RoomForge
RoomForge

Legal

Privacy Policy

Last updated: 1 April 2026 · Effective date: 1 April 2026

Your privacy matters to us. This Privacy Policy explains what information we collect, how we use it, and what choices you have. RoomForge is committed to handling your data responsibly and transparently.

1. Overview

This Privacy Policy applies to RoomForge ("we", "our", "us") and describes how we collect, use, store, and disclose personal information when you access or use the RoomForge property management platform available at roomforge.org (the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

We collect the following categories of information:

Account Information

Your name, email address, and password when you create an account. Organisation name and details you provide during setup.

Operational Data

Guest records, booking details, invoices, payment records, and property configuration data that you enter into the platform. This data belongs to you and is used solely to provide the Service.

Billing Information

Payment details are processed directly by Paystack and are not stored on our servers. We retain transaction references and billing history for accounting purposes.

Usage and Technical Data

Log data including IP address, browser type, device identifiers, pages visited, actions taken, and timestamps. This data is used for security monitoring, debugging, and improving the Service.

Communications

Any correspondence you send us via email or support channels, including feedback, support requests, and feature suggestions.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process and fulfil subscription billing
  • Send transactional emails (account creation, subscription receipts, trial expiry reminders)
  • Respond to support requests and resolve technical issues
  • Monitor platform performance and security
  • Improve and develop the Service based on aggregated usage patterns
  • Comply with legal obligations

We do not sell your personal information, and we do not use your operational data (guest records, bookings, etc.) for any purpose other than providing the Service to you.

4. Sharing of Information

We do not sell or rent your personal information to third parties. We may share information only in the following circumstances:

  • Service Providers: Trusted third-party providers who assist us in operating the platform (cloud hosting, payment processing, email delivery). These providers are contractually bound to process data only as instructed by us.
  • Legal Requirements: When required by applicable law, court order, or government authority.
  • Business Transfer: In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction. You will be notified before your data is transferred and becomes subject to a different privacy policy.
  • With Your Consent: In any other circumstance, with your explicit prior consent.

5. Data Storage and Security

Your data is stored on Supabase, which runs on Amazon Web Services (AWS) infrastructure. All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.2 or higher.

We implement Row Level Security (RLS) at the database layer, ensuring that your organisation's data is completely isolated from all other tenants on the platform. No other organisation can access your data.

While we take all reasonable technical and organisational measures to protect your data, no system is completely immune to security risks. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.

6. Data Retention

We retain your account and operational data for as long as your account is active or as needed to provide the Service.

Upon account cancellation or termination, your data is retained in a read-only state for 30 days. After this period, all data associated with your account is permanently and irreversibly deleted from our systems. If you require a data export before deletion, please contact us at support@roomforge.org before the 30-day window closes.

7. Cookies and Tracking

We use essential cookies and browser storage to maintain your authentication session and remember your preferences. These are strictly necessary for the Service to function and cannot be disabled.

We do not use third-party advertising cookies or tracking pixels. We do not engage in cross-site tracking or behavioural advertising.

8. Third-Party Services

The Service integrates with the following third-party services that have their own privacy policies:

  • Supabase — Database and authentication infrastructure. Supabase Privacy Policy: supabase.com/privacy
  • Paystack — Payment processing for subscription billing. Paystack Privacy Policy: paystack.com/privacy

We are not responsible for the privacy practices of these third-party services. We encourage you to review their privacy policies.

9. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data, subject to any legal obligations we have to retain it.
  • Portability: Request your data in a structured, machine-readable format.
  • Objection: Object to the processing of your data for certain purposes.
  • Withdrawal of Consent: Where processing is based on consent, withdraw that consent at any time.

To exercise any of these rights, contact us at privacy@roomforge.org. We will respond within 30 days.

10. Children's Privacy

The Service is intended for use by adults operating accommodation businesses. We do not knowingly collect personal information from individuals under the age of 18. If you believe a minor has provided us with personal information, please contact us at privacy@roomforge.org and we will take steps to delete it.

11. International Transfers

Your data may be stored and processed in servers located outside your country of residence (including the United States, where AWS infrastructure operates). By using the Service, you consent to the transfer of your data to these locations. We ensure that any such transfers are subject to appropriate safeguards consistent with applicable data protection laws.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and by posting a notice on the platform. The updated policy will be effective on the date stated at the top of this page. Your continued use of the Service after that date constitutes your acceptance of the updated policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us:

RoomForge — Privacy Team

Email: privacy@roomforge.org

Support: support@roomforge.org

Website: roomforge.org