Effective Date: 2026-06-11
Last updated: 2026-07-30
Dejitech, Inc. dba Bcengi
Bcengi is committed to protecting your privacy. This policy explains what personal information we collect, how we collect it, every way we use it, who we share it with, how long we keep it, how you can delete it, and how you can withdraw your consent.
Refunds: for when we refund a charge and how to request one, see our Refund Policy.
1. Who We Are and What This Policy Covers
Bcengi is a trading name of Dejitech, Inc., a corporation incorporated in New Jersey in 2018 and headquartered in New Jersey, United States. In this policy, "Bcengi", "we", "our" and "us" mean Dejitech, Inc. dba Bcengi.
This policy covers all of our services, wherever you use them:
- The Bcengi websites, including www.bcengi.com and our customer web app.
- The Bcengi mobile app for iPhone and iPad, distributed through the Apple App Store.
- The Bcengi mobile app for Android, distributed through Google Play.
- Our eSIM data services (TravelPass, WorkPass and AgentPass), Travel Numbers, our in-app travel assistance features, our reseller and enterprise portals, and our APIs.
If your eSIM or account was provided to you by your employer or another organization, for example through WorkPass or AgentPass, that organization controls your account and can see the usage and policy information associated with it. In that case we act on its instructions, our Data Processing Agreement applies, and you should send privacy requests to that organization first. We will help it respond.
2. Information We Collect and How We Collect It
We collect personal information in four ways: you give it to us, we generate it as we deliver your service, your device and browser provide it automatically when you use our apps and websites, and our service providers pass it to us. We do not buy personal information about you from data brokers.
Information you provide
- TravelPass and AgentPass: your email address for account registration (no password is stored, because we sign you in with a one-time code or through Google or Apple), and your country and postal code for regional service configuration and compliance.
- WorkPass: company name, business contact information, billing details, and administrator and user email addresses for account setup.
- Payment details: saved payment method information, stored by Stripe, our certified payment provider. Bcengi does not store full card details.
- Support messages: anything you write to us by email or in our in-app chat.
- Sign-in through Google or Apple: if you choose this, we receive a signed identity token containing your email address and a provider account identifier. We never receive your password. If you use Apple's Hide My Email, we receive an Apple private relay address, and the app may ask you once for an alternative address so we can reach you about your service.
eSIM and service data we generate
- Data consumption per country.
- Activation and top-up timestamps.
- Plan usage, account balance and balance history.
- eSIM identifiers such as EID and ICCID.
Travel Numbers (voice and SMS)
If you lease a Travel Number:
- Identity verification (government ID, selfie and address) is performed and stored entirely by Stripe Identity, our verification provider. Bcengi does not store your identity documents and receives only the verification outcome.
- The phone number leased to you and the numbers you communicate with.
- Message content and call records (timestamps, duration and destinations), as needed to deliver the service and show you your message and call history.
Device, app and technical information collected automatically
- Device manufacturer and model, operating system version, app version, platform, language and time zone.
- IP address, and the approximate country and region derived from it.
- App and web usage events: screens and pages you open, features you use, and actions such as completing a signup or a purchase.
- Crash and error diagnostics: the stack trace, the app operation that failed, and the device state at the time, such as available memory and storage and whether the app was in the foreground.
- The device and app identifiers listed in section 3.
Referral and marketing parameters
When you arrive from a partner link, an advertisement or a deep link into the app, we capture the referral and campaign parameters in the address, specifically "im_ref", "irpid", "sharedid" and any "utm_" parameters. On Android we may also read the Google Play install referrer once, on first launch, for the same purpose. Section 4 explains how long we keep these and what we do with them.
Location
Our in-app travel assistance features can use your approximate location to show you nearby places and directions. The app asks for location permission first, the feature works without it, and you can turn the permission off at any time in your device settings.
Camera
The app may ask for camera access so you can scan a QR code. Images are used for that scan and are not stored by us.
3. Device and App Identifiers
We and our providers use the following identifiers. None of them reveal your name.
- Your Bcengi user identifier, the internal account number we use to link your data to your account.
- Analytics identifiers generated by our analytics provider to recognize the same browser or app installation between visits.
