Roam ("we", "our", or "us") operates the Roam mobile app and web service (the "Service"). This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to both the web experience and the iOS/Android mobile apps.
1. Information We Collect
Information you provide
- Account details: name, email address, password, profile photo, optional bio.
- Content you post: comments, reviews, photos taken or selected from your device, ratings, and check-ins.
- Offer claims and wallet activity (drops claimed, redemptions, trade history).
- Communications with our support team.
Information collected automatically
- Device information: device type, OS version, unique app install identifier, language.
- IP address and approximate location derived from it.
- Usage data: which screens you visit, features you interact with, errors encountered.
Permissions we request on mobile
The mobile app asks for the following permissions when you use a related feature. You can revoke any of these at any time in your device settings.
- Location (foreground only): used to suggest the right local community, rank nearby drops, and show distance to businesses. Coordinates are sent to our servers to compute distance and are stored only as the last-known location associated with your account; we do not collect background location.
- Camera: used when you choose to take a photo for a post, review, check-in, or a vendor QR-code redemption scan. We never access the camera in the background; access happens only while a camera-enabled screen is open.
- Photo library: used when you pick an existing photo to attach to a post. We only upload the photos you explicitly select.
- Microphone: used only if you record audio for a media post. Not used in the background.
- Push notifications: when you grant permission, we register a push token so we can deliver notifications about drops, replies, and order updates.
2. How We Use Your Information
- Provide, maintain, and improve the Service and its features.
- Personalize your feed: match you to a local community, rank nearby drops, and surface content relevant to your activity.
- Send transactional notifications (order updates, drop alerts, replies, mentions).
- Process payments and refunds, prevent fraud, and meet tax/accounting obligations.
- Detect and prevent abuse, spam, harassment, and violations of our Community Guidelines.
- Diagnose crashes and fix bugs.
3. Third-Party Services
We use the following providers to deliver the Service. They process your data only on our behalf and are bound by appropriate data-protection terms.
- Stripe— payment processing. When you make a purchase, payment details (card number, billing address) are sent directly to Stripe and not stored on our servers. See Stripe's privacy policy.
- Firebase Cloud Messaging (Google)— delivers push notifications on Android.
- Expo Push Notifications— relays push payloads from our servers to FCM (Android) and APNs (iOS).
- Sentry— error monitoring and crash reports. Stack traces and non-personal device metadata are sent to Sentry to help us debug.
- Google Sign-In— if you choose to sign in with Google, your Google account email and name are shared with us by Google for authentication.
- Sign in with Apple— if you choose to sign in with Apple, Apple shares your name and an email address (or a private relay address, if you choose to hide your email) with us for authentication. We never receive your Apple ID password.
- Twilio— powers in-app voice and video calls. Call signaling and media are routed through Twilio when you place or receive a call.
- Hosting providers— we host our infrastructure on Railway (backend) and Vercel (web). They process data on our behalf.
4. Sharing With Other Users and Businesses
Content you post publicly (comments, reviews, photos, ratings) is visible to other users. When you claim or redeem an offer from a business, that business receives the minimum information needed to fulfill the redemption (your display name, redemption code, and claim time). We do not sell your personal information to advertisers or data brokers.
5. Advertising & Tracking
Roam does nottrack you across other companies' apps or websites, and we do notuse device advertising identifiers (Apple's IDFA or the Android Advertising ID) for advertising, attribution, or cross-app tracking. Because we do not track you in this way, the app does not present the App Tracking Transparency prompt.
6. Data Retention
We retain your information for as long as your account is active or as required to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You can delete your account at any time directly in the app (Profile → Edit Profile → Delete account) or by emailing us. When you delete your account, we remove or anonymize your associated personal data within 30 days, subject to legally required retention (e.g., tax records).
7. Security
We use industry-standard safeguards (TLS in transit, encryption at rest, access control, regular dependency updates) to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Choices and Rights
- Update or correct your profile information from the app or web.
- Revoke camera, location, photo, microphone, or notification access in device settings.
- Opt out of non-essential push notifications and emails.
- Delete your account at any time from the app (Profile → Edit Profile → Delete account), or request a copy or deletion of your personal data by emailing the address below. Depending on where you live, you may have additional rights under GDPR, CCPA/CPRA, or other privacy laws.
9. Children
Roam is not directed to children under 13 (or under the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us so we can delete it.
10. International Transfers
Roam is operated from the United States. If you access the Service from outside the U.S., your information may be transferred to, stored, and processed in the U.S. or other countries where our service providers operate.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated through the Service or by email. The "Last updated" date at the top reflects the most recent revision.
12. Contact
Questions about your privacy or this policy? Reach out at privacy@roam.social.