So that you can use overseas eSIM data plans with peace of mind, Bloomy eSIM (the “Service”) establishes the following regarding the handling of personal information.
Article 1 (Basic policy)
The Service handles your personal information appropriately and complies with the laws, guidelines, and other applicable standards relating to the protection of personal information.
The Service strives to clearly explain, as far as possible, the information it collects, the purposes of use, third-party provision, integration with external services, security measures, your rights, and the like.
Article 2 (Information we collect)
For service provision, order management, payment confirmation, eSIM issuance, My Page features, support, fraud prevention, service improvement, and the like, the Service may collect the following information:
- Your name, email address, login information, and other information you enter when contacting us
- Order information such as the eSIM plan purchased, destination, planned countries/regions, period of use, order date and time, order number, payment status, and purchase amount
- Information needed to issue the eSIM and provide the QR code, activation information, SM-DP+ address, APN information, and other setup details
- Information shown on My Page, such as purchase history, eSIM information, remaining data, expiry, additional purchases, and top-ups
- Information needed for support, such as inquiry content, support history, screenshots of error or settings screens, device name, and country/region of use
- Technical information such as IP address, browser information, device information, OS information, access date and time, pages viewed, cookies, advertising identifiers, and analytics information
- Information needed for fraudulent-order, fraudulent-payment, impersonation, and chargeback prevention, security measures, and service improvement
- Information you provide voluntarily, such as surveys, feedback, reviews, your travel purpose, planned use, and use case
Article 3 (Purposes of use)
The Service uses the collected information for the following purposes:
- To accept orders for eSIM data plans, verify identity, confirm payment, and provide products
- To send QR codes, activation information, order confirmation emails, setup guidance, important notices, and the like
- To provide and operate features such as My Page, order history, eSIM information, remaining data, expiry, top-ups, additional purchases, and resending
- To provide support, including inquiries, connection troubles, setup support, order confirmation, and refunds
- To handle eSIM issuance, usage confirmation, remaining-data checks, top-ups, additional purchases, resending, and various procedures
- To prevent, investigate, and respond to fraudulent orders, fraudulent payments, impersonation, chargebacks, abusive behavior, and security issues
- To improve the site display, purchase flow, plan display, search, support structure, email delivery, My Page features, and the like
- To analyze your usage trends and use them for clearer recommendations, plan improvements, support improvements, and marketing measures
- To deliver, by email, LINE, or other means, important notices about the Service, support information, campaigns, and related service information
- To respond to requests from laws and regulations, terms, payment providers, communication-service providers, government agencies, courts, and other public bodies
- To handle disputes, troubles, fraudulent use, infringement of rights, breaches of terms, and other necessary matters
Article 4 (Handling of payment information)
The Service may use external payment services such as Stripe for payment processing.
Payment information such as credit card numbers, expiry dates, and security codes is processed on the secure payment system of the payment provider, and the Service does not directly collect or store card numbers and the like.
For order management, refunds, fraud prevention, accounting, and support, the Service may confirm and store payment status, payment date and time, amount paid, order identifiers, payment identifiers, and the like to the extent necessary.
Saved payment methods
If you save a payment method or use auto top-up / VPN auto-renewal, card details are stored by our payment processor (Stripe). The Service never obtains or holds your card number itself.
Article 5 (Integration with eSIM providers and external services)
For issuing eSIM plans, providing QR codes or activation information, checking usage status and remaining data, top-ups, support, sending email, payment processing, access analytics, security measures, and site operation, the Service may share information with external services to the extent necessary.
External services with which information may be shared include:
- Payment processing services
- eSIM issuance and communication-service providers
- Email delivery services
- Server, WordPress, security, and backup-related services
- Tools for access analytics, ad measurement, site improvement, and error analysis
- Services for accounting, order management, inquiry management, and customer management
- Authentication services such as Google login
- LINE and other external services for support and notifications
The Service may provide or share information with these external services to the extent necessary to provide the Service.
Email delivery
We may outsource the sending of order confirmations, setup information and notices to an email delivery provider.
Article 6 (Processing and storage outside Japan)
For payment processing, eSIM issuance, email delivery, access analytics, server operation, authentication, security measures, and the like, the Service may use services of businesses located outside Japan.
In this case, your information may be processed or stored outside Japan. When using external services, the Service handles information to the extent necessary to provide the Service and strives to ensure appropriate management as far as possible.
Article 7 (Provision to third parties)
Except in the following cases, the Service does not provide your personal information to third parties without your consent:
- When you have consented
- When entrusting or sharing with external businesses to the extent necessary for service provision, payment processing, eSIM issuance, email delivery, support, and the like
- When disclosure is required by law
- When it is necessary to respond to fraudulent use, fraudulent payment, fraud, chargebacks, impersonation, or security issues
- When necessary to protect a person’s life, body, or property
- When a legitimate request is received from a public body, court, government agency, payment provider, communication-service provider, or the like
- When transferring information to the extent necessary due to a business transfer, merger, company split, business succession, or other business reasons
Article 8 (Use of cookies, etc.)
