Privacy Policy

Roamers

Effective Date: September 15, 2026
Last Updated: September 15, 2026
Version: 2.1


What changed in version 2.1

What changed in version 2.0

Version 1.0 (February 2026) no longer matched the product. Version 2.0 (September 14, 2026) moved our infrastructure description to our self-hosted server in Germany, introduced town-level location for other travelers, stated that we run no analytics or advertising SDK, and described account deletion across all tables and storage.

Roamers is operated by Make it Nice GmbH.


Introduction

Welcome to Roamers ("we," "our," or "us"). Roamers is a mobile app that helps independent travelers find and meet other travelers safely, and keep a record of their own trips.

This Privacy Policy explains what data the Roamers app ("App") and its backend ("Services") collect, how we use it, who we share it with, and the choices and rights you have.

Contact information:


Table of Contents

  1. [Information We Collect](#1-information-we-collect)
  2. [How We Use Your Information](#2-how-we-use-your-information)
  3. [Location Data in Detail](#3-location-data-in-detail)
  4. [Who We Share Information With](#4-who-we-share-information-with)
  5. [Data Security](#5-data-security)
  6. [Data Retention](#6-data-retention)
  7. [Deleting Your Account](#7-deleting-your-account)
  8. [Your Rights (GDPR and Others)](#8-your-rights-gdpr-and-others)
  9. [Analytics and Crash Reporting](#9-analytics-and-crash-reporting)
  10. [Age Requirement](#10-age-requirement)
  11. [Wikivoyage and Third-Party Travel Content](#11-wikivoyage-and-third-party-travel-content)
  12. [International Data Transfers](#12-international-data-transfers)
  13. [Changes to This Policy](#13-changes-to-this-policy)
  14. [Contact Us](#14-contact-us)

1. Information We Collect

1.1 Account and sign-in

1.2 Profile information

Fields you fill in on your profile, all editable and most optional: display name, bio, date of birth, gender, home country, languages, travel style tags, interests, profile photos, trip status, and (optionally) your Instagram handle.

1.3 Location

Covered in detail in §3. In short: while the app is open, and your presence is not Hidden, your device sends your position to our server. If you turn on route recording for a trip, the app also records your route: while the app is open, and while it's closed only if you allow location access "Always". Other users never receive your exact coordinates, only a town-level position, and only if your settings allow it. The one exception is a time-limited Live share that you start yourself.

1.4 Content you create

1.5 Emergency contacts

If you add an emergency contact (Settings → Safety), we store the name, phone number, relationship, and optionally an email address you provide for that contact. We use this only to let you start a live-location share with them from the SOS flow. Roamers never contacts them on your behalf, and we do not monitor the SOS flow (see §3.4 and the Terms of Service §7).

1.6 Device and technical information

1.7 What we do not collect

We do not run any advertising, analytics or tracking SDK (see §9). We do not access your device's Contacts app. We do not collect precise location for anything you haven't taken an action to enable: opening the app while your presence isn't Hidden, turning on route recording for a trip, tagging a check-in or diary entry, or starting a Live share.


2. How We Use Your Information

We do not sell your personal information, and we do not use your data for advertising.

2.1 Legal bases (Art. 6 GDPR)

ProcessingLegal basis
Your account, profile, matching, messaging, posts, stories, hails, groups, guides, trip diary, check-ins, maps, emergency contacts you add for yourself, and account emailsPerformance of our contract with you, Art. 6(1)(b)
Location while the app is openArt. 6(1)(b). Access to location on your device only with the iOS permission you grant (§ 25 TDDDG)
Route recording for a tripYour consent, Art. 6(1)(a): you turn it on for a trip, and for recording while the app is closed you also allow the iOS "Always" location permission. You can withdraw it at any time by turning recording off or changing the permission in iOS Settings
Push notificationsArt. 6(1)(b). Only after you allow notifications in iOS (§ 25 TDDDG)
Age check from your date of birthArt. 6(1)(b), and our legitimate interest in keeping minors off an adults-only app, Art. 6(1)(f)
Storing your emergency contacts' detailsLegitimate interest (yours and your contact's) in your safety, Art. 6(1)(f)
Blocks, reports and the copy of reported content, rate limits, share-link view records, sign-in sessions and audit records, server logsLegitimate interest in the safety of our users and the security of the service, Art. 6(1)(f)
Cover image suggestions from Unsplash when you tap "Suggest covers" while creating a groupLegitimate interest in making group creation easy, Art. 6(1)(f). Nothing is sent to Unsplash unless you ask, and you can pick your own photo instead
Keeping or disclosing data where the law requires itLegal obligation, Art. 6(1)(c)

Where we rely on legitimate interest, you can object (§8).


3. Location Data in Detail

Location is central to how Roamers works, so we describe what actually happens on our server, not just what the app shows.

