Privacy policy
Last updated : 8 October 2026
Operator
[to be completed : name or company]
[to be completed : postal address]
[to be completed : email]
This policy explains what data Room processes, why, and for how long. It follows the Swiss Federal Act on Data Protection (FADP) and, for people in the European Union, the GDPR.
1. Controller
The controller is the operator shown at the top of this page. Contact: [to be completed : email].
2. Data we process
- Account: email, username, password (stored only as a one-way hash, unreadable even to us), language, creation date.
- Your room: the objects, texts, links and photos you publish. Photos are resized and their metadata (including GPS location) is removed on upload.
- Subscription: Stripe customer id, subscription status and dates. Card data is processed by Stripe only.
- Visit statistics: views and clicks per day. To count unique visitors we compute a one-way fingerprint (IP address + browser + day + secret), kept for 2 days and then erased. We do not store IP addresses.
- Security: temporary per-IP counters limit abuse (login, signup, uploads). They are erased after 24 hours.
3. Cookies
Room uses no ads and no trackers. Only two cookies: a session cookie, needed to stay logged in, and a cookie that remembers your language.
If a room contains a Spotify, SoundCloud or YouTube player, it only loads when you open the music panel. These services may then set their own cookies under their own policies. YouTube is embedded in “no-cookie” mode.
4. Purposes and legal bases
- Providing the service and showing rooms: performance of the contract.
- Billing Room+: performance of the contract and accounting obligations.
- Security and abuse prevention: legitimate interest.
- Aggregated visit statistics: legitimate interest (no profiles, no data sold).
5. Hosting and recipients
The site and its data are hosted on a server run by the operator, in Switzerland. We never sell or rent any data.
The only recipients are Stripe (payments; Stripe Payments Europe, Ireland, and its sub-processors, with contractual safeguards for transfers outside Switzerland and the EU) and the embedded player providers listed in section 3, only when a visitor opens them.
6. Retention
- Account and room: until the account is deleted. Backups are then overwritten within 14 days at most.
- Photos removed from a room: deleted automatically.
- Billing: invoices and payments are kept by Stripe under its legal obligations. On our side, the subscription status is kept until the account is deleted.
- Visit fingerprints: 2 days. Abuse-prevention counters: 24 hours.
7. Your rights
You can access, correct and export your data, object to processing, or ask for deletion. Your username, room and password can be changed directly in the editor and on the Account page, and deleting your account erases everything. For anything else: [to be completed : email]. We answer within 30 days.
You can also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, in the EU, with the supervisory authority of your country.
8. Security
Connections are encrypted (HTTPS) and passwords are hashed with argon2. Server access is restricted and data is backed up regularly.