Legal

Privacy Policy

Last updated: August 2026

ROAM Travel (“we”, “us”, “our”) respects your privacy and is committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR) (EU 2016/679) and the French Data Protection Act (Loi Informatique et Libertés).

This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit roamtravel.eu (the “Website”) or purchase our digital travel guides.

1. Data Controller & Contact Information

ROAM Travel is operated as a sole proprietorship (entreprise individuelle) registered in France.

For any questions regarding this Privacy Policy or to exercise your privacy rights, please contact:

Data Controller: ROAM Travel

Email: support@roamtravel.eu

Website: roamtravel.eu

2. Personal Data We Collect

Because we exclusively sell downloadable digital products (PDF guides), we minimize our data collection. We do not collect physical shipping addresses, phone numbers, or sensitive personal data.

A. Data Provided Directly by You

When you purchase a product or contact support, we collect:

  • Email Address: Required to process your order and deliver your digital PDF files.
  • Name: Optional, depending on what you enter at checkout.
  • Order History: Details of purchased digital packs, dates, transaction IDs, and download status.
  • Customer Support Communications: Any information you provide when emailing support@roamtravel.eu.

B. Data Collected Automatically

When you browse our Website, we may automatically collect:

  • Device & Network Data: IP address, browser type, operating system, device parameters, and language preferences.
  • Usage Data: Pages viewed, time spent, referring URLs, and links clicked.

C. Data We Never Collect

  • Payment Credentials: All financial data (credit card numbers, CVVs, billing profiles) is collected and processed exclusively by our Merchant of Record, Lemon Squeezy. We never see, receive, or store your payment card details.

3. Legal Basis and Purposes of Data Processing

Under the GDPR, we process your personal data using the following legal bases:

Purpose Category of Data Legal Basis (GDPR Art. 6)
Delivering Purchased Products Email address, order details Contractual Necessity (Art. 6(1)(b))
Order Confirmations & Receipts Email address, order number Contractual Necessity (Art. 6(1)(b))
Customer Support & Service Enquiries Email address, communication history Legitimate Interest (Art. 6(1)(f))
Product Updates & Essential Service Notices Email address, purchase history Legitimate Interest (Art. 6(1)(f))
Website Security, Analytics & Optimisation IP address, usage data, browser info Consent (Art. 6(1)(a)) / Legitimate Interest (Art. 6(1)(f))
Accounting, Tax & Legal Compliance Transaction history, invoice records Legal Obligation (Art. 6(1)(c))

Note: We do not send promotional marketing newsletters unless you explicitly opt in. We never sell, rent, or trade your personal data to third parties.

4. Merchant of Record & Payment Processing

All payments and digital product fulfillment are handled by Lemon Squeezy, which acts as our official Merchant of Record.

When completing a transaction:

  • You are interacting with Lemon Squeezy’s secure checkout infrastructure.
  • Lemon Squeezy collects and processes payment card details through certified PCI-compliant gateways (such as Stripe).
  • Lemon Squeezy provides us with confirmation of purchase (email address, order details, gross amount) so we can support your access.

For full details on how your payment data is managed, please review the Lemon Squeezy Privacy Policy.

5. Third-Party Service Providers (Data Processors)

We share limited data with trusted third-party providers solely to host our platform, process sales, and deliver services:

Service Provider Role / Purpose Data Handled Location
Lemon Squeezy Merchant of Record / Payment & Digital Delivery Email, name, purchase details, billing information USA / Global
Website Hosting Provider Infrastructure & File Delivery IP address, system logs EU / Global
Analytics Providers Traffic Performance & Error Logging Anonymised IP address, browser telemetry EU / Global

Where data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place, such as EU Standard Contractual Clauses (SCCs) or adequacy decisions.

6. Cookies and Tracking Technologies

We use cookies and similar technologies to ensure core website functionality and evaluate site usage.

  • Essential Cookies: Necessary for basic navigation, security, and rendering the Website. These do not require user consent.
  • Analytics / Non-Essential Cookies: Help us understand site performance and visitor habits. These are only activated if you grant explicit consent via our cookie banner.

You can manage or disable cookies directly within your web browser settings. Blocking strictly necessary cookies may affect site functionality.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:

  • Order & Access Records: Kept for as long as needed to maintain your access to digital downloads.
  • Accounting & Tax Records: Retained for 10 years in accordance with French statutory commercial obligations (Code de commerce, Art. L123-22).
  • Support Communications: Deleted or anonymised 2 years following the resolution of your enquiry.

8. Your Data Protection Rights (GDPR)

Under the GDPR, as an individual within the EU/EEA (or where applicable globally), you hold the following rights:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure / “To Be Forgotten” (Art. 17): Request deletion of your data, subject to legal retention obligations.
  • Right to Restriction (Art. 18): Request that we limit the processing of your data.
  • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw cookie or marketing consent at any time without penalty.

To exercise any of these rights, please contact us at support@roamtravel.eu. We will verify your identity and respond within 30 days.

You also have the right to lodge a complaint with a data protection supervisory authority. In France, this is the CNIL (Commission Nationale de l’Informatique et des Libertés – cnil.fr).

9. Data Security

We implement reasonable technical and organisational security measures to protect personal data against unauthorized access, loss, misuse, or alteration:

  • Encrypted HTTPS (TLS) connections across the Website.
  • Offloaded payment processing via PCI-DSS compliant merchants.
  • Strict access limitations to support channels and administrative portals.

10. Children’s Privacy

Our services and travel guides are intended strictly for adult users aged 18 and older. We do not knowingly collect personal data from children under 16. If you believe a minor has provided us with personal data, please contact us at support@roamtravel.eu for prompt removal.

11. Amendments to This Policy

We may update this Privacy Policy to reflect operational, legal, or regulatory changes. Updates take effect immediately upon posting to the Website. The “Last updated” date at the top of this document indicates the latest revision date.

12. Governing Law and Jurisdiction

This Privacy Policy is governed by and construed under the laws of France. Any legal proceedings arising hereunder shall be subject to the jurisdiction of competent French courts, without prejudice to mandatory protective statutory rights granted to consumers under their local national laws.

13. Contact Us

If you have questions, comments, or concerns regarding your privacy or this policy, please reach out: