Privacy Policy
Last updated July 2026
This Privacy Policy explains how Roam Rome, operated by Nexa Holdings LLC (“Roam Rome,” “we,” “us,” “our”), processes personal data when you use www.roamrome.net, contact us, or purchase our travel-planning services. We serve travelers planning trips to Rome, including residents of the EU, UK, and Italy.
1. Who is responsible
Data controller: Nexa Holdings LLC (trading as Roam Rome), United States.
Privacy contact: hello@roamrome.net
We are evaluating whether an EU or UK representative is required under GDPR Article 27 for our regular offering to European travelers. If you need to reach us in that capacity, email hello@roamrome.net with the subject line “GDPR representative”.
2. Personal data we collect
- Identity & contact: name, email, phone number.
- Trip & booking details: travel dates, party size (including children), hotel area, flight numbers, pickup/drop-off addresses, preferences, free-text messages, questionnaire answers submitted after payment.
- Payment data: handled by Stripe (we receive confirmation metadata, amounts, and customer contact details attached to the checkout session — not full card numbers).
- Marketing preferences: whether you opted in to planning-tip emails on the checklist form; purchase records used for similar-service follow-ups where disclosed at checkout.
- Technical & security: IP address (contact-form owner notifications and rate limiting), browser user-agent, anti-spam timing signals, aggregate analytics after cookie consent, and operational logs from our hosting provider.
- Operational events: anonymised or redacted activity in our database (e.g. checklist download events with email fields redacted in stored payloads).
Our public feedback questionnaire does not store your email or answers in our database.
3. Legal bases (GDPR Article 6)
| Processing activity | Legal basis |
|---|---|
| Fulfilling bookings, itineraries, transfers, and concierge services | Contract (Art. 6(1)(b)) — necessary to perform the service you purchased or requested |
| Sending the free checklist PDF you requested | Contract / pre-contractual steps (Art. 6(1)(b)) |
| Optional marketing emails (checklist opt-in; similar-service emails after purchase where disclosed) | Consent (Art. 6(1)(a)) for checklist opt-in; legitimate interest / soft opt-in for existing customers where permitted and disclosed at checkout, with easy opt-out |
| Contact-form inquiries and operational email | Legitimate interest (Art. 6(1)(f)) — responding to your request; pre-contractual steps where you ask for a quote |
| Analytics (GA4, Vercel Analytics) after you accept cookies | Consent (Art. 6(1)(a)) |
| Rate limiting, fraud/abuse prevention, IP in owner alerts | Legitimate interest (Art. 6(1)(f)) — security of our site and staff |
| Tax, accounting, and legal retention | Legal obligation (Art. 6(1)(c)) |
4. How we use personal data
- Respond to inquiries and design or deliver itineraries.
- Coordinate drivers, guides, restaurants, and other local vendors.
- Process payments and send receipts and confirmations.
- Send optional marketing about Rome travel planning when you have opted in or where disclosed at purchase, with unsubscribe in every marketing email.
- Understand aggregate site usage (only after cookie consent) and prevent abuse.
- Meet tax, accounting, and regulatory requirements.
5. Processors & subprocessors
We use vetted service providers who process data on our instructions. We do not sell personal data.
| Provider | Purpose | Typical location |
|---|---|---|
| Stripe | Payment processing | US / global |
| Resend | Transactional and marketing email, contact audiences | US |
| Neon (PostgreSQL) | Orders, receipts, submissions, operational events | EU / US (region configured per project) |
| Vercel | Hosting, CDN, Web Analytics (if accepted) | US / global edge |
| Google (Analytics 4) | Aggregate traffic analytics (if accepted) | US / global |
| Upstash Redis | IP-based rate limiting (when configured) | US / EU |
| GetYourGuide | Affiliate widget (script loads only after cookie consent) | EU |
| Tiqets | Attraction tickets and experiences (partner links; server-side API for availability) | EU (Netherlands) |
| Local vendors (Italy) | Drivers, licensed guides, restaurants — fulfillment only | Italy / EU |
Internal DPA tracking: see docs/compliance/DPA_REGISTER.md in our repository (maintained by our team). Data subject request procedures: docs/compliance/DSR_RUNBOOK.md.
6. Cookie notice (in line with Garante guidelines)
Under Italian Garante guidance on cookies and other tracking tools, we classify technologies below and ask for your free, informed consent before loading non-essential analytics or marketing scripts. You can Accept or Reject in the banner, or change your mind anytime via Cookie preferences in the site footer (equal to withdrawing consent).
Rejecting or withdrawing consent does not block browsing, contact, or checkout. Strictly necessary tools (e.g. payment on stripe.com) still run when you choose to pay.
