Privacy Policy
Last updated: 11 July 2026
RoamMeo ("we", "us", "our") is a real-time local discovery platform. This Privacy Policy has two parts: a base policy that applies to everyone, and one or more region addenda that add local requirements for the market you are in. RoamMeo is launching in Australia first; the Australia Addendum below applies to Australian users. By using RoamMeo you consent to the practices described here.
1. What Data We Collect
We collect the following categories of information:
- Account data: Name, email address, and (where provided) phone number. Consumers may sign in via Google, email/password, or phone; providing a phone number is optional for consumers but required for vendors. Where a phone number is provided, it is verified via SMS one-time code. Phone numbers from any country are accepted.
- Location data (GPS): Approximate or precise device location, collected during an active search session (consumers) or when a vendor activates their live pin (vendors).
- Photos and media (vendors): Business logos, profile photos, and owner headshots you upload to publish on your vendor profile.
- Business information (vendors): Business name, description, service area, contact details, and pricing you choose to publish.
- Business-verification data (vendors): Your business registration number and registered business name, collected for identity verification. In Australia this is your ABN, verified via the Australian Business Register — see the Australia Addendum.
- Usage and interaction analytics: Search queries, profile views, call clicks, directions requests, and shares. Some interaction events are recorded from unauthenticated visitors (people using RoamMeo without signing in) to give vendors accurate engagement analytics. Where a visitor is not signed in, the event is not linked to a named account.
- Ratings and reports: If you submit a rating of a vendor or event, or report another user, we record the content of that submission together with your account identifier. Ratings are currently used for internal moderation and quality purposes and are not displayed publicly.
- Device and fraud-prevention signals: A device identifier (Firebase Installation ID) collected during vendor registration to detect multiple vendor accounts created from the same device. We also use Google reCAPTCHA Enterprise and Firebase App Check to verify requests come from genuine users and the genuine RoamMeo application.
- Technical and network data: Our servers process your IP address when you use certain Platform features (for example, searching or interacting with vendor profiles). IP addresses are used for rate limiting, abuse prevention, and security, and are retained only in short-lived rate-limit records — they are not stored on the content you create.
- Search demand data: When a search returns no results, we log the search term and the approximate search location so we can understand demand for services in different areas. These records are not linked to your name or account identity and are automatically deleted after 90 days.
- Trust and risk signals: An internal trust score for accounts, based on behaviour signals such as reports received, device-sharing patterns, and account history. Used solely for internal moderation and never displayed publicly.
2. How We Use Your Data
- To provide search and discovery features that connect consumers with local businesses.
- To verify vendor identity against the applicable business register.
- To display vendor profiles, locations, and business details to consumers.
- To provide vendors with analytics about their profile's performance.
- To process subscription payments.
- To send service-related communications (account notifications, policy updates, welcome emails).
- To detect fraud and abuse, and to operate our trust and moderation systems.
- To improve Platform performance, fix bugs, and develop new features.
- We do not sell, rent, or trade your personal data to third parties for marketing or advertising purposes.
3. Why We Collect It
We collect each category of data only where it is reasonably necessary for one or more of our functions: operating the discovery marketplace, verifying vendors, keeping the Platform safe, processing payments, and communicating with you about your account. Where the law in your region requires a specific lawful basis or consent for a given use, the relevant region addendum describes it.
4. Third-Party Services
We share data with the following processors only to the extent necessary to operate the Platform. Each is bound by its own privacy and data-processing terms:
- Google Firebase & Google Cloud — authentication, database, file storage, and hosting.
- Google Maps Platform — map display and location-based search.
- Stripe — subscription payment processing. Stripe receives only the information necessary to process your subscription.
- Resend — delivery of transactional email (for example, welcome emails and account notifications). Resend processes the recipient email address and message content needed to send these messages.
- Google reCAPTCHA Enterprise — bot and abuse detection on sign-in, registration, and phone-verification flows.
- Google Analytics (Firebase Analytics) — aggregated usage measurement, such as page views, session counts, and general usage patterns, to help us understand how the Platform is used and improve it. Google Analytics sets identifiers in your browser for this purpose. We do not use Analytics data for advertising, and we do not sell it. You can learn more about how Google processes this data at policies.google.com/technologies/partner-sites.
- Syncorp (syncorp.app) — an affiliated platform. If you choose to link or import your Syncorp profile when registering as a vendor, we receive your Syncorp profile details and store a reference to your Syncorp account. Suspension of a linked RoamMeo account may be notified to Syncorp. This applies only to vendors who actively choose to link accounts — no data is shared with Syncorp otherwise.
