Skip to main content
Roam Rome logoRoam Rome

Privacy Policy

Last updated July 2026

This Privacy Policy explains how Roam Rome, operated by Nexa Holdings LLC (“Roam Rome,” “we,” “us,” “our”), processes personal data when you use www.roamrome.net, contact us, or purchase our travel-planning services. We serve travelers planning trips to Rome, including residents of the EU, UK, and Italy.


1. Who is responsible

Data controller: Nexa Holdings LLC (trading as Roam Rome), United States.

Privacy contact: hello@roamrome.net

We are evaluating whether an EU or UK representative is required under GDPR Article 27 for our regular offering to European travelers. If you need to reach us in that capacity, email hello@roamrome.net with the subject line “GDPR representative”.

2. Personal data we collect

  • Identity & contact: name, email, phone number.
  • Trip & booking details: travel dates, party size (including children), hotel area, flight numbers, pickup/drop-off addresses, preferences, free-text messages, questionnaire answers submitted after payment.
  • Payment data: handled by Stripe (we receive confirmation metadata, amounts, and customer contact details attached to the checkout session — not full card numbers).
  • Marketing preferences: whether you opted in to planning-tip emails on the checklist form; purchase records used for similar-service follow-ups where disclosed at checkout.
  • Technical & security: IP address (contact-form owner notifications and rate limiting), browser user-agent, anti-spam timing signals, aggregate analytics after cookie consent, and operational logs from our hosting provider.
  • Operational events: anonymised or redacted activity in our database (e.g. checklist download events with email fields redacted in stored payloads).

Our public feedback questionnaire does not store your email or answers in our database.

3. Legal bases (GDPR Article 6)

Processing activityLegal basis
Fulfilling bookings, itineraries, transfers, and concierge servicesContract (Art. 6(1)(b)) — necessary to perform the service you purchased or requested
Sending the free checklist PDF you requestedContract / pre-contractual steps (Art. 6(1)(b))
Optional marketing emails (checklist opt-in; similar-service emails after purchase where disclosed)Consent (Art. 6(1)(a)) for checklist opt-in; legitimate interest / soft opt-in for existing customers where permitted and disclosed at checkout, with easy opt-out
Contact-form inquiries and operational emailLegitimate interest (Art. 6(1)(f)) — responding to your request; pre-contractual steps where you ask for a quote
Analytics (GA4, Vercel Analytics) after you accept cookiesConsent (Art. 6(1)(a))
Rate limiting, fraud/abuse prevention, IP in owner alertsLegitimate interest (Art. 6(1)(f)) — security of our site and staff
Tax, accounting, and legal retentionLegal obligation (Art. 6(1)(c))

4. How we use personal data

  • Respond to inquiries and design or deliver itineraries.
  • Coordinate drivers, guides, restaurants, and other local vendors.
  • Process payments and send receipts and confirmations.
  • Send optional marketing about Rome travel planning when you have opted in or where disclosed at purchase, with unsubscribe in every marketing email.
  • Understand aggregate site usage (only after cookie consent) and prevent abuse.
  • Meet tax, accounting, and regulatory requirements.

5. Processors & subprocessors

We use vetted service providers who process data on our instructions. We do not sell personal data.

ProviderPurposeTypical location
StripePayment processingUS / global
ResendTransactional and marketing email, contact audiencesUS
Neon (PostgreSQL)Orders, receipts, submissions, operational eventsEU / US (region configured per project)
VercelHosting, CDN, Web Analytics (if accepted)US / global edge
Google (Analytics 4)Aggregate traffic analytics (if accepted)US / global
Upstash RedisIP-based rate limiting (when configured)US / EU
GetYourGuideAffiliate widget (script loads only after cookie consent)EU
TiqetsAttraction tickets and experiences (partner links; server-side API for availability)EU (Netherlands)
Local vendors (Italy)Drivers, licensed guides, restaurants — fulfillment onlyItaly / EU

Internal DPA tracking: see docs/compliance/DPA_REGISTER.md in our repository (maintained by our team). Data subject request procedures: docs/compliance/DSR_RUNBOOK.md.

6. Cookie notice (in line with Garante guidelines)

Under Italian Garante guidance on cookies and other tracking tools, we classify technologies below and ask for your free, informed consent before loading non-essential analytics or marketing scripts. You can Accept or Reject in the banner, or change your mind anytime via Cookie preferences in the site footer (equal to withdrawing consent).

Rejecting or withdrawing consent does not block browsing, contact, or checkout. Strictly necessary tools (e.g. payment on stripe.com) still run when you choose to pay.

TechnologyProviderCategoryPurposeConsent?Duration
rr-cookie-consent (localStorage)Roam Rome (first party)PreferencesStores whether you accepted or rejected optional analytics and widgets.NoUntil you clear site data or change preferences via Cookie preferences in the footer
Google Analytics 4 (_ga, _ga_*, _gid, …)

Loads only after Accept. Google Consent Mode v2 defaults deny until then.

Google Ireland Ltd.Analytics / statisticsAggregate visit statistics (pages viewed, referral source). No advertising cookies from our GA4 tag.Yes — before loadUp to 24 months (_ga); session cookies shorter — see Google’s policy
Vercel Web Analytics

Loads only after Accept.