3.1 How your location reaches us

To show town names, maps and place search results, the app uses Apple's location services, which receive coordinates or search terms from your device (§3.6).

3.2 What other users can see

Your presence setting (Settings → Privacy) controls who sees your town-level position in Nearby and the town and country on your profile:

What Hidden does not change:

In every mode:

The location of a hail is snapped on our server to the same ~5.5 km grid before it is stored. Distances to hails are shown in whole kilometers.

3.3 "Follow my trip" links

You can create a "Follow my trip" web link that lets anyone who has it see your trip without the app. The link shows your route and current location only at town level (about 5 km), never your exact position. You choose what it includes: location only (the default), location plus your public and friends-visible diary entries, or everything, which adds your check-in names and notes and trip stats. Check-ins attached to a private diary entry are never shown. Every link expires: after 24 hours, 7 days (the default), 30 days, or 3 days after your trip ends (at most 30 days). You can revoke a link at any time, and it stops working immediately. If you widen what a link includes, we create a new link and the old one stops working. Links that no longer work, whether expired, revoked or replaced, all show the same message, so nobody can tell you stopped sharing with them. Once your trip ends, the page keeps showing your route and diary until the link expires, but no longer shows your current town or when you last updated. This is separate from the precise Live share in §3.2.

When someone opens a trip or live-location link, we record a keyed one-way hash of their IP address, their browser type and the time. This lets you see that the link was opened and helps us detect abuse. The hash and browser type are removed after 7 days. Trip-link view records are deleted after 30 days, and live-share view records after 7 days. The map on these pages is Apple MapKit JS (§4.3). When a page has a location to show, the viewer's browser loads the map and map images from Apple, which receives the viewer's IP address and the map area shown. Apart from Apple's map, the pages load no outside scripts, fonts or trackers.

3.4 Emergency / SOS

The SOS flow lets you call your local emergency number and start a live-location share with your saved emergency contacts. This is not monitored by Roamers. No one on our side sees or responds to an SOS action. It is a quicker way to reach the people and services you choose. See the Terms of Service §7 for the full safety disclaimer.

3.5 Trip diary and check-ins

If you tag a trip diary entry or check-in with a location, that coordinate is stored with the entry so it can be shown on your personal trip map. Other travelers never see the exact location, place names, notes, photos or times of your check-ins. Once a trip has ended, travelers who can see that trip may see the town, country and date of its check-ins, but never for check-ins from the last 24 hours. For public trips that is everyone; for friends-only trips, the people you're connected with. A connection starts when you accept someone's message request or they accept yours, and either of you can remove it at any time, which ends this access for both of you immediately. Check-ins that aren't part of a trip are only visible to you. None of this is shown if you are Hidden, if either of you has blocked the other, or if you are set to Visible to matches and haven't matched.

3.6 Apple's location and map services

The app uses Apple's built-in services on your iPhone to show maps, to turn your coordinates into a town and country name, and to search for places and cities when you check in or look at a place. To do this, iOS sends map areas, coordinates or your search text to Apple. Apple processes this under its own privacy policy; we don't receive anything from Apple about it beyond the result.

On-device AI place search (iOS 26 and later, where available) runs entirely on your iPhone and sends nothing to us or to Apple for that search.


4. Who We Share Information With

4.1 With other users

Depending on your privacy settings, other Roamers users may see your profile (name, photos, bio, interests, age), your town and country and town-level position (§3.2), your hails, and content you post (posts and stories with their place label and publishing day, group posts, comments, guides, reviews). Story authors see who viewed their story and on which day. You control this in Settings → Privacy.

Other travelers who can see your profile may also see summary statistics for trips that ended at least two days ago: number of trips, countries visited, and total distance rounded to the nearest 100 km. Profile lookups are rate-limited to prevent bulk collection.

4.2 Service providers who process data for us (processors, Art. 28 GDPR)

ProviderPurposeDataLocation and transfer safeguardIn use
Hetzner Online GmbH, Gunzenhausen, GermanyHosts the server we run ourselves, with our database, authentication, file storage, live updates, server functions, server logs, and our website (legal pages and share pages)All data described in §1Germany (EU)Yes
Resend (Plus Five Five, Inc., San Francisco, USA)Sending account emails: confirmation, password reset, account noticesYour email address, the content of the email (including one-time links), delivery metadataSent from Resend's EU region. The company is in the USA and may access data from there: EU-U.S. Data Privacy Framework certification and EU Standard Contractual ClausesYes

We do not share data with any advertising network, data broker or analytics vendor.

4.3 Other companies that receive data when you use certain features

These companies decide for themselves how they process the data, under their own privacy policies (they are not our processors).

