Skip to content
Nomlo.
Find your planHow it worksFAQs
Coming soon
Find your planHow it worksFAQsContact us

The details matter

Privacy Policy

Effective September 20, 2026 · Nomlo by Notera Labs Limited

On this page

1. Who we are and what this covers2. Information we process3. Why we use information4. Legal grounds for processing5. Who information is shared with6. This website and cookies7. International processing8. Retention and account deletion9. Your rights and choices10. Security11. Children12. Policy changes and contact

1. Who we are and what this covers

Notera Labs Limited, a company registered in Hong Kong (“we”, “us”, or “our”), is responsible for the personal information we process to operate Nomlo: eSIM & Mobile Internet (“Nomlo” or “the app”), esimapp.link and related customer support. You can contact us at [email protected].

This policy covers our handling of information for these services. Payment processors, mobile network operators, connectivity providers and app stores may also process information under their own privacy policies, including when they act as independent controllers for payment, network operation, fraud prevention or legal compliance.

2. Information we process

Depending on how you use the service, we process the following categories:

  • Account and sign-in information: account or guest identifiers, authentication records and information made available by your sign-in provider, such as an email address or an Apple private relay address. We do not receive your Apple account password.
  • Trip and plan selections: destinations, trip lengths and data preferences you enter, selected offers and related purchase information. Choosing a destination is not the same as granting access to your device’s precise GPS location.
  • Orders and payment records: order references, purchased plans, amounts, currency, payment status, transaction identifiers and records needed for refunds or disputes. Stripe handles the payment details entered in its checkout; we do not store your complete payment-card number or security code.
  • eSIM and connectivity records: identifiers such as an ICCID, installation and activation details, plan validity, status, remaining allowance and usage information supplied by the connectivity provider. Installation codes and QR codes are sensitive because they can allow access to an eSIM.
  • Device, network and diagnostic information: device and operating-system details, app version, IP address, request and security logs, error information and identifiers used to operate, authenticate and protect the service.
  • App analytics and attribution information: interactions with app features and technical events collected through Firebase Analytics. Where advertising attribution is enabled, campaign or installation information and available device identifiers may also be processed, subject to applicable device permissions and legal requirements.
  • Support communications: information you include in emails or other support requests, such as your order reference, device model, screenshots and description of a problem. Please avoid sending payment-card credentials or information unrelated to your request.

We receive information directly from you and your device, and from service providers such as sign-in, payment and connectivity providers. A mobile network operator may separately process traffic, network location and other telecommunications information under its own obligations. That does not mean that we receive the content of your internet communications.

3. Why we use information

We use information to:

  • Authenticate users, operate accounts and provide access to purchased plans.
  • Help identify plans based on the preferences you enter.
  • Process and verify payments, fulfil orders, issue eSIMs and display plan and usage status.
  • Investigate installation, activation, network and payment problems and respond to support requests.
  • Protect accounts and systems, detect abuse and fraud, and maintain service reliability.
  • Understand app usage and technical performance and, where enabled, measure the source and performance of marketing campaigns.
  • Keep necessary transaction records, manage disputes and meet applicable legal obligations.

Plan Finder uses the selections you provide to suggest a suitable plan. It does not make decisions with legal or similarly significant effects about you.

4. Legal grounds for processing

Where European or similar data protection laws apply, our legal grounds depend on the purpose:

  • Performance of a contract: providing the service you request, managing your account, fulfilling orders, enabling connectivity and addressing problems with a purchase.
  • Legal obligations: retaining records required by law, responding to valid legal requests and meeting applicable accounting or regulatory duties.
  • Legitimate interests: protecting the service against fraud and abuse, investigating technical problems and understanding basic service performance, where those interests are not overridden by your rights. The relevant interests are service security, reliability and improvement.
  • Consent: processing for which applicable law requires your permission, including certain analytics, advertising identifiers or device permissions. Where consent is required, that processing requires your consent; you can withdraw it without affecting earlier lawful processing.

Information needed to authenticate you, process a purchase or issue a plan is necessary to provide that feature. If you do not provide it, we may be unable to complete the requested service. Other information, such as the contents of a voluntary support message, depends on what you choose to share.