To improve site convenience, maintain login status, analyze access, prevent fraudulent use, measure ad effectiveness, improve the purchase flow, optimize displayed content, and the like, the Service may use cookies, similar technologies, analytics tools, ad-measurement tools, and the like.
If you do not wish to allow cookies, you can disable them in your browser settings. However, if you disable cookies, some features such as login, purchase, My Page, payment, and display optimization may not work properly.
Referral and partner measurement cookies
When you visit via a partner referral link, we store a cookie identifying the referrer and record purchases within its validity period as referral results. This cookie is valid for 24 hours in principle, or up to 30 days under specific partner agreements.
Display preferences
We may use cookies to adjust what is displayed based on, for example, purchase history or language settings. You can delete or block cookies in your browser settings, though some features may stop working.
Article 9 (Access analytics and ad measurement)
For service improvement, ad-effectiveness measurement, understanding site usage, improving the purchase flow, and the like, the Service may use Google Analytics and other analytics tools and ad-measurement tools.
These tools may use cookies and the like to collect access information in a form that does not directly identify individuals. For the information collected, purposes of use, opt-out methods, and the like, please review the terms and privacy policies of each external service.
Article 9-2 (Information sent from your device to external parties)
When you view pages of the Service, some information is sent directly from your device to companies other than us. As of September 8, 2026, the recipients and the content actually being sent are as follows.
Google LLC (Google Analytics 4 / Google Tag Manager)
- Recipient: www.google-analytics.com / www.googletagmanager.com
- Information sent: the URL of the page you are viewing, the page title, the referrer, your browser language setting, screen size, browser and device information, IP address, an identifier assigned per browser, and your consent status
- Purpose of use: understanding how the site is used, and improving the Service
- How to stop it: you can change this at any time from "Cookie settings" on the page. By default, cookies for analytics are not stored. You can also stop it with the opt-out browser add-on provided by Google.
Based on our measurement of the public pages on September 8, 2026, there were no recipients other than the above to which information is sent automatically from your device. Flag images have been delivered from our own servers since that day (previously we used an external image delivery service).
Payment procedures take place on the screens of our payment provider (Article 4).
We re-measure the actual communications periodically and update this list.
Article 9-3 (Information we store on your device)
For display and functionality, the Service stores information on your device. All of it is stored by us and is not sent to any external company (information sent to external parties is described in Article 9-2). The following reflects what we confirmed on September 11, 2026, in both the code and an actual browser.
1. To remember your display choices
- bloomy_currency (365 days) — the currency you chose to display
- bloomy_lang (30 days) — the language you chose to display
- bloomyLangSeen (until deleted) — whether you have already seen the language notice
- bloomyAcctTabSwitch (until you close your browser) — prevents flicker when you switch tabs in My Page
- bloomy_vpn_favs (until deleted) — the countries you marked as favourites in Bloomy VPN
- bp_lang (1 year) — the language of the referral partner screens (partners only)
2. So we do not show you the same notice again
These remember that you closed a notice. Only the fact that it was closed is stored.
- bloomy_promo_dismissed / bloomy_atpromo_dismissed_… — when you close a campaign notice
- bloomyStatusDismiss — when you close a service-status notice
- bloomy_dataused_dismissed_… / bloomy_ach_modal_… / bloomy_armed_bar_… — when you close a notice in My Page
- bloomy_bubble_done — so the AI support bubble does not repeat on the same visit
- bloomy_topup_celebrate / bloomy_acct_refresh_toast — to show a message once after a top-up or a usage refresh
- bloomy_pk_propose_dismissed_v2 (until deleted) / bloomy_pk_propose_session_v2 (until you close your browser) — when you close the passkey suggestion
Items ending in "…" are stored separately per notice. Unless stated otherwise, these last until you close your browser.
3. To record how you reached us
- bloomy_ft (90 days) — which route you first came to the Service through
- bloomy_ref (30 days) — if you arrived through a referral link, which partner referred you
- bloomy_disc (30 days) — if that referral carries a discount, the details of the discount
- bloomy_pc_usd (until you close your browser) — if you arrived from a referral card, to switch the initial currency once
bloomy_ref, bloomy_disc and bloomy_pc_usd are stored only if you arrive through a referral link or card.
4. To recognise the same device
- bloomy_vid (365 days) — a number that distinguishes this device. It is not linked to your name or contact details. It is stored only if you have consented to analytics cookies, and it is deleted if you withdraw that consent.
