Navigation menu

Roamii

Privacy Policy

Plain-language privacy. Because you should be able to understand your privacy.

Published: October 6, 2026. Effective: November 5, 2026.

The Short Version

We think privacy policies should be readable. Here's what matters, in plain English:

We do not sell your personal data. Not to advertisers, data brokers, insurance companies, or anyone else.

We do collect your location during active trips. This is how boundary alerts, safety warnings, and check-ins work. Your location is shared with your trip group according to your role. Sharing outside your trip is limited to the circumstances described in Section 6, including service providers and legal or emergency disclosures. We do not sell your location data.

Location is deleted 30 days after your trip ends, photos after 90, and you can delete your account at any time. Real-time location pings are deleted 30 days after the trip ends. On supervised and organization trips, if the safety system records an incident — someone leaving every safe zone, a phone going dark, or location sharing being switched off — that traveller's location readings are kept for up to one year instead, so they are still available if the incident is reported later. On any trip, anyone on the trip can report an incident about a traveller, during or after the trip, which keeps that traveller's readings for one year. Check-in locations are removed 90 days after your trip ends, along with the photo.

We share data with service providers to run the app, not for profit. Our hosting provider and email service help operate Roamii. They can't use your data for their own purposes.

We use aggregated, non-personal data to improve the app. Things like which features get used most, how trip planning patterns vary by destination, or "70% of groups in Barcelona visited the Gothic Quarter." This data has no names, no user IDs, and cannot identify you.

We do not process payments. Roamii links you to external services like Apple Cash or Venmo. Payments happen there, not in Roamii. We store the expenses you record and any payment handles you add to your profile, such as a Venmo username.

You can delete your account and data at any time. In the app, in Settings. No emails, no hoops.

1. Who We Are

Roamii is a group travel coordination app operated by Roamii L.L.C., a Texas limited liability company ("Roamii," "we," "our," or "us"). We provide mobile and web-based tools for group trip planning, coordination, photo sharing, expense splitting, and safety check-ins.

Email: support@roamii.app

Mail: 5900 Balcones Drive STE 100 Austin Texas 78731

2. Who This Policy Applies To

  • Travelers who create accounts and use the Roamii mobile app — whether on friend trips, supervised trips, or organization trips

  • Trip creators, chaperones, Trip Support, and Trip Leadership who manage trips

  • Parents or guardians who access the parent photo portal

  • Visitors to roamii.app

Age requirement: You must be 18 or older to create a Roamii account. We enforce this with the date of birth you give at signup: it is not checked against an identity document, but our servers refuse any account whose date of birth shows an age under 18. We do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it promptly.

We are working to make Roamii available to younger users in the future. When we are confident we can do so safely, we will update this policy and announce the change.

When you accept our Terms of Service, we record the version you accepted and when you accepted it. We separately record which Privacy Policy notice we presented and any acknowledgment you choose to give. An acknowledgment is not consent to optional processing. Where we rely on your consent for a particular purpose, we ask separately and explain how to withdraw it. Earlier records may identify an acceptance date without identifying the exact document version. See Section 16 for how we notify you about updates.

3. Information We Collect

3.1 Information You Provide

Data Type When Collected Why Full name Account creation Identify you to trip members Email address Account creation Authentication, notifications, recovery Phone number Account creation Shown to your trip members based on your role (Section 6.1) so they can reach you from their own phone. Roamii does not send text messages. Date of birth Account creation. Age check (18+ requirement); it is self-declared, not verified against an identity document, and it is not shown to anyone on your trip. In the future we may derive a broad age band from it (for example 25–34) for the anonymized, aggregate research described in §6.7; we do not do this today. Your date of birth itself would not be included in that research, and no aggregate would be published unless at least three separate trips contributed to it. Password Account creation Security (stored as a hash, not as plain text) Profile photo Optional, in-app Display to trip members Trip content During trip use Expense descriptions, poll responses, itinerary notes Receipt photos When logging expenses Expense documentation for your trip group.