- A Firebase installation identifier and, if you allow notifications, a device push token issued by Apple or Google.
- On iOS: the vendor identifier for your device. We do not collect the Apple advertising identifier (IDFA) and we do not use Apple's AdSupport framework.
- On Android: device manufacturer, model and operating system version, and the Google Advertising ID (AAID), which our analytics and advertising measurement providers collect by default. We do not read your device serial number, IMEI or MAC address.
4. Referral and Attribution Data
Referral and campaign parameters let us credit the partner, creator or campaign that introduced you to Bcengi, and let us measure whether our marketing works.
- On our websites we store them in a first-party cookie named "impact_attrib" on the bcengi.com domain, for 30 days.
- In our apps we store them locally on your device, also for 30 days.
- If you create an account or make a purchase within that window, we attach those parameters to the signup or purchase and report the event to our attribution partner, Impact, so the referring partner is credited.
- After the window expires, or after a purchase has been credited, the stored parameters are no longer used.
5. Push Notifications
Our apps ask your permission to send push notifications. If you allow it, Apple's or Google's push service issues a token for your device, which we use to deliver notifications about your account, your eSIM balance and your service status. We do not use push notifications to send you marketing unless you have separately opted in to marketing. You can turn notifications off at any time in your device settings, or per channel on Android, without losing access to the service.
6. How We Use Your Data
These are all of the purposes for which we use your personal information:
- Create and manage your account and sign you in.
- Activate, provision and manage your eSIMs, and deliver data connectivity.
- Deliver your calls and messages if you lease a Travel Number, and verify your identity as the law and our carriers require before we activate one.
- Process payments, including automatic balance refills when your balance runs low, if you have enabled that.
- Track your account balance and usage, and show you your history.
- Provide customer support and troubleshoot technical problems.
- Manage business and reseller accounts, including WorkPass policies and budgets and AgentPass rewards.
- Detect, investigate and prevent fraud, abuse, card testing and automated attacks, and enforce our Terms of Service.
- Understand how our products are used, so we can improve them, and decide which features to show you, including through feature flags that turn features on or off for groups of users.
- Diagnose crashes and errors, so we can fix them.
- Send you service and account notifications by email and push.
- Send you marketing emails, only if you have opted in.
- Measure whether our marketing and our partner referrals work, as described in sections 4 and 10.
- Meet our legal, tax, accounting, telecommunications and sanctions obligations, and respond to lawful requests from authorities.
We do not use your personal information to build behavioral profiles for third parties, and we do not sell it.
7. Legal Basis for Processing
Where data protection law requires a legal basis, ours are:
- Performance of a contract: creating your account, provisioning eSIMs, delivering connectivity, calls and messages, taking payment and providing support.
- Legal obligation: tax and accounting records, telecommunications and identity-verification requirements, sanctions screening and responses to lawful requests.
- Legitimate interests: keeping the platform secure, preventing fraud and abuse, diagnosing crashes, understanding product usage in order to improve the service, and measuring our own marketing. We balance these against your rights and use the least intrusive option that works.
- Your consent: marketing emails, push notifications, location access, camera access, and, on iPhone and iPad, app tracking permission, which governs whether the conversion events we send to Google Ads and Meta carry the keys that identify you personally, namely your Bcengi user identifier and a hashed version of your email address, as described in section 10. It does not govern whether those conversion events are recorded, which happens either way. You can withdraw consent at any time, as described in section 16.
8. How We Share Your Data
- We do not sell your personal data.
- Telecom operators and mobile network providers, for eSIM provisioning and connectivity.
- Communications providers and carriers, for delivering your calls and messages and for routing and regulatory compliance.
- Payment and identity providers, for secure transactions and verification.
- The service providers named in section 9, each for the single function described there.
- Cloud hosting, infrastructure and support providers operating under confidentiality agreements.
- An organization that provided your account, if your eSIM came to you through WorkPass or AgentPass.
- A buyer or successor, if we are ever involved in a merger, acquisition or sale of assets. We will tell you before your data becomes subject to a different privacy policy.
- Authorities, only when legally required.
Mobile phone numbers and SMS opt-in consent are never shared with third parties or affiliates for marketing or promotional purposes.
