Privacy Policy
Last updated: August 2026
1. Introduction
At Roomio we take the privacy of our users very seriously. This Privacy Policy explains how we collect, use,
share and protect your personal information in accordance with the EU General Data Protection Regulation (GDPR)
and Spanish Organic Law 3/2018 (LOPDGDD).
2. Data Controller
The controller of your personal data is:
- Company: Roomio Studio, S.L. ("Roomio")
- Tax ID (NIF): B88839972
- Address: Calle Naciones 9, 28006 Madrid, Spain
- Contact email: tech@theroomio.com
3. Data We Collect
We collect different types of information:
Information You Provide Directly
- First and last name
- Email address
- Phone number (optional)
- Date of birth
- Profile photos
- Information about your housing preferences
- Personal description and bio
- Location you provide (search area or property location)
- Messages you exchange with other users through chat
Information Collected Automatically
- IP address
- Browser and device type
- Service usage data
- Essential technical cookies
- Approximate location (based on IP)
Third-Party Information
- If you sign up through external providers (e.g. Apple or Google), we receive the basic account data you authorize
4. Legal Basis for Processing
We process your personal data based on:
- Consent: You have given your explicit consent
- Performance of a contract: Necessary to provide our services
- Legal obligation: When the law requires it
- Legitimate interest: To improve our services and prevent fraud
5. How We Use Your Data
We use your personal information to:
- Create and manage your account
- Connect you with potential roommates
- Manage your subscriptions
- Send service-related notifications
- Automatically moderate the images you upload to keep the platform safe
- Improve our platform and services
- Prevent fraud and illegal activity
- Comply with legal obligations
- Analyze service usage through aggregated statistics
6. Sharing Your Information
We do NOT sell your personal information to third parties. We share your data only when:
With Other Users
- Your public profile is visible to other registered users
- Information you share in messages is visible to the recipient
With Service Providers (Data Processors)
We work with providers that process data on our behalf under appropriate safeguards:
- Supabase: hosting, database and storage
- CometChat: messaging and chat between users
- RevenueCat: subscription management
- Expo: push notification delivery
- Google Maps: maps and geolocation
- PicPurify: automated image moderation
- Apple and Google: processing of in-app purchase payments
For Legal Obligations
- When required by a court order
- To protect the rights, property or safety of Roomio or third parties
- In fraud or illegal activity investigations
Business Transfers
- In the event of a merger, acquisition or sale of assets, your data may be transferred
7. Data Retention
We retain your personal information while:
- You maintain an active account
- It is necessary to provide our services
- It is required by legal obligations
When you delete your account, we deactivate it and it stops being visible to other users
immediately. We retain the data associated with your account for a maximum of 90 days —to comply
with legal obligations, resolve disputes and prevent fraud— after which we erase or anonymize it,
unless the law requires us to keep it longer. You can request early erasure of your data at any
time by writing to tech@theroomio.com.
8. Your Rights under the GDPR
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Restrict the processing of your data
- Portability: Receive your data in a structured format
- Objection: Object to the processing of your data
- Withdraw consent: Withdraw consent at any time
- Complaint: Lodge a complaint with the Spanish Data Protection Agency (AEPD)
To exercise these rights, contact us at tech@theroomio.com
9. Data Security
We implement technical and organizational security measures to protect your data:
- SSL/TLS encryption for data in transit
- Encryption of data at rest
- Database-level access controls (RLS)
- Sign-in via a one-time code (OTP) sent to your email
- Automatic moderation of uploaded images
However, no system is 100% secure. We recommend protecting access to your email and device.
10. Cookies
We use only essential technical cookies necessary for the operation of the site and to remember your basic
preferences. We do not use analytics, advertising or third-party tracking cookies. You can manage or block
cookies from your browser settings; disabling them may affect how the site works.
11. International Transfers
Your data is stored primarily on servers in the European Union (Ireland region, through Supabase).
Some of our providers (for example CometChat, RevenueCat, Expo, Google, PicPurify or Apple/Google) may process data outside the
EEA, including the United States. In those cases we ensure adequate protections through:
- Standard Contractual Clauses approved by the European Commission
- EU adequacy decisions
- The EU-US Data Privacy Framework, where the provider is certified
12. Minors
Roomio requires a minimum age of 17 to use the service. If you are 17, you declare that you have your
parents' or legal guardians' permission to use it. We do not knowingly collect information from anyone under
17; if we discover we have, we will delete that data.
13. Service Communications
We may send you communications necessary to provide the service, such as account verification, security
notices, relevant changes or app notifications. We currently do not send marketing communications or
newsletters. If we do so in the future, it will always be with your prior consent and with the option to
unsubscribe at any time.
14. Third-Party Links
Our platform may contain links to third-party websites. We are not responsible for their privacy practices.
We recommend reading their privacy policies.
15. Changes to This Policy
We may update this Privacy Policy occasionally. We will notify you of significant changes by email or through
a prominent notice in the service. The "last updated" date at the top indicates when it was last revised.
16. Contact
For questions about this Privacy Policy or to exercise your rights, contact us:
17. Supervisory Authority
If you are not satisfied with our response, you have the right to lodge a complaint with:
- Spanish Data Protection Agency (AEPD)
- Web: www.aepd.es
- Phone: 901 100 099 / 91 266 35 17