This policy describes how Roamaya stores, processes, and retains your personal and transactional data. It supplements our Privacy Policy with specific details about data storage practices.
1. Data Storage Infrastructure
1.1 Primary Data Storage
- Application Database: Hosted on secure cloud infrastructure within India, storing user accounts, bookings, transactions, messages, and trip data.
- Encryption at Rest: All database storage is encrypted using AES-256 encryption.
- Encryption in Transit: All data transmission uses TLS 1.2+ encryption.
- Backups: Automated daily backups with point-in-time recovery capability, retained for 30 days.
1.2 Media Storage
- Images & Documents: Stored on Cloudinary (cloud-based media management) with data centers that may be located outside India.
- KYC Documents: Aadhaar images, PAN images, and selfie photos are stored in access-restricted Cloudinary folders with no public URLs.
- Trip Images: Gallery photos and cover images uploaded by Hosts are publicly accessible via CDN.
1.3 Authentication Data
- Passwords: Stored as salted cryptographic hashes (never in plaintext).
- JWT Tokens: Short-lived, stored in httpOnly Secure cookies. Not persisted server-side (stateless tokens).
- OAuth Tokens: Google OAuth credentials are exchanged but not stored long-term.
2. Categories of Data Stored
| Data Category | Examples | Storage Location |
|---|---|---|
| Account Data | Name, email, phone, role, avatar | Primary Database (India) |
| KYC Data | Aadhaar, PAN, verification documents | Database + Cloudinary (restricted) |
| Financial Data | Bank accounts, transaction records, payout history | Primary Database (India) |
| Booking Data | Reservations, payments, cancellations | Primary Database (India) |
| Communication Data | Messages, support tickets | Primary Database (India) |
| Media Files | Trip images, profile photos, KYC documents | Cloudinary CDN |
| Analytics Data | Page views, events, session data | Google Analytics (Google servers) |
| Application Logs | Error logs, access logs, audit trails | Cloud logging service |
3. Data Retention Periods
| Data Type | Retention Period | Basis |
|---|---|---|
| Active user account data | Until account deletion | Service delivery |
| Inactive account data | 2 years after last login, then deletion prompt sent | Legitimate interest |
| Booking & transaction records | 8 years from transaction date | Income Tax Act (India), GST compliance |
| Payment records & invoices | 8 years from transaction date | Tax and audit requirements |
| KYC documents (active Hosts) | Duration of active account + 5 years | PMLA, KYC norms |
| KYC documents (rejected/deactivated) | 1 year after rejection/deactivation | Dispute resolution |
| Messages (in-platform) | 3 years after last message in conversation | Dispute resolution |
| Support tickets | 3 years after resolution | Service quality, legal defense |
| Reviews & ratings | Until account deletion or content removal request | Community trust, public interest |
| Server/application logs | 90 days (rolling) | Security monitoring |
| Analytics data | 26 months (aggregated/anonymized thereafter) | Google Analytics default |
| Cookie consent records | 3 years from consent date | Compliance evidence |
4. Data Minimization
- We collect only the minimum data necessary for each function.
- Aadhaar numbers are masked in admin interfaces (only last 4 digits visible).
- Bank account numbers are partially masked in user interfaces.
- Expired JWT tokens are not stored — they simply become invalid.
- Contact information in messages is masked to prevent off-platform transactions.
5. Data Deletion
5.1 Account Deletion
- You may request account deletion at any time by contacting roamayaofficial@gmail.com.
- Account deletion is processed within 30 days of verification.
- Deletion is blocked while there are active bookings or pending payouts.
- Upon deletion: profile data, preferences, and messages are permanently removed.
- Retained post-deletion (legal requirement): Transaction records, tax documents, and anonymized booking history.
5.2 Automated Deletion
- Server logs are automatically purged after 90 days.
- Failed payment attempt records are cleared after 30 days if no successful transaction followed.
- Abandoned (incomplete) registrations are deleted after 7 days.
6. Data Access Controls
- Role-Based Access: Only authorized personnel with specific roles can access user data.
- Admin Access: Admin team members have access to KYC data and transaction records for verification and support purposes.
- Audit Logging: All admin data access is logged with timestamps and user identifiers.
- Principle of Least Privilege: Access is granted only to the minimum data needed for each role.
7. Third-Party Data Processors
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Razorpay | Payment processing | Transaction amounts, order IDs | India |
| Cloudinary | Image/document storage | Uploaded files | Global CDN (primary in US) |
| Google (Analytics) | Usage analytics | Anonymized page views, events | Global (Google Cloud) |
| Google (OAuth) | Authentication | Email, name (at login only) | Global (Google Cloud) |
8. Data Breach Response
- We maintain an incident response plan for data breaches.
- In the event of a breach affecting personal data, affected users will be notified within 72 hours of discovery.
- Notification will include: nature of the breach, data affected, remedial actions taken, and recommended user actions.
- The Data Protection Board of India will be notified as required under the DPDP Act.
9. Your Data Rights
You have the right to:
- Request a summary of all personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion (subject to legal retention requirements).
- Obtain a portable copy of your data in a machine-readable format.
- Withdraw consent for optional data processing.
To exercise any of these rights, email roamayaofficial@gmail.com with your registered email and a description of your request. We will respond within 30 days.