Skip to content

Privacy Policy

Last updated: 2026-08-30

1. Who to contact

RoamWeek is an AI trip planning service operated from France. For anything about your data, including exercising the rights in section 8, write to privacy@roamweek.com. For anything else, support@roamweek.com. We answer within one month, which is the deadline the GDPR sets.

2. What we collect

  • Your account. Email address and a display name.
  • Your travel profile. Travel style, interests, budget level, pace, traveler type, and any dietary preferences or mobility notes you choose to write. You can also add the country codes of passports you hold. Passport data is optional, self declared and can include more than one passport on eligible plans.
  • What you ask for. The text of every trip request you type. This is free text you wrote about your own trip, so it is the most personal column in our database and we treat it that way. It is stored once, against the trip it produced, and is used to regenerate or explain that trip.
  • What we produce. The generated itinerary, its days and activities, and any edits you make.
  • Your travel history. Destinations, ratings and notes you add, used to personalise later suggestions.
  • Usage and balance. How many trip plans you have left, how many you have generated, and a timestamped record of each generation. This record holds no prompt text.
  • Purchases. If you buy trip plans, we keep the amount, the currency, what it bought, and Stripe's identifiers for the payment. We never see or store your card number.
  • Technical data. Our host sees your IP address and request metadata, as any web server does. Travelpayouts also receives the RoamWeek page URL and ordinary request metadata when its affiliate script loads.

When you use the travel business enquiry form, newsletter form or passport alert form, we store the details you enter, the page you used, and the time of the request. The enquiry stores your name, business name, email address and message so we can understand the request. The newsletter stores your email address, its consent timestamp and the source page so we know what you signed up for. A passport alert stores your email address, selected passport code, language, consent and confirmation timestamps, source page and an unsubscribe token. Resend receives the email address and passport name to deliver the confirmation and later material rule-change alerts. Newsletter delivery is not active yet. To request deletion, write to privacy@roamweek.com, which is also listed above and in section 8.

3. Why we are allowed to process it

GDPR Article 13(1)(c) requires a lawful basis for each purpose. Ours are:

  • Performance of a contract for creating your account, generating and storing itineraries, publishing a trip when you press Share, and taking payment for trip plans. Without this data there is no service to provide.
  • Consent for passport rule-change alerts and any newsletter email. Neither list is bundled into an account or purchase. You can withdraw at any time, and withdrawing from a passport alert deletes that subscription.
  • Legitimate interest for keeping the service up, preventing abuse, enforcing quotas, funding the free itinerary pages with affiliate links, using aggregated passport selections to prioritise guide reviews, and measuring which booking links readers use. The click log contains the supplier, page, destination, broad country and search term. It does not contain your name, email address or IP address.
  • Legal obligation for keeping records of money taken.

We do not sell your personal data or train any model on it. Affiliate links can fund the free itinerary pages. We disclose only what is needed to the processors listed below to provide, secure and measure the service.

4. Who else sees it

These are the external services and partners the application talks to. If we add another, this list changes in the same release.

Hostinger

What for
Database, authentication and file storage, on a server we operate
Where
European Union
What reaches them
Account email, password hash, display name, travel preferences, trips, activities and any profile picture you upload.

Anthropic

What for
AI model provider
Where
United States
What reaches them
Your travel preferences and the text of your trip request, sent on each generation.

Vercel

What for
Hosting
Where
United States and European Union
What reaches them
Request metadata including IP address, for serving and securing the site.

Travelpayouts

What for
Affiliate link and booking offer service
Where
Hong Kong, with data storage described as the Netherlands
What reaches them
The RoamWeek page URL and standard request metadata when its script loads, plus affiliate clicks and booking attribution when you use a partner link.

Stripe

What for
Payment processing
Where
United States and European Union
What reaches them
Your email and billing details when you buy trip plans. Card numbers never reach us.

Resend

What for
Transactional email and operator notifications
Where
United States and European Union
What reaches them
Account or alert email, the passport name for a requested alert, and basic account or purchase event details. Passwords, card numbers and travel prompts are never sent.

