Onroom Logo

Onroom – Privacy Policy

Last updated: 18 April 2025

We respect your privacy and are committed to protecting it. This Privacy Policy explains how Onroom ("we", "us") collects, uses, and shares your personal information when you interact with our website (https://on-room.com), applications, and related services (collectively, the "Service").


1. Information We Collect

CategoryExamplesSourcePurpose
Contact dataE‑mail address entered in wait‑list formYouWait‑list confirmation, product updates
Auth dataGoogle UID, display name, avatarGoogle (if you sign in)Account creation, personalisation
Usage dataPages visited, links clicked, referral URLAutomatically via GA4 / PlausibleAnalytics & product improvement
Device dataIP address, browser type, OSAutomaticSecurity & fraud prevention
CommunicationsWelcome e‑mail, beta inviteResend (transactional e‑mail)Service messages & compliance
Account DataWallet balance, ChatPass balance, Emotion score inferenceService UsageCore service delivery, Personalization
Verification Data (Verified Users)Legal name, address, Gov. ID photo, selfieYou (via Stripe)Identity Verification (KYC), Fraud Prevention
Monetary Data (Verified Users)Tax forms, bank details (via Stripe)You (via Stripe)Cash Payout Processing

We do not knowingly collect data from children under 13 (or 16 in EEA).

2. Legal Bases (GDPR)

We process personal data under the following bases:

3. How We Use Data

  1. Deliver and improve the Service.
  2. Send transactional messages, such as welcome or beta invites.
  3. Analytics (aggregate, non‑identifiable).
  4. Legal compliance and protection of our rights.

We do not sell your personal data.

4. Sharing of Data

We share data only with trusted subprocessors necessary to operate the Service:

Sub‑processorPurposeLocationSafeguards
Google Cloud / FirebaseHosting, database, authenticationUSASCCs / GDPR Business Addendum
ResendTransactional e‑mailUSA/EUDPA & SCCs
Google Analytics 4Site analytics (IP anonymised)GlobalIP‑anonymisation, consent banner
Plausible.ioPrivacy‑friendly analyticsEUNo cookies
StripePayment Processing, Identity Verification (KYC)Global (USA HQ)PCI-DSS, DPA & SCCs

We may disclose information if required by law or to protect the Service.

5. International Transfers

Data may be stored and processed in the United States or other countries. When transferring personal data from the EU/UK we rely on Standard Contractual Clauses.

6. Data Retention

7. Your Rights

RegionRights
EEA/UK GDPRAccess, rectification, erasure, restriction, data portability, object, lodge complaint with DPA
California (CCPA/CPRA)Know, delete, opt‑out of "sale" (we don't sell), non‑discrimination
All usersUnsubscribe from e‑mails via link in footer

California residents may have additional rights, including the right to opt-out of the "sale" or "sharing" of personal information. We do not sell your data, but you can exercise your rights via the contact info below.

Submit requests at privacy@on-room.com.

8. Security

We use industry\u2011standard measures (TLS 1.3, Firestore security rules, least\u2011privilege IAM). Sensitive data like payment details submitted for verification are processed directly by Stripe and stored encrypted. No method is 100% secure.

9. Cookies & Similar Tech

10. Changes to This Policy

We may update this Privacy Policy. Material changes will be posted on this page and notified by e‑mail to wait‑list members.

11. Contact

Questions about privacy? E‑mail support@on-room.com