Data protection and UK GDPR
Roam Pal Guide · roampalguide.com · last reviewed 2 October 2026
This page is for organisations, and for anyone who wants the data flows in one place. It covers UK GDPR and the Data Protection Act 2018. The full notice for visitors is our privacy notice. Both pages describe the same data flows.
1. Who is responsible
Roam Pal Guide is provided by ADAI Digital Ltd (“we”, “us”), company number 17242851. Roam Pal began in the UK; the company's registered office is Suite A, 82 James Carter Road, Mildenhall, England, IP28 7DE. This is the statutory registered office, not a customer visiting address. We are the controller for the personal data described here. Our ICO registration number is ZC208103. Contact: admin@adaidigital.co.uk.
We have not appointed a data protection officer. Questions about privacy go to Allan Drummond, a director of ADAI Digital, at the email address above.
2. What stays on the device
Roam Pal saves what people make in their browser’s own storage, on their device. This covers current and past trips, wish lists, day plans, their own places (such as home or caravan storage), notes, photos, videos, voice notes, access needs, travel profiles, journey support plans, assistance requests, bookings and booking references. Saved memberships and discount cards stay on the device too, and Roam Pal never asks for card numbers, proof of eligibility or portal passwords.
We hold no copy. A person removes all of it by clearing the site’s data in their browser or uninstalling the app. A shared trip copy is encrypted on the device and carried in the link. It is not uploaded to us.
3. Every data flow off the device
Automatic, as the app is used
- Google Firebase Hosting serves the website. It receives the internet address (IP address), the page requested and browser details. Google is our processor. Firebase Hosting, the Google service that sits in front of our server, sees your internet address. It keeps internet addresses for a few months, as Firebase states. The log on our server itself shows Firebase Hosting’s address, not yours, for requests that come through it.
- ADAI Digital Hub, adaidigital.co.uk (our own service). When the app opens, and about every five minutes after, it reads video report counts. No cookies, no page address. Like any request, it passes through Firebase Hosting, which sees the internet address. Many of these requests may be answered by Google’s cache, so they never reach our Hub. The Hub does not save the internet address from this request.
- OpenFreeMap, delivered through Cloudflare. Map pictures. It receives the internet address and which part of the map is on screen.
- Wikimedia Commons. The place photos come from Wikimedia Commons under their open licences. They load from Wikimedia’s servers, which may set their own cookie (WMF-Uniq). Privacy notice: Wikimedia privacy policy.
- YouTube (Google). Video pictures. It receives the internet address and which picture.
Only when a person uses a feature
- Overpass API (overpass-api.de, FOSSGIS e.V.). The live accessible places layer. It receives the edges of the map area on screen.
- OSRM demo server (router.project-osrm.org, sponsored by FOSSGIS). Driving times and road routes. It receives the route points, which can include a saved start place such as home.
- postcodes.io. Postcode look-up when adding a place. It receives the postcode typed. We could not find a privacy notice for postcodes.io itself.
- Photon (photon.komoot.io, komoot). Placing a booking on the map. It receives the place name from the booking.
- Hugging Face and GitHub. The optional Roam Mate model download. They receive the internet address and which files. Questions stay on the device.
- The browser’s speech service. The Roam Mate microphone button. Some browsers send the sound to the browser maker.
- Booking links (Hotellook and Aviasales, through Travelpayouts). Only when followed. The link carries the place name (for hotels) and our partner code.
Sent only when a person chooses
- Video reports, to the Hub. See below.
- Access corrections, to the Hub: the place, right or wrong, the date, the note, the page address and title, and the app version. Marked “Anonymous traveller”, with no name or contact. We delete correction reports 6 months after they arrive.
- Venue corrections, on the Hub’s “Is this your venue?” page: venue name, the correction, an optional web link, and the sender’s name, role and email. We delete these 6 months after they arrive. That page has its own notice at adaidigital.co.uk/privacy.
- Emails, to hello@roampalguide.com (Roam Pal feedback and the email options) and admin@adaidigital.co.uk. Google Workspace and MXroute handle our email. Mail sent to hello@roampalguide.com is passed on to admin@adaidigital.co.uk. We delete emails we no longer need. We review them at least once a year.
- Anonymous service measurement, off by default, to the ADAI Digital aggregate measurement service on the Hub: one of two signals (a confirmed install, or one launch a day of the installed app). The Hub keeps daily totals only. Lawful basis: consent.
