Privacy

Room Radius collects personal data — including about people who have never contacted us. This explains exactly what, where it comes from, who is responsible for it, and how to make us stop. Version 2.0, last updated 2026-08-20.

The short version

We hold two different kinds of personal data, and they work differently.

Hotel users. If you have an account, we hold your name, work email, and what you did in the product. We are the data controller for this.

Business contacts. Room Radius finds companies near a hotel and identifies people who may be responsible for booking accommodation — names, job titles, work email addresses and company switchboard numbers. These people did not sign up and have usually never heard of us. For this data the hotel is the controller and we act on its instructions (see the Data Processing Agreement). We describe below how to exercise your rights with either of us.

We do not sell personal data, we do not build advertising profiles, and we do not share it between hotels. Each hotel sees only what its own account gathered.

Who we are

Room Radius provides the software described on this site. Our registered company name and address appear on the terms page. Privacy enquiries and requests: privacy@roomradius.io. We normally respond without undue delay and within one month, subject to any extensions permitted by applicable law.

If a formal complaint is needed instead, you can go directly to your national data protection authority; in Norway that is Datatilsynet.

If you have a Room Radius account

What we hold:your email address and password hash (we never see the password itself), your hotel’s name, address, coordinates and the commercial details you enter, which pages you used and when, and your billing status.

Why: to provide the service you are paying for (performance of a contract), and to keep it working and secure (legitimate interests).

Payment details are not held by us.Card numbers go directly to Stripe and never reach our servers. We store only Stripe’s customer reference, your subscription status and renewal date.

If you connect a mailbox, we store the credentials needed to send on your behalf, encrypted at the application level. Room Radius does not scan the contents of your mailbox. For a Google mailbox we request only permission to send, plus permission to read your email address to label the connection. Where reply detection is enabled for a mailbox connected over SMTP/IMAP, Room Radius accesses only the mailbox metadata — such as message headers — necessary to determine whether a conversation it started received a reply. It does not read the contents of your messages.

If you are a business contact in someone’s account

You are most likely reading this because a hotel emailed you.

What is held:your name, job title, work email address, your employer, your employer’s public phone number and address, and a record of what that hotel sent you and whether you replied. It is business contact information in a professional context. We do not seek personal mobile numbers or personal email addresses, and the settings that would collect them are switched off. A hotel could enter such details itself; if it does, it is the hotel’s own input and its responsibility as controller.

Where it came from:official company registers (in Norway, Brønnøysundregistrene), Google Places, OpenStreetMap, your employer’s own public website, and, where a hotel has it enabled and it is contractually permitted, licensed business-contact providers. Every record in the product shows which source it came from — a hotel can always tell you where your details were found. More detail is on our data sources page.

The lawful basis is the hotel’s to choose. Selecting and documenting the lawful basis for contacting you is the hotel’s responsibility as the controller. Legitimate interests can be relevant for business-to-business outreach to a named role about a service plausibly relevant to that role — but it does not override the electronic-marketing rules that apply in a given country, some of which require prior consent. Where Room Radius processes data for its own purposes, it states its own lawful basis separately. See our compliance page.

Marketing rules apply as well as the GDPR. Every email carries a working unsubscribe link. Once a recipient objects or unsubscribes, the address is placed on a suppression list and is not used for further marketing unless a lawful basis to resume marketing is subsequently established. We keep the suppression record minimal.

Automated processing

Room Radius uses automated systems in a few specific places, and it is worth being precise about where.

  • Ranking and matching. Deciding which companies near a hotel are worth showing, and matching records that describe the same organisation across different sources.
  • Suggesting who to contact. Inferring from a job title whether a role is likely to be involved in booking accommodation. This is a suggestion about a role, not a judgement about a person.

These are deterministic rules and heuristics — not a machine-learning model trained on your data — and Room Radius does not send your personal data to an external AI or large-language-model provider.

Two commitments. No automated decision with legal or similarly significant effect is made about anybody — being ranked as a sales prospect is not one. And the product may only state facts that came from a recorded source: it is not permitted to invent facts about you or your employer, which is why every record carries its source. We do not use your personal data to train any model.

Who else sees the data

We use a small number of providers, each for a stated purpose. Their names, roles, locations and the transfer mechanism for each are on our subprocessors page. In short:

  • Vercel — hosting and compute (processor).
  • Supabase — database and authentication (processor). Where the data lives.
  • Stripe — payments. Stripe acts as an independent controller for processing your payment.
  • Google — Places data (an independent source), and the Gmail API as a processor when you connect a Google mailbox.
  • Licensed contact providers — only where a hotel has enabled them and it is contractually permitted; independent sources of business-contact data.

Some providers are outside the EEA. For each we rely on a lawful transfer mechanism — an adequacy decision, the EU Standard Contractual Clauses, or the EU–US Data Privacy Framework where applicable — identified per provider on the subprocessors page.

We will disclose data if legally compelled. If that happens and we are permitted to tell you, we will.

How long it is kept

  • Account data — kept while your account is open. You can ask us to delete your account and its data at any time by writing to privacy@roomradius.io; we action deletion requests without undue delay.
  • Business contact data — kept while the hotel keeps it, and deleted when the hotel deletes it or asks us to close its account.
  • Suppression records — kept as long as needed to keep honouring an opt-out, minimised to the address and the date.
  • Billing records — kept as long as tax law requires, typically five years.

Some deletion is carried out manually on request today; we are introducing scheduled deletion jobs, and this page will describe them once they run.

Your rights

Whoever you are, you can ask for a copy of your data, ask for corrections, ask for deletion, object to how it is used, or ask us to restrict it. Write to privacy@roomradius.io.

If a hotel contacted you and you want it to stop, two things work: click unsubscribe in the email, which suppresses your address, or write to us and we will suppress you and pass the request to the hotel. You do not have to explain why, and you do not need an account.

Because the hotel is the controller for that data, it may also need to act on requests about its own records. Tell us either way and we will make sure it reaches the right party rather than sending you round in a circle.

Cookies

We set a cookie to keep you signed in, and a short-lived one during signup to stop the search being abused. Both are strictly necessary, so neither needs consent. We do not use advertising or tracking cookies, and the public site sets no cookies at all until you sign in. If analytics is switched on later, this page will say so first and a consent banner will appear before any such cookie is set.

Security

Data is encrypted in transit (TLS). At rest it is stored on infrastructure that provides encryption at rest, and connected-mailbox credentials are additionally encrypted at the application level. Access between hotels is separated at the database level, so one hotel cannot reach another’s data. Secrets are readable only by the server and are never sent to the browser.

We are a small operation and say so plainly: we do not hold ISO 27001 or SOC 2, and if we ever do we will name the certificate rather than imply it. Our infrastructure providers maintain their own certifications; that is theirs, not ours. More detail is on our security page.

We handle personal-data breaches in accordance with applicable data-protection law, including notifying customers, supervisory authorities and affected individuals where legally required.

Changes

The date at the top changes when this policy does. If a change materially affects how we handle your data, account holders are told by email before it takes effect.