Privacy Policy

Last updated: September 2026

This Privacy Policy explains how Rapidez Internet Solutions Limited(trading as CALA, "we", "us", "our") collects, uses, discloses and protects your personal data when you visit our website or purchase and use a CALA eSIM. We process personal data in accordance with the UK GDPR and the EU General Data Protection Regulation (Regulation (EU) 2016/679).

1. Who we are (Data Controller)

  • Company: Rapidez Internet Solutions Limited
  • Registered address: 124 Fergusson House, London EC1V 2NX, United Kingdom
  • Country of incorporation: United Kingdom
  • VAT number: GB441 9929 65
  • Privacy contact: support@calafly.net

We have not appointed a statutory Data Protection Officer as we are not required to do so under Article 37 GDPR. The privacy contact above handles all data-protection enquiries.

2. Personal data we collect

We collect the following categories of personal data:

  • Account data — email address, password (hashed by our authentication provider), display name.
  • Order data — name (first / last), email address, phone number (optional), items ordered, order number, total amount, currency, timestamps.
  • Payment data — Stripe customer ID, Stripe payment intent / session ID, subscription ID (where applicable). We do not receive or store your full payment card details; card data is collected directly by Stripe.
  • Support data — the content of messages you send us and any information you include in them.
  • Technical data — IP address, browser type and version, device type, referring URL and pages visited (server logs, kept short-term for security and abuse prevention).
  • Cookies / local storage — see section 8.

3. Purposes and legal bases for processing

PurposeData usedLegal basis (GDPR Art. 6)
Create and operate your accountAccount dataPerformance of a contract (Art. 6(1)(b))
Process orders, deliver your eSIM, provide subscriptionsOrder data, payment dataPerformance of a contract (Art. 6(1)(b))
Send transactional emails (receipts, delivery, renewal notices)Account data, order dataPerformance of a contract (Art. 6(1)(b))
Provide customer supportAccount data, order data, support dataPerformance of a contract (Art. 6(1)(b)) and our legitimate interests (Art. 6(1)(f)) in helping customers
Comply with tax, accounting and legal obligationsOrder data, payment dataLegal obligation (Art. 6(1)(c))
Fraud prevention, service security, abuse detectionTechnical data, order dataLegitimate interests (Art. 6(1)(f))
Handle data-subject requests (access, deletion, etc.)All relevant dataLegal obligation (Art. 6(1)(c))

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects. We do not currently send marketing emails.

4. Recipients and sub-processors

We share personal data with the following processors, each under a data-processing agreement or equivalent contractual safeguards:

ProcessorPurposeLocation
Stripe Payments Europe, Ltd.Payment processing, subscription billing, customer portalEU / USA
Supabase Inc.Database hosting, authentication, storage (via Lovable Cloud)EU / USA
Lovable AB (Lovable Cloud / AI Gateway)Application hosting and a secure proxy for calls to StripeEU
Cloudflare, Inc.Edge hosting, TLS termination, DDoS protectionGlobal (EU edge)
Google LLC (Google Fonts)Serving typography assets (IP address is logged when your browser fetches fonts)Global
Google LLC (Google Ads & Google Analytics)Advertising, conversion measurement and audience insights — only loaded after you accept marketing cookiesEU / USA
Meta Platforms Ireland Ltd. (Meta Pixel / Facebook & Instagram Ads)Advertising, conversion measurement and audience insights — only loaded after you accept marketing cookiesEU / USA

Internal fulfilment. Order details (name, email, phone where provided, and the items ordered) are also delivered to our in-house operations team via an internal notification channel so we can provision your eSIM and provide support. This data stays within Rapidez Internet Solutions Limited and is not shared with any third-party fulfilment provider.

A current list of sub-processors is available on request from the privacy contact above. We do not sell personal data to third parties.

5. International transfers

Some of our processors are located outside the UK / EEA (in particular in the United States). Where personal data is transferred outside the UK / EEA, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where required), together with supplementary technical and organisational measures, to ensure your data receives an equivalent level of protection.

6. Retention

  • Order and invoice records: retained for 7 years to comply with UK tax and accounting law.
  • Account data: retained for the life of your account; if your account is inactive for more than 24 months we may delete it after notice.
  • Support conversations and messages: automatically deleted 24 months after they were created.
  • Server logs / technical data: retained for up to 90 days.
  • Subscription records: retained for as long as your subscription is active and for 7 years after cancellation for tax purposes.

After the retention period, data is deleted or irreversibly anonymised.

7. Your rights

Under the UK GDPR and EU GDPR you have the following rights in respect of your personal data:

  • Right of access — obtain a copy of the personal data we hold about you.
  • Right to rectification — correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten") — request deletion of your personal data where the legal grounds for erasure apply.
  • Right to restriction of processing — ask us to limit how we use your data.
  • Right to data portability — receive your personal data in a structured, machine-readable format (JSON).
  • Right to object — object to processing based on our legitimate interests.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.

Signed-in customers can exercise the right of access (data export) and the right to erasure (account deletion) directly from the Privacy & data section of the account page. For any other request, or if you cannot access your account, email support@calafly.net. We respond within 30 days as required by Article 12(3) GDPR.

You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ico.org.uk). In the EU, you may contact the supervisory authority of your Member State of residence.

8. Cookies and similar technologies

We use cookies, local storage and similar tracking technologies for two different purposes. Marketing and analytics technologies are only activated after you give explicit consent via our cookie banner, and you can withdraw that consent at any time by clearing your browser data or using the "Cookie preferences" link in the footer.

Strictly necessary (always on)

Required for the website to work. No consent is needed under Art. 5(3) of the ePrivacy Directive.

  • sb-* (local storage) — your authentication session token, set by Supabase.
  • cala.cart.v2 (local storage) — the contents of your shopping cart.
  • cala.currency (local storage) — your preferred display currency.
  • sidebar:state (cookie) — remembers admin UI preferences (admin users only).
  • cala.consent (local storage) — records your cookie preferences.

Marketing and analytics (consent required)

Loaded only if you accept marketing cookies. These help us measure the effectiveness of our advertising, show you relevant ads on other websites, and understand how visitors use CALA.

  • Google Ads & Google Analytics (Google LLC) — conversion tracking, remarketing and traffic analytics. Cookies set under google.com, googletagmanager.com and doubleclick.net. See Google's Privacy Policy.
  • Meta Pixel (Meta Platforms Ireland Ltd.) — conversion tracking and audience building for Facebook and Instagram ads. Cookies set under facebook.com. See Meta's Privacy Policy.

Legal basis for marketing / analytics cookies: your consent (Art. 6(1)(a) GDPR and Art. 5(3) of the ePrivacy Directive). You can withdraw consent at any time without affecting the lawfulness of prior processing.

9. Security

We use appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), row-level access controls on our database, hashed passwords, and strict scoping of administrative access. Payment card data never touches our servers — it is handled entirely by Stripe, a PCI-DSS Level 1 service provider.

10. Children

Our services are not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or via a prominent notice on our website before they take effect. The "last updated" date at the top of this page shows when the policy was last revised.

12. Contact

Questions or requests about this policy or your personal data: support@calafly.net.