acts as its own controller for parts of this.
  • Our database, authentication and hosting providers — to run the service securely.
  • Our transactional email provider — to send order, delivery and account messages.
  • Analytics and advertising providers — only where you have consented to the relevant cookie category.
  • Professional advisers, auditors, insurers, and authorities or courts where the law requires it.
  • A buyer or successor if the business or part of it is transferred, under equivalent protection.

7. International transfers

Merofly is based in the United Kingdom, and some of our providers process information outside the UK, including in the European Economic Area and the United States. Where information leaves the UK we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment, where applicable to that provider. We do not claim that a particular signed safeguard or completed assessment exists unless we can evidence it. Ask privacy@merofly.com for the current position on a specific provider.

8. How long we keep it

Retention depends on the category.

  • Order, invoice, tax and payment records — 7 years from the end of the relevant financial year, to meet UK tax and accounting duties.
  • eSIM service and installation records — for the life of the package plus up to 24 months, to support faults, disputes and top-up history.
  • Account records — while your account is open, then up to 12 months after closure, except where a longer legal period applies.
  • Support conversations — up to 24 months after the enquiry is closed.
  • Travel Assist trip details — up to 12 months after the trip date.
  • Rewards, attribution and reward-reversal records — up to 6 years, because they relate to money owed or reversed.
  • Fraud, abuse and security records — up to 6 years where needed to prevent repeat abuse or defend claims.
  • Cookie consent records — up to 24 months, or until you change your choice.
  • Marketing consent and objections — kept as long as needed to honour your choice.

9. When information is required

Some information is required to buy an eSIM: an email address to deliver it, a device model and eSIM/unlocked confirmation so it can work on your phone, and payment details so we can charge you. If you do not provide these we cannot sell or deliver the eSIM. Travel Assist details, marketing consent and optional cookies are genuinely optional, and declining them does not affect your purchase, your account or your Merofly Credit.

10. Automated checks and human review

We use automated rules and provider-supplied fraud scores to screen orders, payments, invitation attribution and reward eligibility. An automated check can delay an order, hold a reward or refuse a purchase. We do not use this for profiling unrelated to fraud prevention and service integrity. If a decision affects you, email support@merofly.com: a person will review it, explain the reason as far as we safely can, and you can give us further information and contest the outcome.

11. Your rights

Subject to conditions in law, you can ask us to give you access to your information, correct it, erase it, restrict how we use it, or provide it in a portable form. You can object to processing based on legitimate interests, and you can object to direct marketing at any time, which we will always honour. Where we rely on consent you can withdraw it at any time, including analytics and advertising consent through Cookie settings. Email privacy@merofly.com. We respond within one month and will tell you if we need longer because a request is complex. We may ask for proof of identity first. You can complain to the UK Information Commissioner's Office at ico.org.uk, and we would welcome the chance to help first.

12. Travellers who did not buy the eSIM themselves

If a purchaser or an approved professional partner bought your eSIM, Merofly received your email address and device model from them, not from you. We use them only to confirm your device is compatible, issue and deliver the eSIM, and support installation. We hold no payment details for you, we do not add you to any marketing list, and your details are never copied into a marketing consent field. Your first delivery email tells you why Merofly has your address and links to this policy. You have all the rights in section 11, including erasure of your contact details once your eSIM is no longer in service. If you did not expect this eSIM, email privacy@merofly.com and we will investigate and, where appropriate, remove your details.

13. Travel Assist

Travel Assist uses only the trip details you choose to enter, such as destination, arrival date and the help you want, to show relevant arrival information and to pass on a request you ask us to make. We do not track your live location, and we do not use Travel Assist details for advertising.

14. Children

Merofly is intended for adults. We do not knowingly sell to, or collect information from, children. If you believe a child's information has reached us, email privacy@merofly.com and we will delete it.

15. Security

We use encryption in transit, row-level database security, access controls on production systems, restricted administrative access, monitored payment and fulfilment workflows, and private installation links. No online service can promise absolute security. Keep your account credentials, QR codes and activation details private. If we become aware of a personal-data breach that is likely to present a risk, we report it to the ICO within 72 hours of becoming aware of it and tell affected people where the law requires.

16. Cookies and similar storage

Optional analytics and advertising storage is off until you allow it. The Cookie Policy lists exactly what is used, by whom, why and for how long, and Cookie settings lets you change or withdraw your choice at any time. Merofly.com keeps its own consent record; it never reads or writes a consent record for any other site.

17. Changes to this policy

This is version 2026-09-19, effective 19 September 2026. Where a change materially affects how we use your information, we will tell you before it takes effect and keep the earlier version available on request.

To request account deletion, use the Merofly account-deletion form or email privacy@merofly.com. See also the Cookie Policy and the Legal Centre.
Merofly
Cookie policy

Your choice is saved on this browser. Optional tracking stays off until allowed. Rejecting optional cookies does not change plan prices or partner commission rules. Change or withdraw your choice at any time using Cookie preferences.

Read the full cookie policy

Connected before you land.