Privacy Policy
Last updated: May 25, 2026 · Effective date: May 25, 2026
Yovio is an eSIM marketplace that runs inside Telegram. We built it so travellers can buy a data plan and get connected in a couple of taps — without leaving the messenger. To make that work, we have to collect and process a limited amount of personal information. This document explains what we collect, why we collect it, who we share it with, and what you can do about it.
This Policy applies to your use of:
- the Yovio Telegram Mini App and bot;
- our backend API and any related customer support channels;
- any marketing pages, emails, or notifications we send you in connection with the service
(together, the “Services”).
Where a specific rule applies only to one part of the Services, we say so directly. Otherwise, the same rules apply across the whole product.
1. Who is responsible for your data
The data controller for the purposes of the EU/UK GDPR and similar laws is Yovio LLC, a limited liability company organised under the laws of the State of New Mexico, United States (filing number 0008121473), and the operator of the Yovio Telegram Mini App.
Registered office: 1209 Mountain Road Pl Ne, Ste N, Albuquerque, NM 87110, US.
For any privacy-related question, request, or complaint, you can reach us at support@yovio.io or through the support flow inside the Mini App.
2. Scope
This Policy is a single, unified document covering every part of the Services. We have done our best to keep it readable rather than burying things in fine print. It is written to be consistent with the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) as amended by CPRA, and the Telegram Mini App Terms.
Yovio is an independent third-party service that operates on top of Telegram. We are not affiliated with, sponsored by, or endorsed by Telegram. Your use of Telegram itself is governed by Telegram’s own privacy policy, which we do not control.
3. What we collect
3.1 Information Telegram passes to us
When you open the Yovio Mini App, Telegram provides us with a signed initData payload as described in the Telegram Mini App Terms. In practice this gives us:
- your Telegram user ID;
- your first name, last name, and username if you have set one;
- your language code;
- whether your account is a Telegram Premium account;
- the URL of your profile photo, if your Telegram privacy settings expose it;
- any
start/startappparameter you used to open the app (for example a referral code or a deep link to a specific plan); - a cryptographic hash we use on the backend to verify the request really came from Telegram.
We do not have access to your Telegram chats, contacts, files, or message history. We never see your phone number unless Telegram explicitly chooses to share it with us as part of the launch payload — and at the moment, we do not request it.
3.2 Information you provide
- Email address. You can add an email address from the account screen, mainly so we can send you the eSIM activation details and order receipts. Adding an email is optional; if you do not, you can still buy and use a plan, but recovery and receipts will only be available inside the Mini App.
- Order details. When you buy or top up a plan, we collect the destination country or region, the bundle you chose, your order history, and any promo code you used.
- Support messages. If you contact us, we keep the contents of your message, anything you attach (such as a screenshot of an error), and the order or eSIM the conversation is about.
- Issue reports. If you report a problem with an eSIM, we keep a short description of the issue and the corresponding identifiers (ICCID, order ID) so we can investigate it with the underlying network.
3.3 Payment information
Yovio does not store full payment card numbers, CVV codes, or crypto wallet private keys. We never see them.
- Cards, Apple Pay, Google Pay. Card payments and native wallet payments are processed by Stripe, Inc. through Stripe Payment Intents. When you tap “Pay”, your card details are entered directly into a Stripe-hosted iframe; we only receive a payment token, the card brand (e.g. Visa), the last four digits, the billing country, and the transaction status. Apple Pay and Google Pay work the same way — the wallet returns a tokenised credential to Stripe, not to us. For Apple Pay to work, the domain serving the Mini App is registered with Stripe as required by Apple. Stripe’s privacy policy is available at https://stripe.com/privacy.
- Crypto. Crypto payments are handled by NOWPayments. When you select a coin, we ask NOWPayments for a deposit address and the expected amount, show you the QR code and the address inside the Mini App, and then poll our backend for the transaction status. We do not know which wallet you paid from beyond what the blockchain itself makes public; we only receive the order status, the asset and network you used, and the amount.
- Telegram Stars. When you pay with Telegram Stars, the payment is initiated through Telegram’s native invoice flow. We do not receive any payment instrument from you — Telegram tells us whether the invoice was paid, for which order, and that is enough for us to deliver the eSIM.
3.4 Information we collect automatically
When you use the Services, our backend records limited diagnostic information: the IP address the request came from, an approximate country derived from it, the Mini App version and platform (iOS / Android), the endpoints you hit, timestamps, and any error our servers produced while handling your request. We use this to debug, to fight abuse, and to keep the service reliable.
The Mini App keeps a small amount of state in your browser’s localStorage — for example, your theme preference (yovio_theme). That data lives on your device and is not sent to a separate analytics service.
We do not use third-party advertising SDKs. We do not run cross-site or cross-app tracking. We do not collect device identifiers like IDFA or AAID, precise location, microphone input, camera input, contacts, or installed-app lists.
3.5 Information from third parties
The eSIM you buy on Yovio is provisioned through one or more upstream eSIM connectivity providers and the mobile network operators they aggregate. They send us status updates about your eSIM — activation, remaining data, expiry — so we can show them to you inside the app. We share only the minimum reference data they need to provision the eSIM (order reference, destination, plan identifier).
4. Why we use your data, and on what legal basis
We process your information for the purposes below. Where the GDPR applies, the legal basis is in brackets.
- Running the Service. Creating your account from the Telegram payload, taking your order, charging you, provisioning the eSIM, showing your active plan and usage. (performance of a contract)
- Customer support. Answering your questions, investigating eSIM issues, processing refunds. (performance of a contract, legitimate interests)
- Security and abuse prevention. Verifying the Telegram
initDatasignature, rate-limiting suspicious traffic, preventing payment fraud, protecting other users and the platform itself. (legitimate interests, legal obligation) - Transactional communication. Sending order confirmations, eSIM activation instructions, expiry reminders, and policy notices. (performance of a contract)
- Product improvement. Looking at aggregated usage and error trends so we can prioritise bug fixes and features. (legitimate interests)
- Compliance. Keeping records required by tax, accounting, anti-fraud, and consumer-protection laws; responding to lawful requests from authorities. (legal obligation)
We do not sell your personal information. We do not use it for automated decision-making that produces legal or similarly significant effects about you.
5. Who we share data with
We share personal data only with the categories of recipients listed below, and only to the extent each of them needs to do its job. Each external processor is bound by a data-processing agreement with us.
- Stripe — card, Apple Pay, and Google Pay processing.
- NOWPayments — crypto payment processing.
- Telegram — the platform our Mini App runs on; Telegram Stars payment confirmations also pass through Telegram.
- Upstream eSIM connectivity providers and underlying mobile network operators — provisioning and operating the eSIM you bought.
- Hosting and infrastructure providers — running the backend, the database, and the storage for the Mini App.
- Email / messaging providers — delivering transactional emails (e.g. receipts, activation instructions).
We may also disclose information when we genuinely believe we are required to by law, when we need to protect Yovio’s rights, or when we need to protect the safety of our users or of the public. If Yovio is ever involved in a merger, acquisition, or sale of all or part of its assets, your data may be transferred to the acquiring party; we will let you know if and when that happens.
We do not “sell” or “share” personal information for cross-context behavioural advertising within the meaning of the CCPA/CPRA.
6. International transfers
The Services are operated globally. Several of our processors — including Stripe, NOWPayments, and Telegram — operate from countries outside the European Economic Area and the United Kingdom. When we transfer personal data outside those regions, we rely on appropriate safeguards: in most cases, the European Commission’s Standard Contractual Clauses, combined with technical measures (encryption in transit and at rest) and organisational measures (limited access, audit logging).
You can ask us for a copy of the relevant safeguards by writing to support@yovio.io.
7. How long we keep data
- Account and profile data — for as long as your account exists, and for up to 30 days after deletion (backups and abuse prevention).
- Order and payment records — up to 7 years, because tax and accounting rules in several jurisdictions require it.
- Support tickets and issue reports — up to 3 years from the last interaction.
- Server logs and diagnostic data — generally up to 12 months, then aggregated or deleted.
When data is no longer needed for any of the purposes above, we delete it or strip it of anything that could identify you.
8. Security
We use TLS 1.2 or higher for traffic between your device and our servers. Secrets and credentials in our database are stored encrypted at rest. The Telegram initData signature is verified on every request, so a tampered or replayed payload is rejected. Card details are kept inside Stripe’s iframes — they never enter the Mini App’s DOM or our servers, which keeps us in PCI SAQ-A scope. Access to production systems is restricted to a small number of engineers and is logged.
No system is fully secure. We strongly recommend keeping your Telegram account itself protected (two-step verification, a strong cloud password). If we ever become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
9. Your rights
Depending on where you live, you have some or all of the following rights:
- Access — ask for a copy of the personal data we hold about you.
- Rectification — ask us to correct anything that is wrong or out of date.
- Erasure — ask us to delete your data, subject to the records we are required to keep by law (typically billing records).
- Restriction or objection — ask us to stop or limit certain processing, including processing we run on the basis of legitimate interests.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — where we rely on consent, you can withdraw it at any time. This does not affect anything we did before you withdrew.
- Complain — to the supervisory authority in your country of residence.
California residents have the additional rights to know, to delete, to correct, to opt out of sale/sharing (which we do not do), and to non-discrimination for exercising any of these rights.
To exercise a right, write to support@yovio.io. We may need to ask you to confirm your identity through your Telegram account before acting on a request. We respond within the timeframe required by applicable law, typically 30 days.
You can also delete your account directly from the account screen inside the Mini App. Deletion removes your profile from our active systems immediately; residual copies in encrypted backups are overwritten on the schedule described in section 7.
Marketing
We currently send only transactional messages — order confirmations, eSIM activation, expiry warnings, important service notices. If that ever changes and we start sending promotional messages, you will be able to opt out from each one and from the account screen.
10. Children
Yovio is not intended for children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us data, please write to support@yovio.io and we will delete it.
11. Telegram Mini App notice
Yovio is an independent service that happens to run inside Telegram. Nothing in this Policy overrides the Telegram Privacy Policy, the Bot Terms, or the Mini App Terms, which continue to govern your relationship with Telegram itself. If there is a conflict between this Policy and the Telegram terms in relation to data Telegram processes on its own platform, the Telegram terms apply.
12. Links to third parties
The Mini App may link to external websites — for example, payment receipts hosted by Stripe, blockchain explorers for crypto transactions, or the websites of mobile network operators. We do not control those websites and we are not responsible for their privacy practices. Read their policies separately.
13. Changes to this Policy
We may update this Policy. When we do, we will change the “Last updated” date at the top, and — if the change is significant — we will let you know inside the Mini App or by email before it takes effect. Continuing to use Yovio after the new version takes effect means you have accepted it.
14. Contact
Questions, complaints, or requests:
- Email: support@yovio.io
- Phone: +1 575-221-6992
- Support: through the support flow inside the Yovio Mini App
- Post: Yovio LLC, 1209 Mountain Road Pl Ne, Ste N, Albuquerque, NM 87110, US