Privacy
Data controller
The data controller for the processing described here is Mocom LLC, publisher of the Sirocco service (website https://sirocco.mobi and mobile app). For any question about your data: support@sirocco.mobi, subject “Personal data”.
This policy applies to people who visit the website, place an order, use a Sirocco eSIM (including travellers who did not pay themselves) or contact support.
Data collected
We only collect the data needed for the service. No mobile number is required to buy: one is only used if the organiser chooses to send an installation link to a traveller by text message.
- Account: email address, first name or display name (optional), language, currency, technical identifier of your Google or Apple account if you sign in that way, communication preferences.
- Order: destination, dates, number of travellers and the label given to each (for example “Traveller 2”), plans chosen, compatibility confirmation and its timestamp, billing country, amounts, discount, travel credit, invoices.
- A traveller’s contact details (optional): the mobile number or email address entered by the organiser to send that traveller their installation link and, at most, one reminder before departure. The organiser confirms the traveller’s agreement. These contact details are used only for this trip, never for advertising; the traveller can stop text messages from their installation page or by replying STOP.
- Payment: transaction identifier, card type and last four digits, provided by Stripe. The full card number is never received or stored by Sirocco.
- eSIM: eSIM identifier (ICCID), status (delivered, installed, connected, used up, expired), data used and update timestamp provided by the supplier, validity dates, minimal access log for the installation link (date, device in aggregated form).
- Support: your messages, the subject, the trip and eSIM concerned, the replies given.
- Technical: IP address, browser and device type, pages viewed, security logs, cookies (see the Cookies and measurement section).
The following never appear in page addresses or in audience measurement: installation codes, QR codes, email addresses, first names, tokens.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, processing and delivering your orders, providing eSIMs and the trip dashboard, issuing invoices | Performance of the contract |
| Collecting payment, preventing fraud and non-payment | Performance of the contract; legitimate interest (payment security); legal obligation |
| Responding to your support requests | Performance of the contract; legitimate interest |
| Sending service emails (confirmation, eSIMs available, reminder before departure) | Performance of the contract |
| Asking for your feedback on your trip, once per order, one day after your plan ends (reviews published on Trustpilot if you choose to) | Legitimate interest (improving the service); you can object in your account's e-mail preferences or by writing to support |
| Sending Sirocco offers and news | Consent (optional box; consent can be withdrawn at any time from the account or via the unsubscribe link) |
| Keeping the invoices and logs required by law | Legal obligation |
| Measuring audience and improving the service (Google Analytics 4) | Consent (“Audience measurement”), which can be withdrawn at any time via the “Manage cookies” link |
| Measuring purchases that come from our ads and linking an order to the ad that led to it (Google Ads) | Consent (“Advertising”), which can be withdrawn at any time via the “Manage cookies” link |
| Parental control of purchases (Child profile) | Performance of the contract; legitimate interest of the parent |
| Publishing our content on Sirocco’s Facebook Pages and Instagram accounts and following their overall statistics (Meta app) | Legitimate interest (making Sirocco known) |
We do not take any decision based solely on automated processing that produces legal effects concerning you, and we never sell your data.
What the organiser sees
The organiser (the person who pays) sees, for each traveller in their order, the status of the eSIM: to install, installation declared or confirmed, connected, data used up, plan ended. They can assign, reassign before installation, share or revoke an installation link, and top up an eSIM they are paying for.
They never see another adult’s detailed usage, installation codes or contact details. Each traveller sees only their own eSIM, their usage and help; they have no access to the organiser’s contact details. For a Child profile, the parent controls purchases only: no screen allows the content visited to be viewed.
Payment
Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, an authorised payment service provider. Card details are entered in a component provided by Stripe and sent encrypted to its servers. Sirocco does not store card numbers. If you save a card for a future purchase, it is stored by Stripe; you can delete it from Account. Stripe also processes fraud-prevention data (IP address, device fingerprint) under its own privacy policy.
Recipients and processors
- eSIM provider and partner operators: receive the technical information needed to deliver and operate the eSIM (eSIM identifier, plan, area, dates). They receive neither your email address nor your name.
- Stripe: payment, fraud prevention, storage of saved cards.
- Hosting providers: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, United States (website); DigitalOcean, LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, United States (services and database).
- Email delivery provider: delivery of service emails and, with your consent, offers.
- Text message delivery provider: delivery of text messages containing an installation link, when the organiser chooses this method.
- Meta Platforms Ireland Ltd.: receives the content we publish on our Facebook Pages and Instagram accounts and processes it under its own terms and privacy policy. It receives no customer data from us this way.
- Authorities: only upon a lawful request.
Each processor is bound by a contract that complies with article 28 of the GDPR (RGPD) and uses your data only for the service entrusted to it.