Video reports and report counts
- A report someone chooses to send. When a person presses “Report this video” and then Send, their ticks, any note, the video, the place, the page address (without anything after the #) and the app version go to the Hub at adaidigital.co.uk. The report form says: “We keep what you tick, any note you write and the page you were on. A scrambled code made from your connection lets us count each person once. We never store your address. We delete it after 90 days.” We also keep the time, the video and the place. Automatic deletion is now switched on, so we delete a video report 90 days after it arrives.
- Scrambled codes. The Hub makes keyed scrambled codes (HMAC) from the internet address and does not store the address. One code per person and video, for videos found automatically, so each person counts once: kept up to 30 days after their last report about that video, or sooner if we decide about the video. One code per connection and day, to limit reports to 20 a day: kept 2 days.
- A report about a video we cannot count. The Hub can count a report only when it has the video’s YouTube code and the place record. Videos on a creator’s profile have no place record, and some videos have no YouTube code. A report about one is not counted towards hiding. It goes to the same review service as ordinary feedback. A person reads this report. The report form says: “We keep what you tick, any note you write and the page you were on. We delete it after 6 months.” Automatic deletion is now switched on, so we delete this report 6 months after it arrives.
- Report counts. When the app opens, and about every five minutes after, it asks adaidigital.co.uk how many times each automatic video has been reported. The answer holds only counts per video. If the app cannot get a recent answer, it hides automatic videos. Videos checked by a person are never hidden this way.
- Totals per video (report numbers, reasons, first and last report time) hold nothing about the people who reported, and have no deletion date.
4. Where data is held, and transfers
The Hub runs on Google Cloud Run in London, in the europe-west2 region. It stores reports in Google’s Firestore database, which is in London too. Google’s data processing terms say that when Google sends information to a country the UK does not treat as adequate, it uses an approved safeguard that it tells us about, or standard contractual clauses. We have accepted Google’s data processing terms for this project. Firebase Hosting serves pages from a worldwide network. The outside services above act for themselves. Several are outside the UK, for example in the European Union and the United States. The visitor’s device contacts them directly, and we have no separate transfer safeguard with them.
5. Lawful basis and retention
Legitimate interests covers serving the website securely, showing maps and photos, keeping videos and access information accurate and safe, and replying to messages. Trip Check relies on taking the steps a person asks for before a contract, and carrying it out. Consent covers anonymous service measurement. Retention is listed in the privacy notice, section 10. Request logs: 30 days, Google Cloud’s standard setting.
6. Access needs and other sensitive information
Access needs could be special category data under UK GDPR (information about health or disability). Roam Pal keeps the access profile on the device and never sends it to us. Report and correction forms ask people not to include personal or health details, but a note could still contain them. Trip Check emails may describe access needs. For Trip Check health and access details, our condition is Article 9(2)(a): your explicit consent, which you give by ticking the box on the Trip Check request. You can withdraw it at any time by emailing us.
If a person shares a journey support plan or their Access Passport, it goes from their device to the recipient they choose, through their own share or copy options. For a journey support plan, the app shows a plain-text preview first, and booking references, contact details and private notes are excluded unless the person adds them.
7. Security and breaches
The website and the Hub are served only over encrypted connections (HTTPS). There are no user accounts or passwords. The Hub limits video reports to 20 a day per connection. Our approach is set out in our security overview. If a reportable breach of personal data we control ever occurred, we would assess it and, where required, report it to the ICO within 72 hours and tell anyone affected.
8. For organisations considering Roam Pal
- Roles. The people you serve use Roam Pal directly, and you do not send us their data, so in ordinary use we are not your processor. Where a formal arrangement is needed, we will enter a Data Processing Agreement that reflects the actual data flows.
- DPIA support. We will support your Data Protection Impact Assessment and provide the data flows above in the format your information governance team needs.
- Scope. Roam Pal is a travel-planning and information tool. It is not a medical device and does not give clinical advice, diagnosis or treatment.
- Accessibility. See our accessibility and inclusion statement.
9. Rights and complaints
People have the right to access, correct and delete their data, to restrict or object to its use, to data portability where it applies, and to withdraw consent. Most app data is on their own device, so they can view, change, back up and delete it themselves. For anything we hold, email admin@adaidigital.co.uk and we will reply within one month. Anyone can complain to the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113.
All policies · Privacy · Cookies · Security · Back to Roam Pal Guide