9. Third-Party Services We Use
These are the third parties that receive personal information when you use Bcengi, and exactly what each one receives.
- Stripe (payments and Stripe Identity): card and billing details, transaction amounts and, for Travel Numbers, your identity documents and selfie. Bcengi does not store full card details or identity documents.
- HubSpot (customer support and in-app chat): your email address, your support messages and your account identifier.
- Twilio (voice and SMS delivery for Travel Numbers): your leased number, the numbers you communicate with, message content and call metadata.
- PostHog (product analytics and feature flags): app and web usage events, screens and pages viewed, your Bcengi user identifier and your email address as an account property, device and app context, and your IP address. Session and screen recording is switched off. This traffic is routed through our own domain, g.bcengi.com.
- Firebase, part of Google (crash reporting, push delivery and basic app analytics): Crashlytics receives crash and error reports, which include your device model, operating system version, app version, memory and storage state, the app operation that failed and your Bcengi user identifier, but not your email address. Firebase Cloud Messaging receives your device push token in order to deliver notifications. Firebase Analytics receives basic app events such as first open, session start and screen views.
- Google Sign-In and Apple Sign-In (identity): each provider tells us your email address and a provider account identifier when you choose to sign in with it, and each tells your provider account that you signed in to Bcengi.
- Impact, impact.com (referral and affiliate attribution): the referral parameters described in section 4, together with the fact that a signup or a purchase occurred and its value, so that the referring partner can be credited.
- Cloudflare Turnstile (bot and fraud check): when you add a payment method or complete a purchase, and on other sensitive forms such as sign-up and password recovery, Cloudflare receives your IP address, browser or in-app browser signals and the page origin in order to score whether the request is automated. We pass no account data to Turnstile.
- Google Tag Manager, server-side, on our own domain g.bcengi.com (conversion measurement): signup, initial payment and manual payment conversion events, each carrying your Bcengi user identifier, your email address and a hashed version of your email address, the order value and currency, a transaction identifier, and your IP address and approximate country. Section 10 explains what happens to those events.
- Google Ads and Meta (measurement of our own advertising): the signup and purchase conversion events described in section 10, sent from our server-side container at g.bcengi.com, each carrying your Bcengi user identifier and a hashed version of your email address, the order value and currency, a transaction identifier, and your IP address and approximate country. On Android these events can also carry the Google Advertising ID. On iPhone and iPad no advertising identifier is included, and if you decline app tracking we omit your Bcengi user identifier and your hashed email address from these events.
- Sentry (error monitoring on our websites): error reports including your IP address and the request context in which the error happened.
- Google Maps (maps and places in our in-app travel assistance features): map and place requests, which include the approximate area you are looking at.
- Cloud hosting, storage and email delivery providers: the data needed to run the platform and to send you service email.
10. Advertising and Conversion Measurement
We do not run ad networks inside our apps, we do not show you third-party advertisements in our products, and we do not use tracking cookies to build behavioral profiles of you.
We do measure whether our own advertising works. When you sign up or make a purchase, our server-side container at g.bcengi.com reports that a conversion happened, and its value, to the advertising platforms we buy from, which include Google Ads and Meta. On iPhone and iPad this sharing is what makes the app subject to Apple's App Tracking Transparency rules, because those events carry your user identifier and a hashed version of your email address, and not because we collect any advertising identifier there. Under some laws, including the California Consumer Privacy Act as amended by the CPRA, that kind of conversion measurement can count as "sharing" personal information for cross-context behavioral advertising. We treat it as such, and you can opt out at any time by emailing privacy@bcengi.com. We never sell your personal information for money.
11. Cookies and Similar Technologies
We use:
- Essential cookies, for login sessions and account authentication. The service cannot work without these.
- A first-party referral cookie, "impact_attrib", described in section 4, which expires after 30 days.
- First-party analytics and conversion measurement, as described in sections 9 and 10, served from our own domain.
You can clear or block cookies in your browser settings. Blocking essential cookies will stop you from signing in.
12. Protection Required of Third Parties
Every third party with whom we share your personal data is contractually required to provide the same or a greater level of protection for that data than this policy and applicable data protection law require, to process it only for the limited purpose we specify and on our instructions, to keep it confidential and secure, to notify us of any breach, and never to sell it or use it for their own purposes. We assess each provider's security and privacy practices before we engage it, we review them as our use changes, and we end the relationship and require deletion or return of the data if a provider cannot meet that standard.
13. Data Transfers and Storage
We are a United States company, and your data may be stored or processed in the United States, the European Union or other regions where we or our providers operate. Where personal data leaves the European Economic Area, Switzerland or the United Kingdom, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and additional technical measures such as encryption in transit and at rest.
14. Data Retention
We keep personal data only as long as we need it:
- Account and profile data: while your account is active, and then deleted or anonymized when your account is deleted, as described in section 15.
- eSIM usage and balance records: while your account is active, and afterwards in anonymized form for reporting.
- Message and call history for Travel Numbers: while your account is active, or until you delete it. Voicemails and call recordings are automatically deleted after 90 days.
- Transaction, invoice and tax records: for the periods that tax, accounting, telecommunications and anti-fraud law require, typically several years, after which they are deleted or fully anonymized.
- Crash and error diagnostics: for the retention period of the provider, which is currently 90 days for crash reports.
- Referral and attribution parameters: 30 days, as described in section 4.
- Support conversations: for as long as we need them to handle your issue and to show the history of your account, and then deleted on request.
- Anonymized, aggregated statistics that cannot be linked back to you may be kept indefinitely.
15. Account Deletion
You can delete your Bcengi account and its personal data yourself, from inside the app, on both iPhone and Android.
In the app. Open Profile, then Account, then Profile Info, and choose Delete Account. The app first shows you what deletion removes, then asks you to type the word "delete" to confirm, so the action cannot be triggered by accident. Deletion is permanent and cannot be undone.
Without the app, from any web browser. Email privacy@bcengi.com from the address on your account and ask us to delete it. We verify that the request came from you, and we complete verified deletion requests within 30 days.
What deletion does.
- Your login identity is irreversibly detached. Your email address is replaced with a placeholder and any Google or Apple sign-in link is removed, so the account can never be signed into or recovered, and the email address is freed for future signup.
- Your personal details are erased or anonymized, including your name, profile information, address, saved travel assistance data and referral attribution data.
- Your active eSIM lines are deactivated and stop working.
- Your saved payment methods are removed.
- Any loyalty points and tier status are lost.
- Any remaining account balance is forfeited and is not refunded, except where a refund is required by law. Use or move your balance before you delete your account.
- Your session is ended and the app signs you out.
What we keep, and why. We keep transaction, invoice and tax records, and records we are required to retain under telecommunications and anti-fraud rules, for the periods those laws require. Those records are stripped of identifying information and are no longer linked to you as an identified person. We also keep anonymized, aggregated usage statistics that cannot be traced back to you. Nothing we keep can be used to sign in to or restore your account.
If you only want to remove one eSIM or one line rather than your whole account, you can do that in the app without deleting your account.
16. Withdrawing Consent and Managing Your Data
Anything you agreed to, you can take back:
- Marketing emails: use the unsubscribe link in any marketing email, or email privacy@bcengi.com.
- Push notifications: turn them off in your device settings, or per channel in Android settings.
- Location and camera access: turn the permission off in your device settings at any time.
- App tracking on iPhone and iPad: go to Settings, then Privacy and Security, then Tracking, and turn off tracking for Bcengi. We continue to record the conversion events described in section 10, but we stop including your Bcengi user identifier and your hashed email address when we send them to Google Ads and Meta. This setting applies only to Google Ads and Meta. It does not affect the customer support and product analytics services described in section 9.
- The Google Advertising ID on Android: open Settings, then Privacy, then Ads, and delete your advertising ID.
- Automatic balance refills: disable auto-refill or remove your saved payment method at any time in your account settings.
- Product analytics and conversion measurement: email privacy@bcengi.com and we will exclude your account.
- Everything at once: delete your account, as described in section 15.
Withdrawing consent does not affect processing that already happened lawfully, and it does not affect processing we must continue for legal or contractual reasons.
17. Security
We protect your data with encryption in transit and at rest, role-based access controls and least-privilege access, secure infrastructure and network policies, continuous monitoring and vulnerability management, and a bot and fraud check on sensitive actions. While no system is completely secure, we take appropriate steps to safeguard your information.
18. Data Breach Notification
If a data breach occurs that affects your personal data, we will notify affected users promptly, inform regulators within the deadlines the law sets, and provide the details we know and the steps you can take.
19. Your Rights
Wherever you live, you can ask us to:
- Confirm what personal data we hold about you, and give you a copy.
- Correct data that is wrong or incomplete.
- Delete your data and your account.
- Restrict or object to processing that relies on our legitimate interests.
- Receive your data in a portable, machine-readable format.
- Withdraw a consent you gave us.
- Opt out of the conversion measurement described in section 10.
To make a request, email privacy@bcengi.com. We will verify that the request comes from you, respond within 30 days, and tell you if we need longer and why. We do not charge for this and we will not treat you differently for asking.
20. If You Are in the EEA, Switzerland or the United Kingdom
For services you buy directly from us, Dejitech, Inc. dba Bcengi is the controller of your personal data. Where your account was provided by an organization such as your employer, that organization is the controller and we act as its processor.
In addition to the rights in section 19, you have the right to lodge a complaint with your local data protection supervisory authority, and the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you. Section 22 explains that we do not make such decisions. Our legal bases are set out in section 7 and our transfer safeguards in section 13.
EU and UK representative. Bcengi is a United States company and does not currently have an establishment in the European Union or the United Kingdom. If you are in the EEA, Switzerland or the UK, contact us directly at privacy@bcengi.com for any request or complaint under the GDPR or the UK GDPR, and we will answer within the time limits the law sets. Where we are required to appoint a representative under Article 27 of the GDPR or the UK GDPR, we will name that representative and publish their contact details in this section.
21. If You Are in California
This section is for California residents and uses the terms of the California Consumer Privacy Act as amended by the CPRA.
Categories of personal information we collect, drawn from the sources in section 2 and used for the purposes in section 6:
- Identifiers: name where you give it, email address, postal code, country, IP address, account identifier and device identifiers.
- Commercial information: your purchases, balance, top-ups and refunds.
- Internet and network activity: app and website usage, screens and pages viewed, and crash diagnostics.
- Geolocation data: approximate location, and only if you grant location permission.
- Electronic communications content: for Travel Numbers only, the content and metadata of the calls and messages you send and receive through the service.
- Sensitive personal information: for Travel Numbers only, government identification documents and a selfie, collected and held by Stripe Identity and used solely to verify that you are who you say you are, as our carriers and the law require. We do not use sensitive personal information to infer characteristics about you.
Your California rights: to know what we collect, use, disclose and share; to receive a copy of your personal information; to correct inaccurate information; to delete your personal information; to opt out of sharing for cross-context behavioral advertising; to limit our use of sensitive personal information; and not to be discriminated against for exercising any of these rights.
We do not sell personal information for money, and we do not knowingly sell or share the personal information of consumers under 16. The conversion measurement in section 10 may count as sharing, and you can opt out of it by emailing privacy@bcengi.com with the subject "Do Not Share My Personal Information".
To exercise any California right, email privacy@bcengi.com. You may use an authorized agent, in which case we will ask for proof of their authority and may still verify your identity directly.
22. Automated Decision-Making
We do not use your personal data to make automated decisions that affect your access or your legal rights. Our fraud and bot checks can require an extra verification step or decline a payment attempt, and a person reviews the outcome if you ask us to.
23. Children's Privacy
Our services are intended for users aged 16 and up. We do not knowingly collect data from children under 16. If we learn that we have, we will delete it. If you believe a child has given us personal data, email privacy@bcengi.com.
24. Changes to This Policy
We may update this policy. The "Last updated" date at the top of this page always shows the current version. If the changes are significant, we will notify you by email or in our apps and websites before they take effect. Continuing to use our services after that means you accept the updated policy.
25. Contact Us
For privacy questions, requests and complaints: privacy@bcengi.com
For help with your service: support@bcengi.com
Dejitech, Inc. dba Bcengi, New Jersey, United States.
See also our Terms of Service and our Refund Policy.