Privacy Policy

Last updated: June 9, 2026

1. Introduction

Roamly, Inc. (“Roamly,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our travel planning platform and related services.

2. Information We Collect

We collect information that you provide directly to us, including:

  • Account information (name, email address, password)
  • Profile information (profile photo, travel preferences)
  • Trip data (destinations, itineraries, travel dates, notes)
  • Communications you send to us (support requests, feedback)

We also automatically collect certain information, including:

  • Device information (browser type, operating system)
  • Usage data (pages viewed, features used, interactions)
  • Log data (IP address, access times, referring URLs)

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Create and manage your account
  • Generate personalized travel recommendations
  • Send you service-related communications
  • Respond to your requests and provide customer support
  • Analyze usage patterns to improve user experience
  • Protect against fraud and unauthorized access

Legal Bases for Processing (EU/UK)

Where the GDPR or UK GDPR applies, we process your personal data on the following legal bases:

  • Performance of a contract — to provide the Service you signed up for, including your account, trips, and itineraries
  • Legitimate interests — to secure, analyze, and improve the Service, where those interests are not overridden by your rights
  • Consent — for optional features such as marketing emails and non-essential cookies; you may withdraw consent at any time
  • Legal obligation — where processing is required to comply with applicable law

4. Sharing of Information

We do not sell your personal information. We may share your information in the following circumstances:

AI and Machine Learning Providers

To power features like our travel companion, itinerary suggestions, and destination recommendations, we send relevant context (such as your trip details, preferences, and conversation messages) to third-party AI providers, including Google (Gemini) and Anthropic (Claude). These providers process your data solely to generate responses and do not use it to train their models. We only share the minimum data necessary for each request.

Travel and Location Services

To provide place details, maps, directions, flight search, and hotel availability, we share relevant query data with:

  • Google Maps and Places API — for location search, place details, photos, reviews, and routing
  • Amadeus — for flight and hotel search results
  • AviationStack — for flight status and tracking
  • Yelp — for restaurant and business recommendations

These services receive search queries and location data, not your account information or personal profile.

Content Discovery

Our Discover feature aggregates travel content from public platforms including YouTube, Instagram, TikTok, and Reddit. We query these platforms using destination and topic keywords, not your personal data.

Infrastructure and Hosting

Your data is stored and processed by the cloud infrastructure providers that host our application and databases, including Supabase (database, authentication, and storage) and Vercel (application hosting). These providers process data on our behalf under data processing agreements and do not use it for their own purposes.

Other Sharing

  • Other users — when you choose to share trips, invite collaborators, or publish itineraries
  • Email providers — we use Resend to deliver transactional emails such as trip invitations
  • Authentication — if you sign in with Google, we receive your name and email from Google OAuth; we do not share your Roamly data back to Google
  • Business transfers — if Roamly is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction; we will notify you of any change in ownership or use of your personal data
  • Law enforcement — when required by law, court order, or to protect our rights and the safety of our users

5. Data Security

We implement technical and organizational measures designed to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit (TLS) and at rest
  • Database-level access controls, including row-level security that restricts each user’s data to that user and their invited collaborators
  • Least-privilege access for our personnel and service providers
  • Hashed credentials — we never store your password in plain text
  • Monitoring and logging to detect unauthorized access

No method of transmission or storage is 100% secure. If we become aware of a data breach affecting your personal data, we will notify you and the relevant authorities as required by applicable law.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with our services. In general:

  • Account and trip data — retained until you delete your account, after which it is permanently removed within 30 days
  • Server logs and usage data — retained for a limited period for security and debugging, then deleted or anonymized
  • Backups — deleted data may persist in encrypted backups for a limited period before being purged on a rolling basis
  • Aggregated or de-identified data — may be retained indefinitely, as it no longer identifies you

We may retain certain information where required by law, to resolve disputes, or to enforce our agreements.

7. International Data Transfers

Roamly is based in the United States, and your information is processed and stored on servers in the United States. If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S., where data protection laws may differ from those in your jurisdiction. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission’s Standard Contractual Clauses, and we require the same of our service providers.

8. Your Privacy Choices

Depending on where you live, you may have specific rights under privacy laws such as the California Consumer Privacy Act (CCPA), the Colorado Privacy Act, the Virginia Consumer Data Protection Act, or the EU/UK General Data Protection Regulation (GDPR).

Your Rights

  • Right to Know / Access: Request a copy of the personal data we have collected about you, including the categories of data, sources, purposes, and third parties with whom we share it
  • Right to Correct: Request that we correct inaccurate personal data
  • Right to Delete: Request that we delete your personal data, subject to certain legal exceptions
  • Right to Portability: Receive your data in a structured, machine-readable format (e.g., JSON or CSV export of your trips and account data)
  • Right to Opt Out of Sale/Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights

Additional Rights for EU/UK Residents

If the GDPR or UK GDPR applies to you, you also have the right to:

  • Object to processing based on our legitimate interests
  • Restrict processing while a dispute about your data is resolved
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
  • Lodge a complaint with your local data protection supervisory authority

Global Privacy Control and Do Not Track

We honor Global Privacy Control (GPC) signals as a valid opt-out of any sale or sharing of personal information in jurisdictions where GPC is legally recognized. Because we do not sell personal information or engage in cross-context behavioral advertising, honoring this signal does not change how the Service works for you. Our Service does not currently respond to “Do Not Track” browser signals, for which no industry standard exists.

Categories of Personal Information

Under CCPA, the categories of personal information we collect include: identifiers (name, email), internet activity (usage data, browsing history within our Service), geolocation data (trip destinations you add), and inferences (travel preferences derived from your activity).

How to Submit a Request

To exercise any of these rights, email us at privacy@roamly.io with the subject line “Privacy Request.” Please include your account email address so we can verify your identity. You may also designate an authorized agent to submit a request on your behalf.

We will acknowledge your request within 10 business days and respond within 45 calendar days. If we need additional time, we will notify you of the extension and the reason. If we decline your request, you may appeal our decision by replying to our response with the subject line “Privacy Appeal,” and we will review the appeal within the timeframe required by your state’s law.

Managing Your Preferences

  • Marketing emails: Unsubscribe using the link at the bottom of any marketing email, or update your preferences in your account settings
  • Account deletion: You can delete your account from your profile settings page. This will permanently remove your trips, conversations, and personal data within 30 days
  • Cookie preferences: See Section 9 below for cookie management options

9. Cookies and Tracking Technologies

We use cookies and similar technologies to operate our Service, remember your preferences, and understand how you use Roamly. Below are the categories of cookies we use:

CategoryPurposeRequired?
EssentialAuthentication, session management, security. These cookies are necessary for the Service to function.Yes
FunctionalRemembering your preferences, such as language, theme, and recent searches.No
AnalyticsUnderstanding usage patterns, popular features, and performance metrics to improve the Service.No

Managing Cookies

Most browsers allow you to block or delete cookies through their settings. Note that blocking essential cookies may prevent you from using the Service. You can typically find cookie controls under “Privacy” or “Security” in your browser’s settings menu.

We do not use cookies for cross-site tracking or targeted advertising.

10. Children’s Privacy

Roamly is not directed to children under 13. We do not knowingly collect personal information from children under 13, and we do not sell or share the personal information of consumers we know to be under 16. If you believe we have collected information from a child under 13, please contact us immediately and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the “Last updated” date.

12. Contact Us

If you have questions about this Privacy Policy, please contact us at privacy@roamly.io.