When you book a rental, we collect your name, shipping address, email, phone number, and payment information processed via Stripe (we never see full card numbers). When you sign in, we collect your IP address and session metadata for fraud-prevention purposes. When the device is in use, we collect rough connection telemetry (uptime, signal strength, country) so we can confirm the device worked and detect problems.
We do not log the URLs you visit through the hotspot, the apps you open, the messages you send, or the photos you transfer. The device is a network bridge, not a content recorder. Local carrier traffic is subject to that carrier's own logging policies, which are independent of Noomi.
We use your data to ship the device, process refunds, contact you about your trip, and improve future service. We send transactional emails (order confirmation, shipping notices, return reminders). We send marketing emails only if you opted in; you can unsubscribe at any time.
We share necessary data with shipping carriers (USPS, FedEx, UPS), payment processors (Stripe), email delivery (Resend), our eSIM connectivity provider (TelliSIM, which provisions the device's data connection and processes the SIM identifier and usage needed to keep you connected), and tax authorities as required by law. We also share limited data with our advertising partners — Google, Meta, LinkedIn, and TikTok — to measure which ads lead to bookings and to target our ads. That data is limited: a hashed email or phone number, ad click identifiers, the pages you view, and your order value. We never share your full Wi-Fi traffic, the URLs you visit, or your message content with anyone.
We don't sell your data for money. But sharing data with ad partners for measurement and targeting counts as a "sale" or "sharing" under some state privacy laws, including California's. You can opt out of it — see section 6.
We use analytics and advertising cookies and pixels to understand how visitors find us and which ads lead to bookings. These come from Google (Analytics and Ads), Meta, LinkedIn, and TikTok. They let us measure bookings and target our ads to people likely to need travel Wi-Fi. They are consent-gated: they only load after you accept them, and they don't load if you opt out or send a Global Privacy Control signal. Essential cookies that keep you signed in and your booking working are always on — those aren't used for advertising.
You can opt out of ad sharing and targeting at any time using the "Your Privacy Choices" control in the site footer. Turning it on stops the advertising cookies and pixels and tells our server not to share your data with ad partners for targeting. We also honor your browser's Global Privacy Control (GPC) signal automatically — if your browser sends GPC, you're already opted out and the control reflects that. Opting out doesn't affect your booking, your device, or any transactional email; you'll still get order confirmations, shipping notices, and return reminders.
Booking records are kept for 7 years for tax + accounting purposes. Marketing email subscriptions are kept until you unsubscribe. Session data is purged after 90 days unless a fraud investigation is ongoing.
You can request a copy of your data, correction of inaccurate data, or deletion of marketing data at any time by emailing privacy@noomi.travel. You can opt out of ad sharing and targeting any time using "Your Privacy Choices" in the footer (see section 6). Booking records subject to tax-retention rules cannot be deleted before the 7-year window ends.
Privacy questions: privacy@noomi.travel. Data-subject requests: same address.