Privacy Policy

Last updated July 2026

1. Who we are

Fresim is operated by Alex Hile, trading as Fresim, a sole trader established in Australia. Fresim is the data controller for the personal data described in this policy. Privacy questions, access requests, and deletion requests go to alexjhile@gmail.com, which reaches the people who operate the platform directly.

2. What we collect

  • Creator account data: name, email, and profile photo from Google sign-in; the brand name, slug, description, logo URL, and colors you set for your storefront.
  • Customer data: when someone buys a plan through a storefront, we collect their email address and the eSIM activation details generated for them. We do not require an account to make a purchase.
  • Mobile app account data: the Fresim mobile app (iOS/Android) creates an account from your email address — either via a one-time emailed code, or by signing in with Google or Apple, both of which share only the email address associated with that account, nothing else from your Google/Apple profile.
  • Push notification token: if you allow notifications in the mobile app, we store a device push token (issued by Apple/Google via Expo's push service) so we can notify you when an eSIM activates or is running low on data. You can revoke this at any time in your device's notification settings, or by deleting your account in the app.
  • Payment data: handled directly by Stripe. Fresim never receives or stores full card numbers — only the payment outcome (succeeded, amount, etc.) and identifiers Stripe provides.
  • Usage data: traffic-source attribution (e.g. which social link a customer came from), order/top-up history, and eSIM data-usage figures reported back by our eSIM providers.
  • Session cookies / tokens: a session cookie keeps you signed in to the web dashboard; the mobile app instead uses a signed access token stored securely on your device (iOS Keychain / Android Keystore). We don't use third-party advertising trackers on either platform.

3. How we use it

  • To operate the storefront, dashboard, and mobile app, and provision eSIMs when someone buys one.
  • To process payments and payouts through Stripe.
  • To send transactional email and push notifications — activation codes, purchase confirmations, low-data alerts.
  • To show Creators their own analytics (orders, revenue, attribution).
  • To prevent fraud and abuse (e.g. rate-limiting checkout and purchase requests).

We don't sell your data, and we don't use customer or creator data for advertising.

4. Our legal bases

Where the GDPR (or a similar law) applies to you, we rely on the following legal bases:

  • Performance of a contract — operating your Creator account, provisioning an eSIM you bought, processing payments, and sending the transactional emails those steps require.
  • Legitimate interests — preventing fraud and abuse (e.g. rate-limiting checkout and purchase requests), keeping transaction records, securing the platform, and showing Creators analytics about their own storefront.
  • Consent — mobile push notifications (you opt in via your device's notification prompt and can revoke at any time).
  • Legal obligation — retaining accounting and transaction records where required by law.

5. Who we share it with

Data is shared only with the third-party services that make Fresim work:

  • Stripe — payment processing and payouts.
  • eSIM Access and Airalo — the eSIM providers that actually provision and deliver each eSIM.
  • Google and Apple — authentication for Creator accounts (Google, web), mobile app sign-in (Google or Apple), and delivery of transactional emails (Gmail).
  • Expo — delivery of mobile push notifications, using the device token described above.
  • Supabase — our database host.
  • Anthropic — powers the AI chat assistants built into the creator dashboard and the mobile app's "Get help" screen. When you use either, the message text you type is sent to Anthropic's API to generate a response; for the mobile support chat, that also includes read-only eSIM diagnostic data (status, activation state, data usage) the assistant looks up to answer your question. We don't send payment card details, passwords, or account credentials to Anthropic.

Each of these providers has its own privacy policy governing how they handle the data passed to them.

6. Where your data is stored (international transfers)

Our database is hosted by Supabase on servers in the United States (AWS, us-east-1). If you use Fresim from outside the US — including from the EU, UK, or Australia — your personal data is transferred to and stored in the United States. The other providers listed above (Stripe, Google, Apple, Expo, and our eSIM providers) may also process data in the US or other countries where they operate, under their own safeguards. Formal transfer safeguards (such as standard contractual clauses) will be documented here alongside the data-controller entity once counsel has reviewed this policy.

7. Data retention

We keep account, order, and claim records for as long as the associated Creator account is active, plus a reasonable period afterward for accounting and fraud-prevention purposes. Deleting your mobile app account (see below) removes your sign-in identity and push token immediately; past order/claim history tied to your email is kept as a transaction record, the same as it would be for any purchase made without an account.

8. Your rights

Mobile app users can delete their account directly in the app — Account → Delete account — which takes effect immediately. Anyone can also ask us to access, correct, or delete the personal data we hold about them by emailing alexjhile@gmail.com. Creators can update most of their own account and brand data directly from the dashboard. If you're in the EU/UK, you also have the right to object to or restrict processing, to data portability, and to lodge a complaint with your local supervisory authority.

9. Children's privacy

Fresim isn't directed at children, and we don't knowingly collect data from anyone under 16.

10. Security

We use industry-standard measures to protect your data, including encrypted connections (HTTPS), verified webhook signatures on inbound payment events, and sender verification on provisioning events. No system is perfectly secure, and we can't guarantee absolute security.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the date at the top of this page.

12. Contact

Questions about this policy: alexjhile@gmail.com.