Last Updated: March 27, 2026
Privacy Policy
Our Commitment
SonicNest is built to run underneath other people's products. That shapes how we handle personal data: most of it isn't ours, and we treat it accordingly. This Privacy Policy explains what we collect, why, how we use it, and what rights you have. We do not sell personal data.
Two Roles, Two Sets of Rules
As a controller. When you visit our website, contact us, or enquire about a partnership, we decide how your data is used. This policy governs that.
As a processor. When you use an eSIM, travel, gaming, or trade-in service inside a partner's app, that partner is the controller. We process data on their instructions under a Data Processing Agreement. Their privacy policy governs that relationship, and requests about your data should go to them first — though we will always help.
Information We Collect
Provided directly: name, work email, company, role, region, and enquiry details when you contact us or request a partnership conversation; communications sent by email or form.
Collected automatically on our website: browser, operating system, and device information; IP address and approximate location; pages visited and navigation patterns; referral source.
Processed on behalf of partners: to deliver connectivity and ecosystem services, we process account identifiers, device and SIM identifiers, service activation and usage records, transaction and settlement data, and approximate location where a service requires it. We process this only as instructed by the partner and only to deliver, support, secure, and bill for the services.
How We Use Your Information
Delivering the platform and the services our partners offer; responding to partnership enquiries; operating, securing, and improving the platform; detecting and preventing fraud and misuse; sending updates to people who have opted in; meeting legal, regulatory, and telecommunications obligations.
We do not use personal data for automated decision-making producing legal or similarly significant effects, and we do not use partner or end-user data to market to end users directly.
Legal Basis for Processing
Contract — processing necessary to deliver services under a partnership or service agreement. Legitimate interests — website analytics, service improvement, platform security and fraud prevention, where not overridden by individual rights. Consent — marketing communications, and any processing where consent is the required basis. Legal obligation — including telecommunications record-keeping, tax, and financial crime requirements.
Data Sharing
We do not sell personal data. We share it only with: connectivity and carrier partners where necessary to provision and maintain a service; service providers — hosting, payments, analytics, and communication tools, contractually bound to our instructions; professional advisors under confidentiality; regulators and authorities where disclosure is legally required, including lawful requests to telecommunications providers; and successor entities in a merger or acquisition, under equivalent protections.
International Transfers
We operate across many jurisdictions, so personal data may be transferred outside the country where it was collected. Transfers are made under an appropriate legal mechanism — adequacy decisions, standard contractual clauses, or equivalent safeguards — and are set out in the Data Processing Agreement with each partner.
Data Retention
Partnership and business records: for the duration of the relationship and for the period required by applicable financial and regulatory record-keeping rules. End-user service data: for the period specified by the partner in their Data Processing Agreement, or longer only where telecommunications law requires it. Marketing and contact data: until consent is withdrawn or deletion is requested. Website analytics: aggregated and no longer linked to individuals after 26 months.
Your Rights
Depending on your jurisdiction, you may have rights of access, correction, deletion, portability, objection, restriction, and withdrawal of consent.
If you're a website visitor or partnership contact, write to privacy@sonicnest.ai and we'll respond within 30 days. If you used a service inside a partner's app, contact that partner — they hold the controller relationship. If you reach us instead, we'll forward your request and support their response.
Security
We apply technical and organizational measures appropriate to the data we handle, including encryption in transit and at rest, access controls, network segregation, logging, and regular security review. We notify partners of any personal data breach without undue delay, per our agreements. No system is perfectly secure, but we take this seriously.
Children
Our services are not directed at children. Where a partner offers a service to younger users — gaming in particular — age assurance and any parental consent are the partner's responsibility as controller.
Cookies
See our Cookie Policy for how we use cookies and how to manage preferences.
Changes to This Policy
We may update this policy. Changes are posted here with an updated date, and material changes are notified where required by law or otherwise appropriate.
Contact
Privacy questions or rights requests: info@sonicnest.ai