CompanyWhenDataLocationIn use
Apple (Apple Distribution International Ltd., Ireland; Apple Inc., USA)Sign in with Apple, if you use itYour sign-in with Apple; we receive the account identifier and, if you share them, name and emailApple Distribution International Ltd. (Ireland) is responsible for users in the EEA; Apple may process data in the USA under its own transfer safeguardsYes, if you sign in with Apple
Apple, Apple Push Notification servicePush notifications you've allowedYour device token and the notification's title, which names the person and the event (for example "Anna sent you a message"). Never message contentas aboveYes, if notifications are on
Apple, Maps, place search and location names (§3.6)Showing maps, naming your town, searching placesMap areas, coordinates, search text, IP addressas aboveYes
Unsplash (Unsplash Inc.)When you create a group and tap "Suggest covers"The search term (group name and category), sent by our server, so the search doesn't give Unsplash your IP address. To prevent misuse we note that you searched (not what you searched for) and delete that note after 2 days. The suggested photos then load from Unsplash's servers, which gives Unsplash your IP address. When you pick one, our server tells Unsplash which photo was chosen, as Unsplash requires. If you keep the suggested cover, everyone who views the group loads it from Unsplash, which gives Unsplash their IP addressUSA. See Unsplash's privacy policyYes, only when you ask for suggestions
Apple, MapKit JSMap on "Follow my trip" and Live share web pages, when the page has a location to showIP address and browser details of the person opening the page, and the map area shown (town level on trip links; the shared position during an active Live share)as aboveYes, on share pages

Links you tap: some screens link out, for example to a place's Wikivoyage article, a traveler's Instagram profile or Apple Maps. Opening them is an ordinary visit to that website or app, which then receives your IP address under its own privacy policy.

4.4 Built into the app but not switched on

We will update this policy before switching on any of these:

4.5 Legal requirements

We may disclose information when required by law: to respond to valid legal process, to protect our rights or the safety of our users, or to prevent fraud or an imminent risk to life.

4.6 Business transfers

If Roamers were ever acquired or its assets transferred, user data may transfer as part of that transaction. We would notify affected users of any such change.


5. Data Security

5.1 Your security responsibilities

Use a strong, unique password; don't share your login credentials; sign out on shared devices; report suspicious activity to us.

5.2 Breach notification

If a data breach affects your personal information in a way that creates a risk to you, we will notify the relevant supervisory authority within the timeframes required by law (72 hours under GDPR). Where the risk to you is high, we will also notify you.


6. Data Retention

Data typeRetention
Account and profile dataUntil you delete your account
Current location and townOverwritten on every update; not kept as a history. No longer shown as "nearby" after 72 hours without an update
Trip routes, diary and check-in locationsUntil you delete the trip or entry, or your account. This is a history you build on purpose, unlike your current location
Live-location shares (including SOS shares)Until they end (you choose the duration) or you stop them
"Follow my trip" linksUntil they expire (24 hours, 7 days, 30 days, or 3 days after the trip ends, at most 30 days), or earlier if you revoke them or make the trip private
Fingerprints of links that no longer work (one-way hash of the link, not linked to you or your trip; link-open records store only this fingerprint)180 days, so old links can't be revived
Share-link view records (hashed IP, browser type, time)Hash and browser type removed after 7 days; trip-link records deleted after 30 days, live-share records after 7 days
Messages, posts, stories, commentsUntil you or we delete them, or until your account is deleted
Exact time of your posts and stories (visible only to you)Deleted together with the post or story
Story views (who viewed, day)Deleted together with the story or the viewer's account
In-app notifications (who did what, e.g. "Anna liked your post")Deleted automatically 90 days after they were sent once you have read them, 180 days if unread, or earlier if you delete them or your account
HailsDeleted automatically 7 days after they expire or are closed, or earlier if you delete them or your account
Rate-limit records (hail posting, notifications, profile lookups, photo lookups)Deleted automatically after 2 hours to 8 days, depending on the record
Reports (including the copy of reported content)Kept while the report is open or under review, and for 12 months after it has been resolved; then deleted automatically. This also applies after the reported content or either account has been deleted. A report is unlinked from a deleted reporter's account
Emergency contactsUntil you remove them or delete your account
Push notification tokensUntil the token stops working (we remove tokens that fail repeatedly) or you delete your account
Sign-in sessions (IP address, device type)Until you sign out or the session expires, and at the latest when your account is deleted
Sign-in audit records (event, time, account email or identifier)Deleted automatically after 90 days, and straight away when you delete your account (§7)
Server logs (time, requested address; IP addresses in authentication, storage and live-update logs)Deleted automatically after 14 days
Deletion requestsRecorded with a timestamp for the period described in §7

7. Deleting Your Account

You can delete your account from within the app. Deleting your account:

We aim to complete deletion within 30 days of a confirmed request, and immediately where technically possible. Once we run off-server backups (see §5), deleted data will age out of them on our normal backup rotation schedule.