- Business register (region-specific) — vendor verification only. In Australia this is the Australian Business Register (see the Australia Addendum). No consumer data is sent to any business register.
5. Data Storage and Security
- User and vendor records are stored in Google Firebase Firestore and Firebase Authentication. Our primary Firestore database is provisioned in the australia-southeast1 (Sydney) region.
- Vendor-uploaded media (logos, photos, and headshots) is stored in Firebase Cloud Storage in the australia-southeast1 (Sydney) region. All primary user, vendor, and media data is therefore stored in Australia.
- We implement reasonable technical and organisational measures to protect your data. However, no internet transmission or storage is completely secure.
6. Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy:
- Account data: retained while your account is active. When you delete your account or a vendor listing is deleted, records enter a 30-day grace period before permanent deletion, allowing accidental deletions to be reversed.
- Consumer search location: used transiently during your search session and not stored beyond it, except as described under Search demand data below.
- Vendor live-pin location: retained only while your pin is active; deactivating your pin removes your live location.
- Interaction analytics (views, calls, shares, and similar events): retained for up to 365 days, after which individual events are deleted; aggregated statistics may be retained longer in de-identified form.
- Search demand data: retained for 90 days, then automatically deleted.
- Device registration records (fraud prevention): retained for up to 180 days.
- Verification records (for example, evidence that an ABN check occurred and its result): retained for as long as needed to evidence that verification took place.
Where a longer retention period is required by law (for example, tax or accounting records), we retain the relevant records for that period.
7. Your Rights
Subject to the law in your region, you generally have the right to access, correct, and request deletion of your personal information, and to contact us with privacy concerns. Region-specific rights and the exact process are described in the applicable addendum.
- Access: request a copy of the personal information we hold about you.
- Correction: ask us to correct inaccurate or incomplete information.
- Deletion: request deletion of your account and associated personal data. Vendor business data that has been publicly displayed may be retained in anonymised form.
- To exercise any of these rights, contact support@roammeo.app.
8. Account Review and Appeals
In some cases — for example, where our fraud-detection systems identify multiple vendor accounts created from the same device — a vendor account may be placed under review before going live. You will see a notice on your vendor dashboard and may submit an explanation for our review team. We aim to review submissions promptly, though response times are not guaranteed. We do not disclose the internal mechanics of our fraud, trust, or moderation systems.
10. Children's Privacy
RoamMeo is not intended for use by persons under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a person under 18, we will delete it promptly.
11. Changes to This Privacy Policy
- We may update this Policy to reflect changes in our practices or applicable law.
- We will notify registered users of material changes via email at least 14 days before they take effect.
- Continued use after the effective date constitutes acceptance of the revised Policy.
Region Addendum — Australia
The following applies in addition to the base document for users in Australia. Where an addendum conflicts with the base document, the addendum governs for that region.
Australian Privacy Principles
For users in Australia, we handle personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), including how personal information is collected, used, disclosed, secured, and made available for access and correction.
Cross-border disclosure (APP 8). Our primary databases and vendor-uploaded media are stored in Australia (australia-southeast1). However, some of our service providers — including Stripe (payment processing) and Google/Firebase global infrastructure — may process or transmit data outside Australia in the course of providing their services (see Third-Party Services above). Where this occurs, we take reasonable steps intended to ensure those overseas recipients handle the information consistently with the APPs.
Notifiable Data Breaches. If a data breach is likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme, including notifying affected individuals and the OAIC where required.
Review needed: Whether RoamMeo is an "APP entity" (the Privacy Act's small-business exemption generally applies below AU$3M annual turnover, with exceptions) is a legal determination that affects which obligations are mandatory. Confirm with a lawyer.
ABN Handling and Display
- When you register as an Australian vendor and enter your ABN, we query the Australian Business Register (ABR) ABN Lookup API to confirm the ABN is registered and to retrieve the registered entity name.
- Your ABN is displayed on your public vendor profile as part of transparency to consumers.
- ABN verification confirms registration status only. It does not confirm the quality, safety, or trustworthiness of a vendor.
- No consumer personal information is sent to the ABR.
Access, Correction and Complaints
- Access & correction (APP 12 & 13): You may request access to the personal information we hold about you and ask us to correct it. Email support@roammeo.app and we will respond within a reasonable time.
- Complaints: If you believe we have breached the APPs, contact us first. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Additional Region Addenda
RoamMeo is built to expand into new markets. As we launch in additional regions, a region-specific addendum for each new market will be added here — covering that region's privacy, consumer, and business-verification laws — without changing the base document above. No additional regions are active yet.