Privacy Policy
Last updated: June 4th 2026
This Privacy Policy explains how Wander Services Pte. Ltd., a company incorporated in Singapore, operating under the brand Journey Stack (“Journey Stack”, “we”, “us”, or “our”), collects, uses, discloses, stores, and protects personal data when you visit journeystack.co, use our platform, APIs, agent portal, white-label storefronts, eSIM services, or otherwise interact with us.
By using our website, platform, products, or services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our services.
1. Who We Are
Journey Stack helps travel companies, travel agents, OTAs, airlines, DMCs, and other partners offer travel eSIM and global connectivity services to their customers. Our services may include access to an agent portal, APIs, white-label storefronts, eSIM plan search, eSIM issuance, eSIM status tracking, top-ups, customer support, and related connectivity services.
For privacy matters, you may contact us at:
Wander Services Pte. Ltd.
Email: support@journeystack.co
Registered address: [Insert registered Singapore address]
2. Scope of This Privacy Policy
This Privacy Policy applies to personal data collected through:
- our website;
- our Journey Stack platform and dashboards;
- our agent portal;
- our APIs;
- our white-label or co-branded storefronts;
- eSIM purchase, issuance, activation, top-up, and support flows;
- customer support, sales, onboarding, and partner communications;
- marketing, newsletters, forms, events, surveys, and demonstrations.
Where Journey Stack provides services through a business partner, travel company, agent, reseller, or white-label storefront, that partner may also collect and process personal data under its own privacy policy. You should review the privacy policy of the relevant partner where applicable.
3. Personal Data We Collect
The personal data we collect depends on how you interact with us.
3.1 Business and account information
When a partner, agent, or business user creates an account, requests a demo, signs up to our platform, or communicates with us, we may collect:
- name;
- business email address;
- phone number;
- company name;
- job title;
- country or region;
- billing details;
- login credentials;
- account role and permissions;
- communication preferences;
- information submitted through forms, chat, email, or customer support channels.
3.2 End-user and eSIM service information
When an eSIM is purchased, issued, activated, topped up, or supported through Journey Stack, we may collect or process information such as:
- customer name, where provided;
- email address;
- phone number, where provided;
- country of travel;
- selected eSIM plan;
- order ID;
- transaction reference;
- eSIM QR code or activation details;
- ICCID, IMSI, or related eSIM identifiers;
- activation status;
- usage status;
- top-up history;
- device compatibility confirmation;
- customer support history.
We collect only the information reasonably required to provide, manage, troubleshoot, and support the eSIM service.
3.3 Device, technical, and usage information
When you visit our website or use our platform, we may automatically collect:
- IP address;
- browser type and version;
- device type;
- operating system;
- referring URLs;
- pages visited;
- time and date of access;
- language preferences;
- approximate location based on IP address;
- API logs;
- error logs;
- authentication logs;
- usage and performance data.
This information helps us operate, secure, improve, and troubleshoot our services.
3.4 Payment and billing information
Where payments are made through Journey Stack, we may collect:
- billing name;
- billing email;
- billing address, where required;
- invoice details;
- transaction amount;
- tax information;
- payment status;
- payment reference IDs.
We use third-party payment processors such as Stripe, Razorpay, or other payment providers. We do not intentionally store full credit card numbers, CVV codes, UPI credentials, or complete payment instrument details on our own systems.
3.5 Communications and marketing information
If you contact us, subscribe to updates, attend a demo, download materials, or interact with our marketing campaigns, we may collect:
- name;
- business email;
- company name;
- country;
- marketing preferences;
- communication history;
- responses to surveys, feedback forms, or research requests.
You may opt out of promotional emails at any time by using the unsubscribe link or contacting us. We may still send non-promotional service messages, including account, billing, security, legal, or operational notices.
4. How We Use Personal Data
We may use personal data for the following purposes:
- to create and manage accounts;
- to onboard partners, agents, and business users;
- to provide access to our platform, APIs, agent portal, and dashboards;
- to search, issue, activate, manage, and top up eSIMs;
- to process orders, wallet balances, invoices, payments, and refunds;
- to confirm eSIM compatibility and service availability;
- to troubleshoot technical issues;
- to provide customer and partner support;
- to monitor service performance and network availability;
- to prevent fraud, abuse, misuse, and unauthorized access;
- to comply with telecom, tax, accounting, regulatory, law enforcement, or legal obligations;
- to communicate service updates, security notices, and policy changes;
- to improve our website, platform, products, and user experience;
- to conduct analytics, reporting, and business planning;
- to send marketing communications where permitted by law;
- to enforce our Terms and Conditions and other agreements;
- to protect our rights, users, partners, systems, and business.
5. Legal Basis and Consent
Where required by applicable law, we rely on one or more of the following grounds to collect, use, or disclose personal data:
- consent;
- performance of a contract;
- legitimate business interests;
- compliance with legal obligations;
- protection of rights, safety, and security;
- purposes that a reasonable person would consider appropriate in the circumstances.
