Privacy Policy
Last updated: 17 July 2026
soda (soda.travel, “we”) takes your privacy seriously — and not just as a slogan: we're registered in Switzerland, we don't need your ID documents, and our default analytics use no cookies. This policy explains what we collect, why, who we share it with, how long we keep it, and the choices you have.
1. What we collect, and why
Account data. Your email (your sign-in identity and where verification codes go), the public key of your passkey (if you create one), and sign-in records. soda has no passwords, so we store none.
Payment data. Payments are processed by Stripe; your full card number lives only with Stripe and never passes through or gets stored by soda. We keep top-up and settlement records (amounts, timestamps, the plan combination applied) for billing, receipts, and refunds.
eSIM and usage data. The eSIM identifier (ICCID), provisioning status, and data volume per market with timestamps. These come from our upstream carrier suppliers' metering records and are the basis of usage-based billing — without them the lowest-combination settlement cannot be computed. We do not inspect your traffic: what you browse or message is not visible to soda, and we want it that way.
Notification data. If you enable browser push, we store the push subscription endpoint and its encryption keys (a browser-generated public key and auth secret, which ensure only your browser can decrypt the content) to deliver essential notifications (usage alerts, install confirmation, trip receipts); disabling push invalidates and removes it. Email notifications use your account email.
Support records. Your correspondence with support and the context needed to resolve the issue.
Waitlist data. The email and interest you chose to leave us (e.g. which feature you want), along with the rough country and browser info of the submission, used only to notify you and understand demand — no marketing blasts.
Website analytics, via two tools:
- Plausible: privacy-friendly, uses no cookies, doesn't track individuals, and only reports aggregates (e.g. how many views a page got). It can't identify you, so it runs by default.
- Google Analytics 4 (GA4): more detailed analytics. It runs only after you click “Accept”, setting cookies in your browser (such as
_ga) to distinguish unique visitors. If you don't accept, it does nothing and sets no cookies.
What we don't collect: identity documents. soda requires no KYC — carrier-side registration is handled by the telecom layer and cardholder verification by the payment provider, so we never hold a copy of your passport or ID.
2. Legal bases
We only process personal data with a basis for it:
- Performing our contract — providing connectivity, billing and settlement, receipts, refunds, account sign-in.
- Legal obligations — keeping transaction records for tax and accounting.
- Your consent — GA4 analytics and browser push. Withdrawing consent is as easy as giving it, any time.
- Legitimate interests — preventing fraud and abuse, operating and debugging the service, improving the product using aggregates.
3. Cookies and your consent
Two kinds, treated differently:
Essential cookies. The session cookie after you sign in — without it you can't stay signed in. It isn't used for tracking and doesn't require a consent banner. Your cookie choice itself is stored in your browser's localStorage.
Analytics cookies. We use Google Consent Mode v2: no analytics cookies are enabled until you make a choice.
- On your first visit you'll see a cookie banner — Accept or Decline.
- Decline → GA4 stays off; only the cookieless Plausible runs.
- Accept → GA4 is enabled and sets analytics cookies.
- You can change your choice anytime:
4. Who we share data with
We don't sell your data, and we don't trade it for ad targeting. It's only processed by the services that help us operate, each getting only what it needs:
- Stripe — payment processing and refunds. Your card number is held by Stripe under its own policies.
- Upstream eSIM suppliers and local carriers — provisioning the eSIM, providing connectivity, reporting usage. They handle the eSIM identifier and network-level data; they never see your email or payment details.
- Cloudflare — website and API hosting, CDN, and database connection proxying (Hyperdrive) — database queries pass through its infrastructure.
- Neon — managed database. Account data, top-up and settlement records, usage records, push subscriptions, and the waitlist are stored here.
- Resend — transactional email delivery (sign-in codes, journey receipts, billing and usage notices); it handles your email address and message contents.
- Browser push services (depending on your browser — e.g. Apple, Google, or Mozilla) — deliver the push notifications you opt into. They handle the subscription endpoint, delivery metadata, and the encrypted notification payload — which they cannot decrypt; only your browser can read it.
- Plausible — cookieless aggregate analytics.
- Google — GA4 analytics, only after your consent.
Beyond that, we may disclose data where the law requires it (for example, a valid law-enforcement request) or to establish or defend legal claims. If soda goes through a merger or asset transfer, data moves under equivalent protection and you'll be notified in advance.
5. International transfers
The providers above may process data in countries other than yours. We choose providers with appropriate safeguards; where EU or similar personal data is involved, transfers rely on Standard Contractual Clauses (SCCs) or an applicable adequacy decision.
6. How long we keep data
- Account data — for the life of the account; deleted or anonymised within statutory limits after closure.
- Top-up and settlement records — for the periods required by tax and accounting law.
- Usage records — as long as needed for settlement to become final and refund disputes to close, then aggregated.
- Support records — a reasonable period after resolution.
- Waitlist data — a reasonable period after launch notification, or until you ask us to delete it.
- Analytics data — per Google's and Plausible's own policies.
7. Your rights
Wherever you are, you can: access the data we hold about you, correct mistakes, delete your account and data, get a portable copy, object to processing based on legitimate interests, and withdraw consent (e.g. turn off GA4 or push). In the EU, UK, and similar regions these are statutory rights, and you may also lodge a complaint with your supervisory authority.
To exercise them, email privacy@soda.travel. We'll ask you to verify through your account so we know it's you. Note: records we're legally required to keep (e.g. accounting) can't be deleted within their statutory period, but we stop using them for anything else.
8. Security
All data is encrypted in transit (HTTPS). Sign-in uses email codes and passkeys — there is no password to leak — and money-related operations require re-verification. Database access follows least privilege.
No system can guarantee absolute security. If a data incident affects your rights, we'll notify you and the authorities as the law requires.
9. Children
soda is intended for travellers aged 18 or over (or the age of majority where you live) and is not directed at children. If we learn we've collected a child's personal data by mistake, we'll delete it promptly.
10. Updates and contact
We may update this policy; material changes will be posted here with an updated date above. For any privacy questions, or to exercise your rights, contact privacy@soda.travel.