Last updated: August 2026
Welcome to roam your way. This Privacy Policy explains how we collect, store and use your information when you use our travel planning app at roamyourway.app and our iOS application. We are committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR).
roam your way is operated by Roam Your Way, registered with the Dutch Chamber of Commerce (KvK) under number 42057065, based in the Netherlands. Correspondence is handled by email at privacy@roamyourway.app. We aim to respond to all data protection requests within 30 days.
When you sign in with Google, we receive your name, email address and profile photo from your Google account.
When you sign in with Apple (available in our iOS application), we receive your name and an email address. You may choose to share your real Apple ID email or to use Apple's "Hide My Email" private relay address — in the latter case we only ever see and store the relay address, and Apple privately forwards mail to your real inbox. Profile photos are not provided by Sign in with Apple.
In both cases, the information we receive is stored in our database and used to identify your account and associate your data across sessions and devices.
Trip itineraries, wishlists, checklists, budget entries, hotel and transport information, day-by-day plans, past trip history, travel goals, shared expenses and split-cost records that you create or import in roam your way are stored in our cloud database (Supabase), linked to your email address. This data persists across devices and browser sessions.
When you use the ask roam your way assistant, generate a trip with AI, or import an itinerary via text, the content you provide — along with relevant context about your current trip — is sent to Anthropic's API for processing.
We also generate scheduled travel tips for active and upcoming trips: on a daily schedule, your trip context (destinations, dates, hotel details, day-by-day plan) is processed by Anthropic's API to produce a short tip surfaced in the app and, if you have opted in, delivered as an email or push notification.
We track your ask roam your way usage to manage free and Pro tier access: a lifetime counter for the free tier (10 message cap) and a daily counter for Pro (40 message cap, resets at midnight UTC). No message content is retained for usage tracking — only the counts.
If you use trip sharing features, the email addresses of people you invite (and those who invite you) are stored in our database to facilitate the share invitation, deliver the invitation email, and load shared trips. Shared trip data is made accessible to the invited user for the duration of the share. When you collaborate on a trip, edit notifications generated by your collaborators (and vice versa) are stored to enable change history.
Each shared trip has one communal conversation. Everyone on that trip — the person who owns it and everyone who has accepted an invitation to it — is in the same conversation, and a message you send is visible to all of them, including anyone who joins that trip later. There is no private or direct messaging between individuals in roam your way.
The text of each message, the email address of the person who sent it and the time it was sent are stored in our cloud database (Supabase) alongside the rest of your trip data. Message content is not sent to Anthropic or to any other AI provider — the ask roam your way assistant described above is a separate feature and does not read your conversations.
Your first name is shown to the other people in a trip's conversation, next to each message you send. This is why we ask you for a name when you first sign in. If no name is stored on your account, a name derived from the first part of your email address is shown instead.
For each conversation you are in, we also store a record that you are a participant, when you joined, when you left (if you have), and the point at which you last read the conversation, so that we can show it to you and count what is unread.
Messages are kept after a trip ends, and after a trip is deleted — the conversation stays readable to the people who were in it and is labelled as no longer active. Leaving a shared trip does not remove you from its conversation or delete your messages: you keep access to the history you were part of. Messages cannot be edited or deleted once sent, by you or by anyone else; this is enforced in our database and not only in the app. See Section 8 for retention.
If you forward a hotel, flight or transport confirmation email to your personal roam your way alias address, the contents of that email (including sender, subject and body) are received by our inbound email processor (Postmark), forwarded to our backend, and processed by Anthropic's API to extract structured booking details. The structured booking is then stored against your trip. The original email is not retained beyond the duration of processing. You may stop using this feature at any time by not forwarding emails to the alias.
If you opt in to push notifications:
You can revoke push permissions at any time in your browser or device settings, and disable individual categories from within the app.
roam your way may request access to your device's location to show your current position on the in-app map and, if you ask for directions from your current location, to calculate a route. To compute that route, your current coordinates are sent to Google Maps Platform in real time. We do not otherwise store or log your device location. You can deny or revoke location access at any time in your device or browser settings.
To display destination, activity and hotel imagery, we send city names, activity names and hotel keywords to third-party photo services (Pexels and Unsplash). Only the search query string is transmitted; no personal data is included. Images are loaded from these services' CDNs.
A small subset of preferences and session state is stored locally in your browser's localStorage and your device's app storage:
This local data is removed when you sign out, clear browser data, or uninstall the iOS app.
roam your way offers an optional paid Pro subscription, purchased through the Apple App Store on iOS or Google Play on Android. Your purchase is processed by Apple or Google — we do not receive or store your payment card details. We use RevenueCat to manage and verify subscription status: your account email (as a subscriber identifier) and your entitlement and subscription state (for example, whether Pro is active and when it renews or expires) are processed by RevenueCat and synced to your account so we can unlock Pro features.
