1. Introduction & Scope
Welcome to ConnectMeGuru ("we", "us", or "our"). We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and protect your information when you purchase travel eSIM profiles, utilize our website, mobile applications, Model Context Protocol (MCP) servers, or interact with our authorized ChatGPT Plugin and Custom GPT Actions.
2. Explicit Non-Collection of Sensitive Personal & PCI Data
To ensure strict compliance with international privacy laws and AI platform safety standards, ConnectMeGuru explicitly discloses that we do NOT collect, solicit, or process sensitive personal data through ChatGPT, AI plugins, or conversational tool interfaces:
- No Payment Card Industry (PCI) Information in Chat: We never solicit, process, or store credit card numbers (PAN), CVVs, expiration dates, or bank account credentials inside ChatGPT or conversational interfaces. All credit card and fiat payment transactions are conducted exclusively via external, PCI-DSS Level 1 compliant hosted checkout pages (Stripe and PayPal). In-chat purchases are strictly restricted to pre-funded customer wallet balances.
- No Government IDs, Passports, or SSNs: ConnectMeGuru travel eSIMs are prepaid data-only international roaming bundles. We do not collect Social Security Numbers (SSNs), national identity numbers, passport scans, or require telecommunications eKYC verification.
- No Health or Biometric Information: We do not collect, process, or store medical, health, genetic, or biometric data of any kind.
3. Information We Collect & AI Tool Inputs/Outputs
We collect and process only the minimal data strictly necessary to fulfill your travel data connectivity and provide account support. When using our website or our ChatGPT Plugin / Actions, data is handled as follows:
- Catalog Search & Destination Queries (Tool Input): Destination country names, ISO country codes, or data volume keywords (e.g., "Japan", "Europe 10GB") submitted to discover compatible eSIM data plans.
- User Contact & Delivery Details: Email address provided for account creation, login verification, and delivery of your eSIM profile, activation QR codes, and purchase invoices.
- eSIM Technical & Provisioning Data (Tool Output): Unique eSIM package codes, ICCID identifiers, SM-DP+ carrier server addresses, manual matching IDs, and direct LPA (Local Profile Assistant) activation strings (e.g.,
LPA:1$...). - Account & Wallet Ledger Information: Internal transaction identifiers, promotional discount codes, and digital travel wallet balances (denominated in USD).
- Network & Location Identifiers: Originating IP address and user-agent string, automatically recorded during checkouts, top-ups, and balance operations to calculate applicable regional VAT/sales taxes and prevent fraudulent transactions.
4. How We Use Your Information
We process your data exclusively for legitimate operational, service delivery, and statutory compliance purposes, including:
- Provisioning on-demand cellular data profiles via telecommunications carrier interfaces.
- Delivering eSIM QR codes, activation credentials, and order confirmations via email and in-app display.
- Calculating accurate destination and regional taxes (such as European Union VAT OSS) based on originating network location.
- Atomically managing customer wallet balances, processing top-ups, and issuing automated refunds if an activation fails.
- Authorizing secure customer login sessions via one-time email verification codes (OTPs).
- Safeguarding our platform against payment fraud, spam, and duplicate transactions.
5. Data Recipients & Third-Party Disclosures
We do not sell, rent, or trade your personal data to third parties or advertising networks. We disclose information only to the following trusted infrastructure recipients strictly for service fulfillment:
- Telecommunications Infrastructure Wholesaler (eSIMAccess): Technical package codes and order references are transmitted via secure HMAC-SHA256 signatures to allocate and activate cellular data profiles across global carrier networks.
- External Payment Processors (Stripe & PayPal): Customer billing details are processed directly on secure external payment pages; no card data touches our chat tools.
- Blockchain Settlement Networks (Base, Polygon, Arbitrum): Public wallet transaction hashes for cryptocurrency settlements (USDC, USDT, EURC) without transmitting personal identity details.
- OpenAI: Acts as the conversational interface relaying user queries and receiving structured catalog responses in accordance with OpenAI’s data and privacy policies.
6. Data Retention Schedule
We retain your personal information only as long as necessary to fulfill the purposes outlined in this policy:
- Financial & Invoicing Records: Retained for five (5) years in accordance with international tax compliance, accounting standards, and statutory audit obligations.
- eSIM Operational Records: Retained for the duration of your data plan validity plus ninety (90) days to support data top-ups and customer service inquiries.
- Temporary Security Tokens & OTPs: One-time verification codes expire automatically within fifteen (15) minutes; OAuth access tokens are active until revoked by you.
- Server & Security Logs: IP address logs recorded for tax and security verification are archived in encrypted storage and routinely cycled after ninety (90) days.
7. User Controls & Data Rights (GDPR & CCPA)
Regardless of your geographic location, you retain full ownership and control over your personal data:
- Access & Portability: You may request a machine-readable export of all personal data and order history associated with your account.
- Correction: You may update or correct your account information at any time.
- Erasure ("Right to be Forgotten"): You may request the permanent deletion of your account and associated personal data, subject only to mandatory legal tax retention obligations.
- Revocation of AI Access: You can disconnect and revoke ChatGPT or API tool authorizations at any time.
To exercise any of these rights, contact our Data Protection Officer at support@connectmeguru.com. Requests are verified and fulfilled within thirty (30) days free of charge.
8. OAuth Scopes & Tool Authorizations
When authorizing ConnectMeGuru through ChatGPT or third-party AI assistants, permissions are strictly sandboxed using standard OAuth 2.0 / 2.1 scopes:
read:catalog— Allows the assistant to search active travel eSIM destinations, data plans, and retail pricing.read:wallet— Allows the assistant to check your pre-funded customer wallet balance.write:orders— Allows the assistant to purchase an eSIM plan on your behalf using your available wallet funds.
9. Data Security & Token Revocation
All authentication and API communications are protected by end-to-end Transport Layer Security (TLS 1.3 / SSL) encryption. Your primary account credentials and passwords are never shared with or stored by AI clients. AI clients receive a scoped, cryptographically signed Bearer token that can be revoked by you at any time directly within your ConnectMeGuru Profile Settings.