3.2 Information Collected Through App Features

Data Type When Collected Why Check-in photos When you check in Safety confirmation and trip memories Location data (precise) Continuously during an active trip, including in the background Boundary alerts, check-in verification, rogue detection, departure warnings, safety features Contacts (transient access) Only when you invite someone to a trip To help you find and invite friends. We access your contacts for this action only and do not store them. Battery level and charging state, recorded with each location ping during an active trip. Device information App usage Troubleshooting, crash reporting, app performance

Addresses: When you add a stay, lodging or a reservation to a trip, the address you enter is stored and shown to your trip group as part of the plan, and it is looked up through Google's mapping service to place it on the map. For stays, it is also used to work out whether a traveller is at their homebase.

About background location: Roamii collects your location in the background while you are on an active trip. This applies to everyone on a supervised trip, including trip leaders, trip support and chaperones — not only travellers. On friends trips, your location is collected while you have allowed Roamii to use your location on your phone and location sharing is on in Roamii. Each member decides this for themselves, and you can stop sharing at any time.

You can turn location sharing off at any time, whichever role you hold. If you do, Roamii shows you that others can no longer see your location, and anyone viewing you sees "No Location" rather than a stale position as soon as your phone next reaches Roamii's servers. This is how we power safety features like boundary alerts ("you're leaving the group area"), rogue detection at night, departure warnings when a friend leaves the group, and activity zone monitoring. Without background location, these features cannot work.

What this means: Your device shares its location with Roamii's servers while your trip is active, even when the app is not in the foreground. This stops when the trip ends. Within your trip, location visibility depends on your role (see Section 6). Sharing outside your trip is limited to the circumstances described in Section 6, including service providers and legal or emergency disclosures. We do not sell your location data.

You can disable background location at any time in your device settings. However, doing so will disable safety features like boundary alerts and rogue detection. On organization and supervised trips, your Trip Leadership may require background location to be enabled as a condition of participation. On friend trips, location sharing is always optional and controlled by each individual.

3.3 Information Collected Automatically

When you use Roamii, we automatically collect limited technical data: device type, Battery level and charging state, recorded with each location ping during an active trip, OS version, app version, IP address, and general usage analytics (which features are used and how often). This helps us maintain and improve the app.

3.4 Information We Do NOT Collect or Store

  • Your contacts (Roamii does not read your address book; invites go out through your phone's own share sheet, and Roamii does not see who you send them to)

  • Browsing history or data from other apps on your device

  • Biometric data — biometric login is handled entirely by your device OS

  • Financial or payment information — Roamii links to external payment apps (Apple Cash, Venmo, etc.) and does not process or store payment data

4. How We Use Your Information

  • Providing the service: Account creation, trip participation, check-ins, photo sharing, expense tracking, notifications.

  • Safety features: Processing check-in photos, evaluating your location against trip boundaries, alerting trip leaders to potential safety concerns, detecting rogue status, sending departure/boundary warnings.

  • Communications: Transactional emails for account verification, sign-in, password resets, guardian photo-access invitations and other account-related notices. Trip activity and check-in reminders appear in the app; selected notices also use push notifications when enabled. Roamii does not send text messages. We save the time zone used for your expense reminders with your account, initially using your device's time zone; you can change it without sharing your location. Time Sensitive safety notifications can appear through Focus when you allow them in iOS settings, and respect silent mode.

  • Improvement: Analyzing aggregated, non-personal usage patterns to understand how people use the app, what features they enjoy, and where we can improve. This data is not tied to you personally, and it is not shared in a form that could identify you.

  • Research: In the future, using anonymized, aggregate data (with all personal identifiers removed) to understand travel patterns and improve the platform. We do not do this today.

  • Legal compliance: Responding to valid legal processes and protecting our users.

  • Product intelligence (planned): In the future we may use anonymized, aggregate trip data to improve features like trip recommendations, budget suggestions, and itinerary optimization, which may include training models on patterns across trips. We do not do this today. If we start, it will only use data that cannot identify any individual, and we will update this policy first.

We do not use your information for profiling or automated decision-making. We use it only for the purposes listed above, except that we may also use photos for advertising, marketing, or promotion with your explicit, separate consent as described in Section 11.

5. How We Limit the Use of Your Data

We do not sell your personal data.

