Privacy Policy

Last updated: 18 July 2026

1. Who we are (data controller)

This Privacy Policy explains how Design & Desktop, LLC (“we”, “us”, “our”), a Delaware limited liability company based in the United States, operating the brand Plota at https://plota.app, processes personal data when you visit our website or buy travel eSIM plans.

We sell online to customers worldwide. We are the data controller for personal data processed through the Service. Contact: support@plota.com.

Privacy laws can differ by country. Where the GDPR / UK GDPR or similar laws apply to you (for example if you are in the EEA, UK, or Switzerland), the sections below describe those rights and our corresponding practices. Other customers receive the protections described in this Policy and any rights available under their local law.

2. Scope

This Policy applies to plota.app, related subdomains we operate, customer accounts, checkout, order delivery, support communications, and cookies/similar technologies on our site — regardless of where you access the Service from.

It does not cover third-party websites or apps that we do not control, including mobile network operators that provide radio coverage after your eSIM is installed.

3. Personal data we collect

Depending on how you use the Service, we may process:

  • Account data — email address, name, password (hashed by our auth provider), phone/country if you add them, and profile preferences.
  • Order and transaction data — plan purchased, destination, price, currency, order IDs, delivery status, and eSIM-related fulfilment details needed to provide the product.
  • Payment data — payment is processed by Stripe. We do not store full card numbers on our servers. Stripe may process card details, billing name/address, and fraud-prevention signals under its own terms and privacy notice.
  • Usage and device data — IP address, approximate location derived from IP, browser/device type, pages viewed, referrer, and timestamps.
  • Support communications — messages you send via contact forms, email, or tickets.
  • Cookie / analytics data (only with consent) — Google Analytics and Microsoft Clarity interaction data as described in our Cookie Policy.

4. How we obtain data

  • Directly from you (account signup, checkout, support).
  • Automatically from your device when you browse (necessary technical logs; analytics only after consent).
  • From payment and infrastructure providers (e.g. Stripe payment status, hosting/auth providers) as needed to run the Service.

5. Purposes and legal bases

We process personal data for the purposes below. Where the GDPR applies, we rely on these lawful bases:

  • Contract (Art. 6(1)(b)) — create/manage your account; process orders; deliver eSIM instructions/QR; provide customer support related to your purchase.
  • Legal obligation (Art. 6(1)(c)) — keep tax, accounting, and fraud-related records where required by law.
  • Legitimate interests (Art. 6(1)(f)) — secure the Service, prevent abuse, diagnose outages, improve product reliability, and defend legal claims. We balance these interests against your rights.
  • Consent (Art. 6(1)(a)) — non-essential cookies and analytics (Google Analytics, Microsoft Clarity). You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

6. Payments (Stripe)

Payments are processed by Stripe, Inc.. When you pay, you also interact with Stripe’s systems. See Stripe’s privacy notice: https://stripe.com/privacy.

We receive confirmation of payment status, limited billing metadata, and identifiers needed to match a payment to your order. Card data is handled by Stripe; we do not receive or store full PAN/CVC on our servers.

7. Analytics (Google Analytics & Microsoft Clarity)

With your prior consent, we use Google Analytics (Google Ireland Limited / Google LLC) and Microsoft Clarity (Microsoft Corporation) to understand site usage, measure performance, and improve UX (including session replay/heatmaps via Clarity).

These tools may set cookies or use similar identifiers and process IP address, device/browser data, and interaction events. They are not loaded if you choose “Necessary only”.

Provider notices: Google https://policies.google.com/privacy; Microsoft https://privacy.microsoft.com/privacystatement. Details of cookies are in our Cookie Policy.

8. Recipients and processors

We share personal data only with providers that help us operate the Service, under contracts (including data processing terms) where required:

  • Stripe, Inc. — payments.
  • Supabase (Supabase, Inc.) — authentication and database hosting.
  • Hosting / infrastructure providers for the website and APIs.
  • eSIM wholesale / connectivity suppliers needed to provision your plan.
  • Google and Microsoft — analytics only with consent.
  • Professional advisers or authorities where required by law or to protect rights.

9. International transfers

We and some providers are based in the United States or other countries outside the EEA/UK. Where we transfer personal data from the EEA/UK/Switzerland to a country without an adequacy decision, we use appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) (and UK equivalents where applicable), plus supplementary measures where needed.

You may request more information about transfer safeguards by contacting us.

10. Retention

  • Account data — while your account is active, then deleted or anonymised within a reasonable period after closure unless we must keep it longer.
  • Orders / invoices — typically kept for the period required by tax and commercial law (often up to 7–10 years depending on applicable rules).
  • Support tickets — for as long as needed to resolve your request and for a limited follow-up period.
  • Security logs — short retention for security and abuse prevention.
  • Analytics — according to the retention settings of Google Analytics / Microsoft Clarity and your consent status.

11. Your rights (EEA / UK / Switzerland)

Subject to applicable law, you may have the right to:

  • Access your personal data and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase data (“right to be forgotten”) in certain cases.
  • Restrict or object to certain processing (including processing based on legitimate interests).
  • Data portability for data you provided where processing is based on contract or consent and is automated.
  • Withdraw consent at any time for consent-based processing (e.g. analytics cookies).
  • Lodge a complaint with a supervisory authority — in particular in your EU/EEA Member State of residence, place of work, or place of the alleged infringement. A list of EEA authorities is available via the European Data Protection Board.

12. How to exercise your rights

Email support@plota.com with the subject “Data rights request”. We may need to verify your identity. We respond within the time limits required by law (generally one month under the GDPR, extendable where permitted).

13. Security

We implement appropriate technical and organisational measures (access controls, encryption in transit, least-privilege access, and provider security reviews) to protect personal data. No method of internet transmission or storage is completely secure.

14. Children

The Service is intended for users aged 18+. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it.

15. Automated decision-making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects about you within the meaning of GDPR Art. 22. Payment fraud checks may be performed by Stripe as part of payment processing.

16. Changes to this Policy

We may update this Policy from time to time. We will post the new version on this page and update the “Last updated” date. For material changes, we may also notify you by email or a prominent site notice where required.

17. Contact

Data controller: Design & Desktop, LLC (Delaware limited liability company).

Privacy contact: support@plota.com.

Website: https://plota.app.