1. Who is responsible for your data
RoamDay is published by Lunchlab, a French registered micro-entreprise:
- Legal representative: François Lacoumette
- DPO / contact email: contact@roamday.fr
- Postal address: available on request at contact@roamday.fr
As a data controller within the meaning of the GDPR (EU 2016/679), we guarantee that your data is processed lawfully, fairly, transparently, and only for the purposes described below.
2. What data we collect
Data you provide directly
| Data | When | Why |
|---|---|---|
| First name, last name, email, profile photo | Sign-up / profile edit | Account identification |
| Country, city of residence, language, currency | Onboarding / Profile | Adapt UI and recommendations |
| Trips, destinations, dates, budgets | Creating a notebook | Core service: planning your trip |
| Tickets (references, QR codes, prices) | Manual add or import (.pkpass / PDF) | Centralize your bookings |
| Photos linked to a trip | You add via Memories | Chronological storage and organization |
Data collected automatically
| Data | Source | Purpose |
|---|---|---|
| Unique identifier (UUID) | Supabase Auth | Link your account to your data |
| Precise location | iOS permission ("while using") | Map around you, routes |
| Device type, iOS version | App at launch | Debugging and compatibility |
| Preferences (travel style, dietary restrictions) | Profile | Contextual recommendations |
3. Legal bases for processing (GDPR art. 6)
- Performance of the contract (art. 6.1.b) — to provide the service you request: create a notebook, calculate a route, display a ticket
- Consent (art. 6.1.a) — for location, notifications, and access to photos. You can withdraw it at any time in iOS Settings
- Legitimate interest (art. 6.1.f) — for technical debugging and fraud prevention
4. Who we share with
We only share with technical sub-processors that host or process the data on our behalf. No sale, no third-party monetization.
| Sub-processor | Role | Server location |
|---|---|---|
| Supabase | Database, auth, photo storage | EU (Frankfurt, eu-west-3) |
| HERE Maps | Geocoding, routes, weather | EU (Frankfurt) |
| Vercel | roamday.fr website hosting | EU (Frankfurt) |
| Apple iCloud (optional) | Sync across your devices if enabled | Per your Apple region |
When you click on a booking link (Tiqets, GetYourGuide, Air France-KLM, Booking…), you're redirected to their site in a Safari window embedded in the app. From that moment, their privacy policy applies. RoamDay receives no booking data back.
5. Retention period
| Data | Duration |
|---|---|
| Account data (email, name) | As long as your account exists |
| Trips and tickets | 3 years after your last trip |
| Trip photos | As long as your account exists (deletion on request) |
| Technical logs | 30 days then auto-deletion |
| Everything after account deletion | Immediate erasure (see section 7) |
6. Your rights (GDPR chap. III)
You have the following rights:
- Right of access — know what data we hold about you
- Right to rectification — correct inaccurate information
- Right to erasure ("right to be forgotten") — delete your account and all your data
- Right to restriction — temporarily freeze processing
- Right to portability — retrieve your data in a structured format (JSON)
- Right to object — refuse certain processing
- Right to withdraw consent — at any time, without justification
To exercise any of these rights, email contact@roamday.fr. Response within 30 days maximum (GDPR art. 12.3).
If you believe your rights are not being respected, you can file a complaint with the CNIL (French data protection authority).
7. Account deletion
If you prefer, you can email us at contact@roamday.fr with your account's email. We process the deletion within 7 days and confirm by email.
8. Data security
- TLS 1.3 end-to-end encryption for all app ↔ server communications
- At-rest encryption (AES-256) for the Supabase database
- Two-factor authentication on the technical team side
- No OAuth secret in the app binary — sensitive keys remain server-side (Supabase Edge Functions)
- Audit log of all actions on user accounts (30 days)
9. Cookies and trackers
The iOS app sets no cookies or trackers. The roamday.fr website only uses Vercel Web Analytics (anonymized, cookieless, EU-hosted). No third-party analytics (Google Analytics, Meta Pixel, etc.).
10. Minors
RoamDay is intended for users 16 years and older. We do not knowingly collect data about minors under 16. If you discover such a case, contact us: we will delete the account within 48 hours.
11. Transfers outside the EU
All our data is hosted within the European Economic Area (Supabase / Vercel servers in eu-west-3, Frankfurt). No transfer to the United States or other jurisdictions without standard contractual clauses validated by the European Commission.
12. Changes
We may update this policy. The last update date is shown at the top. In case of substantial changes, you will be notified in-app and by email.
13. Contact
For any question, email us: contact@roamday.fr
RoamDay is published by Lunchlab (Paris, France). Postal address available on request at contact@roamday.fr.