We do not provide your name, email, phone number, photos, trip information, or any data that identifies you to third parties in exchange for money or other consideration.

Additionally, we do not:

  • Share your personal location data with advertisers, data brokers, or insurance companies

  • Use your photos for advertising, marketing, or promotion without your explicit, separate consent

  • Sell or share your personal data with any third party for their marketing purposes

  • Build behavioral profiles about you for sale or advertising

  • Include third-party advertising or tracking SDKs in the Roamii app

6. Who Sees Your Data

6.1 Your Trip Group — Location Visibility by Role

Who can see your location depends on the type of trip and your role within it:

Your Role What Others See About You Traveler (friend trip) Other travelers see your check-in status (Safe, Roaming, etc.) and last check-in neighborhood. Friends can see your location on the map if location sharing is enabled. Location sharing on friend trips is always optional. Traveler (org/supervised trip) Other travellers see your last check-in neighbourhood only (not exact location). Chaperones, Trip Leadership, Trip Support, and org admins can see your exact check-in location, previous locations, and current location on a map. Battery level: everyone on your trip. This is broader than location, which stays by role.

Trip leaders, trip support and chaperones are also visible on the map themselves. On a supervised trip, every member — travellers included — can see a supervisor's exact current location. This is deliberate and reciprocal: a traveller who needs help should be able to find the adult responsible for them.

On friends trips there are no supervisors. Every member who is sharing their location can see every other member who is sharing, and safety notifications go to everyone on the trip. If you turn location sharing off on a friends trip, no one is sent an alert; your pin simply reads "No Location". It is a mutual arrangement between equals rather than a monitored one. This is required for safety features to function. Chaperone / Trip Leadership / Trip Support Can see exact location, location history, and current position of all travellers on the trip map. Their own exact location is likewise visible to everyone on the trip. This enables boundary monitoring, rogue detection, and safety alerts.

On organization and supervised trips, background location sharing may be required by your trip's organization or chaperone as a condition of participation. Roamii itself does not require this — the requirement comes from your trip's leadership. On friend trips, location sharing is optional and controlled by each individual.

6.2 Check-In Photos — Who Sees Them

When you check in, you choose the visibility of your photo:

  • Share with all travelers: Your check-in photo is visible to everyone in your trip group.

  • Keep private: Your check-in photo is visible only to you.

Exception for org and supervised trips: Even if you mark a check-in photo as private, it is still visible to chaperones, Trip Leadership, Trip Support, and organization admins. This is a safety feature — trip leadership must be able to confirm your well-being from check-in photos. Marking a photo "private" on these trip types hides it from other travelers, not from leadership.

Photo approval queue: On organization and supervised trips, check-in photos go through an approval queue before reaching the group feed. Trip Leadership reviews each photo to protect the group from inappropriate content, photos taken while someone is visibly intoxicated or in a compromising situation, images that could be used for bullying or embarrassment, and anything sexual or depicting illegal activity. If a photo is rejected, it stays visible only to you. It does not go to the group, and your check-in still counts.

6.3 Parent/Guardian Photo Portal

If you or a chaperone invite a parent or guardian, they can see the approved photos of your whole trip, grouped by city, with the trip dates. Every guardian invited on that trip sees the same photos. They cannot see your location, check-in status, itinerary, expenses, or anything else. You can remove your guardian's access at any time from your traveler page on that trip.

6.4 Service Providers

We work with a small number of companies that help us run Roamii. They process data on our behalf, under signed Data Processing Agreements, and cannot use it for their own purposes.

Cloud hosting, database, and authentication (Supabase, Inc.) — stores and serves all app data, including accounts, trip content, photos, location records, and check-in data. All data is encrypted at rest and in transit. Supabase uses sub-processors to deliver the service, including Amazon Web Services (infrastructure hosting), Cloudflare (content delivery and security), Google Cloud, and Vercel. A complete current list of Supabase's sub-processors is available on request. Supabase processes personal data under a signed Data Processing Addendum that includes EU Standard Contractual Clauses. Supabase's GDPR supervisory authority is the Data Protection Commission of Ireland.

