Privacy Policy
Effective Date: June 25, 2026
Roemance™ (“Roemance,” “we,” “us,” or “our”) operates the Roemance progressive web application located at roemance.app(the “App”). This Privacy Policy describes what information we collect, why we collect it, how we use and protect it, and your rights regarding that information.
By accessing or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please do not use the App.
1. Information We Collect
1.1 Information You Provide
Email address. If you choose to create an account or link a backup account, we collect the email address you provide. This is used solely for authentication via magic link (passwordless login).
Tasting log entries. When you log an oyster tasting, we store the oyster name/identifier, date, and any optional notes you choose to add. This data is associated with your account.
1.2 Information Collected Automatically
Session data. When you authenticate, we create a session and may record your IP address, user agent string, and the timestamp of the session. This information is used exclusively for security purposes (detecting unauthorized access and enforcing rate limits).
Local storage data. The App stores tasting log data in your browser’s local storage. This data resides entirely on your device and is not transmitted to our servers unless you explicitly create an account and migrate your data.
1.3 Information We Do Not Collect
We do not collect, purchase, or otherwise obtain: payment or financial information, precise geolocation data, biometric data, social media account information, data from third-party data brokers, or any sensitive personal data as defined under GDPR Article 9.
2. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we process your personal data on the following legal bases:
| Data | Lawful Basis | Reason |
|---|---|---|
| Email address | Contract (Art. 6(1)(b)) | Necessary to provide the authentication service you requested |
| Tasting log entries | Contract (Art. 6(1)(b)) | Necessary to provide the tasting log service you chose to use |
| Session data (IP, user agent) | Legitimate Interest (Art. 6(1)(f)) | Necessary for security: detecting unauthorized access and preventing abuse |
3. How We Use Your Information
We use the information we collect exclusively for the following purposes:
- To authenticate you and maintain your session
- To store and display your tasting log entries back to you
- To send you transactional emails (magic link login emails only)
- To detect and prevent unauthorized access, fraud, and abuse
- To comply with applicable legal obligations
We do not use your data for advertising, profiling, automated decision-making, marketing communications, or any purpose other than those listed above. We do not sell, rent, lease, or trade your personal information to any third party for any reason.
4. Data Retention
| Data | Retention Period |
|---|---|
| Email address & tasting logs | As long as your account is active, plus 30 days after a deletion request (to allow recovery from accidental deletion) |
| Session data (IP, user agent) | 30 days after session expiration |
| Magic link tokens | Deleted immediately upon use or expiration (whichever occurs first) |
After the applicable retention period, data is permanently and irreversibly deleted from our systems.
5. Who Has Access to Your Data
Access to your personal data is strictly limited to:
- Roemance™ — the sole operator of the App
- Vercel Inc. — our hosting and serverless infrastructure provider (Vercel Privacy Policy)
- Turso (ChiselStrike, Inc.) — our database provider (Turso Privacy Policy)
- Resend Inc. — our transactional email service provider, used exclusively to deliver magic link login emails (Resend Privacy Policy)
No other person, company, or entity has access to your data. We do not share, sell, rent, or disclose personal information to any other third party unless required by law, court order, or valid governmental request.
Note on Google Fonts: The App loads typefaces from Google’s servers (fonts.googleapis.com). When your browser requests these fonts, Google receives your IP address directly. This is not a data transfer initiated by Roemance, but we disclose it here for transparency. Google’s handling of this data is governed by Google’s Privacy Policy.
6. International Data Transfers
Our servers and service providers are located in the United States. If you access the App from outside the United States, including from the European Economic Area, United Kingdom, or Switzerland, your personal data will be transferred to and processed in the United States.
Our service providers participate in and/or comply with frameworks designed to ensure an adequate level of data protection for international transfers. By using the App, you acknowledge and consent to the transfer and processing of your data in the United States, subject to the protections described in this Privacy Policy.
7. Cookies & Similar Technologies
7.1 Session Cookie
When you log in, we set a single, strictly necessary session cookie. This cookie is HttpOnly (inaccessible to JavaScript), Secure (transmitted only over HTTPS), and SameSite=Strict (not sent with cross-site requests). It contains only a session identifier and is used solely to keep you authenticated. Under GDPR, strictly necessary cookies do not require consent, but we disclose them here for transparency.