We record a small set of first-party product events to understand how roam your way is used and to operate the service — for example, account sign-ups, trips created, AI generations run, paywall views and subscription activations. Each event is stored in our own database (Supabase) with an event name, a timestamp, the app version and your account email, plus minimal context such as a related trip identifier. We do not use third-party analytics platforms, advertising SDKs, tracking pixels, cross-app or cross-site tracking, or behavioural profiling for advertising. These events are used only by us, in aggregate, for product and operational insight.
We also track your ask roam your way usage counts (a lifetime free-tier counter and a daily Pro counter) to manage tier access, and the technical request data necessary to operate the service (see Section 5 — Vercel and Supabase).
To keep the app stable, we use Sentry to collect crash reports, error events and basic performance data (such as stack traces, the screen or action in progress, and timing metrics). Email addresses are stripped from this data before it is sent, and we do not attach your account identity to crash reports. This information is used only to diagnose and fix problems.
We process your personal data only where we have a lawful basis to do so under the GDPR. The table below sets out each processing activity and its legal basis.
| Processing activity | Legal basis |
|---|---|
| Google Sign In and Sign in with Apple / account authentication | Performance of a contract (Art. 6(1)(b)) |
| Storing and syncing trip data, wishlists, checklists, budgets, expenses, goals | Performance of a contract (Art. 6(1)(b)) |
| AI features (ask roam your way, itinerary generation, itinerary import, automated tips) | Performance of a contract (Art. 6(1)(b)) |
| Trip sharing and collaboration (storing invitee emails, edit notifications) | Legitimate interests (Art. 6(1)(f)) — to enable a feature you have explicitly requested |
| Trip messaging (storing message content, sender email, participant and read records) | Legitimate interests (Art. 6(1)(f)) — to enable a feature you have explicitly requested |
| Booking email forwarding (inbound parsing of forwarded emails) | Performance of a contract (Art. 6(1)(b)) — opt-in by forwarding |
| Push notifications (storing subscription endpoints, sending pushes) | Consent (Art. 6(1)(a)) — you may revoke at any time |
| Location data (map display) | Consent (Art. 6(1)(a)) — you may revoke at any time |
| ask roam your way usage counters (lifetime + daily) | Legitimate interests (Art. 6(1)(f)) — to manage service tiers and prevent abuse |
| Pro subscription management and verification (RevenueCat) | Performance of a contract (Art. 6(1)(b)) |
| First-party product analytics events | Legitimate interests (Art. 6(1)(f)) — to understand usage and improve the service |
| Crash reporting and performance diagnostics (Sentry) | Legitimate interests (Art. 6(1)(f)) — to keep the service stable and secure |
We use your data only to:
We do not sell or rent your personal data. Data is shared with third-party processors only as described in Section 5. Data Processing Agreements (DPAs) are in place with each processor listed below.
roam your way uses the following third party processors. Each processes data as described below, acts as a data processor under a Data Processing Agreement, and is subject to its own privacy policy.
Used as our cloud database and backend. Your account information, trips, wishlists, checklists, budget entries, past trip history, sharing records, trip conversations and messages, notifications, push subscription endpoints, notification preferences and other application data are stored on Supabase's infrastructure (hosted on AWS). Acts as a data processor under a Data Processing Agreement.
supabase.com/privacyUsed to power the ask roam your way AI assistant, AI-generated trip planning, itinerary text import, automated daily tip generation, and inbound booking-email parsing. When you use these features (or when the daily tip cron runs for your active trips), your messages and relevant trip context are sent to Anthropic's API for processing. Anthropic does not use data submitted via the API to train its models. Only the content necessary to fulfil the request is sent; processing is limited to query resolution. Acts as a data processor under a Data Processing Agreement.
anthropic.com/privacyUsed for authentication. Acts as a data processor under a Data Processing Agreement.
policies.google.com/privacyUsed to display maps, location search, place information and directions. When you request directions from your current location, your device coordinates are sent to Google in real time to compute the route. Acts as a data processor under a Data Processing Agreement.
policies.google.com/privacyUsed to host and serve the roam your way web application. Vercel may process standard web request data (IP address, browser information) as part of serving the app. Acts as a data processor under a Data Processing Agreement.
vercel.com/legal/privacy-policyUsed to manage and verify in-app subscription status for the Pro tier. Your account email (as a subscriber identifier) and your entitlement and subscription state are processed by RevenueCat. Payment itself is handled by the Apple App Store or Google Play; we do not receive your payment card details. Acts as a data processor under a Data Processing Agreement.
revenuecat.com/privacyUsed for crash reporting, error monitoring and performance diagnostics. Stack traces, error events and performance metrics are processed by Sentry to help us diagnose and fix problems. Email addresses are removed from this data before transmission, and account identity is not attached to crash reports. Acts as a data processor under a Data Processing Agreement.
