Privacy Policy Overview

This Privacy Policy explains how GSMXCODE LLC collects, uses, discloses, stores, and protects personal information when you visit GSMXCODE websites, create an account, purchase a Service, use our APIs, SaaS products, diagnostic or device-information services, communicate with support, or otherwise interact with GSMXCODE.

We aim to collect information that is reasonably necessary for providing our Services, operating and securing the Platform, processing transactions, preventing fraud, meeting legal obligations, and supporting our customers.

Privacy Principles

Transparency
We explain what information we collect, why we use it, and with whom it may be shared.
Data Minimization
We seek to collect information reasonably necessary for identified business and service purposes.
Security
We maintain reasonable technical and organizational safeguards.
User Rights
Applicable privacy rights remain available subject to jurisdiction and law.

1. Scope & Company

1.1 About This Policy

This Privacy Policy describes how GSMXCODE LLC ("GSMXCODE," "we," "us," or "our") processes personal information in connection with the GSMXCODE website, customer accounts, software, SaaS products, diagnostic and repair tools, device information services, APIs, subscriptions, customer support, and related Services.

1.2 Company

GSMXCODE LLC is a limited liability company organized under the laws of the State of New Mexico, United States.

1.3 Privacy Contact

Privacy Contact: [email protected]

1.4 Jurisdiction-Specific Rights

The rights and obligations applicable to a particular person depend on their location, the nature of the processing, and the laws that apply to that person and processing activity.

Where applicable, GSMXCODE seeks to provide the notices, rights, choices, and protections required by relevant privacy and data-protection laws.

2. Information We Collect

2.1 Account & Identity Information

Depending on how you use the Platform, we may collect:

  • name or account holder name;
  • email address;
  • telephone number, where provided;
  • username;
  • country or general location;
  • business or company information;
  • account credentials and authentication data; and
  • verification information where required.

2.2 Transaction Information

When you purchase a GSMXCODE Service, we may collect or generate information such as:

  • order ID;
  • product or Service purchased;
  • purchase quantity;
  • price and currency;
  • payment status;
  • transaction identifier;
  • refund or cancellation records;
  • subscription information; and
  • related fulfillment information.

2.3 Payment Information

Payment information is generally handled by the applicable payment provider.

Depending on the payment method, payment providers may process card, bank, billing, fraud, device, and authentication information necessary to authorize and manage the transaction. GSMXCODE generally receives only the transaction and payment-related information returned by the applicable provider.

GSMXCODE may receive limited payment-related information such as payment status, provider transaction IDs, billing country, payment method type, amounts, and other information returned by the payment provider.

2.4 Service Information

Depending on the Service, customers may submit information necessary to provide an API, SaaS, software, diagnostic, device- information, repair, or other supported Service.

This may include technical parameters, device or service identifiers, configuration information, API inputs, account information, eligibility information, or other data submitted through the Platform.

2.5 Device & Technical Service Information

For device-related Services, GSMXCODE may process device identifiers, model information, warranty or eligibility information, network-status information, diagnostic information, and other technical information necessary to provide the requested Service.

Customers are responsible for ensuring that they have the authority and lawful basis required to submit device, account, identifier, or technical information to GSMXCODE.

2.6 Support Communications

We may collect information contained in support requests, emails, chat messages, attachments, screenshots, troubleshooting information, and other communications with GSMXCODE.

2.7 Technical & Usage Information

We may automatically collect technical and security information, including where applicable:

Category Examples
Network IP address, approximate network information
Device Browser, operating system, device type, and technical or device identifiers where available and relevant to the Service
Usage Pages viewed, features used, API request activity, timestamps, access events
Security Authentication events, failed logins, security events, abuse indicators
Diagnostics Error messages, application logs, performance information

2.8 Information From Other Sources

We may receive limited information from payment providers, service providers, fraud-prevention systems, identity-verification providers, technical or service partners, or other sources where reasonably necessary for providing Services, security, fraud prevention, or compliance.

3. How Information Is Collected

3.1 Directly From You

We collect information directly when you:

  • create or maintain an account;
  • purchase or subscribe to a Service;
  • configure API access;
  • submit support requests;
  • communicate with us; or
  • voluntarily provide information.

3.2 Automatically

Certain technical, security, performance, and usage information may be collected automatically when you use the Platform.

3.3 Through Service Providers

Third-party service providers may independently collect information when you interact with their systems, such as payment checkout, authentication, security, email, analytics, or infrastructure services.

4. How We Use Information

GSMXCODE uses information for legitimate business, contractual, security, operational, and legal purposes.

Purpose Examples
Account Management Registration, authentication, account maintenance, security
Service Delivery SaaS access, API access, software delivery, subscriptions, diagnostic, device-information, repair, and technical Services
API Operations Authenticate requests, measure usage, apply quotas, troubleshoot, secure APIs
Payments Authorize transactions, reconcile payments, issue refunds
Fraud Prevention Detect unauthorized transactions, account abuse, suspicious activity
Customer Support Resolve account, billing, technical, and Service issues
Security Protect infrastructure, accounts, APIs, and customer information
Legal & Compliance Meet legal, tax, regulatory, contractual, and dispute obligations
Improvement Improve performance, reliability, functionality, and customer experience
Communications Transactional messages, support, account notices, Service updates

6. Payments & Transaction Data

6.1 Payment Providers

GSMXCODE may use independent payment processors, acquiring institutions, banks, card networks, and payment platforms to process customer transactions. GSMXCODE accepts payments for its own products and Services and does not operate a general payment or money-transfer service.

