Cookie Policy

Last updated: 31 July 2026

This Cookie Policy explains how ELVORIN LTD uses cookies and similar technologies when you visit or use arvosim.com and the ArvoSim Service, which categories we use, when consent is required, and how you can manage or withdraw your choices.

1. About this Cookie Policy

This Cookie Policy explains how ELVORIN LTD uses cookies and similar technologies when you visit or use arvosim.com and the ArvoSim Service.

It explains:

  • what cookies and similar technologies are;
  • which categories of technologies we use;
  • why we use them;
  • when consent is required;
  • how long information may be stored;
  • how third parties may use these technologies; and
  • how you can manage or withdraw your choices.

This Policy should be read together with the ArvoSim Privacy Policy and Terms and Conditions.

ArvoSim is operated by ELVORIN LTD, company number 17344051, Dept 6946, 196 High Road, Wood Green, London, United Kingdom, N22 8HH. Email: info@arvosim.com. Website: arvosim.com.

In this Policy, "ArvoSim", "we", "us" and "our" refer to ELVORIN LTD.

2. What Are Cookies?

Cookies are small text files or pieces of information stored on a device when a website is visited.

Cookies may allow a website to:

  • recognise a browser or device;
  • maintain a secure login session;
  • remember preferences;
  • retain information during checkout;
  • prevent fraud;
  • understand how the Website is used; and
  • improve reliability and performance.

Some cookies are deleted when the browser is closed. Others remain on the device for a defined period or until they are deleted.

3. Similar Technologies

This Policy also applies to technologies that store information on, or access information from, a user's device, including:

  • localStorage;
  • sessionStorage;
  • tracking pixels;
  • web beacons;
  • tags;
  • scripts;
  • software development kits;
  • link-decoration identifiers;
  • device identifiers;
  • browser or device signals; and
  • similar storage and access technologies.

References to "cookies" in this Policy include these similar technologies unless the context requires otherwise.

4. First-Party and Third-Party Cookies

4.1 First-party cookies — First-party cookies are placed or controlled by ArvoSim through arvosim.com. They may be used to:

  • authenticate users;
  • protect Accounts;
  • operate the Wallet;
  • maintain a transaction session;
  • remember cookie choices; and
  • save Website preferences.

4.2 Third-party cookies — Third-party cookies are placed or controlled by another organisation whose service is used through the Website. Depending on the services implemented, third parties may include:

  • payment providers;
  • 3D Secure providers;
  • fraud-prevention providers;
  • hosting and security providers;
  • analytics providers;
  • error-monitoring providers;
  • customer-support providers; and
  • embedded-content providers.

Third parties may process information under their own privacy notices.

ArvoSim will not intentionally enable non-essential third-party cookies before obtaining consent where consent is legally required.

5. Categories of Cookies

ArvoSim may use the following categories.

5.1 Strictly Necessary Cookies are required to operate the Website or provide a service expressly requested by the user. They may be used to:

  • create and maintain a login session;
  • authenticate the user;
  • protect against cross-site request forgery;
  • detect fraud or security incidents;
  • maintain Wallet and checkout functionality;
  • remember items or selections during a transaction;
  • route communications correctly;
  • balance Website traffic;
  • record cookie choices; and
  • comply with security obligations.

The Website may not function correctly without these technologies. Strictly Necessary Cookies do not require consent where the applicable legal exemption applies.

5.2 Preference and Appearance Cookies may remember choices such as:

  • selected currency;
  • language;
  • country or region;
  • display settings;
  • theme;
  • accessibility preferences; and
  • other interface settings.

Where a preference technology falls within an applicable legal exception, it may be used without prior consent provided that it is used solely to adapt the Website to the user's preference; clear information is provided; and the user has a simple and free way to object. Where those conditions are not met, consent will be requested before the technology is used.

5.3 Analytics and Performance Cookies may help us understand:

  • how many people visit the Website;
  • which pages are viewed;
  • how users move between pages;
  • where users encounter errors;
  • how quickly pages load;
  • which device or browser types are used;
  • how users reach the Website; and
  • how the Website may be improved.

