PANAM eSIM

Privacy Policy

Last updated: August 6, 2026

Jag Project, LLC (PANAM SafeTrip eSIM division; "we", "us") handles personal data in PANAM eSIM and Travel AI Rescue (together, the "Service") in accordance with Japan's Act on the Protection of Personal Information (APPI) and other applicable laws.

1. Operator and contact

Operator: Jag Project, LLC (PANAM SafeTrip eSIM division). Address: 7-13-3 Kameido, Koto-ku, Tokyo 136-0071, Japan.
For privacy inquiries or requests for disclosure, please use our contact form. When you make a request for disclosure, we can also assist you by phone (050-5051-1141).

2. Information we collect

We do not provide a voice (microphone) input feature. Please do not enter or store passwords, card PINs or security codes, or one-time passwords.

3. Purposes of use

We use this information to issue and support eSIMs; process payments and refunds; provide Travel AI Rescue answers, translations, local-language cards, and explanatory drafts; prevent misuse; send important notices; comply with laws; and improve the Service.

4. Special-care-required personal information

Special-care-required personal information such as health, accident, or crime-victimization details is handled only with your prior consent, and only to the extent needed to answer, translate, or draft for the current consultation. We do not use it to train or retrain general-purpose AI models, or for advertising.

5. On-device storage and cloud storage

Information you save in "Safety Registration" and "My Trip" is, by default, stored only on your own device. It is not sent to our servers unless you take an action such as attaching it to an AI consultation, enabling cloud storage, or sharing it with support.
If you enable cloud backup, we store only encrypted data, and the restore code is not sent to our servers, so we cannot decrypt the contents either. On-device encryption takes effect when you set a password on your device.

6. Provision to AI providers and AI training

We use OpenAI, L.L.C. to generate Travel AI Rescue answers. To the extent needed for an answer, we send the consultation text, the images you selected (with location data and EXIF removed), your destination, and recent conversation. The data we send is not used to train general-purpose models (configured so OpenAI does not retain it — store:false). It may be retained for up to about 30 days for misuse monitoring. Processing takes place in the United States. Where possible, we avoid sending your name, email, order number, passport number, card number, detailed hotel address, or precise location. See also our subprocessors and cross-border processing list.

7. Review by our staff

Our staff normally do not read the body of your consultation. Authorized staff review it only to the extent necessary when you share it with support, when we investigate a safety issue or misuse, or when required by law. All such access is logged.

8. Outsourcing and cross-border processing

We use external providers for eSIM issuance (SoftBay Co., Ltd.), payments (PAY, Inc. / Stripe, Inc.), email (Resend, Inc.), AI processing (OpenAI, L.L.C.), and hosting, database, and storage (Cloudflare, Inc.), among others. Subprocessors, processing countries, retention, and AI-training settings are set out in our subprocessors and cross-border processing list, and transmissions from your device are set out in our cookies and external transmissions list. We do not sell personal information.

9. Retention periods

10. Security management

We apply security measures including encryption in transit, access controls, multi-factor authentication for administrators, and operation logging. Cloud backups are stored encrypted. We do not output the body of consultations to logs or error monitoring.

11. Disclosure, correction, deletion, and suspension of use

To request disclosure, correction, deletion, or suspension of use of your information, please make a request from your account page or the contact form. On your account page, you can export your data (disclosure) and delete your account using a confirmation code. Deleting your account removes AI consultations, incident records, support shares, and on-device information. Records required by law, such as orders, payments, and consent, may remain in limited form. Even after we delete information we hold, external subprocessors may retain data for a period under law or contract.

12. Handling of data breaches

If personal data is, or is likely to be, leaked, lost, or damaged, we take the necessary steps in accordance with the law, including reporting to the Personal Information Protection Commission and notifying affected individuals.

13. Minors

Minors should use the Service with the consent of a parent or guardian.

14. Cookies

We use cookies that are necessary for login, purchases, and safety measures. In the EEA, UK and Switzerland, usage analytics run only with your consent; in other regions they run by default and can be stopped anytime from the cookies page. For details, see our cookies and external transmissions list.

15. Changes to this policy

We may revise this policy in response to changes in law or improvements to the Service. When we make a change with a significant impact on users, we will, where appropriate, provide notice before it takes effect.

See also our Terms of Service, Refund & Guarantee, and business disclosure.