Privacy Policy
Last Updated: September 2026 • Compliant with POPIA & GDPR
1. Overview
At Roemio (operated via www.roemio.com), protecting your privacy and ensuring the security of your personal data is paramount. This Privacy Policy explains what personal information we collect, why we collect it, how it is shared with travel fulfillment partners (such as Emerging Travel Group / RateHawk), and your rights regarding your data.
2. Information We Collect
We collect personal information necessary to facilitate and manage travel reservations:
- Contact & Profile Details: Full name, email address, mobile phone number, residency/citizenship country, and account credentials.
- Guest & Room Occupancy Data: First and last names of all travelling guests, child ages (where applicable for hotel occupancy and bed configurations), and special requests (e.g. non-smoking, quiet room).
- Transaction & Booking Records: Order IDs, check-in and check-out dates, selected room types, board basis, total amounts paid, and cancellation records.
- Technical & Security Identifiers: IP addresses (transmitted for fraud prevention and supplier audit compliance as required by ETG APIv3 Section 4), browser details, and device identifiers.
3. How We Use and Share Your Data with Suppliers
We process your personal information strictly for legitimate travel booking and customer service operations:
- Reservation Fulfillment with RateHawk: When you complete a booking, Roemio securely transmits the guest names, contact email, phone number, residency, and room specifications to our global supply partner (Emerging Travel Group / RateHawk) and the receiving lodging property to issue your official Hotel Confirmation Number (HCN) and travel voucher.
- Customer Communication: Delivering booking confirmations, hotel vouchers, schedule change notices, and cancellation receipts.
- Fraud Detection & Compliance: Verifying transaction authenticity and safeguarding against fraudulent reservations.
Roemio does not sell, rent, or trade your personal information to third parties for advertising purposes.
4. Data Security & Storage
We implement industry-standard administrative, physical, and technical security safeguards. All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS 1.3 / HTTPS). Sensitive database records are protected with restricted access protocols.
5. Your Privacy Rights
Under the South African Protection of Personal Information Act (POPIA) and international standards (including GDPR), you have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate or outdated information.
- Request deletion of your account and associated personal data (subject to legal and accounting record-keeping requirements).
To exercise any of these rights, please email us at privacy@roemio.com.
6. Cookies & Tracking
Roemio uses essential session cookies to keep you signed in, remember your search parameters (dates, guests, destination), and complete your checkout seamlessly. We do not use intrusive third-party cross-site tracking cookies.