Privacy Policy
Last updated 22 September 2026
This policy covers the DimeRoam iPhone app and this website. The data controller is Alexarix Limited, incorporated in Hong Kong SAR. Questions and rights requests: privacy@alexarix.com.
1. What we collect and why
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Random device identifier generated on first launch, stored in your device keychain | To know which eSIMs belong to your device, with no account to create | Contract (Art. 6(1)(b)) |
| Orders: plan, price, time of purchase, payment status | To deliver the plan, support you, and keep accounting records | Contract; legal obligation (Art. 6(1)(b),(c)) |
| eSIM technical identifiers: ICCID, transaction number, profile status | To issue, display and troubleshoot the eSIM | Contract (Art. 6(1)(b)) |
| Data volume used, plan expiry, activation time — reported to us by the network | To show you how much data is left | Contract (Art. 6(1)(b)) |
| Payment confirmation from Stripe: amount, currency, result, last four digits and card brand | To confirm you paid before we issue an eSIM, and to handle refunds and chargebacks | Contract; legal obligation (Art. 6(1)(b),(c)) |
| Messages and screenshots you send to support | To answer you | Contract; legitimate interest (Art. 6(1)(b),(f)) |
| Server request logs (IP address, timestamp, endpoint), kept short-term | Security, abuse prevention, debugging | Legitimate interest (Art. 6(1)(f)) |
2. What we never collect
- Your browsing. We do not see, log or receive the sites you visit or the apps you use over the eSIM.
- Your location. The app does not request location permission. We know which country a plan covers because you chose it, not because we tracked you.
- Your identity. No name, email, address or phone number is required to buy. If you write to support, we have whatever you put in that message and nothing more.
- Card numbers. Card details go straight from your device to Stripe and never touch our servers.
- Advertising identifiers. The app contains no advertising SDK, no analytics SDK, and does not use the IDFA or App Tracking Transparency, because it does not track you.
3. Who else processes your data
| Processor | What it receives | Where |
|---|---|---|
| eSIM Access (Red Tea Mobile) | The order and the eSIM profile identifiers. It issues and operates the eSIM profile. | Singapore / Hong Kong |
| Stripe, Inc. and Stripe Payments Europe | Payment details you enter, the amount and the result. Stripe is an independent controller for fraud prevention. | United States / Ireland |
| Cloudflare, Inc. | Hosts our API and this site and processes the requests your app makes. | Global edge network |
| Apple Inc. | If you pay with Apple Pay, Apple handles the payment token. Apple also operates the eSIM installation on your device. | United States |
Mobile network operators in the country you travel to carry the traffic itself under their own local regulation. We do not receive their traffic records beyond aggregate volume.
We do not sell personal data and we do not share it for cross-context behavioural advertising.
4. International transfers
We operate from Hong Kong SAR and our processors operate globally. Where personal data of people in the EEA or UK is transferred outside those areas, the transfer relies on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) concluded with the relevant processor, together with the technical measures described in this policy.
5. How long we keep it
| Record | Retention |
|---|---|
| Device identifier and the eSIMs tied to it | Until you ask us to delete it, or two years after the last eSIM expires |
| Order and payment records | Seven years, as accounting and tax law in Hong Kong SAR requires |
| Support conversations | Two years from the last message |
| Server request logs | 30 days |
6. Your rights
Wherever you live, you can ask us to give you a copy of what we hold, correct it, delete it, restrict or object to processing, or send it to another provider in a portable format. If you are in the EEA or UK you also have the right to complain to your data protection authority. If you are in California, see your California rights.
Write to privacy@alexarix.com from the device in question, or include the ICCID of one of your eSIMs so we can identify the records. We answer within 30 days and never charge for a first request.
7. Security
Traffic between the app and our servers is TLS-encrypted. Reseller and payment credentials live only on the server and are never shipped in the app. The device identifier is stored in the iOS keychain rather than in app storage. Access to production data is limited to the people who operate the service.
8. Children
DimeRoam is not directed at children under 13 (under 16 in the EEA) and we do not knowingly collect their personal data. If you believe a child has given us data, write to us and we will delete it.
9. Automated decision-making
We make no decisions about you by automated means that produce legal or similarly significant effects. Stripe applies automated fraud scoring to payments; a payment it declines can be retried or queried with us.
10. Changes
If this policy changes materially we will update the date above and show a notice in the app before the change takes effect.