Privacy
Privacy policy
Last revised : 1 October 2026
A. Identity and contact
Romory is a brand and service operated by the company Cretes Capital, with which you contract. Legal form: SASU. Share capital: 1 000 €. SIREN : 990195364. SIRET : 990 195 364 00015. RCS : Paris. Registered office: 60, rue François 1er, 75008 Paris, France. VAT: TVA non applicable, article 293 B du CGI (French VAT franchise). Contact : hello@romory.ai. Cretes Capital is the data controller for the personal data described in this notice, except where Romory acts on behalf of an accommodation provider (see below).
Privacy contact: hello@romory.ai.
B. Responsibilities
Romory determines the purposes and means for host accounts, authentication, subscriptions and billing, tailored-offer enquiries, support, security, platform administration and commercial communications it chooses to send.
For an accommodation provider’s guest guide and related reporting, the provider determines why the guide is offered and what it contains. Romory processes that data on the provider’s instructions, except for its own security and service-operation purposes.
Romory’s commitments as a processor under Article 28 GDPR are set out in the Terms, “Personal data” section.
When someone voluntarily creates a Romory account or personal carnet, Romory determines the purposes of that account. One email-identified account can technically link uses across several accommodation providers; this data is not described as anonymous or necessarily isolated between properties.
C. Data categories and sources
Data may be supplied directly by a host or guest, added to a guide by the accommodation provider, or collected automatically during use.
- Hosts: email, authentication identifiers, name if supplied, role, interface language and property memberships.
- Properties and guides: name, address, coordinates, city, country, contact details, practical stay information, Wi-Fi, rules, links and published documents.
- Host content: logos, photos, poster backgrounds, copy, recommendation comments and brand settings.
- Commercial enquiries and support: contact details, property or company name, establishment and room counts, locations, message, topic, page context and active property.
- Subscription: selected plan, quantity, billing frequency, subscription status and dates, plus customer and subscription identifiers sent by Paddle. Card details are entered directly with Paddle; Romory never receives or stores them.
- Guests: guide and stay-guide opens; selected preferences, moods, categories and cuisines; places shown and opened; server-stored favourites; feedback; optional notes; outbound directions, website and booking-service clicks.
- In identified flows, name, email, phone, party size, room number and stay dates may be supplied by the provider or guest. Scanning a QR code alone does not disclose identity or booking details.
- Technical data: random device and session identifiers, coarse device type, action timestamps, security and operational logs, and IP address in service logs.
- An outbound click does not prove a booking, physical visit or revenue.
D. Purposes and legal bases
Required fields are necessary for the relevant account, security, response or service action. Without them, Romory may be unable to provide that action. Optional fields are identified as such.
Acceptance of this notice is not used as blanket consent.
| Purpose | Legal basis and detail |
|---|---|
| Host account and access | Contract performance or pre-contractual steps. |
| Subscription and billing | Contract performance and legal invoicing/accounting obligations. Payment, invoicing and tax are handled by Paddle as Merchant of Record. |
| Guest guide and reporting | The legal basis chosen by the accommodation provider; Romory acts on its instructions. |
| Security | Legitimate interests in proportionate protection of accounts, data and service availability. |
| Support and enquiries | Pre-contractual steps, contract performance or legitimate interests, depending on the request. |
| Marketing | Consent where required, or legitimate interests only where permitted. Marketing choice remains separate from contract acceptance. |
| Optional tracking | Prior consent where required. No optional tracking is used today. |
E. Personalisation and analytics
Romory ranks host-approved places using choices expressed by the guest, such as activity, mood, company, setting, cuisine or need, then may use saved or rated places to order relevant results. These choices are not described as medical, psychological or sensitive profiling.
Provider reporting includes guide and stay opens, selected preferences, places shown and opened, saves, feedback, directions and outbound clicks. Reporting is scoped to the relevant property; identified internal previews are excluded.
Random identifiers are pseudonymous, not necessarily anonymous. Email-identified guest accounts can technically link use across properties, so Romory does not promise a general absence of cross-property linkage.
F. Recipients and external services
Data is accessible, according to role, to authorised staff of the relevant provider, the Romory operator and necessary service providers. Published guides and shared links can be opened by anyone with the link and must not contain private guest data or access secrets.
| Service | Role and data |
|---|---|
| Lovable Cloud | Application, database, storage, authentication and managed email hosting; receives necessary account data, content, files, enquiries and logs. |
| Google Maps Platform | Address and place search, coordinates, public place details, reviews and photos. Host requests use Lovable’s connector service; browser-loaded maps and fonts may receive IP and browser information. |
| Lovable AI Gateway and model providers | Drafting from public place information, translations and some host-facing metric summaries. Current functions call OpenAI or Google models. No retention or training promise is made without verified contractual documentation. |
| Paddle (Merchant of Record) | Official reseller of Romory subscriptions: sales, subscription management, payments, tax compliance and invoicing. Receives the customer’s email, payment and billing data and acts as controller for these operations (see paddle.com/legal/privacy). |
| Professional advisers and authorities | Legal and accounting advisers where needed; public authorities where required by law. |
| External sites | Venue websites, directions and booking services apply their own privacy notices once opened. |
G. Hosting and international transfers
The application and its database are hosted by Lovable Cloud in the European Union (Ireland).
Some providers (including Google, OpenAI and Paddle) may process data outside the European Economic Area, notably in the United States or the United Kingdom. These transfers rely on a European Commission adequacy decision (including the EU–US Data Privacy Framework) or, failing that, the European Commission’s standard contractual clauses.
H. Retention
Data is kept only as long as needed for the purposes described, then deleted or anonymised. Maximum periods are as follows.
| Category | Retention period |
|---|---|
| Host accounts and guide content | For the life of the account. On account deletion, account data is deleted; shared content needed by other members of a property may be kept and detached from the account. |
| Guest interactions and preferences | Up to 24 months after the departure date or, if none, after creation. |
| Guide favourites | Free-text notes: 90 days. Other favourites: same period as guest interactions. |
| Personal carnet | Until the guest deletes the account, and at most 3 years after last activity. |
| Support and commercial enquiries | 3 years after the last exchange. |
| Security logs | Up to 12 months. |
| Invoices | Invoices are issued and kept by Paddle for the applicable legal periods. Romory keeps subscription information for the life of the subscription and then for applicable limitation periods. |
| Backups | Deleted data leaves technical backups as they rotate. |
I. Cookies and browser storage
The site uses a one-year romory_locale_v2 language cookie and a seven-day host-sidebar cookie. The guest guide stores the chosen language, one random device identifier per property, whether a UI hint was seen and, where relevant, a personalised-link token. Session identifiers, temporary choices and event de-duplication markers remain for the tab session.
These items support operation, continuity and the internal measurement described above. Romory uses no advertising cookies or third-party audience-measurement tools.
As these items are strictly necessary, they do not require consent. Should optional trackers ever be added, your consent would be requested first.
J. Rights and complaints
Depending on the circumstances, you may request access, rectification, erasure, restriction and portability, object to legitimate-interest processing, and withdraw consent without retrospective effect.
For guide data, contact the relevant accommodation provider first. You may also email hello@romory.ai for assistance or forwarding. Responses are normally provided within one month, subject to lawful extensions.
You may complain to the CNIL or another competent supervisory authority where relevant.
K. Updates
Material changes will be communicated appropriately, including in-app or by email where they affect an account. The revision date appears at the top of this page.