Who is responsible for your information
Merofly is operated by SPACE AI TECHNOLOGY UK LTD, company number 15446027, of 142–143 Parrock Street, Gravesend, Kent, DA12 1EY, United Kingdom. We are the controller for personal information described in this policy.
For privacy questions, access requests or complaints, email support@merofly.com.
Information we collect and where it comes from
- Directly from you: email, destination, package, device model or regional answer, support messages, account and partner-application information, and checkout consent.
- From your use of Merofly: compatibility result, timestamps, page path, referring website, consent record, authentication events, security logs and truncated or hashed network and browser identifiers.
- From service providers: Stripe payment identifiers, status and limited fraud information; Airalo package, ICCID, installation, activation, usage and top-up information; and transactional-email delivery status. Merofly does not receive your full card number.
- Rewards and partner details: referral code, attributed visits and orders, earnings, business details, promotion channels, payout status and terms acceptance.
Order email, package and payment information are required to enter and perform the contract. Optional fields and optional referral storage are identified when requested. If required information is not provided, we cannot complete that part of the service.
Why we use it and our lawful basis
- To perform our contract: show plans, create an order, take payment, deliver an eSIM, provide installation details, display usage and handle support.
- Legitimate interests: secure the service, prevent fraud and self-referrals, improve compatibility and customer journeys, keep operational records and measure referrals. We balance these interests against your rights.
- Legal obligations: accounting, tax, fraud prevention, regulatory enquiries, dispute handling and compliance with consumer law.
- Consent: optional marketing and any non-essential cookies. You can withdraw consent at any time without affecting earlier lawful use.
Compatibility and plan recommendations help you decide, but Merofly does not use them to make decisions that produce legal or similarly significant effects about you.
International transfers
Some providers and mobile network partners operate outside the United Kingdom. Where UK personal information is transferred internationally, we use an approved adequacy decision, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard. You may ask us for more information about the safeguard used.
How long we keep information
We keep information only as long as reasonably needed. Our standard periods are:
- orders, invoices, payment and contract records: generally six years for accounting, tax and legal claims;
- eSIM installation, usage and support records: for the service life and usually up to 24 months afterwards;
- security and referral-attribution logs: normally up to 12 months;
- unsuccessful partner applications: normally 12 months after a final decision;
- marketing preferences: until you withdraw, plus a minimal suppression record so we respect that choice.
We may keep information longer when a dispute, legal hold or regulatory requirement applies, and shorter where it is no longer needed.
Your rights and how to object
Depending on the circumstances, UK data protection law gives you rights to access, correct, erase or restrict your information; receive portable data; and withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.
You have a separate right to object to processing based on legitimate interests, including referral measurement and service improvement. Tell us what you object to and your circumstances; we will stop unless we have compelling legitimate grounds or need the information for legal claims. You can object to direct marketing at any time and we will stop it.
Email support@merofly.com to exercise a right. We may verify identity and will normally respond within one month. You may complain to the UK Information Commissioner's Office at ico.org.uk, although we welcome the chance to help first.
Security and your responsibilities
We use encryption in transit, access controls, row-level database security, hashed technical identifiers, restricted administrative access and monitored payment and fulfilment workflows. No online service can promise absolute security.
Keep installation QR codes, activation details and account links private. Tell us promptly if you believe someone else has accessed them.
Children and changes to this policy
Merofly purchases, Rewards and Partner accounts are intended for people aged 18 or over. We do not knowingly collect information from children for these services.
We may update this policy as Merofly changes. The effective date at the top shows the current version. If a change materially affects you, we will provide a prominent notice or contact you where appropriate.
