Privacy Policy

Last updated: September 15, 2026

Notice: This is template text. Review with legal counsel before launch.

1. Overview

RoomBase (“we”, “us”) operates a room booking and workspace management platform. This Privacy Policy describes how we collect, use, and protect your personal data when you use our Service.

2. Data We Collect

2.1 Account Data

We collect your name, email address, and profile image through our authentication provider, WorkOS AuthKit. We also store organization membership information.

2.2 Booking Data

We store booking details you create, including room selections, time slots, titles, descriptions, and guest email addresses for invitations.

2.3 Billing Data

Payment processing is handled by Stripe. We store subscription plan information, billing status, and tenant company counts, but do not store credit card numbers.

2.4 Usage Data

We log audit entries for actions taken within hubs (e.g., booking approvals, member invitations, settings changes) for administrative purposes.

2.5 Optional Product Insights

If this optional feature is available and you agree, RoomBase uses PostHog Cloud EU to understand feature use, navigation, booking steps and recurring use of the app. Collection is off until you consent. Declining does not restrict your use of RoomBase. You can change your choice under Product insights in your account menu.

Events contain an opaque identifier, event time, predefined feature and screen categories, language and a mobile/desktop category. This is pseudonymous personal data, not anonymous data. We do not send names, email addresses, booking text, room or hub names, full URLs, search text or your browser IP address to PostHog. There is no advertising tracking or automatic capture of page content. Our server forwards the approved events to the EU service.

2.6 Optional Website Analytics and Session Replay

If you accept in the consent banner, your browser loads the PostHog analytics SDK and sends page views, clicks on buttons and links, and technical error reports directly to PostHog Cloud EU (Frankfurt). Session replays may be recorded with all form inputs masked. A PostHog identifier is stored in a cookie and local storage only after you accept; before consent the SDK stays in memory-only mode and sends nothing. IP-based geolocation is disabled. If you are signed in, this identifier is linked to your account id so we can connect usage to your workspace.

Declining keeps this collection off and does not restrict your use of RoomBase. You can change your choice at any time via Cookie settings in the footer of our legal pages or under Privacy settings in your account menu. Requesting deletion of your analytics data also covers session replays and identified events from this SDK.

3. How We Use Your Data

  • To provide and maintain the Service
  • To manage bookings, approvals, and notifications
  • To process payments and manage subscriptions
  • To send transactional emails (invitations, booking confirmations)
  • To provide audit logs for hub administrators
  • With your consent, to improve features and understand aggregate usage patterns
  • To comply with legal obligations

4. Data Storage

Your data is stored in our backend infrastructure (Convex) hosted in the EU region. Authentication data is managed by WorkOS. Payment data is managed by Stripe. Transactional emails are sent via Resend. Optional Product Insights events are sent to PostHog Cloud EU.

5. Data Sharing

We do not sell your data. We share data only with our service providers (WorkOS, Stripe, Resend, Convex and, for optional Product Insights, PostHog) as necessary to operate the Service, and as required by law. Hub administrators can see booking data and audit logs within their hub.

6. Your Privacy Rights

Depending on the law that applies to you, including the EU GDPR, Swiss Federal Act on Data Protection and other applicable privacy laws, your rights may include:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data (“right to be forgotten”)
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing of your data
  • Withdrawal of consent: Withdraw consent at any time

To exercise these rights, contact us at privacy@roombase.app. Hub administrators can export hub data from the settings page. In Product insights in your account menu, you can withdraw consent, export your analytics events and request their deletion. Withdrawal stops new collection and requests deletion of earlier analytics events. The separate deletion control also lets you repeat a deletion request. Deletion runs asynchronously: a submitted status means the provider accepted the request, not that physical deletion is complete. Deletion requests cover both the pseudonymous product-insights events and the browser SDK data described in section 2.6. The website analytics choice can be withdrawn at any time via Cookie settings in the footer of our legal pages or under Privacy settings in your account menu. These controls apply to analytics; other account data requests can be sent to the contact above.

7. Cookies

We use essential cookies for authentication and session management via WorkOS AuthKit. Product Insights does not add analytics cookies or browser analytics identifiers. We store your consent choice on your account and may save a local refusal preference in your browser so collection stays off even if saving the choice fails. Recognized Global Privacy Control signals also disable this optional collection.

The optional website analytics SDK adds a PostHog identifier cookie and a local-storage entry only after you accept in the consent banner; your banner choice itself is stored locally as posthog_consent. Declining keeps these analytics cookies off.

8. Data Retention

We retain your data for as long as your account is active. Upon account deletion, we remove your personal data within 30 days. Booking and audit data may be retained for longer if required by law or legitimate business interests.

Optional Product Insights is designed for a 90-day event retention period and remains disabled until that retention policy has been separately configured and verified with the provider. Consent and deletion request records are held separately to apply your choice and handle your requests.

9. Security

We use industry-standard security measures including encrypted data transmission (TLS), secure authentication (WorkOS AuthKit), and isolated backend infrastructure (Convex). However, no method of transmission over the Internet is 100% secure.

10. International Transfers

Your data may be processed by our service providers (WorkOS, Stripe, Resend and PostHog) which may be located outside the EU/EEA. We rely on Standard Contractual Clauses (SCCs) for such transfers where applicable. EU hosting of analytics does not by itself exclude international access or onward processing by subprocessors.

11. Children’s Privacy

The Service is not intended for individuals under 16 years of age. We do not knowingly collect data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes via email or in-app notification.

13. Contact

For privacy questions or data requests, contact us at privacy@roombase.app.