Product analytics (PostHog, Inc.) — processes app usage events, feature flags, and error reports to help us understand how Roamii is used and where we can improve it. Your analytics data is hosted in the European Union (Frankfurt, Germany). Some operational and support activities by PostHog occur in the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses. Data processed includes device information, app usage events, IP address, and pseudonymous user identifiers (not your name or email). We have a signed Data Processing Agreement with PostHog. PostHog is contractually prohibited from using your data for its own purposes and does not use your data to train AI or machine learning models.

Maps and location services (Google Maps Platform) — provides map display, geocoding, and location features in the app. Google Maps receives location coordinates during active trips and map tile requests. Google's use of this data is governed by its own privacy policy.

Email delivery (Resend) — sends verification codes, trip invitations, and transactional notifications. Resend receives your email address and name for the purpose of delivering these messages. Crash and error reporting (Sentry) — receives technical diagnostics when something in the app fails: the error itself, the sequence of in-app actions leading up to it, your device model, operating system and app version, and your Roamii user ID, so we can tell whether one person or many hit the same problem. If you choose to send feedback from inside the app, the name and email you type into that form go with it. Sentry does not receive screen recordings, screenshots, photos, or location coordinates, and it does not receive your email address unless you type it into the feedback form.

App stores (Apple, Google) distribute the Roamii app and receive account information as required by their store policies. Push notifications travel through Expo and the device platform's notification service. These services process the device's push address, the notification text and the identifiers needed to open the relevant screen.

A note about payments: Roamii does not process payments. When you settle expenses, the app links you to external payment services such as Venmo, Apple Cash, PayPal, and Cash App, which open outside of Roamii. Your card and bank details do not reach our servers. We store the expenses you record and any payment handles you add to your profile, such as a Venmo username or an Apple Cash phone number, so trip members can settle up. The privacy policies of those external services govern your use of them.

We do not share personal data with any service provider for their own commercial benefit. Every provider listed above is contractually bound — through a Data Processing Agreement, Data Processing Addendum, or equivalent — to process your data only for the purpose of operating Roamii on our behalf.

6.5 Disclosures Required by Law or to Prevent Harm

We may disclose your data in the following limited circumstances:

  • Legal process: If required by a valid court order, subpoena, or other legal process. We will attempt to notify you unless prohibited by law.

  • Imminent harm: If we believe in good faith that disclosure is necessary to prevent imminent physical harm to a person. In Roamii's context, this means situations where a traveler's safety may be at immediate risk — for example, a traveler who has not checked in and cannot be reached during an active trip, a traveler whose location indicates they may be in danger (such as an unexpected border crossing or location in a known high-risk area), or a situation where a chaperone or Trip Leadership has reason to believe a traveler is experiencing a medical or safety emergency. Disclosure in these cases would be limited to the minimum information necessary (such as last known location) and directed only to emergency services, Trip Leadership, or emergency contacts.

6.6 Business Transfers

If Roamii is acquired or merges with another company, your data may transfer as part of that transaction. This privacy policy will continue to apply. We will notify you before your data becomes subject to a different policy.

6.7 Anonymized, Aggregate Data

In the future we may create and use anonymized, aggregate data that cannot identify any individual. For example: "70% of groups visiting Barcelona chose evening free time in the Gothic Quarter" or "average daily spend for travelers in Rome was $52." We do not create such data today; if we start, this section will describe exactly how before it begins.

How it would be created: expiring location readings would be folded into counts per area and time window, with no user or trip attached and a minimum group size per count, and the original readings deleted. Nothing in the result could be traced back to any individual.

We use this data internally to improve the app — understanding which features get used most, how trip planning patterns vary by destination, and where we can make the experience better. Because this data cannot identify any individual, it is not considered personal information under GDPR, CCPA, or other privacy laws. In the future, we may share or license anonymized, aggregate data to third parties such as tourism organizations, travel industry partners, or research institutions. If and when we do, we will update this section to reflect that change. We do not reverse the anonymization process or attempt to re-identify individuals from aggregate data.