5. Who information is shared with

Information may be shared, to the extent relevant to the purpose, with:

  • Connectivity providers and mobile network operators, including the eSIM fulfilment provider eSIM Access, to issue and manage eSIMs, deliver connectivity, report plan status and resolve technical issues.
  • Stripe and payment-service participants to process, verify and refund transactions and handle fraud or payment disputes. See Stripe’s Privacy Policy.
  • Google Firebase, used for app analytics. See Google’s Privacy Policy and Firebase’s privacy information.
  • Hosting, infrastructure and security providers, including Cloudflare for website delivery, to serve content and maintain service security and availability.
  • Sign-in and app-distribution providers, such as Apple, when you use their sign-in or distribution services. Their independent handling of data is governed by their own notices.
  • Professional advisers and competent authorities, where necessary for legal compliance, accounting, protecting rights or responding to a valid legal request.

If the business is reorganised, merged or transferred, relevant records may be transferred as part of that transaction, subject to applicable protections and any required notice. Information is shared for the purposes described in this policy; a provider’s independent legal or network obligations may require it to retain or use some information separately.

6. This website and cookies

The current website is a static informational site. It does not include a sign-up form, marketing pixels, embedded third-party analytics or cookies set by our website code. Its interactive preview works in your browser without sending the selected step to us.

Hosting and delivery infrastructure may process IP addresses, request details and security logs when serving the website. Following an App Store link, emailing us or visiting another website takes you to a service with its own privacy practices. The app’s analytics described above are separate from this website.

7. International processing

Our company is registered in Hong Kong. Providers may process information in other countries, including the United States and countries where connectivity or technical infrastructure is supplied. Data protection laws can differ between these locations.

Where a transfer is subject to a legal restriction, it requires an applicable transfer mechanism, such as an adequacy decision, approved contractual safeguards or another lawful basis. Contact us for information about the safeguards relevant to your information and how to obtain a copy where available. This statement does not mean that every provider stores information only in the European Economic Area.

8. Retention and account deletion

Retention depends on the purpose and the record involved:

  • Account and service records are used while your account or purchased services require them, and as needed to resolve outstanding issues.
  • Order, payment and related records may be retained after account deletion for applicable accounting, legal, fraud-prevention and dispute-handling requirements.
  • Diagnostic, security and analytics records are retained according to their operational purpose, provider settings and the period needed to investigate incidents or evaluate service performance.
  • Support records may be retained as needed to resolve the request and handle subsequent questions or disputes.

The relevant criteria include whether the service is still active, whether a dispute or incident remains open, mandatory retention requirements and whether identifying information is still needed. We cannot state a single retention period that applies to every category or provider.

You can request account deletion using the available in-app controls or by contacting us. Account deletion removes or de-identifies account information where appropriate, but does not mean every operational record is immediately erased. Some necessary records may be retained in pseudonymised form, and information may remain in backups until those backups are replaced or expire. Pseudonymised records can still be personal information and remain subject to applicable protections.

Deletion of your account does not automatically revoke an issued eSIM, erase a network provider’s independent records or reverse a purchase. Contact us if you also need help with an active plan or a refund.

9. Your rights and choices

Depending on your location and applicable law, you may have rights to access, correct, delete or obtain a portable copy of your personal information; to restrict certain processing; and to object to processing based on legitimate interests. You may withdraw consent for processing that relies on consent. These rights are subject to the conditions and exceptions in applicable law.

To make a request, email [email protected]. We may need proportionate information to verify your identity and locate the relevant records. We will respond within the period required by applicable law and explain any limitation that applies to the request.

You can review applicable device permissions in your device settings. Withdrawing a permission may affect the related feature, and does not itself delete data already processed. You may also complain to your local data protection authority. People in the EEA may also contact the authority in their usual place of residence, work or the place of an alleged infringement.

10. Security

We use technical and organisational measures intended to protect information, including controls around access, authentication and service operations. No method of storage or transmission is completely secure. Keep your device, sign-in credentials and eSIM installation information private, and contact us if you believe your account or data has been compromised.

11. Children

The service is not directed to children under 13. If you believe a child has provided personal information without the authorisation required by applicable law, contact us so we can investigate and take appropriate action. The minimum age and authorisation required to make a purchase are also subject to our Terms & Conditions and applicable law.

12. Policy changes and contact

We may update this policy as the service or its processing changes. The effective date at the top identifies the current version. Where required, we will provide additional notice or request consent before making a relevant change.

For privacy questions and requests, contact Notera Labs Limited, Hong Kong, at [email protected] or +357 99 555 128.

Notera Labs Limited · Hong Kong

Email: [email protected]

Phone: +357 99 555 128

Terms & Conditions · Privacy Policy

Nomlo.

A little less planning.
A little more exploring.

How it worksFAQsContact us ↗
Terms & ConditionsPrivacy PolicyAbout Notera Labs ↗
© 2026 Notera Labs LimitedMade for wherever comes next.