Legal
Privacy policy.
Last updated 27 September 2026
Placeholder notice: this page is a starting draft, not legal advice. Fill in your legal entity details where marked, and have a lawyer confirm it covers GDPR/UK GDPR if you have EU or UK customers, before going live.
This policy explains what [legal entity or individual name] ("GoRoam", "we") collects when you use GoRoam, why, and who we share it with. It applies to goroam.vercel.app and the GoRoam dashboard.
1. What we collect
- Account details, from Google Sign-In: your name, email address and profile photo.
- Trip details you give us: source and destination, dates, budget, who's travelling, pace, interests, dietary needs, occasion and any notes you type — used to generate your itinerary.
- Generated itineraries: the day-by-day plan, stays, tips and packing lists GoRoam creates for you, stored to your account so you can come back to them.
- Credit and purchase records: your credit balance, and for each purchase the pack, amount, currency and status. We do not collect or store your card number, UPI ID or other payment credentials — those go directly to Dodo Payments.
- Basic technical data: standard server logs (like IP address and browser type) kept for security and debugging.
2. Cookies & local storage
We keep this deliberately small:
- A session cookie from our sign-in provider, so you stay signed in. This is essential — GoRoam doesn't work without it.
- Your browser's local storage, only on your device, for things like a trip's packing-list progress or an in-progress plan while you're mid-checkout. This never leaves your browser and we can't read it.
We don't run third-party advertising or analytics trackers on GoRoam.
3. Who we share it with
- Google — to sign you in.
- OpenAI — the trip details you submit are sent to OpenAI's API to generate your itinerary. OpenAI processes this to return the result to us; see OpenAI's privacy policy.
- Dodo Payments — handles checkout, payment processing and, for supported payment methods, acts as merchant of record. They receive your email, name and purchase details to process payment; we never see your card or bank details.
- Our hosting and database providers (Vercel and our database host) — to run the Service and store your data.
We don't sell your personal data, to anyone, ever.
4. Sharing itineraries
If you use GoRoam's share feature, anyone with that link can view the itinerary's contents without signing in. Don't share a link publicly if the trip contains anything you'd rather keep private.
5. How long we keep it
We keep your account and itineraries for as long as your account exists. Delete your account (see Contact) and we'll delete your personal data and itineraries, except records we're required to keep for tax, accounting or fraud-prevention purposes — typically purchase records, which we retain for as long as the law requires.
6. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to certain processing. To exercise any of these, contact us — see below. If you're in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.
7. Children
GoRoam isn't directed at children, and you must meet the minimum age to hold a Google account in your country to use it.
8. Changes
We may update this policy as GoRoam changes. Material changes will be reflected here with a new "last updated" date.
9. Contact
Questions, or want to exercise a data right? See our Contact page, or email hello@goroam.com.