This Privacy & Cookie Notice explains how Rooni collects, uses, stores, and protects personal data in connection with our website, our business, and Rooni Trust Signal. It also explains how we use cookies and similar technologies.
1. Who we are
Rooni provides Trust Signal, a consent management platform for websites, apps, and digital services.
- Company name: Rooni
- Product name: Trust Signal
- Website: rooni.io
- Contact email: privacy@rooni.io
- Data Protection Officer: We have not appointed a Data Protection Officer. Privacy enquiries can be sent to the contact above.
2. When this notice applies
This notice applies when you visit our website; create a Trust Signal account; request a demo; contact us; subscribe to our service; use our dashboard or platform; interact with our support, sales, marketing, or billing processes; or receive communications from us. It also explains, at a high level, how we process end-user consent data on behalf of our Customers.
3. Our role: controller and processor
When Rooni acts as controller. Rooni acts as controller when we decide why and how personal data is processed. This includes data relating to website visitors to rooni.io, account owners and authorised users, demo requests, billing contacts, support enquiries, marketing communications, security monitoring, and service improvement.
When Rooni acts as processor. Rooni generally acts as processor when we process consent records, preference data, and related technical data on behalf of our Customers using Trust Signal. In that case, the Customer is usually the controller and is responsible for explaining the processing to its own website or app users. If you are an end user of a website that uses Trust Signal, you should contact the owner of that website to exercise privacy rights relating to that website's use of your data.
4. Personal data we collect
Account and user data: name, email address, company name, job title, login details, account settings, team membership, authentication information, user role and permission settings.
Billing and subscription data: billing contact details, company details, billing address, tax information, subscription plan, payment status, invoices and transaction references. Payment card details are processed by our payment provider (Paddle) and are not stored directly by Rooni.
Website and device data: IP address, browser type, device type, operating system, pages viewed, referral source, approximate location, interaction events, cookie identifiers, consent preferences.
Support and communication data: emails and messages you send us, support tickets, chat messages, call notes, feedback, uploaded files or screenshots, technical diagnostic information.
Product usage data: login events, dashboard usage, websites or domains added to your account, configuration changes, scan history, consent banner settings, consent categories, integration settings, API usage, error logs, audit logs.
Consent and preference data processed for Customers: consent choices, consent category status, consent signal values, timestamps, banner version, policy version, preference centre interactions, user region or jurisdiction, device or browser information, anonymous or pseudonymous identifiers, proof-of-consent records.
5. How we collect personal data
We collect personal data directly from you when you submit forms, create accounts, or contact us; automatically through our website, platform, cookies, logs, and analytics tools; from payment, authentication, support, and infrastructure providers; from Customers who configure and use Trust Signal; and from public sources where relevant for business contact or security purposes.
6. Why we use personal data
| Purpose | Examples | Likely lawful basis |
|---|---|---|
| Provide Trust Signal | Account access, dashboard, consent tools, scans, scripts, support | Contract |
| Manage subscriptions and billing | Plans, invoices, payment status, tax records | Contract / legal obligation |
| Support Customers | Troubleshooting, tickets, diagnostics | Contract / legitimate interests |
| Secure the service | Fraud prevention, logs, access controls, abuse detection | Legitimate interests / legal obligation |
| Improve the product | Usage analytics, error monitoring, feature improvement | Legitimate interests |
| Service communications | Account notices, security alerts, product updates | Contract / legitimate interests |
| Marketing | Newsletters, product updates, demo follow-up | Consent / legitimate interests depending on context |
| Comply with law | Accounting, tax, regulatory requests, legal claims | Legal obligation / legitimate interests |
| Process Customer consent records | Store and manage consent choices for Customer websites | Customer instructions / processor role |
7. Cookies and similar technologies
Cookies and similar technologies may store or access information on a user's device. We may use cookies, pixels, local storage, scripts, tags, and similar technologies on our website and platform.
8. Types of cookies we use
Strictly necessary cookies. Required for our website or platform to function. They may support security, login, session management, load balancing, consent storage, fraud prevention, and core service functionality. These cannot usually be disabled.
Functional cookies. Help remember choices such as language, region, interface settings, or saved preferences.
Analytics cookies. Help us understand how users interact with our website and platform, such as which pages are visited, which features are used, and where errors occur.
Marketing cookies. May help us measure campaigns, understand referrals, or show relevant advertising.
Consent management cookies. Trust Signal may set or read cookies or local storage to remember consent preferences and ensure the correct consent state is applied.
9. Cookie consent
Where required, we ask for consent before setting non-essential cookies. You can update your choices using our cookie banner or preference centre at any time — Trust Signal itself is the consent layer on rooni.io.
10. Managing cookies
You can manage cookies through our consent banner or preference centre, your browser settings, your device privacy settings, and third-party opt-out tools where available. Blocking some cookies may affect website or platform functionality.
11. How long we keep personal data
We keep personal data only as long as reasonably necessary for the purposes described in this notice.
| Data type | Typical retention |
|---|---|
| Account data | For the life of the account, then deleted or anonymised within 90 days |
| Billing records | Retained for legal, accounting, and tax periods (typically up to 10 years) |
| Support records | Retained for 24 months after closure |
| Security and audit logs | Retained per workspace configuration (12–120 months; default 24 months) |
| Marketing contacts | Until unsubscribed or inactive for 24 months |
| Consent records processed for Customers | Retained per Customer configuration (12–120 months) and the DPA |
| Website analytics | Retained for 14 months |
12. Who we share personal data with
We may share personal data with hosting and infrastructure providers, database and storage providers, payment processors, authentication providers, analytics providers, email and communication providers, customer support tools, professional advisers, regulators, courts, or public authorities where required, and buyers or successors in connection with a business sale, merger, or restructuring. We do not sell personal data.
