← DimeRoam

Privacy Policy

Last updated 22 September 2026

This policy covers the DimeRoam iPhone app and this website. The data controller is Alexarix Limited, incorporated in Hong Kong SAR. Questions and rights requests: privacy@alexarix.com.

The short version. No account, no name, no email, no advertising identifiers, no third-party analytics or tracking SDKs in the app. We hold a random device identifier, your order history and the technical identifiers of the eSIMs issued to you. We never see what you browse or where you are.

1. What we collect and why

DataWhyLegal basis (GDPR)
Random device identifier generated on first launch, stored in your device keychainTo know which eSIMs belong to your device, with no account to createContract (Art. 6(1)(b))
Orders: plan, price, time of purchase, payment statusTo deliver the plan, support you, and keep accounting recordsContract; legal obligation (Art. 6(1)(b),(c))
eSIM technical identifiers: ICCID, transaction number, profile statusTo issue, display and troubleshoot the eSIMContract (Art. 6(1)(b))
Data volume used, plan expiry, activation time — reported to us by the networkTo show you how much data is leftContract (Art. 6(1)(b))
Payment confirmation from Stripe: amount, currency, result, last four digits and card brandTo confirm you paid before we issue an eSIM, and to handle refunds and chargebacksContract; legal obligation (Art. 6(1)(b),(c))
Messages and screenshots you send to supportTo answer youContract; legitimate interest (Art. 6(1)(b),(f))
Server request logs (IP address, timestamp, endpoint), kept short-termSecurity, abuse prevention, debuggingLegitimate interest (Art. 6(1)(f))

2. What we never collect

3. Who else processes your data

ProcessorWhat it receivesWhere
eSIM Access (Red Tea Mobile)The order and the eSIM profile identifiers. It issues and operates the eSIM profile.Singapore / Hong Kong
Stripe, Inc. and Stripe Payments EuropePayment details you enter, the amount and the result. Stripe is an independent controller for fraud prevention.United States / Ireland
Cloudflare, Inc.Hosts our API and this site and processes the requests your app makes.Global edge network
Apple Inc.If you pay with Apple Pay, Apple handles the payment token. Apple also operates the eSIM installation on your device.United States

Mobile network operators in the country you travel to carry the traffic itself under their own local regulation. We do not receive their traffic records beyond aggregate volume.

We do not sell personal data and we do not share it for cross-context behavioural advertising.

4. International transfers

We operate from Hong Kong SAR and our processors operate globally. Where personal data of people in the EEA or UK is transferred outside those areas, the transfer relies on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) concluded with the relevant processor, together with the technical measures described in this policy.

5. How long we keep it

RecordRetention
Device identifier and the eSIMs tied to itUntil you ask us to delete it, or two years after the last eSIM expires
Order and payment recordsSeven years, as accounting and tax law in Hong Kong SAR requires
Support conversationsTwo years from the last message
Server request logs30 days

6. Your rights

Wherever you live, you can ask us to give you a copy of what we hold, correct it, delete it, restrict or object to processing, or send it to another provider in a portable format. If you are in the EEA or UK you also have the right to complain to your data protection authority. If you are in California, see your California rights.

Write to privacy@alexarix.com from the device in question, or include the ICCID of one of your eSIMs so we can identify the records. We answer within 30 days and never charge for a first request.

Deleting is real. Because we hold no account, your device identifier is the only link between you and your eSIMs. Once it is deleted, eSIMs bought with it can no longer be shown in the app or recovered by support, though an installed profile keeps working until it expires.

7. Security

Traffic between the app and our servers is TLS-encrypted. Reseller and payment credentials live only on the server and are never shipped in the app. The device identifier is stored in the iOS keychain rather than in app storage. Access to production data is limited to the people who operate the service.

8. Children

DimeRoam is not directed at children under 13 (under 16 in the EEA) and we do not knowingly collect their personal data. If you believe a child has given us data, write to us and we will delete it.

9. Automated decision-making

We make no decisions about you by automated means that produce legal or similarly significant effects. Stripe applies automated fraud scoring to payments; a payment it declines can be retried or queried with us.

10. Changes

If this policy changes materially we will update the date above and show a notice in the app before the change takes effect.