For users in Singapore, we handle personal data in accordance with the Personal Data Protection Act 2012 of Singapore and its related regulations, where applicable.
For users in the European Economic Area, United Kingdom, or other jurisdictions with specific privacy rights, we will apply applicable data protection requirements where they apply to our services.
6. Sharing of Personal Data
We may share personal data with third parties where necessary to provide our services, operate our business, or comply with legal obligations. These third parties may include:
- telecom operators;
- eSIM suppliers;
- roaming partners;
- SM-DP+ or eSIM provisioning providers;
- cloud hosting providers;
- payment processors;
- analytics providers;
- fraud prevention and security providers;
- customer support tools;
- email and communication providers;
- professional advisers;
- auditors, accountants, lawyers, and insurers;
- government authorities, regulators, courts, law enforcement agencies, or other parties where required by law.
Where Journey Stack works with partners, agents, resellers, OTAs, airlines, DMCs, or travel companies, relevant service data may be shared with such partners for the purpose of fulfilling orders, managing customer support, reporting, billing, reconciliation, and service delivery.
We do not sell personal data in exchange for money.
7. International Transfers
Journey Stack is based in Singapore, but our service providers, telecom partners, cloud providers, payment processors, and business partners may be located in other countries. By using our services, you understand that personal data may be transferred to, stored in, or processed in countries outside your country of residence. Where required by applicable law, we will take reasonable steps to ensure that overseas recipients provide a standard of protection comparable to the protection required under applicable data protection laws.
8. Cookies and Similar Technologies
We may use cookies, pixels, tags, analytics tools, and similar technologies to:
- operate the website;
- remember user preferences;
- maintain secure sessions;
- understand website usage;
- improve platform performance;
- measure marketing effectiveness;
- detect fraud or abuse;
- personalize user experience.
Cookies may be set by Journey Stack or by third-party providers we use, such as analytics, advertising, payment, support, or hosting providers.
You can control cookies through your browser settings. If you disable cookies, some parts of our website or platform may not function properly.
9. Data Retention
We retain personal data only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
As a general guide:
- account data may be retained while the account remains active;
- billing, tax, and invoice records may be retained for legal and accounting purposes;
- eSIM order and service records may be retained for service, dispute, fraud prevention, and regulatory purposes;
- customer support records may be retained for quality, training, and dispute resolution;
- marketing data may be retained until you unsubscribe or ask us to delete it, unless we need to retain limited records to respect your opt-out.
When personal data is no longer required, we will delete, anonymize, or securely archive it, unless retention is required by law or legitimate business purposes.
10. Security
We take reasonable technical and organizational measures to protect personal data against unauthorized access, loss, misuse, disclosure, alteration, or destruction.
These measures may include:
- access controls;
- encryption where appropriate;
- secure cloud infrastructure;
- authentication controls;
- monitoring and logging;
- internal policies;
- limited access based on role;
- vendor due diligence;
- incident response processes.
However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.
11. Data Accuracy
You are responsible for providing accurate and up-to-date information. If you provide incorrect information, we may be unable to deliver the eSIM service, process orders, provide support, or comply with legal obligations. You may contact us to update or correct your personal data.
12. Your Rights
Depending on your location and applicable law, you may have rights to:
- request access to your personal data;
- request correction of inaccurate personal data;
- withdraw consent where processing is based on consent;
- request deletion of personal data;
- object to certain processing;
- request restriction of processing;
- request portability of your data;
- opt out of marketing communications;
- file a complaint with a data protection authority.
To exercise your rights, please contact us at support@journeystack.co.
We may need to verify your identity before responding to your request. We may also retain certain information where required for legal, security, fraud prevention, accounting, dispute resolution, or service purposes.
13. Children’s Privacy
Our services are intended for business users, travel partners, agents, and travelers who are legally able to use our services. We do not knowingly collect personal data from children without appropriate consent. If you believe a child has provided us personal data without proper consent, please contact us.
14. Third-Party Websites and Services
Our website, platform, emails, or partner storefronts may contain links to third-party websites, applications, payment providers, or services. We are not responsible for the privacy practices, security, or content of third-party services. You should review their privacy policies before providing personal data to them.
15. Business Transfers
If Journey Stack or Wander Services Pte. Ltd. is involved in a merger, acquisition, financing, restructuring, sale of assets, or transfer of business, personal data may be disclosed or transferred as part of that transaction, subject to applicable law.
16. Data Breach Notification
If a data breach occurs, we will assess the incident and take reasonable steps to contain, investigate, and remediate it. Where required by applicable law, we will notify affected individuals, partners, regulators, or authorities.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on our website with the revised “Last updated” date. Your continued use of our services after the updated Privacy Policy is posted means you accept the updated policy.
18. Contact Us
For questions, requests, or concerns about this Privacy Policy or our handling of personal data, please contact: