Privacy Policy
Last updated: June 5, 2026
Introduction
Eximgroup (“we”, “our”, “us”), trading as whitecatesim.com, operates this website and sells prepaid eSIM data plans. This Privacy Policy explains what personal data we collect, why we use it, and the choices you have.
By using our website or buying a plan, you acknowledge this policy. Where consent is required by law, we will ask for it separately.
Data we collect
Information you provide
- Email address and name collected at checkout or when you sign in
- Messages and details you send through our contact form
- Order and payment references needed to fulfill your purchase
Information collected automatically
- Device and browser type, pages visited, and referral information
- Approximate attribution data such as campaign tags (for example gclid, utm parameters, yclid)
- Session and cookie identifiers needed to run the site and checkout
- IP address for security, fraud prevention, and support troubleshooting
Payment information
Card payments are processed by Stripe. We do not store full card numbers on our servers. Stripe handles payment data under its own privacy policy.
How we use your data
- Process orders and deliver eSIM activation details
- Provide customer support and respond to inquiries
- Operate accounts, order history, and magic-link sign-in
- Improve the website, measure marketing performance, and prevent abuse
- Comply with legal, tax, and accounting obligations
Legal bases (EEA / UK users)
Where GDPR or similar law applies, we rely on: contract performance (fulfilling your order), legitimate interests (security, analytics, service improvement), legal obligation, and consent where required (for example optional marketing if offered).
How we share data
We do not sell your personal data. We share data only when needed to run the service:
- Stripe — payment processing
- Cloudflare Turnstile — spam protection on the contact form
- Mobile network and eSIM provisioning partners — to activate the plan you purchased
- Infrastructure providers — hosting and email delivery
- Authorities when required by law or to protect rights and safety
International transfers
Some providers may process data outside your country. Where required, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms.
Retention
- Order and billing records — kept as long as needed for support, tax, and legal compliance
- Contact form messages — typically up to 2 years after resolution
- Analytics visit records — kept for reporting and attribution analysis
- Session data — for the duration of your browser session or configured session lifetime
Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, or object to certain processing, and to receive a copy of your data in a portable format.
To exercise these rights, email [email protected]. We may need to verify your identity. You may also lodge a complaint with your local data protection authority.
Security
We use technical and organizational measures appropriate to the data we process, including HTTPS, access controls, and secure payment handling through Stripe/Paddle. No online service can be guaranteed 100% secure.
Children
Our services are not directed at children under 16. We do not knowingly collect personal data from children.
Cookies
See our Cookie Policy for details on cookies and how to control them.