13. Sub-processors
To provide Rooni Trust Signal, we use trusted third-party service providers that may process personal data on our behalf. Where required, we enter into contracts with our sub-processors that impose data protection obligations designed to provide an appropriate level of protection for personal data. We remain responsible for our sub-processors where required by applicable data protection law and by our Data Processing Addendum.
| Sub-processor | Service | Region | Data processed |
|---|---|---|---|
| Supabase | Database, authentication, storage | EU | Account data, configuration, consent records, logs |
| Cloudflare | Hosting, CDN, edge runtime | Global | HTTP requests, IP address, configuration |
| Paddle | Billing and subscriptions (Merchant of Record) | UK / EU | Billing contact, subscription, invoice and payment metadata |
| Browserless | Headless browser for website scans | EU | Scanned website URLs, scan output |
| Google AI (Lovable AI Gateway) | Script classification and translations | EU / US | Script URLs, snippets, content to classify or translate |
| Google (Auth) | Optional sign-in with Google | Global | Name, email, authentication identifiers |
We may update our sub-processors from time to time. Where Rooni acts as a processor for a Customer, we will provide notice of intended changes where required by our DPA. Customers may object to a new sub-processor where they have a reasonable data protection concern. Questions about our sub-processors can be sent to privacy@rooni.io.
14. International transfers
Some service providers may process data outside your country, the UK, or the European Economic Area. Where required, we use appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, transfer risk assessments, or other lawful transfer mechanisms.
15. Security
We use reasonable technical and organisational measures to protect personal data, including access controls, encryption where appropriate, logging, monitoring, backups, and secure infrastructure practices. However, no system is completely secure.
16. Children
Trust Signal is not intended for children and should not be used by individuals under 16 years old. We do not knowingly collect personal data from children.
17. Automated decision-making
Rooni does not use personal data to make decisions that produce legal or similarly significant effects solely by automated means.
18. Your privacy rights
Depending on the law that applies, you may have the following rights in relation to personal data we process.
Who to contact. If you are a Rooni website visitor, account user, trial user, customer contact, or billing contact, contact Rooni directly at privacy@rooni.io. If you are a visitor to a website using Trust Signal, Rooni usually acts as a processor for that website owner — the website owner is normally responsible for responding to your privacy request, and you should contact the website or business where you submitted your consent choice. If you contact Rooni about a Customer website, we may redirect your request to the relevant Customer where appropriate.
Right to be informed. You have the right to receive clear information about how your personal data is collected, used, shared, and stored. This is why we provide this Privacy & Cookie Notice.
Right of access. You may request confirmation of whether we process your personal data and ask for a copy of that data.
Right to rectification. You may ask us to correct inaccurate or incomplete personal data.
Right to erasure. You may ask us to delete your personal data in certain circumstances. This right may not apply where we need to keep data for legal, security, contractual, accounting, or legitimate business reasons.
Right to restriction. You may ask us to restrict how we use your personal data in certain circumstances.
Right to data portability. Where applicable, you may ask to receive personal data you provided to us in a structured, commonly used, machine-readable format.
Right to object. You may object to processing based on legitimate interests or direct marketing. If you object to direct marketing, we will stop using your personal data for that purpose.
Right to withdraw consent. Where we rely on consent, you may withdraw that consent at any time. Withdrawing consent does not affect processing that took place before consent was withdrawn. For cookies, you can update your choices through our cookie banner or preference centre.
Rights relating to automated decision-making. You may have rights relating to decisions made solely by automated processing where those decisions have legal or similarly significant effects. Rooni does not currently use personal data for this type of automated decision-making.
How to submit a request. Email privacy@rooni.io with your name, your email address, the right you want to exercise, the account, website, or service your request relates to, and enough information for us to verify and process the request. We may need to verify your identity before responding.
Response times. We aim to respond within the timeframe required by applicable law. For GDPR and UK GDPR requests, this is usually within one month, although it may be extended where requests are complex or numerous.
When we may refuse or limit a request. We may refuse, limit, or delay a request where permitted by law, including where we cannot verify your identity; the request is manifestly unfounded or excessive; the data is required for legal claims; the data must be retained for legal, tax, accounting, or security reasons; or the request relates to data controlled by one of our Customers rather than Rooni.
Complaints. You may have the right to complain to a data protection authority. If you are in the UK, this may be the ICO. If you are in the EEA, you may contact your local supervisory authority (in France, this is the CNIL). We encourage you to contact us first so we can try to resolve the issue.
Cookie and consent choices. For Rooni's own website, you can manage cookie choices through our cookie banner or preference centre. For websites using Trust Signal, your consent choices are controlled by the relevant website owner — use that website's banner, preference centre, or privacy contact.
Customer website consent records. If Trust Signal is used on a Customer website, the Customer decides what technologies are used; what consent categories are shown; what lawful basis applies; how long consent records are retained; and how privacy requests are handled. Rooni processes those records according to the Customer's instructions and the Data Processing Addendum.
19. Changes to this notice
We may update this Privacy & Cookie Notice from time to time. If we make material changes, we will take reasonable steps to notify users, such as by posting a notice on our website or within the platform.
20. Contact us
For privacy questions, contact the Rooni Privacy Team at privacy@rooni.io.
For questions, contact us at support@rooni.io.