Payment providers may independently collect and process payment and identity information according to their own terms and privacy policies.

6.2 Information Returned to GSMXCODE

Depending on the payment provider and payment method, GSMXCODE may receive:

  • payment status;
  • provider transaction ID;
  • payment method type;
  • billing country or region;
  • transaction amount and currency;
  • refund status; and
  • fraud or verification results.

6.3 Transaction Records

We may retain transaction records for accounting, reconciliation, customer support, fraud prevention, disputes, chargebacks, legal compliance, and contractual obligations.

7. API & Technical Data

7.1 API Logs

When customers use GSMXCODE APIs, we may process technical information necessary to authenticate, operate, secure, meter, and troubleshoot the API. Where an API supports device or diagnostic Services, submitted technical inputs may include supported device or service identifiers and related information required for the requested operation.

Depending on the API, this may include:

  • account identifier;
  • API key or token identifier;
  • endpoint requested;
  • request timestamp;
  • request quantity;
  • response status;
  • source IP address;
  • technical headers or metadata; and
  • error or diagnostic information.

7.2 Customer-Submitted Data

Some API, SaaS, diagnostic, device-information, or other Services may require customers to provide technical inputs or other data necessary for the requested operation.

Customers are responsible for ensuring that they have the legal right and necessary authorization to submit such information to GSMXCODE.

7.3 Sensitive Credentials

Customers should not submit passwords, payment-card credentials, private authentication secrets, or other sensitive information through an API unless the particular Service expressly requires it and provides an approved secure mechanism.

7.4 API Security & Abuse

API and security logs may be used to detect abuse, unauthorized access, excessive usage, attempted attacks, fraud, and violations of documented technical restrictions.

8. Sharing & Service Providers

GSMXCODE does not sell personal information as a commercial data product. We may disclose personal information to service providers and other recipients where reasonably necessary for the purposes described in this Privacy Policy.

Recipient Category Typical Purpose
Payment Providers Payment processing, refunds, risk and fraud prevention
Cloud & Hosting Providers Hosting, databases, backups, application infrastructure
Security Providers Fraud prevention, abuse detection, network and application security
Email & Communications Transactional notices, support, account communications
Technical Providers APIs, infrastructure, monitoring, diagnostics, and supporting systems
Professional Advisors Legal, accounting, tax, compliance, and professional advice

8.1 Legal Disclosures

We may disclose information where reasonably necessary to comply with law, legal process, governmental requests, court orders, regulatory requirements, or to establish, exercise, or defend legal rights.

8.2 Security and Fraud

Information may be disclosed to payment providers, security providers, law enforcement, or other appropriate recipients when necessary to investigate fraud, unauthorized activity, abuse, security incidents, or threats to users or the Platform, subject to applicable law.

8.3 Device & Technical Service Providers

Where reasonably necessary to provide an expressly supported device, diagnostic, eligibility, or authorized technical Service, GSMXCODE may disclose relevant technical or device information to applicable service providers, technical partners, carriers, manufacturers, suppliers, or other recipients involved in that Service, subject to applicable law and the terms governing the Service.

8.4 Business Transfers

Personal information may be transferred as part of a merger, acquisition, reorganization, financing, sale of assets, or similar business transaction, subject to applicable law and appropriate safeguards.

9. Cookies & Similar Technologies

9.1 Essential Technologies

GSMXCODE may use cookies, local storage, session identifiers, and similar technologies that are necessary to:

  • maintain authentication sessions;
  • protect account security;
  • remember essential settings;
  • maintain shopping or checkout functionality; and
  • provide core Platform functionality.

9.2 Performance & Analytics

Where used, GSMXCODE may use analytics or performance technologies to understand website performance, diagnose technical issues, measure usage, and improve the customer experience.

9.3 Security Technologies

Security and fraud-prevention technologies may use technical information to detect suspicious activity, abuse, automated attacks, or unauthorized access.

9.4 Browser Controls

Most browsers allow users to block, delete, or restrict cookies. Disabling essential technologies may cause portions of the Platform to stop functioning properly.

10. Security

10.1 Security Measures

GSMXCODE uses reasonable technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, loss, or destruction.

Technical Measures

  • TLS/HTTPS communications where applicable
  • Authentication and access controls
  • Logging and monitoring
  • Security controls for APIs
  • Backup and recovery measures

Operational Measures

  • Restricted access to sensitive information
  • Fraud and abuse monitoring
  • Security procedures
  • Incident-response processes
  • Vendor and infrastructure controls

10.2 Security Limitations

No electronic transmission or storage system can guarantee absolute security. We therefore cannot guarantee that information will never be compromised by circumstances beyond our reasonable control.

10.3 Security Incidents

Where required by applicable law, GSMXCODE will provide notifications or take other actions relating to a security incident or personal-data breach.