Data export: self-service export in the app is not fully available yet. Until it is, email us at the privacy address in §14 and we will send you a copy of your data within 30 days.


8. Your Rights (GDPR and Others)

If you are in the European Union / EEA, you have the right to:

If you are in California or another place with a comparable law, you have similar rights (to know, to delete, and not to be discriminated against for using these rights). We do not sell personal information, so there is nothing to opt out of in that respect.

How to exercise your rights: use Settings → Privacy → Delete Account in the app, or email us at the address in §14. We will respond within 30 days, or sooner where required by law.

You also have the right to lodge a complaint with a data protection supervisory authority (§14).


9. Analytics and Crash Reporting

Roamers does not run any analytics or crash-reporting SDK. The only crash and usage data we see is what Apple provides through App Store Connect and TestFlight, and only if you have chosen in iOS Settings to share analytics with app developers (or, as a TestFlight tester, when you send feedback).

We plan to add:

None of these track you across apps or companies for advertising. We will update this policy and our App Store privacy label before any of them ships, not after.


10. Age Requirement

Roamers is for adults only. You must be 18 years of age or older to create an account. We ask for your date of birth at sign-up and enforce the minimum age there. We do not knowingly collect data from anyone under 18. If we learn an account belongs to someone under 18, we will delete it. See the Terms of Service §1 for the full eligibility terms.


11. Wikivoyage and Third-Party Travel Content

Points of interest and guide content on the map (about 280,000 listings as of September 2026) include content from Wikivoyage, a community-maintained, freely licensed travel guide. This is public travel-guide content, not personal data. We import it to our own server, so browsing it sends nothing to Wikivoyage. Only if you tap a link to a Wikivoyage article does your device visit Wikivoyage's website.

Wikivoyage content is licensed under Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0). We credit Wikivoyage as the source and link to the article each listing comes from. We have adapted the content: listing fields are extracted from Wikivoyage articles and re-categorized, and a listing's country is filled in from its coordinates rather than taken from the article text. The Wikivoyage-derived text remains available under CC BY-SA 4.0.

Country boundary data comes from Natural Earth (public domain).


12. International Data Transfers

Our own infrastructure (database, authentication, file storage, logs, websites) runs on a server we operate in Germany, within the EU. Some companies listed in §4.2 and §4.3 are based in, or process data in, the USA:

CompanyTransfer safeguard
Resend (Plus Five Five, Inc.)EU-U.S. Data Privacy Framework certification (EU adequacy decision, Art. 45 GDPR) and EU Standard Contractual Clauses (Art. 46 GDPR)
AppleApple Distribution International Ltd. (Ireland) is responsible for users in the EEA; Apple applies its own transfer safeguards, as described in Apple's privacy policy
Unsplash Inc.Our server sends your cover search to Unsplash when you ask for suggestions, and your device loads the suggested photos from Unsplash. Unsplash states in its privacy policy that it complies with GDPR requirements for transfers from the EU

The services in §4.4 are not in use. If we switch them on, we will name their transfer safeguards here first.


13. Changes to This Policy

We'll post material changes here with a new "Last Updated" date and a note under "What changed". Where a change meaningfully affects how your data is used, we'll tell you in the app before it takes effect.


14. Contact Us

Privacy questions: hallo@makeitnice.de

Mailing address: Make it Nice GmbH, An der Koppel 1, 53909 Zülpich, Germany (Amtsgericht Bonn, HRB 28837)

Data Protection Officer: none appointed (not required under § 38 BDSG).

Supervisory authority: if you're in the EU/EEA and unhappy with our response, you may contact the data protection authority in your country of residence, or the authority responsible for our registered office: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

Applicable law: this policy is governed by German law, subject to the mandatory data protection law of your country of residence.


Summary of Key Points

TopicKey point
LocationOther users see at most a town-level (~5.5 km) position, depending on your presence setting. Exact location is only shared through a time-limited Live share you start. Hidden stops sharing your position, but not trips you track or Live shares you start.
Posts and storiesOthers see the day, not the time. Place labels you add are visible to travelers who can see the post.
InfrastructureOur own server at Hetzner in Germany; Resend for account emails.
Other companiesApple (sign-in, push, maps, including the map on share pages), Unsplash (group cover suggestions). Google sign-in and purchases are built in but switched off.
AnalyticsNone today. Privacy-first analytics and crash reporting are planned, and this policy will be updated first.
DeletionDeleting your account removes your data and files, including files in your conversations and your sign-in audit records. Safety reports are the exception (§7).
Age18+ only.
Selling dataWe don't sell your personal information.

This Privacy Policy describes the app as it is actually built. If you find something in the app that doesn't match what's written here, please tell us. We treat that as a bug in the app, the policy, or both.