7. How We Protect Your Data

  • Data is encrypted in transit (TLS/HTTPS) between the app and our servers, and at rest in our database and photo storage (Supabase, AES-256)

  • Photos stored in private cloud storage, accessed only through authenticated, time-limited signed URLs (15-minute expiry)

  • Passwords hashed and salted — we cannot read your password

  • Parent portal uses email-verified sessions that expire after 24 hours; the access link itself expires 30 days after it is sent

  • When someone opens a parent portal link, we keep a scrambled (hashed) record of the link and email used, plus the network address, for two days, so we can block repeated wrong attempts. The link and email themselves are not stored in that record

  • Row-level security policies ensure users can only access data they are authorized to see

No system is perfectly secure. While we implement industry-standard protections, we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you in accordance with applicable law.

8. How Long We Keep Your Data — And How We Delete It

Roamii is designed around deletion, not retention. We do not preserve your trip data indefinitely. When your trip ends and your retention period expires, your data is gone. Trip templates can be saved for reuse (structure only, no personal data or photos).

Account information (name, email, phone, date of birth) is kept until you delete your account. You can delete your account in Settings at any time, and deletion is processed within 30 days.

Check-in photos are deleted 90 days after your trip ends, along with the location recorded with them.

Real-time location pings — the precise GPS coordinates used for live tracking during your trip — are deleted 30 days after your trip ends. If a safety incident is recorded during or after the trip (see Section 10), that traveller's location readings are kept for up to one year instead, so they are still available if the incident is reported later.

Check-in location records are removed 90 days after your trip ends, along with the photo. Nothing about that location is kept.

Flagged safety incidents keep that traveller's location readings for up to one year (see Section 10) for liability and dispute resolution purposes. They are deleted when the hold ends unless we are legally required to retain them longer.

Photo location metadata Photo location metadata is deleted along with your photos, 90 days after your trip ends.

Leaving or being removed ends your trip access; it does not erase shared expenses, settle outstanding balances, or remove shared stays and photos. Those records remain subject to their normal retention and deletion rules. A change of trip owner does not transfer authorship of your contributions. We store the participants, timestamps and outcome of ownership requests to operate the handoff and show its status. Requests expire after seven days; their history remains with the trip until the trip is deleted or a participating account is deleted.

Trip content (expenses, polls, reservations, itinerary items) stays with the trip until the trip owner deletes the trip or you delete your account. If you delete your account, items you shared with other people stay with the trip with your name removed. You may save a trip template, which preserves structure only — no personal data or photos.

Parent portal sessions expire after 24 hours or when you revoke access, whichever comes first; the access link itself expires 30 days after it is sent.

Device and usage analytics are kept for one year by our analytics provider under a pseudonymous identifier, then deleted. We do not record your screen, and IP addresses are discarded on receipt.

After account deletion, your login and email, profile, guardian email, payment details, consent record, check-ins and photos, location history, poll votes and personal budgets are deleted within 30 days. Expenses, reservations and polls you shared with other people stay with that trip, with your name removed, and trips you created pass to an eligible adult member. If no eligible adult can take over, remaining members' shared trip content is preserved while ownership requires resolution. Location readings placed under a safety-incident hold during a supervised trip are kept for the hold's period and reviewed by a named person when you ask to delete; if they are not released, we tell you why, and you can complain to a data protection authority. Some data may persist in encrypted backups for up to 7 days before being fully purged.

Deletion requests during active trips. If you request deletion while you are on a supervised or organization trip that is already under way, your account is deleted 30 days after that trip ends, and no more than 90 days after your request. This is based on our legitimate interest in keeping that trip's safety record complete until it ends. The app shows you the date when you ask, and we email you when the deletion is done. On friends trips there is no deferral: your account is deleted 30 days after your request. You can cancel your request before the scheduled date by choosing “Cancel deletion request” in your account settings. Signing in or reviewing or accepting updated Terms does not cancel it.

9. Your Rights

Depending on where you live, you have some or all of these rights:

Access: Request a copy of your personal data.

Correction: Fix inaccurate or incomplete data.

Deletion: Delete your account and data directly in the app (Settings). Processed 30 days after your request, or 30 days after a supervised trip that is under way ends (no more than 90 days), as described in Section 8.

Portability: Request a machine-readable copy of your data.