11. International Processing

GSMXCODE uses service providers and infrastructure that may operate in countries different from the country in which a customer resides.

As a result, personal information may be processed, accessed, or stored internationally.

11.1 International Transfer Safeguards

Where applicable law requires safeguards for international data transfers, GSMXCODE seeks to use appropriate mechanisms recognized under that law, such as contractual safeguards or other legally recognized transfer mechanisms.

11.2 Provider-Specific Processing

Payment processors, cloud providers, security providers, communication providers, and other service providers may process information under their own privacy policies and contractual arrangements.

The particular providers used by GSMXCODE may change as our infrastructure and business requirements evolve.

12. Data Retention

GSMXCODE retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy or as required or permitted by applicable law.

Data Category Retention Principle
Account Data Generally retained while the account is active and for a reasonable period afterward where necessary for legal, security, or operational purposes.
Transaction Data Retained as reasonably necessary for accounting, tax, disputes, fraud prevention, contractual obligations, and applicable law.
API Usage Logs Retained for service operation, metering, security, troubleshooting, dispute management, and legitimate operational requirements.
Security Logs Retained for periods appropriate to security, fraud prevention, abuse investigation, and legal requirements.
Support Records Retained as reasonably necessary for customer support, quality assurance, disputes, and legal purposes.

12.1 Deletion

When personal information is no longer required, GSMXCODE may delete, anonymize, or securely dispose of it, subject to legal, contractual, security, accounting, tax, backup, and dispute-retention requirements.

13. Privacy Rights

Depending on your jurisdiction and applicable law, you may have rights relating to personal information processed by GSMXCODE.

Right Description
Access / Know Request information about personal data we process and, where required, access to that data.
Correction Request correction of inaccurate or incomplete personal information.
Deletion Request deletion where provided by applicable law.
Restriction Request restriction of certain processing where applicable.
Objection Object to certain processing where applicable law provides such a right.
Portability Request certain information in a portable format where required by applicable law.
Withdraw Consent Withdraw consent where processing is based on consent and where withdrawal is legally available.
Opt Out of Sale/Sharing Where applicable law recognizes this right, request that GSMXCODE not sell or share personal information as defined by that law.
Limit Sensitive Information Where applicable law provides this right, request limits on certain uses or disclosures of sensitive personal information.

13.1 How to Submit a Request

Privacy requests may be submitted by email:

We may need to verify your identity before processing certain requests to protect against unauthorized access to personal information.

13.2 Authorized Agents

Where applicable law permits requests through an authorized agent, GSMXCODE may require documentation reasonably necessary to verify the agent's authority and the identity of the individual making the request.

13.3 Response

GSMXCODE will respond within the period required by applicable law, subject to lawful extensions, verification requirements, and applicable exceptions.

13.4 Non-Discrimination

GSMXCODE will not unlawfully discriminate against individuals for exercising privacy rights protected by applicable law.

14. Children's Privacy

GSMXCODE's Services are intended primarily for adults, businesses, and professional users.

We do not knowingly direct our Services to children where doing so would violate applicable law.

If you believe that a child has provided personal information to GSMXCODE in circumstances where the collection is not permitted, please contact:

[email protected]

15. Automated Risk & Fraud Decisions

15.1 Risk Screening

GSMXCODE and its payment or security providers may use automated systems to identify transactions or account activity that may present fraud, security, abuse, or compliance risks.

These systems may evaluate signals such as transaction information, account history, technical information, device or network indicators, usage patterns, and other fraud-related signals where relevant to security or transaction risk.

15.2 Possible Outcomes

Risk controls may result in additional verification, delayed processing, restricted access, declined transactions, temporary account restrictions, or other protective measures.

15.3 Human Review

Where required by applicable law, GSMXCODE will provide information regarding applicable automated decision-making rights and available review or challenge mechanisms.

16. Changes to This Privacy Policy

GSMXCODE may update this Privacy Policy to reflect changes in our Services, technologies, infrastructure, business operations, legal requirements, or privacy practices.

16.1 Effective Date

The current effective date is displayed at the end of this policy.

16.2 Material Changes

Where required or appropriate, GSMXCODE may notify users of material changes through the Platform, email, account notifications, or another reasonable communication method.

16.3 Continued Use

Continued use of the Platform after the effective date of an updated Privacy Policy is subject to the revised policy to the extent permitted by law.

17. Contact

GSMXCODE LLC
Privacy: [email protected]
General Support: [email protected]
Live Chat: Available through the GSMXCODE Platform

Effective Date: October 24, 2025

Service Scope: GSMXCODE processes personal information only as reasonably necessary to operate its Platform and the products and Services expressly described on applicable product pages, including software, diagnostics, device information, APIs, and authorized technical services.
Third-Party Privacy Policies: When you use a third-party payment provider, hosting provider, analytics service, authentication service, or other external system, that provider may separately process personal information under its own privacy policy and terms.
Privacy Commitment: GSMXCODE is committed to processing personal information responsibly, limiting collection to legitimate purposes, supporting documented Service operations, maintaining reasonable safeguards, and respecting privacy rights required by applicable law.