Where analytics are used solely to create aggregate statistical information for improving ArvoSim and all conditions of the applicable statistical exception are met, prior consent may not be required. In those circumstances: the technology will be used solely for statistical purposes; individual users will not be profiled or tracked across unrelated services; information will be aggregated; identifiable information will not be retained longer than necessary; a third-party provider, if used, must act on our behalf for that limited purpose; and users will be given a simple and free means of objecting.

Consent will be requested where analytics track identifiable users; link Website activity to an Account for non-essential analysis; create user profiles; monitor users across websites or applications; support advertising; measure advertising conversions; combine ArvoSim information with unrelated third-party information; or otherwise fall outside an applicable exemption.

5.4 Functional Cookies support optional features that are not strictly necessary to provide the core Service. They may be used for:

  • optional customer-support tools;
  • interactive maps;
  • embedded videos;
  • external content;
  • enhanced forms;
  • social media features; or
  • other user-requested integrations.

Where these technologies are not exempt, they will be disabled until the user provides consent or actively requests the relevant feature after receiving clear information.

5.5 Advertising and Targeting Cookies — ArvoSim does not currently intend to use cookies for behavioural advertising or cross-site advertising profiles. If Advertising or Targeting Cookies are introduced in the future, they will not be activated before valid consent is obtained. Such technologies may not be treated as Strictly Necessary Cookies merely because they support Website revenue, campaign measurement or commercial performance. The Cookie Policy and cookie register will be updated before advertising technologies are introduced.

6. Technologies Used Without Consent

We may use a cookie or similar technology without consent only where an applicable legal exception is satisfied.

This may include technologies used solely for:

  • transmitting a communication;
  • providing a service expressly requested by the user;
  • Account authentication;
  • transaction security;
  • fraud prevention;
  • technical fault detection;
  • recording a user's checkout selections;
  • remembering cookie preferences;
  • limited aggregate statistical purposes;
  • adapting the Website's appearance or functionality to the user's expressed preference; or
  • another legally recognised exempt purpose.

An exception applies only to the relevant limited purpose. If the same technology is also used for another non-exempt purpose, consent may be required for the combined use.

7. Cookie and Technology Register

The following register describes the technologies intended for the current ArvoSim implementation.

The exact cookie names and durations used in production must match this register. Where a third-party provider generates dynamic names, the live cookie-preference centre may provide additional current details.

arvosim_session — Provider: ArvoSim. Category: Strictly Necessary. Purpose: Authenticates the user and maintains a secure Account session. Typical duration: Session, or up to 30 days where a persistent login is expressly selected. Consent: Not required where strictly necessary.

arvosim_csrf — Provider: ArvoSim. Category: Strictly Necessary. Purpose: Helps protect forms, Account actions, Wallet operations and Orders against cross-site request forgery. Typical duration: Session. Consent: Not required.

arvosim_cookie_preferences — Provider: ArvoSim or the consent-management provider. Category: Strictly Necessary. Purpose: Records whether the user accepted, rejected or customised optional technologies. Typical duration: Up to 6 months. Consent: Not required for the sole purpose of remembering the choice.

arvosim_currency — Provider: ArvoSim. Category: Preference / Appearance. Purpose: Remembers the user's selected display currency, such as GBP, EUR or USD. Typical duration: Up to 6 months. Consent: May be exempt where used solely for this preference and an objection method is available.

arvosim_language — Provider: ArvoSim. Category: Preference / Appearance. Purpose: Remembers the user's selected Website language where multilingual functionality is provided. Typical duration: Up to 6 months. Consent: May be exempt where applicable conditions are satisfied.

arvosim_checkout_session — Provider: ArvoSim. Category: Strictly Necessary. Purpose: Maintains the selected Top-Up or Order information while the user completes a transaction. Typical duration: Session or a short period necessary to complete the transaction. Consent: Not required.

Security and load-balancing cookies — Provider: ArvoSim, hosting or security provider. Category: Strictly Necessary. Purpose: Protects the Website, detects attacks, distributes traffic and maintains technical reliability. Typical duration: Session or short-lived. Consent: Not required where used solely for security or communications.