Restriction: Limit how we process your data.

Objection: Object to specific processing.

Withdraw consent: Where processing is based on consent (such as location sharing on friend trips or marketing communications), you can withdraw consent at any time through the app or your device settings. Withdrawing consent does not affect the lawfulness of processing that occurred before withdrawal. If you withdraw consent for location sharing on a friend trip, location processing stops on your phone immediately, and the people who could see you are shown "No Location" as soon as your phone next reaches Roamii's servers.

Contact legal@roamii.app to exercise any of these rights. We will respond within the time required by the law that applies to you. We do not discriminate against you for exercising your rights.

10. Location Data — The Full Picture

Location data is sensitive. We want to be completely transparent about how Roamii handles it.

  • When we collect it: While you are on an active trip, including in the background when your phone's location permission allows it. Collection begins when the trip becomes active and stops when the trip ends.

  • Why we need background location: Boundary alerts ("you're leaving the safe zone"), rogue detection at night ("this traveler has left their accommodation"), departure warnings ("a friend has left the group area"), and activity zone monitoring all require knowing where you are even when you're not actively using the app. Without this, these safety features cannot function.

    While a trip is active, Roamii's server sends your phone a silent check about every 20 minutes. Your phone answers with whether it can be reached, whether location sharing is on, and whether background tracking is running. It does not take a new location reading to answer. If it already holds a position from the last 15 minutes, it may send that one along with your battery level. If a phone that has been answering stops for 30 minutes, the people who can see you are shown "No Location": Trip Leadership on supervised and organization trips, and everyone on a friends trip with safety on.

    Roamii shows a note when it has no active push-notification connection recorded for your account. On supervised trips, the trip owner and chaperones can see this note. On friends trips with safety on, all trip members can see it. The note does not reveal why the connection is unavailable. An active connection does not guarantee that a notification reached your phone.

  • Who sees your location: This depends on your trip type and role. See Section 6.1 for the full breakdown. In summary: on friend trips, sharing is optional and peer-to-peer. On org/supervised trips, chaperones, Trip Leadership, and Trip Support see your exact location, previous locations, and current position on a map.

  • Location access limits: Parents/guardians see the city and country of each approved check-in in the photo portal, not your GPS position, and Roamii staff do not monitor individual locations. Sharing outside your trip is limited to the circumstances described in Section 6, including service providers and legal or emergency disclosures. We do not share your personal location data with advertisers or data brokers.

  • When we delete it: Live location readings are deleted 30 days after your trip ends. On supervised and organization trips, the safety system places a hold when someone leaves every safe zone, a phone goes dark, or location sharing is switched off. On any trip, anyone on the trip can report an incident about a traveller, during or after the trip, which also places a hold. A hold keeps that traveller's readings for one year from the event; for a missed check-in on its own, or a phone that went dark because its battery died, it keeps them for 90 days after the trip ends, and a second event extends it to one year. Check-in locations are removed 90 days after your trip ends. We do not currently keep any anonymized copy.

  • Can I disable it? Yes, in your device settings. However, this will disable safety features. On org/supervised trips, your organization or chaperone may require background location as a condition of participation. On friend trips, it is always optional.

  • When we request permission: We ask for location permission in context — when you join a trip and need the feature — not on first app launch. We explain why before the system dialog appears.

  • Alongside each location ping, your phone's battery level and whether it is charging are recorded, so your group can tell a dead phone from a person in trouble. Everyone on your trip can see your battery level, whatever their role. Each ping also records which Roamii version and phone platform it came from. These are kept and deleted together with your location pings, 30 days after the trip ends.

    We use battery readings for one further purpose: measuring how much battery a phone uses while Roamii is tracking, so that we can reduce Roamii's share of it. That measurement is a combined figure across many people, grouped only by phone platform and Roamii version. It is not linked to you, your trip, or your device, and because it identifies no one it is not deleted when your pings are. Pings recorded before battery readings existed have none.

11. Photos — The Full Picture

  • Check-in photos: You choose whether to share your check-in photo with all travelers or keep it private. On organization and supervised trips, photos marked "private" are hidden from other travelers but remain visible to chaperones, Trip Leadership, and Trip Support for safety verification.

