ROAMORA LEGAL
Privacy policy
Effective 8 September 2026
Roamora uses the minimum information needed to plan trips, save your choices, send requested emails, and manage optional beta-list updates. We do not sell personal information or run advertising profiles.
Who is responsible
Roamora is operated by Lovro Mraović in Croatia. In this policy, “Roamora,” “we,” and “us” refer to that service and its operator.
Information Roamora handles
Account information includes a random user ID, your email address, a salted password hash, and expiring session records. Profile information may include your display name, home airport, language, currency, interests, accessibility choices, and notification settings.
Trip data may include destinations, dates, budgets, travelers, itineraries, favorites, price watches, searches, and planning-guide messages. If you choose to track a booking made elsewhere, Roamora may also store the provider, provider-issued confirmation number, amount, currency, notes, reminder preference, and status.
Support information includes the reply address and message you choose to send through the Contact Us form. If you join the beta list, Roamora stores your normalized email address, subscription status and source, consent time, confirmation time, unsubscribe time, and delivery status for messages sent to the list. A secure confirmation link is required before beta or launch updates are sent. Technical information may include session identifiers, request logs, device or browser information, IP addresses processed briefly for abuse prevention, and diagnostic data needed to protect and maintain the service.
When an app user opens a provider result, Roamora records only the provider category, provider label, app surface, source type, and time. This aggregate referral measurement is not linked to a user ID, email, destination, dates, or selected property and is deleted after 90 days.
For aggregate website statistics, Roamora records only the public page path and time of the view. Query strings are never sent. This measurement uses no analytics cookies, fingerprint, IP address storage, or visitor identifier, so it cannot report unique visitors. In the signed-in app, a separate conversion-funnel record stores only the random Roamora account ID, a stage name such as completed search, saved trip, opened provider, or tracked booking, and the time. It does not contain a destination, search details, provider, price, URL, or booking confirmation. Page-view and funnel records are deleted after 90 days; account-linked funnel records are also removed when the account is deleted.
How information is used
We use information to create and save trip plans, personalize results, refresh eligible supplier-priced watches when requested, track provider confirmations you choose to enter, provide support, manage requested beta access and launch updates, maintain security, diagnose problems, and comply with legal obligations.
The current referral flow never stores a real card number, charges a payment method, or makes a supplier reservation.
Storage and providers
Roamora stores an offline planning cache in the operating system app sandbox and synchronizes signed-in account data with the Roamora API. On Android and iOS, the app stores its opaque session token in encrypted platform storage. Browser sessions end with the browser session.
Information needed to answer a search may be sent to travel and destination providers such as Open-Meteo, Wikimedia, OpenStreetMap, Google Routes, Duffel, and KAYAK. For a KAYAK sandbox flight search, KAYAK also receives the original client IP and a pseudonymous identifier derived from the current sign-in session for bot prevention and service compliance. KAYAK does not receive the Roamora account ID, email address, or raw session ID through this search integration. When you open a Booking.com link through CJ, a Stay22 accommodation link, or another provider link, the destination, dates, guest counts, preferred currency, and selected property may be included so the provider can show current options and attribute a possible commission. The provider and affiliate network process that visit under their own policies.
Resend processes the reply address and message submitted through Contact Us and delivers beta-list confirmation, beta-access, and launch-update messages to confirmed addresses. Every list message includes a visible unsubscribe link and email-client one-click unsubscribe headers. Resend may also deliver account-verification and password-recovery messages. Cloudflare may process browser and network signals for hosting and the optional Turnstile anti-spam check.
When crash reporting is configured for a beta build, Sentry may receive a pseudonymous Roamora user ID, app and operating-system version, device model, stack trace, and limited route or request metadata. Roamora disables default collection of email addresses and IP addresses in the app monitoring SDK.
Sharing and legal basis
Roamora does not sell personal information or use it to build advertising profiles. Information is shared only with service providers that help operate Roamora, when you direct us to share it, or when disclosure is required by law.
Depending on the context, processing is based on providing the service you request, our legitimate interest in operating a safe and reliable beta, your consent, or a legal obligation.
Retention, security, and your choices
Account and planning information is kept until you delete it or your account. Sessions expire after 14 days or 7 idle days, and each account is limited to five active sessions. Android removes the local encrypted session token when the app is uninstalled, so a reinstall requires sign-in again but does not delete the account stored by the Roamora API. Verification links expire after 24 hours; password-reset links expire after one hour and are single use. The newest 14 daily database backups are retained locally and, when configured, in encrypted off-site object storage, so deleted data may remain in rotating backups for approximately 14 days.
Support messages are retained only as long as needed to answer the request and maintain an appropriate support record. Unconfirmed beta-list requests expire and are removed after 30 days. Confirmed beta-list addresses are used until beta and launch updates are complete or you unsubscribe. After unsubscribe, Roamora keeps the address, unsubscribed status, consent time, and unsubscribe time as a suppression record so the address is not contacted again; you may ask us to delete that record. Aggregate website page-view records, app provider-click records, and account-linked funnel-stage records are retained for 90 days. Crash reports follow the retention period configured in the monitoring provider and are periodically reviewed. We use safeguards appropriate to the beta, but no internet service can promise absolute security.
You may request access, correction, deletion, restriction, or a copy of your information, and may object to certain processing where applicable. Every beta-list message has a one-click unsubscribe option. You can download a portable JSON copy of account data in the app under You → Your data → Export my data. You can permanently delete your account under You → Your data → Delete account, or follow the public account deletion instructions. A beta-list subscription is separate from an app account, so deleting one does not automatically delete the other.
Children and policy updates
Roamora is not directed to children under 13 and does not knowingly collect their personal information. A parent or guardian should contact us if they believe a child submitted information.
We may update this policy as the product and its providers change. Material updates will appear with a new effective date and, where required, an in-app notice.
Contact
Questions and privacy requests can be sent to Lovro Mraović, operator of Roamora.