Privacy
Privacy policy
Last revised : 23 September 2026
A. Identity and contact
Romory is currently operated personally by its founder, based in France. No future company or country of incorporation has been decided. Full legal name: [À compléter : operator’s civil identity or future registered name]. Postal address: [À compléter : operator’s postal address]. Registration number: [À compléter : if applicable].
Privacy contact: hello@romory.ai.
B. Responsibilities
Romory determines the purposes and means for host accounts, authentication, subscriptions and billing once enabled, tailored-offer enquiries, support, security, platform administration and commercial communications it chooses to send.
For an accommodation provider’s guest guide and related reporting, the provider determines why the guide is offered and what it contains. Romory processes that data on the provider’s instructions, except for its own security and service-operation purposes.
This notice does not replace the required data-processing agreement. [À compléter : finalise and provide the data-processing agreement before contracting].
When someone voluntarily creates a Romory account or personal carnet, Romory determines the purposes of that account. One email-identified account can technically link uses across several accommodation providers; this data is not described as anonymous or necessarily isolated between properties.
C. Data categories and sources
Data may be supplied directly by a host or guest, added to a guide by the accommodation provider, or collected automatically during use.
- Hosts: email, authentication identifiers, name if supplied, role, interface language and property memberships.
- Properties and guides: name, address, coordinates, city, country, contact details, practical stay information, Wi-Fi, rules, links and published documents.
- Host content: logos, photos, poster backgrounds, copy, recommendation comments and brand settings.
- Commercial enquiries and support: contact details, property or company name, establishment and room counts, locations, message, topic, page context and active property.
- Payment: no card or paid subscription is currently processed in the app. This notice will be updated with the verified provider and accessible payment data before activation.
- Guests: guide and stay-guide opens; selected preferences, moods, categories and cuisines; places shown and opened; server-stored favourites; feedback; optional notes; outbound directions, website and booking-service clicks.
- In identified flows, name, email, phone, party size, room number and stay dates may be supplied by the provider or guest. Scanning a QR code alone does not disclose identity or booking details.
- Technical data: random device and session identifiers, coarse device type, action timestamps, security and operational logs, and IP address in service logs.
- An outbound click does not prove a booking, physical visit or revenue.
D. Purposes and legal bases
Required fields are necessary for the relevant account, security, response or service action. Without them, Romory may be unable to provide that action. Optional fields are identified as such.
Acceptance of this notice is not used as blanket consent.
| Purpose | Legal basis and detail |
|---|---|
| Host account and access | Contract performance or pre-contractual steps. |
| Subscription and billing | Contract performance and legal invoicing/accounting obligations, once payment is active. |
| Guest guide and reporting | The legal basis chosen by the accommodation provider; Romory acts on its instructions. |
| Security | Legitimate interests in proportionate protection of accounts, data and service availability. |
| Support and enquiries | Pre-contractual steps, contract performance or legitimate interests, depending on the request. |
| Marketing | Consent where required, or legitimate interests only where permitted. Marketing choice remains separate from contract acceptance. |
| Optional tracking | Prior consent where required; it must not be activated before suitable controls exist. |
E. Personalisation and analytics
Romory ranks host-approved places using choices expressed by the guest, such as activity, mood, company, setting, cuisine or need, then may use saved or rated places to order relevant results. These choices are not described as medical, psychological or sensitive profiling.
Provider reporting includes guide and stay opens, selected preferences, places shown and opened, saves, feedback, directions and outbound clicks. Reporting is scoped to the relevant property; identified internal previews are excluded.
Random identifiers are pseudonymous, not necessarily anonymous. Email-identified guest accounts can technically link use across properties, so Romory does not promise a general absence of cross-property linkage.
F. Recipients and external services
Data is accessible, according to role, to authorised staff of the relevant provider, the Romory operator and necessary service providers. Published guides and shared links can be opened by anyone with the link and must not contain private guest data or access secrets.
| Service | Role and data |
|---|---|
| Lovable Cloud | Application, database, storage, authentication and managed email hosting; receives necessary account data, content, files, enquiries and logs. |
| Google Maps Platform | Address and place search, coordinates, public place details, reviews and photos. Host requests use Lovable’s connector service; browser-loaded maps and fonts may receive IP and browser information. |
| Lovable AI Gateway and model providers | Drafting from public place information, translations and some host-facing metric summaries. Current functions call OpenAI or Google models. No retention or training promise is made without verified contractual documentation. |
| External sites | Venue websites, directions and booking services apply their own privacy notices once opened. |
G. Hosting and international transfers
Romory uses Lovable Cloud. [À compléter : contractually confirm primary hosting region, backup locations, remote-access locations and applicable transfer mechanisms].
Where data is accessed or processed outside the EEA, the relevant safeguard must be stated here: [À compléter : verified safeguard by provider and country].
H. Retention
Romory separates active data, legally required archiving and backups. The existing deletion process defaults to simulation and is not enabled for live deletion, so not every period below is currently enforced automatically.
| Category | Verified position |
|---|---|
| Host accounts and guide content | [À compléter : define post-closure retention, recovery and deletion] |
| Guest interactions and preferences | Stored in the database. A technical rule proposes deletion 24 months after departure, or creation where no departure exists; live deletion is not enabled and many flows have no departure date. |
| Guide favourites | Stored server-side. Free-text notes are intended for redaction after 90 days once retention is enabled; other items currently follow the guest record. |
| Personal carnet | [À compléter : define and implement inactivity retention and deletion] |
| Support and commercial enquiries | [À compléter : define and implement separate periods] |
| Security logs | [À compléter : inventory logs by service and enforce a verifiable period] |
| Invoices | No active billing; retain for applicable legal periods once enabled and documented. |
| Backups | [À compléter : confirm frequency, location and expiry after live-data deletion] |
I. Cookies and browser storage
The site uses a one-year romory_locale language cookie and a seven-day host-sidebar cookie. The guest guide stores the chosen language, one random device identifier per property, whether a UI hint was seen and, where relevant, a personalised-link token. Session identifiers, temporary choices and event de-duplication markers remain for the tab session.
These items support operation, continuity and the internal measurement described above. The public code also prepares navigation events for a possible analytics tool, but no third-party analytics script was found to be loaded currently.
There is no preferences panel yet for optional trackers. [À compléter : implement consent, refusal and withdrawal before activating optional or advertising trackers].
J. Rights and complaints
Depending on the circumstances, you may request access, rectification, erasure, restriction and portability, object to legitimate-interest processing, and withdraw consent without retrospective effect.
For guide data, contact the relevant accommodation provider first. You may also email hello@romory.ai for assistance or forwarding. No complete self-service export or erasure tool is promised. Responses are normally provided within one month, subject to lawful extensions.
You may complain to the CNIL or another competent supervisory authority where relevant.
K. Updates
Material changes will be communicated appropriately, including in-app or by email where they affect an account. The revision date appears at the top of this page.