Payment-session cookies — Provider: Payment Provider. Category: Strictly Necessary. Purpose: Enables secure card entry, payment authorisation, fraud checks and transaction processing. Typical duration: Session or provider-defined short period. Consent: Not required where essential to complete the requested payment.

3D Secure authentication cookies — Provider: Payment Provider, card issuer or authentication provider. Category: Strictly Necessary. Purpose: Supports cardholder authentication and fraud prevention. Typical duration: Session or provider-defined period. Consent: Not required where essential to authentication or security.

Aggregate analytics technology — Provider: ArvoSim or approved analytics provider. Category: Analytics / Performance. Purpose: Produces aggregate statistics about Website use for the sole purpose of improving the Website. Typical duration: Limited to the period necessary to aggregate the information. Consent: Consent or statistical-purpose exception, depending on implementation.

Error-monitoring identifiers — Provider: ArvoSim or error-monitoring provider. Category: Analytics / Performance or Strictly Necessary. Purpose: Identifies technical faults, crashes and performance issues. Typical duration: Session or limited diagnostic period. Consent: Depends on whether the use is strictly necessary and whether individual users are tracked.

Customer-support technology — Provider: ArvoSim or support provider. Category: Functional. Purpose: Enables an optional chat, support widget or related feature. Typical duration: Session or provider-defined period. Consent: Consent may be required unless activated only when the user requests the feature.

Embedded-content cookies — Provider: Relevant content provider. Category: Functional. Purpose: Loads third-party videos, maps or other embedded content. Typical duration: Provider-defined. Consent: Consent or feature-led choice may be required.

8. Payment and 3D Secure Technologies

When you add funds to your Wallet Balance, a Payment Provider, card issuer or 3D Secure provider may use cookies or similar technologies to:

  • maintain the secure payment session;
  • authenticate the transaction;
  • prevent fraud;
  • identify technical failures;
  • apply transaction-risk controls; and
  • complete the payment requested by you.

These technologies may be strictly necessary to complete the Wallet Top-Up.

The Payment Provider may also use information independently for purposes described in its own privacy or cookie notice.

ArvoSim must not permit a Payment Provider to use payment-session information for unrelated advertising through ArvoSim without obtaining any required consent.

9. Cookie Consent Mechanism

Where consent is required, ArvoSim will provide a cookie banner or preference centre that allows users to make a real and informed choice.

The mechanism should provide:

  • an Accept All option;
  • a Reject Non-Essential or equivalent option;
  • a Manage Preferences option;
  • clear category descriptions;
  • access to this Cookie Policy; and
  • a method to change the choice later.

Non-essential cookies must not be activated before the user has provided valid consent.

10. Requirements for Valid Consent

Where we rely on consent, consent must be:

  • freely given;
  • specific;
  • informed;
  • unambiguous;
  • provided through a clear positive action; and
  • capable of being withdrawn.

We will not treat the following as valid consent:

  • silence;
  • inactivity;
  • continued browsing by itself;
  • pre-ticked boxes;
  • hidden settings;
  • consent bundled into general Terms and Conditions; or
  • an interface designed to make rejection materially harder than acceptance.

Refusing non-essential cookies will not prevent access to the core ArvoSim Service.

11. Rejecting Non-Essential Cookies

Users must be able to reject non-essential technologies without unnecessary steps.

Rejecting non-essential cookies will not prevent users from:

  • browsing available eSIM Plans;
  • creating or accessing an Account;
  • maintaining a Wallet Balance;
  • placing an Order;
  • receiving an eSIM; or
  • contacting support,

except where an optional feature genuinely depends on the relevant technology.

12. Objecting to Exempt Statistical or Appearance Technologies

Where we rely on the statistical-purpose or appearance exception instead of consent, we will provide a simple and free means to object.

The objection mechanism may be available through:

  • the cookie banner;
  • the cookie-preference centre;
  • a persistent Cookie Settings link;
  • an Account preference; or
  • another clearly accessible Website control.

Objecting must not require the user to:

  • create an Account;
  • provide unnecessary personal information;
  • pay a fee;
  • contact support where a simpler Website control can reasonably be provided; or
  • navigate through an excessive number of steps.

