Skip to main content

Legal and privacy

Privacy policy

This privacy policy explains how Rovefold uses information in the storefront, account, checkout, monitoring, and trip workspace features.

Effective: September 1, 2026

1. Who controls your personal data

The controller is Martin Zbořil, Smrková 194/3, Strašín, 251 01 Říčany, Czech Republic, Czech business ID (IČO): 07520301; not registered for VAT.. For privacy questions or requests, email support@rovefold.com.

Rovefold has not appointed a data protection officer. Privacy questions and rights requests are handled through the contact above; any future appointed privacy contact will be added to this notice.

2. Categories and sources of data

  • Account: name, email, verification state, password credential held by the server, and account status.
  • Social sign-in: provider, provider account identifier, and profile details you approve, such as name, email, and avatar.
  • Preferences: language, origin or citizenship selection, and workspace display choices.
  • Orders: selected product, price and currency, order code, ownership, and transaction or accounting data returned by the Store service.
  • Trip content: routes, dates, travelers, logistics, accommodation, notes, activities, checklists, reviews, attachments, and sharing settings you add.
  • Support: messages, identifiers, screenshots, and other information you choose to provide when asking for help or exercising a right.
  • Security and diagnostics: IP and request metadata processed by the server, device and browser information, error details, page or operation context, timestamps, and internal account ID used by error monitoring.
  • Consent-based analytics: pseudonymous analytics session ID, page route, locale, product and commerce codes, event timestamps, and purchase value, currency, and a hashed transaction reference. Rovefold does not intentionally send names, email addresses, phone numbers, authentication tokens, full URLs, or trip content to GA4.

Most data comes directly from you or your device. Social sign-in providers supply the basic data you authorize. Product and trip data may also come from the Rovefold Store service or content already included in a purchased template.

3. Why we process data

PurposeTypical dataLegal basis
Create and secure an account; sign you inAccount, session, social sign-in, security dataContract; legitimate interest in account security
Supply a purchase and trip workspaceOrder, ownership, preferences, trip contentContract
Save, export, and share a trip at your requestTrip content, attachments, sharing tokenContract; actions you request
Provide support and handle requestsAccount, order, support communicationContract; legal obligation; legitimate interest
Keep accounting and legal recordsOrder, transaction, invoice, complaint dataLegal obligation; legal claims
Detect errors, abuse, and security eventsDiagnostics, request context, internal account IDLegitimate interest in a reliable and secure service
Measure product usage and commerce through GTM and Google Analytics 4Pseudonymous session, route, product, event, and commerce dataConsent

Providing account and order data is necessary to create an account, complete an order, and supply the workspace. Without it, those features cannot be provided. Optional profile, preference, and trip details can be omitted unless a specific feature needs them.

Rovefold does not use automated decision-making that produces legal or similarly significant effects for customers.

4. Recipients, processors, and international transfers

Data may be shared only as needed with categories such as:

  • DigitalOcean and deployment infrastructure providers for hosting and databases;
  • Bunny.net for media and content delivery;
  • Postmark for transactional email delivery;
  • Google or Facebook when you choose their authentication service;
  • Google Tag Manager and Google Analytics 4 for consented product and commerce analytics;
  • Sentry for sanitized error monitoring when configured;
  • Stripe for payment processing, checkout, invoices, and transaction evidence;
  • professional advisers, authorities, or counterparties where legally required.

Rovefold does not sell personal data. Some providers may process data outside the European Economic Area. Where required, those transfers rely on an adequacy decision, standard contractual clauses, or another lawful safeguard described by the relevant provider.

6. How long data is kept

Rovefold keeps data only for as long as needed for the purpose described. The following retention criteria apply:

  • account and active workspace data: while the account and service relationship continue;
  • browser cart and preferences: until cleared, replaced, or browser storage is removed;
  • short-lived confirmation and support-session state: for the browser session or stated workflow;
  • diagnostic events: for a limited operational and security period set in the monitoring service;
  • consented GA4 event-level data: currently configured for two months; the related _ga cookies can remain for up to two years unless consent is withdrawn or browser storage is cleared;
  • support and complaint records: while the request is handled and for a justified claims period;
  • purchase, invoice, and accounting records: for periods required by tax and accounting law;
  • deleted data: until deletion propagates through protected backups under the backup schedule.

7. Your data protection rights

Depending on the processing and applicable law, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing.

Email support@rovefold.com. We may need proportionate information to verify identity. We normally respond without undue delay and within one month, subject to any lawful extension.

You may also complain to your competent supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), uoou.gov.cz .

For account deletion steps, see Data deletion .

8. Security and browser storage

Current safeguards include encrypted transport, server-managed sessions, CSRF protection, access controls, email verification for important actions, optional social authentication, sanitized error monitoring, and restrictions on support impersonation. No online system is risk-free.

Rovefold uses essential cookies and browser storage for security and requested product functions. Google Tag Manager and Google Analytics 4 use Consent Mode v2 Basic and remain unloaded until Analytics consent is granted. The Cookies & local storage notice lists the known categories and explains when consent would be required.

9. Changes to this notice

We may update this notice when the service, providers, or legal requirements change. We will show a new effective date and provide additional notice where a change materially affects users or a new consent is required.

Back to top