Privacy Policy

Last updated: May 2026 ยท Version 1.1

๐Ÿ“‘ Table of Contents โ–พ
๐Ÿ›ก๏ธ Privacy at a Glance

Rompo.Travel collects only what's needed to plan your trips โ€” your name, email, and the trip details you enter. We use AI to generate personalised itineraries based on your party's ages and preferences. We never sell your data, we don't track your GPS location, and we don't access your photos or contacts. Your data is stored securely and you can delete your account and all associated data at any time from your profile.

1Who We Are

Controller: Rompo Travel

Contact: daniel@bein.fit

Website: rompo.travel

Rompo Travel ("we", "us", "our") operates the Rompo.Travel family travel planning application. This Privacy Policy explains how we collect, use, and protect your personal data when you use our service.

2Data We Collect

Account Information

DataSourceRequired
Email addressRegistrationYes
Full nameRegistrationYes

Trip Data

DataPurpose
Destination & countryTrip planning & itinerary
Travel datesTrip planning & countdown
Party namesGroup organisation
Member names & agesAge-appropriate itinerary
Transport legs (flights, trains, etc.)Timeline & logistics
Accommodation detailsTrip planning

Collaboration Data

DataPurpose
Invited email addressesSend trip invitations
Invite statusTrack collaboration access
Share tokensEnable shareable trip links

Analytics & Device Data

DataPurpose
Anonymised usage eventsImprove product experience
Device/offline cacheEnable offline access
โœ… Data We Do NOT Collect
  • Payment card details
  • GPS / precise location
  • Photos or media files
  • Contact lists
  • Biometric data
  • Health information

3How We Use Your Data

PurposeData Used
Create & manage your accountEmail, name
Build & store trip itinerariesTrip data, party & member info
Generate AI-powered itinerariesDestination, dates, traveller age groups, preferences
Enable trip collaborationInvited emails, share tokens
Send trip invitations & notificationsEmail addresses
Provide offline accessCached trip data on device
Improve the productAnonymised analytics events

๐Ÿšซ We do not sell your data to third parties. We do not use your data for advertising.

4Lawful Basis (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your data on the following legal bases:

Processing ActivityLawful Basis
Account creation & managementContract performance
Trip data storage & itinerary generationContract performance
Sending trip invitationsContract performance
Analytics & product improvementLegitimate interest

5AI-Generated Content

Rompo uses artificial intelligence to generate itinerary suggestions. When you request a generated itinerary, Rompo sends the following information to Base44's AI service (powered by OpenAI):

  • Your trip destination and dates
  • Traveller age groups (e.g. "adult", "child", "senior") โ€” not exact ages
  • Activity preferences and notes you have added to the trip

Rompo does not send exact ages, full names, or payment information to AI services. Age groups are derived from ages you enter; the specific ages you enter are stored only on your device and in your Rompo account.

You will be asked to confirm this before your first AI-generated itinerary. You can withdraw consent at any time in Settings โ†’ Privacy.

6Third-Party Login

Rompo supports Sign in with Apple, Sign in with Google, and email/password login.

If you use Sign in with Apple with Hide My Email, Rompo will receive and store your Apple-assigned relay email address. This address is used only to identify your account and send trip-related notifications.

7Third Parties & Sub-Processors

ProviderServicesLocation
Base44Backend infrastructure, authentication, data storage, AI processing, email deliveryUnited States
Google Places APILocation search & autocomplete (query text only)United States
Apple App StoreIn-app purchase processing (handled entirely by Apple)United States

8International Data Transfers

Your data may be transferred to and processed in the United States by our sub-processors. These transfers are protected by:

  • Standard Contractual Clauses (SCCs) with Base44
  • Data Processing Agreements (DPAs) with Base44 and Google

For copies of relevant transfer safeguards, contact daniel@bein.fit.

9Data Retention

Data TypeRetention Period
Account data (email, name)Life of account + 30 days after deletion
Trip data (itineraries, parties, members)Life of account
Analytics data24 months (anonymised)
Support communications3 years

10Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

RightDescription
AccessRequest a copy of your personal data
RectificationCorrect inaccurate or incomplete data
ErasureRequest deletion of your personal data
PortabilityReceive your data in a portable format
RestrictionLimit how we process your data
ObjectionObject to processing based on legitimate interest
Withdraw ConsentWithdraw consent where processing is consent-based

You also have the right to lodge a complaint with your supervisory authority. For UK residents, this is the Information Commissioner's Office (ICO).

We aim to respond to all rights requests within 30 days.

11California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:

RightDescription
Right to KnowRequest disclosure of personal information collected
Right to DeleteRequest deletion of your personal information
Right to CorrectRequest correction of inaccurate information
Right to Opt-Out of SaleWe do not sell personal information
Non-DiscriminationEqual service regardless of exercising rights

We will acknowledge your request within 10 business days and respond within 45 calendar days.

CCPA Categories of Information Collected

CategoryExamplesCollected
IdentifiersName, emailYes
Commercial informationTrip plans, itinerariesYes
Internet activityAnonymised usage eventsYes
GeolocationPrecise GPS locationNo
BiometricFingerprints, face dataNo
FinancialCredit card numbersNo

12Children's Privacy

Rompo.Travel is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13.

The "member age" feature within trip planning is provided by adult account holders for the sole purpose of generating age-appropriate AI itinerary recommendations. This data is not used for profiling, advertising, or any purpose other than trip personalisation.

If you believe a child under 13 has provided us with personal information, please contact daniel@bein.fit and we will promptly delete it.

13Security

We implement appropriate technical and organisational measures to protect your data:

  • HTTPS encryption for all data in transit
  • Base44 authentication with secure session management
  • Role-based access controls for admin functions
  • Tokenised share links that can be deactivated at any time
  • No plaintext password storage

In the event of a data breach, we will notify affected users and relevant authorities within 72 hours where legally required.

14Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision.

For material changes, we will notify you by:

  • Email to your registered address, or
  • A prominent notice within the app

Continued use of Rompo.Travel after changes constitutes acceptance of the updated policy.

15Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please reach out:

Rompo Travel

๐Ÿ“ง daniel@bein.fit

๐ŸŒ rompo.travel

We aim to respond to all enquiries within 30 days.