After an objection, the relevant technology will be disabled or adjusted as required.

13. Changing or Withdrawing Your Choice

You may change or withdraw your cookie consent at any time through the Cookie Settings link displayed on the Website.

Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.

After withdrawal:

  • non-essential cookies will no longer be set;
  • optional scripts should be disabled;
  • existing cookies will be deleted where technically possible and appropriate; and
  • third-party providers will be informed of the changed preference where the consent system supports this.

Some information may remain where retention is required for security, legal compliance or another lawful purpose.

14. Browser and Device Settings

Most browsers allow users to:

  • view stored cookies;
  • delete cookies;
  • block all cookies;
  • block third-party cookies;
  • restrict cookies to particular websites; or
  • receive a warning before a cookie is stored.

Browser settings operate separately from the ArvoSim cookie-preference centre.

Blocking all cookies may prevent parts of the Service from functioning, including:

  • Account login;
  • Wallet functionality;
  • secure checkout;
  • payment authentication;
  • fraud-prevention controls; and
  • the recording of cookie choices.

15. LocalStorage and SessionStorage

ArvoSim may use localStorage or sessionStorage for purposes such as:

  • maintaining temporary Website state;
  • remembering a selected currency;
  • recording a cookie choice;
  • retaining a non-sensitive form selection;
  • supporting Account functionality; or
  • improving interface performance.

Information in sessionStorage is normally deleted when the browser tab or session ends.

Information in localStorage may remain until:

  • it expires under the Website's logic;
  • it is replaced;
  • the user clears Website data; or
  • ArvoSim removes it.

The same consent and transparency rules that apply to cookies may also apply to localStorage and sessionStorage.

16. Embedded Content

The Website may contain content provided by another organisation, such as:

  • videos;
  • maps;
  • social media content;
  • support widgets; or
  • interactive tools.

Embedded content may allow the third party to place or access cookies.

Where possible, ArvoSim will:

  • use privacy-enhanced embedding settings;
  • prevent the third-party content from loading automatically;
  • display a placeholder before activation;
  • explain that activating the content may share information with the third party; and
  • obtain consent or a valid feature-led choice where required.

Users who do not activate the embedded content may be provided with an ordinary external link where practical.

17. Analytics Providers

Where a third-party analytics provider is used under the statistical-purpose exception, ArvoSim will take reasonable steps to ensure that the provider:

  • acts on ArvoSim's behalf;
  • uses the information only to improve ArvoSim;
  • does not combine it with information from unrelated services;
  • does not use it for advertising;
  • does not create independent user profiles;
  • does not retain individual-level information longer than necessary;
  • produces aggregate statistical results; and
  • provides appropriate contractual and security protections.

If those conditions cannot be met, analytics technologies will require consent before activation.

18. Advertising and Cross-Site Tracking

ArvoSim does not currently use the Website to create behavioural advertising profiles or track users across unrelated websites.

We will not use an exception intended for:

  • security;
  • Website statistics;
  • user preferences; or
  • technical communications

as a basis for advertising, profiling or cross-site tracking.

If advertising technologies are introduced:

  • this Policy will be updated;
  • the relevant providers and purposes will be disclosed;
  • the cookie register will identify the technologies;
  • prior consent will be obtained; and
  • users will be able to reject or withdraw consent.

19. Device Fingerprinting

Device fingerprinting involves combining device or browser characteristics to distinguish or identify a device or user.

ArvoSim will not use device fingerprinting for:

  • behavioural advertising;
  • cross-site tracking;
  • hidden profiling; or
  • circumventing a user's cookie choice.

Limited device information may be used where reasonably necessary for:

  • Website security;
  • fraud prevention;
  • payment protection;
  • diagnosing technical faults; or
  • ensuring device compatibility.

Where fingerprinting or comparable processing falls outside a legal exception, consent will be obtained.

20. Email Technologies

Transactional or marketing emails may contain limited technologies that help determine whether:

  • an email was delivered;
  • a delivery failed;
  • a link was clicked;
  • a QR-code email reached the correct destination; or
  • a technical issue occurred.