  • Photo approval queue: On organization and supervised trips, check-in photos are reviewed by Trip Leadership before being shared with the group feed. This protects against inappropriate content, intoxicated or compromising photos, bullying, and sexual or illegal content. Rejected photos stay visible to the person who submitted them — others just can't see them.

  • Storage: All photos are stored in private, encrypted cloud storage. They are not publicly accessible. Access is controlled through time-limited signed URLs that expire after 15 minutes.

  • Parent portal: If you or a chaperone invite a parent or guardian, they can see the approved photos of your whole trip, grouped by city; every guardian invited on that trip sees the same photos. You can remove that access at any time.

  • Retention: Check-in photos are deleted 90 days after your trip ends, as described in §8.

  • We use your photos only to provide the Roamii service to you and your trip group, unless you give explicit, separate consent for advertising, marketing, or promotion. We do not use your photos for AI training.

12. International Data Transfers

Roamii is operated from the United States. Your personal data is processed in both the United States and the European Union, depending on the service involved:

Our hosting provider (Supabase) primarily processes data in accordance with your account region, with sub-processors including Amazon Web Services and Cloudflare. Our product analytics provider (PostHog) hosts your analytics data in the European Union (Frankfurt). Some operational and support activities by both providers occur in the United States.

For users in the EEA, UK, and Switzerland, we protect international transfers through EU Standard Contractual Clauses, the EU-US Data Privacy Framework (where applicable), and Swiss/UK adaptations. Signed Data Processing Agreements are in place with all providers handling personal data on our behalf.

13. Jurisdiction-Specific Provisions

13.1 EEA, UK, and Switzerland (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) or equivalent local law applies to our processing of your personal data. Below is the lawful basis we rely on for each category of data we process.

Account data (name, email, phone, DOB) — Lawful basis: contractual necessity. Required to create your account and provide the service.

Location data on supervised and organization trips — Lawful basis: legitimate interest (safety). Required for boundary alerts, check-in verification, and rogue detection. Trip leadership is notified if you disable location sharing. Disabling it does not lock you out of the app.

Location data on friend trips — Lawful basis: consent. Entirely optional. You choose whether to share your location with your trip group. You can withdraw consent at any time in your device settings or in the app. Location processing stops on your phone immediately, and the people who can see you are updated as soon as your phone next reaches Roamii's servers.

Check-in photos on supervised and organization trips — Lawful basis: legitimate interest (safety). Trip leadership reviews photos to confirm traveler well-being and to moderate content shared with the group.

Check-in photos on friend trips — Lawful basis: consent. You choose whether to share photos with your trip group.

Device and technical data — Lawful basis: legitimate interest (app stability). Used for crash reporting and app performance. Analytics events are kept for one year under a pseudonymous identifier, then deleted; crash reports carry your user ID only.

Marketing communications — Lawful basis: consent. Only sent if you explicitly opt in. You can withdraw consent at any time in your profile settings.

Important notes on location sharing for supervised and organization trips: Roamii does not require location sharing as a condition of using the app. If you disable location sharing, you retain full access to all other app features. However, your trip leadership (chaperone, Trip Leadership, or organization admin) will be notified that location sharing has been disabled. Your organization may have its own policies requiring location sharing as a condition of trip participation — that is their policy, not ours. Roamii enforces the notification; the organization enforces their own requirements.

Your rights under GDPR: You have the rights listed in Section 9 of this policy (access, correction, deletion, portability, restriction, objection, and withdrawal of consent). To exercise any of these rights, contact legal@roamii.app. We will respond within the time required by the law that applies to you. You may also lodge a complaint with your local data protection authority.

Data protection contact: For data protection inquiries from EU/EEA/UK/Swiss users, contact legal@roamii.app. We will evaluate whether a formal Data Protection Officer appointment is required as Roamii scales, and will update this section accordingly.

13.2 California (CCPA/CPRA)

  • We do not sell your personal information as defined by CCPA/CPRA.

  • We do not share personal information for cross-context behavioral advertising.

  • You have the right to know, request deletion, and opt out of any sale (though we do not sell).

