Privacy Policy
Roameo Resort is dedicated to upholding your privacy and complying with applicable data protection regulations, including the General Data Protection Regulation (GDPR), where applicable. This Privacy Policy outlines how we collect, use, store, and protect your personal information when you engage with our services or visit our website.
Who We Are
We are Roameo Resort, a hospitality provider committed to offering a safe and comfortable experience to our guests. This Privacy Policy applies to our website and any services we provide, including marketing platforms and third-party tools we use to enhance guest experience and communication.
Personal Information We Collect
When you contact us, make a reservation, or use our services, we may collect:
- Full name
- Email address
- Address
- Contact number
We may also collect certain information automatically when you visit our website, including:
- Browser type and device information
- IP address and approximate location
- Pages visited and interaction behavior
- Referral source (e.g., a link from another website or social media)
How We Use Your Information
We may use your information for purposes such as:
- Process and manage reservations
- Communicate booking confirmations or updates
- Coordinate special requests or services
- Personalize your experience based on preferences
- Respond to inquiries or customer service requests
- Analyze site traffic and improve website functionality
Third-Party Tools and Analytics
To improve our website and marketing performance, we use third-party services such as:
- Google Analytics and Google Ads – to track engagement and display relevant content or ads.
- TikTok Pixel and API tools – to understand visitor interactions from TikTok and monitor advertising performance.
If you interact with Roameo Resort via TikTok (e.g., through an ad or account connection), we may receive limited public information such as your TikTok display name or engagement metrics. This data is used only for internal dashboard reporting and performance insights, and is not sold, displayed publicly, or shared with third parties.
You can revoke Roameo Resort’s access to your TikTok data at any time through your TikTok account settings.
You can manage your ad preferences via:
- Google Ad Settings
- TikTok Ad Preferences
Meta Platform Permissions We Request and How We Use Them
When you connect our Facebook Page or Instagram account to our services, we may request specific permissions from Meta (Facebook & Instagram). We request only the minimum access necessary to operate automatic replies and message delivery diagnostics. We do not sell, rent, or share Platform Data, and we do not use it for unrelated advertising.
Facebook Page permissions
- pages_messaging (Approved)
What we access: Message content and message metadata for conversations that a person initiates with our Page.
Why: To send automated replies and follow-ups that the person requested by messaging the Page.
Retention: Message payloads are processed in memory for reply generation and logged in server logs for troubleshooting for up to 30 days, then deleted.
- pages_show_list
What we access: The list (ID & name) of Facebook Pages you manage.
Why: To let an admin choose which Page to connect to our webhook for automated messaging. No posts, comments, or audience data is read.
- pages_manage_metadata
What we access: Page webhook subscriptions and related settings.
Why: To create, verify, and maintain the webhook subscription (e.g., messages, message_reads, message_deliveries) so our server can receive those events in real time. We do not post content or change Page settings beyond managing the subscription.
- pages_read_engagement
What we access: Delivery/read status and limited engagement signals related to messages we send (e.g., message_reads, message_deliveries).
Why: To monitor delivery health, detect failures, and improve the reliability of messaging. We do not build profiles from this data.
Instagram permissions
- instagram_basic
What we access: Basic account information (e.g., IG user ID, username, profile picture, account type) for the business account connected to our Page.
Why: To verify ownership and link the correct Instagram account to our messaging service.
- instagram_manage_messages
What we access: Instagram Direct messages and related metadata only for conversations that a person initiates with our IG business account.
Why: To send automated replies and follow-ups requested by the person who messaged us.
Retention: Same as Facebook messaging—processed for replies, with server logs retained up to 30 days for troubleshooting, then deleted.
What we do not do with Platform Data
- We do not read or store historical inboxes beyond conversations relevant to current support or automation.
- We do not use Platform Data to create audience profiles or for unrelated advertising.
- We do not sell Platform Data to third parties.
Your choices & how to revoke access
You can revoke our app’s access at any time:
- Facebook: Settings & Privacy → Settings → Business Integrations → remove our app.
- Instagram (Professional): Meta Accounts Center → Your information and permissions → Apps and services → remove access.
Messages previously sent to your Page/IG account remain in Facebook/Instagram per their own policies.
Lawful basis & retention
We process Platform Data under legitimate interests to provide reliable customer messaging and under contractual necessity to deliver requested services (automatic replies). Logs are retained up to 30 days for diagnostics and compliance, then deleted. You may request access or deletion by emailing marketing@roameoresorts.com.
Legal Basis for Processing Your Information
We process your personal information based on:
- Contractual necessity to confirm and manage your reservation
- Legitimate interests to enhance services and secure operations
- Consent for optional marketing communications or analytics (which you may withdraw at any time)
Data Sharing
We do not sell your personal information. We may share data only:
- With internal team members managing your reservation
- With trusted service providers (e.g., analytics tools, cloud hosting)
- To comply with legal or regulatory obligations
All third-party tools we use are subject to strict data handling and confidentiality agreements.
Cookies and Website Tracking
Cookies help us understand how visitors use our site and enhance their browsing experience.
We use cookies for:
- Remembering user preferences
- Analyzing website traffic
- Measuring ad performance
You can control cookies via your browser settings. Some services may not function properly if cookies are disabled.
International Data Transfers
If your data is processed using services hosted outside your region (e.g., in the United States), we ensure appropriate safeguards are in place such as Standard Contractual Clauses approved by relevant authorities.
Data Retention
We retain your personal information only for as long as needed to fulfill the purposes described in this policy or to comply with legal obligations. Analytical data is anonymized and retained for operational improvement.
Your Rights
Depending on your jurisdiction, you may have rights to:
- Access your personal data
- Request correction or deletion
- Object to certain processing
- Withdraw consent
- Request a copy of your data in a portable format
To exercise your rights, contact us at: marketing@roameoresorts.com
Data Security
We implement industry-standard measures to protect your data, including:
- Secure hosting environments
- HTTPS encryption
- Role-based access controls
We do not process any online payments through the website. All payments are handled manually via bank transfer or in-person arrangements.
Policy Updates
We may update this Privacy Policy periodically. Updates will be posted on this page with the revised date. We encourage you to check back occasionally.
Effective Date: July 24, 2025
Contact Us
If you have any questions or concerns about how your data is used, please reach out to:
marketing@roameoresorts.com