Where required, consent or another appropriate legal basis will be used.

Users may unsubscribe from marketing emails, but essential communications relating to Accounts, Wallet transactions, Orders, security and support may still be sent.

21. International Data Transfers

Some cookie or technology providers may process information outside the United Kingdom.

Where personal data is transferred internationally, ArvoSim will use an appropriate transfer mechanism where required, such as:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the European Commission Standard Contractual Clauses; or
  • another legally recognised safeguard.

Further information is provided in the Privacy Policy.

22. Data Protection and Lawful Bases

Where cookie information is personal data, ArvoSim must also comply with applicable data protection law.

Depending on the technology and purpose, the lawful basis may include:

  • consent;
  • performance of a contract;
  • compliance with a legal obligation; or
  • legitimate interests.

Where applicable cookie law requires consent, relying on a different data-protection lawful basis does not remove the cookie-consent requirement.

23. Retention

Cookies and similar technologies will not be retained for longer than reasonably necessary for their stated purpose.

When setting retention periods, we consider:

  • the purpose of the technology;
  • whether it is session-based or persistent;
  • the sensitivity of the information;
  • user expectations;
  • security requirements;
  • legal obligations; and
  • whether a shorter duration can achieve the same purpose.

Consent preferences will normally be remembered for up to six months.

We may request a new choice sooner where:

  • the purposes change;
  • new providers are introduced;
  • the categories materially change;
  • consent records are lost; or
  • a legal or regulatory change requires a renewed choice.

24. Cookie Audits

ArvoSim will periodically review the Website to identify:

  • cookies;
  • localStorage keys;
  • sessionStorage keys;
  • third-party scripts;
  • pixels;
  • tags;
  • embedded content;
  • payment-provider technologies; and
  • other storage or access technologies.

The audit should verify:

  • the exact name;
  • provider;
  • category;
  • purpose;
  • first- or third-party status;
  • trigger;
  • duration;
  • information collected;
  • international transfers;
  • consent requirement; and
  • whether the technology remains necessary.

The public cookie register and consent mechanism should be updated when material changes are identified.

25. Third-Party Changes

A third-party provider may change the names, duration or behaviour of its technologies.

ArvoSim will take reasonable steps to keep the cookie register accurate, but provider-controlled identifiers may change between Policy updates.

The live cookie-preference centre may contain more current technical details.

A material change in purpose will not be implemented without updating the relevant information and obtaining fresh consent where required.

26. Children

The ArvoSim Service is intended for users aged 18 or over.

We do not intentionally use cookies to profile children or serve behavioural advertising to them.

If we become aware that a technology presents a particular risk to children, we will assess and adjust or remove it as appropriate.

27. Security

Cookie values used for authentication or security should, where technically appropriate, use protections such as:

  • Secure attributes;
  • HttpOnly attributes;
  • appropriate SameSite settings;
  • encryption or signing;
  • limited retention;
  • restricted domain and path settings; and
  • protection against unauthorised modification.

Users should not share session identifiers or Account access with another person.

28. Complaints and Questions

Questions or complaints about cookies may be sent to: info@arvosim.com

Please include:

  • the device or browser used;
  • the relevant page;
  • the date and approximate time;
  • the name of the cookie or technology, if known;
  • a description of the concern; and
  • any relevant screenshot.

Privacy complaints will be handled in accordance with the Privacy Policy.

You also have the right to complain to the UK Information Commissioner's Office where applicable.

29. Changes to this Policy

We may update this Cookie Policy to reflect changes to:

  • Website functionality;
  • the Wallet or checkout;
  • payment providers;
  • analytics or support tools;
  • cookies or similar technologies;
  • applicable law;
  • regulatory guidance; or
  • our business operations.

The updated Policy will be published on arvosim.com with a revised "Last updated" date.

Where a change requires a new consent choice, we will request that choice before activating the affected non-essential technology.

30. Contact Information

Questions about this Policy may be directed to ELVORIN LTD, company number 17344051, Dept 6946, 196 High Road, Wood Green, London, United Kingdom, N22 8HH.

Email: info@arvosim.com. Website: arvosim.com.