13.3 Texas

Roamii L.L.C. is incorporated in Texas. We comply with the Texas Data Privacy and Security Act (TDPSA) and all applicable Texas privacy laws. Texas residents have the right to access, correct, delete, and obtain a copy of their personal data, and to opt out of the sale of personal data (which we do not do).

13.4 Other US States

We monitor and comply with applicable state privacy laws. If you have questions about your rights under your state's privacy law, contact legal@roamii.app.

14. Cookies and Tracking

Our product analytics provider (PostHog) uses anonymous pseudonymous identifiers to count unique users and sessions. These are not cookies in the web sense and do not track you across other apps or websites. No advertising identifiers, tracking pixels, or cross-context behavioral advertising technologies are used anywhere in Roamii.

15. Third-Party Links

Roamii may link to third-party services (map providers, external payment apps like Apple Cash or Venmo). We are not responsible for their privacy practices. When you open a payment link, you leave Roamii and are subject to that service's privacy policy.

16. Changes to This Policy

We may update this Privacy Policy. For material changes, we will notify affected users through the app or by email before the changes take effect, explaining what changed and when. We may ask you to acknowledge the notice, but acknowledgment does not grant consent. If a change requires your consent, we will ask separately before using your data for that purpose. We do not treat continued use or acceptance of our Terms as consent to optional processing or as a release of commitments that apply to data collected under an earlier policy. The current policy is at roamii.app/privacy-policy; dated versions and change summaries are at roamii.app/legal/versions.

17. Contact Us

Email: legal@roamii.app

Mail: Roamii L.L.C. 5900 Balcones Drive, STE 100, Austin Texas 78731

Response time: Within the time required by the law that applies to you.

Appendix A: Data Map

This section shows exactly what data we collect and where it goes.

Profile data includes your name, email, phone number, date of birth, and profile photo. Your name, phone number and profile photo are visible to your trip members; your email and date of birth are not shown to anyone on your trip. Profile data is shared with service providers (hosting, email) to operate the app. We do not sell profile data.

Trip addresses — the addresses you enter for stays, lodging and reservations. Visible to your trip group, shared with our hosting provider to operate the app, and sent to Google's mapping service to place them on the map. Kept with the trip (see Section 8, "Trip content"). We do not sell trip addresses.

Location data includes precise GPS coordinates collected continuously during active trips, including in the background. Your location is visible to your trip group based on your role (see Section 6.1). Real-time location pings are deleted 30 days after your trip ends, or kept for up to one year if a safety incident was recorded during or after the trip (see Section 10). Photos are deleted 90 days after your trip ends. We do not sell personal location data.

Photos include check-in photos and receipt photos. These are visible to your trip group based on your privacy setting. On organization and supervised trips, Trip Leadership can see all photos. Parents can see approved photos only if you invite them to the parent portal. Photos are deleted 90 days after your trip ends. We do not sell photos.

Trip content includes expenses, polls, and itinerary notes. This is visible to your trip group and retained under Section 8.

Device and technical data This is shared with PostHog (EU-hosted product analytics, under signed DPA with SCCs) and Supabase (our cloud database, also under signed DPA). Both providers are contractually prohibited from using your data for their own purposes. Analytics events are kept for one year under a pseudonymous identifier, then deleted; crash reports carry your user ID only.

Payment data — no card or bank details. Payments are handled entirely by external apps like Venmo, Apple Cash, PayPal, and Cash App. Roamii stores the expenses you record and the payment handles you choose to add to your profile (for example a Venmo username or an Apple Cash phone number).

Appendix B: App Store Privacy Labels

Data Linked to Your Identity

Category Data Types Purpose Contact Info Name, email, phone App functionality Location Precise location (continuous during active trips, including background) App functionality (safety features) User Content Photos, expense data, trip content App functionality Identifiers User ID App functionality Contacts Accessed transiently for invitations (not stored) App functionality

Data NOT Collected

Health & fitness, financial info, browsing history, search history, sensitive info, advertising data.

Tracking: No. Roamii does not track users across other companies' apps or websites.

This policy works alongside our Terms of Service, Sensitive Content Policy, and Trust & Safety page.