Transfers outside the European Union
Some providers (Stripe, hosting providers) may process data in the United States. These transfers are based on the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission’s standard contractual clauses, supplemented by appropriate technical measures (encryption in transit and at rest). Using an eSIM in the destination country necessarily involves the processing of technical connection data by that country’s local operator.
Retention periods
- Account and preferences: for as long as the account is active, then deleted 7 days after your deletion request (cooling-off period); an account with no activity for 3 years is deleted after notice by email.
- Orders, eSIMs and statuses: for the duration of the trip, then 3 years for evidence and support purposes.
- Invoices and accounting records: 10 years (article L123-22 of the French Commercial Code, Code de commerce), with no link to the deleted profile.
- Support requests: 3 years after closure.
- Installation links: until they expire or are revoked, then access log for 12 months.
- A traveller’s mobile number: erased 30 days after the end of the trip; the sending log then keeps only a masked number.
- Technical and security logs: 12 months.
- Consent to offers: until withdrawn, and no longer than 3 years after the last contact.
Publishing on our social media (Meta)
Sirocco publishes its content on its Facebook Pages and Instagram accounts through a Meta app. Data processed:
- Sirocco’s accounts: identifiers and names of our Facebook Pages and Instagram accounts, name of the Meta business account, access tokens granted by the member of the Sirocco team who connects these accounts. Tokens are stored encrypted, never displayed, and erased when an account is disconnected.
- Published content: Sirocco’s text, photos and videos.
- Overall statistics: reach and number of likes, comments, saves and shares of each post, with no data about individuals.
This app collects no data about website visitors or about people who follow, like or comment on our posts. Meta (Meta Platforms Ireland Ltd.) receives this content and processes it under its own terms. To remove the app’s access or ask for data to be deleted: Data deletion.
We place nothing on your device for audience measurement or advertising without your consent. You are offered the choice when you arrive on the site; until you accept something, no Google tool is loaded.
Strictly necessary cookies (no consent needed)
- Sign-in session: keeps you signed in (30 days).
- Basket: the trip you are ordering (24 hours).
- Chosen language and currency (12 months).
- Your cookie choice, so that we do not ask again (6 months).
Audience measurement (only with your consent)
Google Analytics 4 measures page visits and the steps of the order, to improve the site. It is only loaded after you accept “Audience measurement”. It receives no purchases.
Advertising (only with your consent)
The Google Ads tag measures purchases that come from our ads. It is only loaded after you accept “Advertising”. We then keep the identifier of the last ad click to link your order to that ad. With this same consent, the Google Ads tag also receives your hashed email address (made unreadable) to link the purchase to the ad.
Retention periods
- Your cookie choice: 6 months, after which you are asked again.
- Last ad click (with consent): 30 days.
- Visit trace (campaign, landing page, with consent): the length of the visit.
- Google cookies (with consent): 13 months at most.
- IP address and browser of an order (with consent): deleted on payment, and at the latest 3 days after an unpaid order.
Changing your mind
You can give or withdraw your consent at any time with the link at the bottom of every page. Withdrawing stops the tools concerned straight away and deletes their cookies.
What is never shared
Installation codes, QR codes, eSIM identifiers, the details of your order (destination, travellers, plans) and your name are never shared with Google. Your answer to “How did you hear about us?” stays with us.
Security
Communications are encrypted (TLS). Data is stored in a database encrypted at rest, accessible only to Sirocco’s services through named, logged access. Installation codes are shown only to the traveller concerned, through a personal, time-limited and revocable link; they never appear in emails sent to the organiser. In the event of a personal data breach likely to result in a high risk to you, we will inform you within the time limits set by the GDPR.
Your rights
You have the rights of access, rectification, erasure, restriction of processing, objection and data portability, as well as the right to set instructions regarding what happens to your data after your death, and the right to withdraw your consent at any time.
- Download my data (Account): export of your profile, orders, eSIMs, consents and help requests, sent by an email link valid for 7 days; one request per 24 hours. Installation codes and card details are excluded.
- Delete my account (Account): deletion of your profile, preferences, saved cards, installation links and travel credit after a period of 7 days; invoices are kept for the legally required period. Deletion is not possible during a trip in progress. See Delete my account.
- Change your email, language, currency or offers: from Account.
- Other requests: by email to support@sirocco.mobi, stating the account’s email address. Reply within one month. Proof of identity may be requested in case of reasonable doubt.
You may lodge a complaint with the CNIL, the French data protection authority (cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France), or with the supervisory authority of your country of residence.
Minors
The Service is intended for adults. A parent may order an eSIM and assign it to a child under a Child profile: the data of this profile (label, eSIM status, data usage) is processed on behalf of the parent, who exercises the corresponding rights. No account is created in the child’s name and no data about the content viewed is collected.
Changes
This policy may change as the Service evolves. The version date appears at the top of the page; any substantial change is announced by email or by a message in the account before it takes effect.