| Technology | Provider | Category | Purpose | Consent? | Duration |
|---|---|---|---|---|---|
| rr-cookie-consent (localStorage) | Roam Rome (first party) | Preferences | Stores whether you accepted or rejected optional analytics and widgets. | No | Until you clear site data or change preferences via Cookie preferences in the footer |
| Google Analytics 4 (_ga, _ga_*, _gid, …) Loads only after Accept. Google Consent Mode v2 defaults deny until then. | Google Ireland Ltd. | Analytics / statistics | Aggregate visit statistics (pages viewed, referral source). No advertising cookies from our GA4 tag. | Yes — before load | Up to 24 months (_ga); session cookies shorter — see Google’s policy |
| Vercel Web Analytics Loads only after Accept. | Vercel Inc. | Analytics / statistics | Aggregate page-view and performance metrics without third-party ad profiling from this tag. | Yes — before load | Session / short-lived identifiers per Vercel documentation |
| GetYourGuide partner widget Script loads only after Accept. | GetYourGuide Deutschland GmbH | Marketing / third-party content | Embeds affiliate tour listings on selected pages. | Yes — before load | Per GetYourGuide partner cookie policy when you interact with the widget |
| Tiqets (tiqets.com) No Tiqets script loads on roamrome.net. Cookies and booking data apply on tiqets.com after you leave our site. Product availability may be fetched server-side via the Tiqets API. | Tiqets International B.V. | Marketing / third-party content | Attraction and experience product pages and partner checkout when you choose a Tiqets booking link. | No | Per Tiqets cookie policy on tiqets.com |
| Stripe Checkout (stripe.com) Third-party domain during payment only. | Stripe Payments Europe Ltd. / Stripe Inc. | Strictly necessary | Secure payment processing on Stripe-hosted checkout pages you open voluntarily. | No | Per Stripe cookie policy for the checkout session |
We use Google Consent Mode v2 defaults that keep ad-related storage off until you accept analytics. For more on Italian rules, see the Garante per la protezione dei dati personali.
7. Marketing communications
For Italian recipients, promotional email follows Art. 130 of the Codice Privacy (see internal audit docs/compliance/ART130_MARKETING_AUDIT.md).
- Checklist: we send the PDF you requested regardless of marketing choice. Promotional follow-ups (day 2 and day 7) go only to people who tick the optional opt-in checkbox.
- Purchases: airport transfers and itinerary purchases may enroll you in similar-service planning emails as disclosed on the checkout page and in Stripe. Every marketing email includes an unsubscribe link.
- Contact form: we do not add general inquiries to marketing lists.
8. Retention
| Data category | Typical retention |
|---|---|
| Inquiries & trip planning records | Up to 3 years after last contact |
| Paid orders, receipts, submissions | Duration of service + up to 7 years for tax/accounting |
| Marketing audience (Resend) | Until you unsubscribe or we delete your contact |
| Site events (redacted payloads) | Up to 24 months |
| Rate-limit counters (IP) | Minutes to hours (rolling windows) |
| Analytics (Google / Vercel) | Per provider settings (aggregate) |
9. Your rights
If you are in the EU, UK, or Italy, you may have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase data (subject to legal retention exceptions)
- Restrict or object to certain processing
- Data portability where applicable
- Withdraw consent at any time (without affecting prior lawful processing)
- Unsubscribe from marketing via the link in any marketing email or by emailing us
To exercise these rights, email hello@roamrome.net. We respond within 30 days (extendable to 90 days for complex requests, as permitted by GDPR).
10. Right to complain to a supervisory authority
- Italy (Garante): garanteprivacy.it
- EU/EEA: your national data protection authority — list of EU authorities
- United Kingdom (ICO): ico.org.uk
11. International transfers
Nexa Holdings LLC is based in the United States. Personal data may be processed in the U.S. and by providers globally. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, and/or the EU–US Data Privacy Framework (where the provider participates). Stripe, Google, Resend, Vercel, Neon, Upstash, GetYourGuide, and Tiqets publish their own transfer mechanisms in their data processing terms.
12. Children
Our services are directed at adults booking travel. We do not knowingly collect data from children under 16 without parental authority. Trip forms may include the number of child travelers in your party for logistics (e.g. child seats) — this is information you provide about your booking, not direct marketing to children.
13. Security
We use HTTPS, access controls on admin areas, signed unsubscribe tokens, rate limiting, and provider security features. No method of transmission or storage is completely secure.
14. Changes
We may update this policy. The “Last updated” date above reflects the current version. Material changes will be posted on this page.
Riepilogo in italiano
Sintesi in italiano dei punti principali. In caso di discrepanza fa fede la versione inglese sopra.
Titolare del trattamento
Nexa Holdings LLC (Roam Rome), Stati Uniti. Contatto privacy: hello@roamrome.net
Dati che trattiamo
Nome, email, telefono, dettagli di viaggio e prenotazione, dati di pagamento tramite Stripe (non conserviamo i numeri di carta), preferenze marketing e dati tecnici (es. indirizzo IP per sicurezza e anti-spam).
Base giuridica
Esecuzione del contratto o richiesta di servizi; consenso per analytics e cookie non essenziali; consenso esplicito per email promozionali dopo il download della checklist; soft opt-in dopo un acquisto per servizi simili, con informativa al checkout e possibilità di opposizione; obblighi di legge per contabilità.
Cookie e tracker
Prima di caricare Google Analytics, Vercel Analytics o il widget GetYourGuide chiediamo il tuo consenso (Accetta / Rifiuta). Puoi modificare la scelta in qualsiasi momento con Cookie preferences nel piè di pagina. Vedi la tabella nella sezione 6.
Email promozionali (Art. 130)
- Checklist gratuita: solo email di servizio; promozioni solo se spunti la casella opzionale.
- Dopo un acquisto (transfer, itinerario): possiamo inviare email su servizi simili, con informativa al pagamento e link di disiscrizione.
- Modulo contatti: non ti iscrive a newsletter.
I tuoi diritti
Accesso, rettifica, cancellazione, limitazione, portabilità, opposizione e revoca del consenso. Rispondiamo entro 30 giorni a hello@roamrome.net.
15. Contact
Privacy questions or data subject requests: hello@roamrome.net
See also our Terms & Conditions.