Vercel Inc.Analytics / statisticsAggregate page-view and performance metrics without third-party ad profiling from this tag.Yes — before loadSession / short-lived identifiers per Vercel documentation
GetYourGuide partner widget

Script loads only after Accept.

GetYourGuide Deutschland GmbHMarketing / third-party contentEmbeds affiliate tour listings on selected pages.Yes — before loadPer GetYourGuide partner cookie policy when you interact with the widget
Tiqets (tiqets.com)

No Tiqets script loads on roamrome.net. Cookies and booking data apply on tiqets.com after you leave our site. Product availability may be fetched server-side via the Tiqets API.

Tiqets International B.V.Marketing / third-party contentAttraction and experience product pages and partner checkout when you choose a Tiqets booking link.NoPer Tiqets cookie policy on tiqets.com
Stripe Checkout (stripe.com)

Third-party domain during payment only.

Stripe Payments Europe Ltd. / Stripe Inc.Strictly necessarySecure payment processing on Stripe-hosted checkout pages you open voluntarily.NoPer Stripe cookie policy for the checkout session

We use Google Consent Mode v2 defaults that keep ad-related storage off until you accept analytics. For more on Italian rules, see the Garante per la protezione dei dati personali.

7. Marketing communications

For Italian recipients, promotional email follows Art. 130 of the Codice Privacy (see internal audit docs/compliance/ART130_MARKETING_AUDIT.md).

  • Checklist: we send the PDF you requested regardless of marketing choice. Promotional follow-ups (day 2 and day 7) go only to people who tick the optional opt-in checkbox.
  • Purchases: airport transfers and itinerary purchases may enroll you in similar-service planning emails as disclosed on the checkout page and in Stripe. Every marketing email includes an unsubscribe link.
  • Contact form: we do not add general inquiries to marketing lists.

8. Retention

Data categoryTypical retention
Inquiries & trip planning recordsUp to 3 years after last contact
Paid orders, receipts, submissionsDuration of service + up to 7 years for tax/accounting
Marketing audience (Resend)Until you unsubscribe or we delete your contact
Site events (redacted payloads)Up to 24 months
Rate-limit counters (IP)Minutes to hours (rolling windows)
Analytics (Google / Vercel)Per provider settings (aggregate)

9. Your rights

If you are in the EU, UK, or Italy, you may have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase data (subject to legal retention exceptions)
  • Restrict or object to certain processing
  • Data portability where applicable
  • Withdraw consent at any time (without affecting prior lawful processing)
  • Unsubscribe from marketing via the link in any marketing email or by emailing us

To exercise these rights, email hello@roamrome.net. We respond within 30 days (extendable to 90 days for complex requests, as permitted by GDPR).

10. Right to complain to a supervisory authority

11. International transfers

Nexa Holdings LLC is based in the United States. Personal data may be processed in the U.S. and by providers globally. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, and/or the EU–US Data Privacy Framework (where the provider participates). Stripe, Google, Resend, Vercel, Neon, Upstash, GetYourGuide, and Tiqets publish their own transfer mechanisms in their data processing terms.

12. Children

Our services are directed at adults booking travel. We do not knowingly collect data from children under 16 without parental authority. Trip forms may include the number of child travelers in your party for logistics (e.g. child seats) — this is information you provide about your booking, not direct marketing to children.

13. Security

We use HTTPS, access controls on admin areas, signed unsubscribe tokens, rate limiting, and provider security features. No method of transmission or storage is completely secure.

14. Changes

We may update this policy. The “Last updated” date above reflects the current version. Material changes will be posted on this page.


Riepilogo in italiano

Sintesi in italiano dei punti principali. In caso di discrepanza fa fede la versione inglese sopra.

Titolare del trattamento

Nexa Holdings LLC (Roam Rome), Stati Uniti. Contatto privacy: hello@roamrome.net

Dati che trattiamo

Nome, email, telefono, dettagli di viaggio e prenotazione, dati di pagamento tramite Stripe (non conserviamo i numeri di carta), preferenze marketing e dati tecnici (es. indirizzo IP per sicurezza e anti-spam).

Base giuridica

Esecuzione del contratto o richiesta di servizi; consenso per analytics e cookie non essenziali; consenso esplicito per email promozionali dopo il download della checklist; soft opt-in dopo un acquisto per servizi simili, con informativa al checkout e possibilità di opposizione; obblighi di legge per contabilità.

Cookie e tracker

Prima di caricare Google Analytics, Vercel Analytics o il widget GetYourGuide chiediamo il tuo consenso (Accetta / Rifiuta). Puoi modificare la scelta in qualsiasi momento con Cookie preferences nel piè di pagina. Vedi la tabella nella sezione 6.

Email promozionali (Art. 130)

  • Checklist gratuita: solo email di servizio; promozioni solo se spunti la casella opzionale.
  • Dopo un acquisto (transfer, itinerario): possiamo inviare email su servizi simili, con informativa al pagamento e link di disiscrizione.
  • Modulo contatti: non ti iscrive a newsletter.

I tuoi diritti

Accesso, rettifica, cancellazione, limitazione, portabilità, opposizione e revoca del consenso. Rispondiamo entro 30 giorni a hello@roamrome.net.

15. Contact

Privacy questions or data subject requests: hello@roamrome.net

See also our Terms & Conditions.