- bloomy_customer (1 year) — whether you have purchased before, so we do not show first-time guidance to existing customers
- bloomy_ga4_purchase_… (until deleted) — so the same purchase is not counted twice
5. For login and security
- bloomy_cookie_consent_v1 (until deleted) — your cookie choices themselves
- bloomy_chat_sid (until you close your browser) — keeps your conversation with AI support connected while you stay on the site
- bloomy_ml_rk (15 minutes) — when you use an email login link
- bloomy_oauth_state / bloomy_oauth_return (10 minutes each) — for the round trip of signing in with Google and returning you to the page you came from
- bloomy_pk_creds_v1 (until deleted) / bloomy_pk_hint_v1 (180 days) — so you can sign in quickly next time on a device where you use a passkey. The passkey itself and its private key are not stored here (they are kept inside your device)
6. About our operational screens
Only if you open a screen we use to operate the business (such as BLOOM HQ) do we store that screen's display settings on your device (abTab / hqTheme / hqMask / sushiTab / bloomy_chat_dev / bloomy_internal). These are never stored during ordinary use of the Service.
Deleting or refusing, and what changes
You can delete or refuse all of the above in your browser settings. You can also change analytics cookies at any time from the cookie settings on the page (by default they are not stored). If you refuse them, the following changes:
- Your currency and language choices are not remembered, and the default display returns on your next visit
- Notices you have already closed will appear again
- If you arrive through a referral link, the referral and any discount are not recorded
- Your conversation with AI support starts over each time you move to another page
- If you refuse the items used for signing in, login may not complete
We do not store anything for advertising purposes. If the above changes, we will update this article.
Article 10 (Contact by email, LINE, etc.)
The Service may send order confirmations, eSIM setup details, important notices, support responses, payment confirmations, usage-status guidance, and the like by email, LINE, My Page, or other methods designated by the Service.
In addition, with your consent or to the extent permitted by law, the Service may deliver campaigns, service improvements, related services, and information related to living abroad and studying abroad.
For communications that can be stopped, you can opt out using the method designated by the Service. However, communications necessary for service provision—such as order confirmations, payments, eSIM issuance, important notices, changes to terms, security, and support—may still be sent after you opt out.
Article 11 (Information management)
The Service takes reasonable security measures to prevent unauthorized access, loss, destruction, alteration, leakage, and misuse of the personal information it collects.
When using external services, the Service shares information to the extent necessary for service provision and strives to ensure appropriate management as far as possible.
However, due to the nature of Internet communication, external services, user devices, email-receiving environments, and the like, complete security of information cannot be guaranteed.
Passkeys (biometric sign-in)
If you sign in with a passkey, biometric data such as your fingerprint or face is processed only on your device and is never sent to or stored by the Service. We store only the public key used for authentication.
Push notifications
If you enable browser push notifications, we store the subscription data needed to send them. You can unsubscribe at any time in your browser or device settings.
Article 12 (Retention period)
The Service retains the collected information for the period necessary for service provision, order management, inquiry handling, payment confirmation, accounting, legal compliance, fraud prevention, dispute handling, and improving support quality.
For information that no longer needs to be retained, the Service strives to delete or anonymize it by reasonable means.
However, for information that needs to be retained for a certain period for laws, accounting, fraud prevention, dispute handling, order-history management, support, and the like, the Service may continue to retain it to the extent necessary.
Article 13 (Your rights)
Regarding your own personal information held by the Service, you may request notification of the purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, suspension of provision to third parties, and the like.
If you wish to make a request, please contact the inquiry channel designated by the Service. After verifying your identity, the Service will respond within a reasonable scope in accordance with law.
Depending on the content of your request, we may ask you to submit additional information for identity verification. Also, for information necessary for order management, accounting, legal compliance, fraud prevention, dispute handling, and service operation, we may not be able to delete or suspend its use immediately.
Article 14 (Use by minors)
If you are a minor, please use the Service only after obtaining the consent of a parent or legal guardian.
If a minor uses the Service, it is deemed that they did so with the consent of a parent or legal guardian.
Article 15 (Surveys and feedback)
For service improvement, plan improvement, improving recommendations, enhancing the support structure, and the like, the Service may ask for your voluntary cooperation with surveys, reviews, feedback, and the like.
These responses are voluntary, and not responding will not result in any disadvantage in using the Service.
The Service may analyze and use survey results and feedback in a form that does not directly identify individuals.
Article 16 (Changes to this privacy policy)
The Service may revise this privacy policy in response to changes in laws, service content, the external services used, operating policy, and the like.
The revised content applies from the time it is posted on this site or from a time otherwise specified by the Service. In the event of material changes, we will notify you by posting on the site or by other appropriate means.
Article 17 (Contact)
For inquiries regarding the handling of personal information, please contact us through the channels below.
- Operator
- BLOOM CONSULTING
- Privacy inquiry desk
- Bloomy eSIM Support
- Contact
- Contact form
- Contact
- Please contact us via our contact form.
This page shows the above information as the contact point regarding personal-information protection. For the disclosure under the Specified Commercial Transactions Act and other legally required business information, please see the separate “Legal Notice (Specified Commercial Transactions Act)” page.
