Skip to content

Privacy Policy

How Roomi handles personal data under the EU General Data Protection Regulation (GDPR): what we process, why, on what lawful basis, and what you can require of us.

Status: draft, not yet in force

Draft. Not yet in force.

This document has not been reviewed by a lawyer yet and does not bind anyone. It is published so you can see how Roomi intends to handle your data. Telegram.

1. Who is responsible for your data

The controller for the personal data described in this policy is Individual Entrepreneur Vladimir Shinkarenko (“Roomi”, “we”). You can reach us at Telegram.

In full: Individual Entrepreneur Vladimir Shinkarenko, an individual entrepreneur registered in Georgia, identification number 305852495, registered with the LEPL National Agency of Public Registry, Georgia on 22 April 2026, registered address: 8 Kukuri Gogiashvili Lane, floor 3, apt. 44, Saburtalo, Tbilisi, Georgia. We have not appointed a representative in the European Union; if we do, this section will name them.

This document is still marked as a draft at the top of the page: it has not been reviewed by a lawyer yet. The identity of the controller above, however, is final.

2. Two different roles, and why it matters

We are the controller for data about you as a Roomi user: your account, your properties, your settings, your billing details if paid plans exist, and the technical records of how you use the service.

We are a processor for data about your guests, your cleaners and anyone else you put into Roomi. You decide what to collect and why; we process it on your instructions in order to run the service. For that data you are the controller and your own privacy notice applies to your guests. A data processing agreement is available on request and will be offered as a standard document before launch.

3. What we process

  • Account data. Name, email address, phone number if you add one, password (stored only as a hash), language and currency settings.
  • Property and booking data. Your apartments, prices, availability, bookings, expenses, and the guest details you or a connected channel put into a booking.
  • Messages. Conversations with guests that pass through Roomi, including automatic and AI-assisted replies.
  • Team data. Accounts you create for cleaners or co-hosts, and the jobs assigned to them.
  • Technical data. IP address, device and browser information, timestamps, error logs and records of actions taken in the account.

We do not ask for special category data (health, beliefs, biometrics) and you should not put it into Roomi. Identity document details, where local law requires you to record them for guests, are your responsibility as controller and should only be stored where the product provides a field for them.

4. Why we process it, and on what lawful basis

PurposeDataLawful basis (Art. 6 GDPR)
Providing the service you signed up forAccount, property, booking, message and team dataPerformance of a contract, Art. 6(1)(b)
Keeping the service secure and availableTechnical data, error and action logsLegitimate interests, Art. 6(1)(f)
Support and answering your questionsAccount data and what you tell usPerformance of a contract, Art. 6(1)(b)
Service emails about outages, changes and pricingName and email addressLegitimate interests, Art. 6(1)(f)
Marketing emails, if we ever send themName and email addressConsent, Art. 6(1)(a), withdrawable at any time
Meeting accounting and legal obligationsTransaction and invoicing recordsLegal obligation, Art. 6(1)(c)

Where we rely on legitimate interests we have weighed them against your rights, and you can object at any time (see section 8).

5. Who else processes the data

We use a small number of service providers as sub-processors, each bound by a data processing agreement and each limited to what the service needs:

  • cloud database and application hosting;
  • transactional email delivery;
  • push notification delivery to mobile devices;
  • an AI model provider, used only for the automatic reply and report features described in section 6;
  • booking channels and smart lock providers that you choose to connect, such as Booking.com, Airbnb or TTLock. Those connections exist because you set them up, and the provider’s own privacy terms apply to what they receive.

The named list of sub-processors, with company names and locations, will be published here before this policy comes into force. We do not sell personal data and we do not share it with advertising networks.

6. Automated replies and AI

If you switch on AI replies, the content of the guest conversation and the relevant booking details are sent to an AI model provider so that a reply can be drafted. The feature is off unless you enable it, and you can pause it on any individual conversation.

These replies are message drafting, not decision-making. Roomi does not make automated decisions that produce legal effects or similarly significant effects on anyone within the meaning of Art. 22 GDPR.

7. International transfers

Some of our providers process data outside the European Economic Area. Where that happens we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision, together with additional safeguards where required.

The exact hosting locations for the European service are being finalised and will be stated here, per provider, before this policy comes into force. If that matters to your own compliance, ask us before you sign up rather than after.

8. How long we keep it

  • Account, property and booking data: for as long as your account is open, and up to 30 days after you delete it so that an accidental deletion can be reversed.
  • Technical and security logs: normally up to 12 months.
  • Records we must keep for accounting or tax reasons: for the period required by the applicable law, typically several years.

9. Your rights

Under the GDPR you can ask us to:

  • give you access to the personal data we hold about you (Art. 15);
  • correct data that is wrong or incomplete (Art. 16);
  • delete your data (Art. 17);
  • restrict how we process it (Art. 18);
  • give you a copy in a portable, machine-readable format (Art. 20);
  • stop processing based on legitimate interests, including profiling (Art. 21);
  • withdraw consent where we rely on it, without affecting what happened before (Art. 7(3)).

Write to Telegram and we will respond within one month. Account deletion and data export are also available directly in the app, without asking anyone.

If you think we have handled your data badly, you can complain to the data protection authority in the EU country where you live or work. We would rather you told us first, but you do not have to.

10. Security

Data is encrypted in transit. Passwords are stored as hashes, never in readable form. Access to production data is limited to the people who need it to run the service. Access rules inside your account are enforced by the database itself, which is why a cleaner cannot read your revenue even if they go looking.

No system is perfect. If a breach affects your data and creates a risk to you, we will notify you and the relevant supervisory authority as the GDPR requires.

11. Children

Roomi is a business tool and is not intended for anyone under 16. We do not knowingly create accounts for children.

12. Cookies

This website uses only strictly necessary storage and runs no analytics or advertising scripts. The details are on the Cookie Policy page.

13. Changes to this policy

When this policy changes in a way that affects you, we will say so by email and update the date at the top of the page. Older versions are available on request.