Privacy Policy
How Roomi handles personal data under the EU General Data Protection Regulation (GDPR): what we process, why, on what lawful basis, and what you can require of us.
Holati: loyiha, hali kuchga kirmagan · Bu hujjat ingliz tilida eʼlon qilingan.
Loyiha. Hali kuchga kirmagan.
Bu hujjatni yurist hali koʻrib chiqmagan va u hech kimni majburlamaydi. U Roomi maʼlumotlaringiz bilan qanday ishlashni moʻljallaganini koʻrsatish uchun eʼlon qilingan. Savol va eʼtirozlarni Telegram orqali kutamiz.
1. Who is responsible for your data
The controller for the personal data described in this policy is Individual Entrepreneur Vladimir Shinkarenko (“Roomi”, “we”). You can reach us at Telegram.
In full: Individual Entrepreneur Vladimir Shinkarenko, an individual entrepreneur registered in Georgia, identification number 305852495, registered with the LEPL National Agency of Public Registry, Georgia on 22 April 2026, registered address: 8 Kukuri Gogiashvili Lane, floor 3, apt. 44, Saburtalo, Tbilisi, Georgia. We have not appointed a representative in the European Union; if we do, this section will name them.
This document is still marked as a draft at the top of the page: it has not been reviewed by a lawyer yet. The identity of the controller above, however, is final.
2. Two different roles, and why it matters
We are the controller for data about you as a Roomi user: your account, your properties, your settings, your billing details if paid plans exist, and the technical records of how you use the service.
We are a processor for data about your guests, your cleaners and anyone else you put into Roomi. You decide what to collect and why; we process it on your instructions in order to run the service. For that data you are the controller and your own privacy notice applies to your guests. A data processing agreement is available on request and will be offered as a standard document before launch.
3. What we process
- Account data. Name, email address, phone number if you add one, password (stored only as a hash), language and currency settings.
- Property and booking data. Your apartments, prices, availability, bookings, expenses, and the guest details you or a connected channel put into a booking.
- Messages. Conversations with guests that pass through Roomi, including automatic and AI-assisted replies.
- Team data. Accounts you create for cleaners or co-hosts, and the jobs assigned to them.
- Technical data. IP address, device and browser information, timestamps, error logs and records of actions taken in the account.
We do not ask for special category data (health, beliefs, biometrics) and you should not put it into Roomi. Identity document details, where local law requires you to record them for guests, are your responsibility as controller and should only be stored where the product provides a field for them.
4. Why we process it, and on what lawful basis
| Purpose | Data | Lawful basis (Art. 6 GDPR) |
|---|---|---|
| Providing the service you signed up for | Account, property, booking, message and team data | Performance of a contract, Art. 6(1)(b) |
| Keeping the service secure and available | Technical data, error and action logs | Legitimate interests, Art. 6(1)(f) |
| Support and answering your questions | Account data and what you tell us | Performance of a contract, Art. 6(1)(b) |
| Service emails about outages, changes and pricing | Name and email address | Legitimate interests, Art. 6(1)(f) |
| Marketing emails, if we ever send them | Name and email address | Consent, Art. 6(1)(a), withdrawable at any time |
| Meeting accounting and legal obligations | Transaction and invoicing records | Legal obligation, Art. 6(1)(c) |
Where we rely on legitimate interests we have weighed them against your rights, and you can object at any time (see section 8).
5. Who else processes the data
We use a small number of service providers as sub-processors. Each one is bound by a data processing agreement, each is limited to what its service needs, and each is named below with the country where the data it handles is stored. We do not sell personal data and we do not share it with advertising networks.
| Provider | What it does for us | Where the data sits |
|---|---|---|
| Supabase Inc. (USA) | Database, file storage and server functions - the core of the service | Singapore (AWS ap-southeast-1) |
| Cloudflare, Inc. (USA) | Hosting and delivery of this website | Global edge network |
| Resend (USA) | Transactional email: sign-up confirmation, password reset | USA |
| Expo (USA) | Delivery of push notifications to the mobile app | USA |
| Google (Gemini API) | Drafting AI replies and written summaries - only if you switch that on | USA / EU |
| Our channel distribution partner | Exchange of bookings, availability and prices with Booking.com, Airbnb, Expedia, Agoda, Trip.com and Hostelworld | European Union |
The channel distribution partner works under our own contract and is not named on this page for commercial reasons. We give the company name, country and a copy of the agreement to any customer who asks - before you sign up, not after. If your own compliance requires the name in writing, ask us and you will get it.
Services you connect yourself are a separate matter. Telegram and WhatsApp for messaging, TTLock for smart locks, Ostrovok for bookings from that channel: those connections exist because you created them, the data goes where you sent it, and the provider’s own terms apply to what it receives. TTLock in particular is operated from China; if that is unacceptable to you, do not connect it.
Roomi also runs a Russian version of the service on separate infrastructure. Nothing from a non-Russian account is stored there: no bookings, no guest data and no identity documents. The two installations share code, not data.
6. Automated replies and AI
If you switch on AI replies, the content of the guest conversation and the relevant booking details are sent to an AI model provider so that a reply can be drafted. The feature is off unless you enable it, and you can pause it on any individual conversation.
These replies are message drafting, not decision-making. Roomi does not make automated decisions that produce legal effects or similarly significant effects on anyone within the meaning of Art. 22 GDPR.
7. International transfers
Be aware of this before you sign up: our database, file storage and server functions run in Singapore, not inside the European Economic Area. Personal data you and your guests put into Roomi is therefore transferred out of the EEA, and so is the data handled by the email, push and AI providers listed in section 5, which are based in the United States.
For every one of those transfers we rely on the European Commission’s Standard Contractual Clauses, together with encryption in transit and at rest and access limited to the people who operate the service. Data is not stored in Russia for any non-Russian account.
We would rather tell you this plainly than bury it. If hosting inside the EEA is a hard requirement for you, say so before you sign up: an EU-hosted installation is on our roadmap, and we will not pretend it already exists.
8. How long we keep it
- Account, property and booking data: for as long as your account is open, and up to 30 days after you delete it so that an accidental deletion can be reversed.
- Technical and security logs: normally up to 12 months.
- Records we must keep for accounting or tax reasons: for the period required by the applicable law, typically several years.
9. Your rights
Under the GDPR you can ask us to:
- give you access to the personal data we hold about you (Art. 15);
- correct data that is wrong or incomplete (Art. 16);
- delete your data (Art. 17);
- restrict how we process it (Art. 18);
- give you a copy in a portable, machine-readable format (Art. 20);
- stop processing based on legitimate interests, including profiling (Art. 21);
- withdraw consent where we rely on it, without affecting what happened before (Art. 7(3)).
Write to Telegram and we will respond within one month. Account deletion and data export are also available directly in the app, without asking anyone.
If you think we have handled your data badly, you can complain to the data protection authority in the EU country where you live or work. We would rather you told us first, but you do not have to.
10. Security
Data is encrypted in transit. Passwords are stored as hashes, never in readable form. Access to production data is limited to the people who need it to run the service. Access rules inside your account are enforced by the database itself, which is why a cleaner cannot read your revenue even if they go looking.
No system is perfect. If a breach affects your data and creates a risk to you, we will notify you and the relevant supervisory authority as the GDPR requires.
11. Children
Roomi is a business tool and is not intended for anyone under 16. We do not knowingly create accounts for children.
12. Cookies
This website uses only strictly necessary storage and runs no analytics or advertising scripts. The details are on the Cookie Policy page.
13. Changes to this policy
When this policy changes in a way that affects you, we will say so by email and update the date at the top of the page. Older versions are available on request.