Privacy

Privacy policy

Last revised : 23 September 2026

This policy explains what data Romory processes, why, which services are involved and what choices are available. Items that are not yet verified are explicitly marked.

A. Identity and contact

Romory is currently operated personally by its founder, based in France. No future company or country of incorporation has been decided. Full legal name: [À compléter : operator’s civil identity or future registered name]. Postal address: [À compléter : operator’s postal address]. Registration number: [À compléter : if applicable].

Privacy contact: hello@romory.ai.

B. Responsibilities

Romory determines the purposes and means for host accounts, authentication, subscriptions and billing once enabled, tailored-offer enquiries, support, security, platform administration and commercial communications it chooses to send.

For an accommodation provider’s guest guide and related reporting, the provider determines why the guide is offered and what it contains. Romory processes that data on the provider’s instructions, except for its own security and service-operation purposes.

This notice does not replace the required data-processing agreement. [À compléter : finalise and provide the data-processing agreement before contracting].

When someone voluntarily creates a Romory account or personal carnet, Romory determines the purposes of that account. One email-identified account can technically link uses across several accommodation providers; this data is not described as anonymous or necessarily isolated between properties.

C. Data categories and sources

Data may be supplied directly by a host or guest, added to a guide by the accommodation provider, or collected automatically during use.

  • Hosts: email, authentication identifiers, name if supplied, role, interface language and property memberships.
  • Properties and guides: name, address, coordinates, city, country, contact details, practical stay information, Wi-Fi, rules, links and published documents.
  • Host content: logos, photos, poster backgrounds, copy, recommendation comments and brand settings.
  • Commercial enquiries and support: contact details, property or company name, establishment and room counts, locations, message, topic, page context and active property.
  • Payment: no card or paid subscription is currently processed in the app. This notice will be updated with the verified provider and accessible payment data before activation.
  • Guests: guide and stay-guide opens; selected preferences, moods, categories and cuisines; places shown and opened; server-stored favourites; feedback; optional notes; outbound directions, website and booking-service clicks.
  • In identified flows, name, email, phone, party size, room number and stay dates may be supplied by the provider or guest. Scanning a QR code alone does not disclose identity or booking details.
  • Technical data: random device and session identifiers, coarse device type, action timestamps, security and operational logs, and IP address in service logs.
  • An outbound click does not prove a booking, physical visit or revenue.

D. Purposes and legal bases

Required fields are necessary for the relevant account, security, response or service action. Without them, Romory may be unable to provide that action. Optional fields are identified as such.

Acceptance of this notice is not used as blanket consent.

PurposeLegal basis and detail
Host account and accessContract performance or pre-contractual steps.
Subscription and billingContract performance and legal invoicing/accounting obligations, once payment is active.
Guest guide and reportingThe legal basis chosen by the accommodation provider; Romory acts on its instructions.
SecurityLegitimate interests in proportionate protection of accounts, data and service availability.
Support and enquiriesPre-contractual steps, contract performance or legitimate interests, depending on the request.
MarketingConsent where required, or legitimate interests only where permitted. Marketing choice remains separate from contract acceptance.
Optional trackingPrior consent where required; it must not be activated before suitable controls exist.

E. Personalisation and analytics

Romory ranks host-approved places using choices expressed by the guest, such as activity, mood, company, setting, cuisine or need, then may use saved or rated places to order relevant results. These choices are not described as medical, psychological or sensitive profiling.

Provider reporting includes guide and stay opens, selected preferences, places shown and opened, saves, feedback, directions and outbound clicks. Reporting is scoped to the relevant property; identified internal previews are excluded.

Random identifiers are pseudonymous, not necessarily anonymous. Email-identified guest accounts can technically link use across properties, so Romory does not promise a general absence of cross-property linkage.

F. Recipients and external services

Data is accessible, according to role, to authorised staff of the relevant provider, the Romory operator and necessary service providers. Published guides and shared links can be opened by anyone with the link and must not contain private guest data or access secrets.

ServiceRole and data
Lovable CloudApplication, database, storage, authentication and managed email hosting; receives necessary account data, content, files, enquiries and logs.
Google Maps PlatformAddress and place search, coordinates, public place details, reviews and photos. Host requests use Lovable’s connector service; browser-loaded maps and fonts may receive IP and browser information.
Lovable AI Gateway and model providersDrafting from public place information, translations and some host-facing metric summaries. Current functions call OpenAI or Google models. No retention or training promise is made without verified contractual documentation.
External sitesVenue websites, directions and booking services apply their own privacy notices once opened.

G. Hosting and international transfers

Romory uses Lovable Cloud. [À compléter : contractually confirm primary hosting region, backup locations, remote-access locations and applicable transfer mechanisms].

Where data is accessed or processed outside the EEA, the relevant safeguard must be stated here: [À compléter : verified safeguard by provider and country].

H. Retention

Romory separates active data, legally required archiving and backups. The existing deletion process defaults to simulation and is not enabled for live deletion, so not every period below is currently enforced automatically.

CategoryVerified position
Host accounts and guide content[À compléter : define post-closure retention, recovery and deletion]
Guest interactions and preferencesStored in the database. A technical rule proposes deletion 24 months after departure, or creation where no departure exists; live deletion is not enabled and many flows have no departure date.
Guide favouritesStored server-side. Free-text notes are intended for redaction after 90 days once retention is enabled; other items currently follow the guest record.
Personal carnet[À compléter : define and implement inactivity retention and deletion]
Support and commercial enquiries[À compléter : define and implement separate periods]
Security logs[À compléter : inventory logs by service and enforce a verifiable period]
InvoicesNo active billing; retain for applicable legal periods once enabled and documented.
Backups[À compléter : confirm frequency, location and expiry after live-data deletion]

I. Cookies and browser storage

The site uses a one-year romory_locale language cookie and a seven-day host-sidebar cookie. The guest guide stores the chosen language, one random device identifier per property, whether a UI hint was seen and, where relevant, a personalised-link token. Session identifiers, temporary choices and event de-duplication markers remain for the tab session.

These items support operation, continuity and the internal measurement described above. The public code also prepares navigation events for a possible analytics tool, but no third-party analytics script was found to be loaded currently.

There is no preferences panel yet for optional trackers. [À compléter : implement consent, refusal and withdrawal before activating optional or advertising trackers].

J. Rights and complaints

Depending on the circumstances, you may request access, rectification, erasure, restriction and portability, object to legitimate-interest processing, and withdraw consent without retrospective effect.

For guide data, contact the relevant accommodation provider first. You may also email hello@romory.ai for assistance or forwarding. No complete self-service export or erasure tool is promised. Responses are normally provided within one month, subject to lawful extensions.

You may complain to the CNIL or another competent supervisory authority where relevant.

K. Updates

Material changes will be communicated appropriately, including in-app or by email where they affect an account. The revision date appears at the top of this page.