Privacy Policy

Last updated: 9/9/2026

Notice: This is template text. Review with legal counsel before launch.

1. Overview

RoomBase (“we”, “us”) operates a room booking and workspace management platform. This Privacy Policy describes how we collect, use, and protect your personal data when you use our Service.

2. Data We Collect

2.1 Account Data

We collect your name, email address, and profile image through our authentication provider, WorkOS AuthKit. We also store organization membership information.

2.2 Booking Data

We store booking details you create, including room selections, time slots, titles, descriptions, and guest email addresses for invitations.

2.3 Billing Data

Payment processing is handled by Stripe. We store subscription plan information, billing status, and tenant company counts, but do not store credit card numbers.

2.4 Usage Data

We log audit entries for actions taken within hubs (e.g., booking approvals, member invitations, settings changes) for administrative purposes.

3. How We Use Your Data

  • To provide and maintain the Service
  • To manage bookings, approvals, and notifications
  • To process payments and manage subscriptions
  • To send transactional emails (invitations, booking confirmations)
  • To provide audit logs for hub administrators
  • To comply with legal obligations

4. Data Storage

Your data is stored in our backend infrastructure (Convex) hosted in the EU region. Authentication data is managed by WorkOS. Payment data is managed by Stripe. Transactional emails are sent via Resend.

5. Data Sharing

We do not sell your data. We share data only with our service providers (WorkOS, Stripe, Resend) as necessary to operate the Service, and as required by law. Hub administrators can see booking data and audit logs within their hub.

6. Your Rights (GDPR)

Under the GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data (“right to be forgotten”)
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing of your data
  • Withdrawal of consent: Withdraw consent at any time

To exercise these rights, contact us at privacy@roombase.app. Hub administrators can export hub data from the settings page.

7. Cookies

We use essential cookies for authentication and session management via WorkOS AuthKit. We do not use tracking or advertising cookies.

8. Data Retention

We retain your data for as long as your account is active. Upon account deletion, we remove your personal data within 30 days. Booking and audit data may be retained for longer if required by law or legitimate business interests.

9. Security

We use industry-standard security measures including encrypted data transmission (TLS), secure authentication (WorkOS AuthKit), and isolated backend infrastructure (Convex). However, no method of transmission over the Internet is 100% secure.

10. International Transfers

Your data may be processed by our service providers (WorkOS, Stripe, Resend) which may be located outside the EU/EEA. We rely on Standard Contractual Clauses (SCCs) for such transfers where applicable.

11. Children’s Privacy

The Service is not intended for individuals under 16 years of age. We do not knowingly collect data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes via email or in-app notification.

13. Contact

For privacy questions or data requests, contact us at privacy@roombase.app.