sentry.io/privacyUsed to display weather forecasts. Only city coordinates are sent to retrieve weather data. No personal data is transmitted. Acts as a data processor under a Data Processing Agreement.
open-meteo.com/en/termsUsed to deliver transactional emails — share invitations, copy-trip links and (if you opt in) trip tip digests. The recipient email address, sender display name and the content of the message are processed by Resend. Acts as a data processor under a Data Processing Agreement.
resend.com/legal/privacy-policyUsed as the inbound email processor for booking-email forwarding. When you forward a confirmation to your roam your way alias address, Postmark receives the email, validates it, and forwards it to our backend for parsing. The email content and sender address are processed by Postmark. Acts as a data processor under a Data Processing Agreement.
postmarkapp.com/eu-privacyUsed for iOS application distribution (App Store), push notification delivery (Apple Push Notification service), and Sign in with Apple. When you use the iOS app, Apple processes standard App Store and APNs metadata necessary to install and deliver notifications. When you sign in with Apple, Apple authenticates you and provides your name and email (or a "Hide My Email" private relay address). Acts as a data processor under a Data Processing Agreement.
apple.com/legal/privacyFor web push notifications, your browser routes pushes through its vendor's push service (Mozilla autopush, Google's web push endpoint, or Apple, depending on your browser). Each is subject to its own privacy policy.
Used to source destination, hotel and activity imagery. Only search query strings (e.g. city or activity name) are sent to Pexels. No personal data is transmitted.
pexels.com/privacy-policyUsed as a fallback for destination and activity imagery. Only search query strings are sent to Unsplash. No personal data is transmitted.
unsplash.com/privacySome of our processors are based outside the European Economic Area (EEA), including Anthropic (US), Google (US), RevenueCat (US), Sentry (US), Resend (US), Postmark (US), Apple (US), Pexels (Germany — EEA) and Unsplash (Canada). Data processed by these services may be transferred to and stored outside the EEA, including in the United States, Canada, or other jurisdictions. Where this occurs, transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, or an equivalent transfer mechanism. Supabase infrastructure is hosted on AWS and may process data in regions outside the EEA subject to the same safeguards.
Your trip data is stored in Supabase's cloud infrastructure (hosted on AWS). This means your data is available across devices and is not lost when you clear your browser. All data in transit is encrypted via HTTPS. Data stored on Supabase is encrypted at rest. Push notification subscription endpoints are stored encrypted at rest and used only to deliver notifications you have opted into. Access to your data is restricted to authorised systems and personnel only.
A subset of session and preference data (sign-in identity, active trip, theme, home country, hydration cache) is stored locally in your browser's localStorage or your iOS device's app storage. This local data is not synced to our servers beyond what is described in Section 2.
We retain your personal data for as long as your account remains active. If you request deletion of your account, we will remove your account and all associated data — including trips, wishlists, checklists, budgets, sharing records, notifications, push subscriptions and device push tokens, notification preferences, product analytics events and subscription records — from our systems within 30 days. You may delete individual trips, wishlist items, checklist entries, budget entries and shared expenses directly within the app at any time.
Two things are kept deliberately, because erasing them would take other people's data with yours. Shared expenses and settlements you recorded on a trip belonging to someone else stay on that trip, so the travellers still on it keep a complete record of who paid for what; shared expenses on your own trips are deleted along with the trip. And a trip's conversation survives, as described next.
Trip messages are retained differently, by design. A trip's conversation is communal, and it is kept when the trip ends, when the trip is deleted, and when one of the people in it deletes their account — so that the others can still read the history they took part in. When you delete your account we remove your membership of every conversation, we delete outright any conversation in which you were the only remaining participant, and on the messages you sent we replace your name and email address with an anonymous marker, so they show as sent by a former traveller. The text of those messages is kept, because it is part of a conversation other people were in — so if something you wrote needs removing, contact privacy@roamyourway.app and we will handle it as an erasure request under Section 9. Messages cannot be edited or deleted from within the app once sent — the capability does not exist, in the database as well as in the interface.
Under the GDPR you have the following rights in relation to your personal data:
To exercise any of these rights, contact privacy@roamyourway.app. We will respond within 30 days.
roam your way is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. Use of roam your way by persons under 16 requires verifiable parental or guardian consent. If you believe a child under 16 has provided us with personal data without consent, please contact privacy@roamyourway.app and we will delete it promptly.
We may update this Privacy Policy from time to time. The date at the top of this page reflects the most recent update. Continued use of roam your way after changes constitutes acceptance of the updated policy.
For any privacy-related questions, data subject requests, or to exercise your GDPR rights, contact us at: privacy@roamyourway.app. We aim to respond to all requests within 30 days.