7.2 Google Fonts
The App loads typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). When your browser requests these fonts, Google may receive your IP address and set cookies. Google’s use of this data is governed by Google’s Privacy Policy. We do not control and are not responsible for Google’s data practices.
7.3 No Tracking or Advertising Cookies
We do not use advertising cookies, tracking pixels, social media widgets, or any third-party analytics that set cookies. We do not engage in cross-site tracking or behavioral advertising of any kind.
7.4 Affiliate Links
Some outbound links to caviar and wine retailers are affiliate links. If you make a purchase through them, we may earn a commission at no additional cost to you. The App itself sets no cookies for this; after you click through, the retailer’s site operates under its own privacy policy and may set its own cookies. We do not choose our recommendations based on commissions — the same links appear whether or not a program exists for that merchant.
8. Data Security
We implement and maintain reasonable technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS/HTTPS for all communications)
- Encryption at rest (database-level encryption)
- Cryptographically hashed authentication tokens (SHA-256)
- HttpOnly, Secure, SameSite=Strict session cookies
- Per-email and per-IP rate limiting on authentication endpoints
- Strict access controls limiting data access to authorized personnel
No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your personal data, we cannot guarantee its absolute security.
9. Your Rights Under GDPR
If you are located in the EEA, UK, or Switzerland, you have the following rights under the General Data Protection Regulation:
- Right of access (Art. 15) — You may request a copy of all personal data we hold about you.
- Right to rectification (Art. 16) — You may request correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17) — You may request deletion of your account and all associated personal data (“right to be forgotten”).
- Right to restrict processing (Art. 18) — You may request that we stop processing your data while keeping it stored.
- Right to data portability (Art. 20) — You may request your data in a structured, commonly used, machine-readable format (JSON).
- Right to object (Art. 21) — You may object to processing of your data based on legitimate interest.
To exercise any of these rights, contact us at support@roemance.app. We will respond within 30 days. If we need more time (up to an additional 60 days for complex requests), we will inform you of the reason for the delay.
You also have the right to lodge a complaint with a data protection supervisory authority in your jurisdiction.
10. Your Rights Under the California Consumer Privacy Act (CCPA)
If you are a California resident, the CCPA grants you the following rights:
- Right to know — You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.
- Right to delete — You may request deletion of your personal information, subject to certain exceptions.
- Right to opt out of the sale of personal information — We do not sell your personal information. We have never sold personal information and have no plans to do so.
- Right to non-discrimination — We will not discriminate against you for exercising any of your CCPA rights. You will not receive different pricing, quality, or service levels for exercising your rights.
To exercise your CCPA rights, contact us at support@roemance.app.
11. Do Not Sell My Personal Information
Roemance does not sell, has never sold, and will never sell your personal information to any third party, as defined under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). This applies to all users, not only California residents.
12. Deleting Your Data
You may delete your data at any time using any of the following methods:
- Local data (localStorage): Clear your browser’s site data for roemance.app, or use the “Delete all my data” option within the App if available.
- Server-side account and data: Use the “Delete my account” feature within the App, or send a request to support@roemance.app.
Upon receiving a deletion request, we will permanently delete all personal data associated with your account — including your email address, tasting log entries, and session data — within 30 days. We retain data for 30 days after a deletion request solely to allow recovery in case the deletion was accidental. After 30 days, deletion is irreversible.
13. Data Export & Portability
You may request a complete copy of your data at any time. Exports are provided in JSON format (a structured, machine-readable format as required by GDPR Article 20). Your export will include: your email address, all tasting log entries with all fields, and your account creation date.
To request an export, use the “Download my data” feature within the App, or contact us at support@roemance.app.
14. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users without undue delay and no later than 72 hours after becoming aware of the breach, as required by GDPR Article 33. Notification will be sent to the email address associated with your account and will include: a description of the nature of the breach, the categories of data affected, the likely consequences, and the measures taken or proposed to address the breach.
Where required by applicable law, we will also notify the relevant data protection supervisory authority.
15. Children’s Privacy
The App is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16, we will take immediate steps to delete that data. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@roemance.app.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date at the top of this page and, where practical, notify you via the App or by email. Your continued use of the App after any changes constitutes acceptance of the updated Privacy Policy. We encourage you to review this page periodically.
17. Contact Us
If you have any questions about this Privacy Policy or your data, contact us at:
Roemance
Email: support@roemance.app