Unsplash

What for
Destination photography
Where
United States
What reaches them
A destination search term. No information about you is sent.

OpenStreetMap Foundation

What for
Map tiles
Where
United Kingdom and European Union
What reaches them
Your IP address and the map area you are looking at, requested by your browser.

Two of these are worth spelling out because they are easy to miss. Map tiles are fetched by your browser directly from the OpenStreetMap Foundation, which means it sees your IP address and the area of the map you are looking at, including on a shared trip page viewed by someone with no account. And your travel profile plus the text of your request go to Anthropic on every single generation, because that is what produces the itinerary.

5. Transfers outside the EU

Some providers above are in the United States. Travelpayouts is based in Hong Kong and describes its data storage location as the Netherlands. Where a transfer leaves the European Economic Area, we rely on the safeguards in the provider's data processing terms, including Standard Contractual Clauses where required.

We say this precisely because the previous version of this page said something different. It asked you to consent to the transfer. Consent is the Article 49(1)(a) derogation, which exists for occasional and non-repetitive transfers, and every generation is a transfer, so it was the wrong instrument. Naming the real mechanism is both more accurate and better for you: it does not depend on a consent you could be nudged into.

6. Sharing a trip makes it public

Pressing Share on a trip publishes it at a link that anyone holding the link can open, with no account and no sign in. The shared page shows the trip title, destination, dates, the day by day plan, and your display name. It does not show your email, and it does not show the request you typed.

A link is a capability: anyone you send it to can send it on. Turn sharing off on the trip and the link stops working immediately.

7. Cookies and browser storage

  • Strictly necessary cookies keep you signed in. The session cookie is set by RoamWeek itself and holds an opaque token, never your email or password. Signing out clears it.
  • Local storage. If you type a trip idea on the home page before you have an account, your browser saves that text under the key roamweek_pending_prompt so it is still there after you sign up. It is read once, then deleted. It never leaves your device until you sign in and generate. This is storage on your own device and we mention it because being small is not the same as being exempt.
  • Travelpayouts. Its Drive script loads on RoamWeek pages to provide affiliate links and booking offers. The script receives the page URL and ordinary request metadata when it loads. If you follow an affiliate link, Travelpayouts or the supplier may use an attribution cookie on its own domain. The exact attribution period depends on the supplier.
  • Stripe. If you go to checkout, Stripe sets its own cookies on its own pages for fraud prevention.

8. Your rights, and how to use them

You can ask for a copy of your data, correct it, restrict or object to how it is used, take it elsewhere, or have it erased. Write to privacy@roamweek.com. You can also complain to the CNIL, the French supervisory authority, at cnil.fr.

Deleting your account. Profile, then Delete account. It asks you to confirm, and then it is done immediately and cannot be undone. It removes your account, your profile, every trip and its days and activities, your travel history, your remaining trip plan balance and your usage records. Any trip you had shared stops being reachable at the same moment.

One thing survives, and you should know which. The record of a payment stays, detached from you: amount, currency, what it bought and Stripe's identifiers, with no link back to a person. Keeping records of money taken is a legal obligation, which is the exception GDPR Article 17(3)(b) makes to erasure.

9. How long we keep things

  • Account, profile, trips and prompts: for as long as your account exists. Deleting the account deletes them the same day.
  • Passport alert subscriptions: until you unsubscribe or ask us to delete the request. Unsubscribing deletes that passport alert subscription immediately.
  • Usage records: 24 months, then removed. They hold a timestamp and a count, never prompt text.
  • Rate limit counters: 7 days.
  • Payment records: 10 years from the payment, which is the retention French accounting rules require.
  • Server logs: kept by our host on its own schedule for security and debugging, and not used for anything else.

10. Automated decisions

An AI model writes your itinerary. That is the product, and it is disclosed on the generate page before you use it. Nothing here makes a decision with a legal or similarly significant effect on you, so the Article 22 rules on automated decision making are not engaged. The model can be wrong, and the terms say so plainly.

11. Changes

If this policy changes materially, we email the address on your account before the change takes effect. The date at the top always reflects the current version.