Last updated 21 July 2026

Privacy Policy

How the company responsible for Roamplan handles account, trip-planning, payment, support and device data.

Core service boundary: Roamplan is not a travel agency or tour operator. We do not sell, book, bundle or hold funds for flights, accommodation, tickets, rental vehicles or insurance. All travel arrangements are made by you with third parties.

1. Who is responsible

ANDY JENKINS LIMITED is the data controller for personal data processed through Roamplan. Our registered contact address, support email and telephone are shown below. This policy applies to the website, account, planner, visual and video generation, billing support and customer service.

2. What we collect

  • Account data: email address, authentication identifiers, subscription status and account preferences.
  • Trip inputs: destinations, dates or trip length, pace, interests, companion descriptions, constraints, adjustment requests and any text or files you choose to submit.
  • Generated results: itineraries, day cards, route sketches, packing lists, budget ranges, recap videos and export metadata.
  • Order and payment records: plan, billing interval, amount in USD, status, transaction identifiers, billing country and limited card metadata such as brand and last four digits supplied by the payment provider. We do not receive or store complete card numbers or security codes.
  • Support and lead data: name, email, topic, message, trip brief and consent record.
  • Technical data: IP address, browser, device, timestamps, security events, cookie choices and diagnostic logs.

Do not provide passport numbers, government identifiers, complete payment-card data, detailed health records or a child's full name. Companion information, especially information relating to children, should be general and limited to what is needed for pace and itinerary structure.

3. Collection sources

We collect data directly from you when you create an account, type or revise a planner prompt, choose itinerary settings, upload a file where that feature is available, generate or export content, subscribe, contact support or submit a trip brief. Payment and subscription status come from Stripe or PayPal. Device, cookie, access and security data come automatically from your browser, hosting, database and security services. We may also receive a limited referral URL or campaign parameter when you follow a link to Roamplan.

4. Why we use it and legal bases

  • Contract: provide accounts, generate and store requested plans, deliver exports, administer subscriptions and respond to service requests.
  • Legitimate interests: secure the service, prevent abuse, diagnose failures, improve reliability and understand aggregated feature use, balanced against your rights.
  • Consent: optional analytics or non-essential cookies, and optional communications where required. Consent can be withdrawn.
  • Legal obligation: accounting, tax, fraud prevention, disputes and lawful requests.

We do not claim a right to train general-purpose AI models on your private trip inputs or generated results. Our own service does not use them for model training. AI processors receive the content needed to produce the requested output and may process it under their service and security terms.

5. User inputs, uploads and generated data

Your planner text, settings, adjustment requests and any files you choose to upload are used to fulfil the generation you request. We send only the prompt, itinerary context, media instructions or uploaded content needed for that task to the relevant AI processor. Generated itineraries, images, videos and export metadata are returned to Roamplan so you can review, revise, download or store them.

Generated files may be retained in account storage for up to 12 months after last activity or until you delete them, subject to backups and legal needs. Temporary uploads, generation files and provider task records normally expire or are removed within 30 days. Support attachments are normally retained for 24 months. You can delete available account content in the workspace or request account and content deletion through support. Active storage is cleared after the request is verified; residual encrypted backups age out through the normal rotation, generally within 90 days.

Roamplan does not use private user inputs, uploads or generated results to train its own or a general-purpose AI model, and does not authorise AI processors to use that content for model training. AI processors may retain narrowly scoped task data for security and service operation only as permitted by our processor terms.

6. Who we share it with

We use processors only as needed: Vercel or equivalent providers for hosting and logs; Supabase for authentication, database and file storage; Stripe and, where offered, PayPal for payment and billing; transactional email providers; AI text, image and video generation providers for requested generations; and security, monitoring or analytics providers where enabled. An AI provider receives the specific prompt, itinerary context, upload or generated asset required for the selected task, but not payment-card credentials. These providers act under processing terms and their own security controls. We do not permit them to train models on private Roamplan content. We may also disclose data to professional advisers, courts, regulators or authorities where legally required, or during a lawful corporate transaction.

Stripe and PayPal collect payment credentials directly in their hosted interfaces. Roamplan does not handle complete card numbers. Your purchase is only for access to this online-only digital SaaS; no physical goods, shipping or travel products are sold.

7. International transfers

Processors may handle data outside the United Kingdom or European Economic Area. Where UK GDPR or EU GDPR applies, we use an adequacy decision, the UK International Data Transfer Agreement or Addendum, EU Standard Contractual Clauses and supplementary measures as appropriate. Contact us for information about relevant safeguards.

8. Retention

  • Account and itinerary data: while the account is active, then normally up to 12 months after closure unless deleted sooner.
  • Subscription, invoice and tax records: normally 6 years after the relevant financial year.
  • Support and lead records: normally 24 months after resolution or last contact.
  • Security logs: normally 90 days, longer where an incident requires investigation.
  • Cookie consent records: normally up to 12 months.

We may keep narrowly scoped records longer where required for legal claims, fraud prevention, tax or regulatory duties.

9. Security

We use access controls, encryption in transit, managed secret storage, least-privilege service credentials, webhook signature verification, audit logging and backups. No system can be guaranteed completely secure. Contact us promptly if you believe your account or data has been compromised.

10. Your rights

Under UK GDPR and, where applicable, EU GDPR, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. We may need to verify identity. You may complain to the UK Information Commissioner's Office or your applicable supervisory authority.

California residents may request to know, correct or delete covered personal information, and may limit certain uses of sensitive personal information. We do not sell personal information for money and do not share it for cross-context behavioural advertising. We will not discriminate for exercising a privacy right. An authorised agent may submit a verified request.

11. Do Not Sell or Share

Roamplan does not sell personal information or use trip inputs for cross-context behavioural advertising. If our practices change, we will provide the legally required notice and opt-out mechanism before that change applies.

12. Cookies and analytics

Strictly necessary cookies support sessions, security, checkout and preferences. Optional analytics or marketing cookies are used only where enabled and legally permitted. See the Cookie Policy for purposes, durations and controls.

13. Automated decisions and children

AI generates planning content, but Roamplan does not make decisions that produce legal or similarly significant effects about you. You decide whether to use any output. The service is not for children under 13. Users aged 13–17 require permission from a parent or legal guardian. We do not intentionally collect children's precise identity or sensitive details.

14. Complaints and contact

Send privacy requests to support@andyjenkinns.shop with “Privacy request” in the subject. We aim to respond within one month where UK GDPR applies, subject to lawful extensions. You may also complain to the Information Commissioner's Office at ico.org.uk.

15. Changes

We may update this policy to reflect service, processor or legal changes. The date above identifies the current version. Material changes will be communicated through the service or by email where appropriate.


Contact: ANDY JENKINS LIMITED, 8 Castle View Way, Kintore, Aberdeen, Aberdeenshire, United Kingdom, AB51 0SB. Email support@andyjenkinns.shop; telephone +44 7213000985.