Privacy Policy

Last updated: September 14, 2026

This Privacy Policy explains how the personal data of individuals (“User” or “You”) who use the Carettago.com website and all telecommunications/eSIM services offered by Caretta Digital OÜ (the “Company”, “We”, or “Carettago”) is collected, used, shared, and protected. By using our services, you accept the practices stated in this policy.

1. Introduction and Scope

This Privacy Policy explains how the personal data of individuals who use the Carettago.com website, mobile applications, and all telecommunications/eSIM services offered by Caretta Digital OÜ, established under the laws of Estonia, is collected, used, shared, and protected.

2. Information We Collect

Our company has adopted the principle of minimal data collection to provide services and ensure platform security.

  • Information provided by you: name, email address, and billing address provided during account creation or guest purchases.
  • Device and usage information: IP address, browser type, device model, operating system, EID (Embedded Identity Document) number, and network activation status information, automatically collected for the Service (eSIM) to work on your device.
  • Financial information: our Company cannot see, store, or process your credit card or bank card numbers on its servers. All payment transactions are managed directly and securely, via encryption, by international PCI-DSS certified third-party payment providers (e.g. Stripe).

3. Purposes of Using the Information

  • Creating eSIM profiles, delivering them to your device, and providing cellular data access in the targeted country.
  • Technically reviewing and finalising refund and cancellation requests subject to the “0 byte data usage” condition described in our Refund Policy.
  • Ensuring platform security, detecting fraud attempts, and defending our legal rights during chargeback processes.
  • Fulfilling our commercial and financial legal obligations in Estonia and the European Union.

4. Information Sharing and Third Parties

Carettago never sells your data to third parties for advertising purposes. However, due to the nature of our telecommunications business model, your data must be shared with certain business partners:

  • Local operators and API providers: for the data plan you purchased to work in the respective country, your device’s connection data (EID, activation signal) is transferred to telecom operators in that country. From the moment your data reaches that local operator’s network, the security and processing of this data is subject to the operator’s own privacy policies, and Caretta Digital OÜ cannot be held responsible for the data processing practices of local operators.
  • Service providers: authorised companies we work with for matters such as hosting, customer support, and payment infrastructure.
  • Legal obligations: where necessary to comply with court orders, requests from official authorities, or to protect our company’s legal rights.

5. International Data Transfer

As a global telecommunications provider, when you purchase an eSIM for a destination outside the European Economic Area (EEA), transferring your device and activation data to that country is mandatory for the performance of the contract (establishing your connection). By purchasing the Service, you accept this technical necessity and the international data transfer.

6. Data Security and Limited Liability

Our company uses SSL encryption and industry-standard firewalls to protect your personal data against unauthorised access, alteration, or destruction. However, no data transmission over the internet can be guaranteed to be 100% secure. Even though our company has taken reasonable security measures, it cannot be held financially or legally responsible for data breaches resulting from potential cyberattacks.

7. Cookies and Tracking Technologies

Our platform uses cookies to improve your experience, keep your session active, and prevent fraud. See our Cookie Policy for full details on the types of cookies we use and how to control them.

8. Data Retention Period and User Rights

In accordance with the EU GDPR and relevant data protection laws, you have the right to access, correct, delete (right to be forgotten), and port your data. However, data that may be subject to invoice and payment dispute (chargeback) processes must be kept securely during the legal statute of limitations (7 years) in accordance with Estonian financial legislation. You can contact us at support@carettago.com to exercise your rights.

9. Policy Changes

Caretta Digital OÜ reserves the right to unilaterally update this policy without prior notice due to legal requirements or changes in the business model. Changes take effect the moment they are published on the site.

Scroll to Top