Privacy Policy

1. Who we are

VoiceRoam is operated by Travelfall Technologies Private Limited, a private limited company registered in India under CIN U62013UT2026PTC020981, with its registered office at C/O Dhruv Pant, Tipola, Gaon, Kherana Road, Ranikhet, Almora, Almora- 263645, Uttarakhand, India.

Note on EU Representation: We are in the process of appointing an EU-based representative under GDPR Article 27. This section will be updated with their contact details upon appointment. In the interim, all data-related enquiries, including rights requests and complaints, should be directed directly to dhruv.pant@voiceroam.com.

Our lead supervisory authority in the European Union is the Agencia Española de Protección de Datos (AEPD) in Spain.


2. What this policy covers

This policy applies to the VoiceRoam mobile app (iOS and Android) and the VoiceRoam marketing website at www.voiceroam.com. The app is the full operational product, covering tour browsing, purchasing, playback, Pause & Ask, and all other features. The website is marketing only, with no accounts, no purchases, and no tour playback.


3. Age Attestation and Requirements

VoiceRoam is strictly intended for users who are 16 years of age or older. By accepting this Privacy Policy and our Terms of Service, you explicitly confirm and warrant that you are at least 16 years old. We do not knowingly collect personal data from anyone under the age of 16. If we become aware that we have inadvertently collected personal data from a user under 16, we will take immediate steps to delete that information and terminate the account.


4. What we collect and why

We process the following data points based on the clear legal frameworks outlined below:

4.1 Account information

When you create an account, we collect:

We automatically generate a pseudonymous user ID, a Firebase Installation ID (used to deliver push notifications), a registration method log, and a profile creation timestamp.

Legal basis: Contract performance (to manage your account profile). The age check record is stored under legitimate interest and legal obligation to verify contract formation eligibility.

Retention: Kept for the life of your account. Deleted within 30 days of an account deletion request, except the core status record of age confirmation which is kept for 3 years post-deletion for regulatory audit purposes.

4.2 Location data

When you are on an active tour, the app checks your position against known coordinates. Raw GPS coordinates are processed ephemerally on your device or our backend server solely to trigger tour entries. These raw coordinates are never stored, logged, or persisted. What we record is only the point of interest ID that was triggered, whether it was triggered automatically by the geofence or manually by you, and the GPS accuracy in meters at that moment. Location is never checked or recorded while the app is in the background.

Legal basis: Contract performance.

Retention: 90 days for POI trigger metric records. Raw GPS coordinates are processed transiently and deleted instantly.

4.3 Pause & Ask: photos and questions

When you use Pause & Ask, you can type a question and optionally upload a photo. Your question text and photo are sent through our backend server to Google's Gemini AI to generate a response. An anonymous, ephemeral session ID is attached to the request. No account identifier, email, or user ID is included in the request sent to Google.

Legal basis: Contract performance.

Retention: Photos are stored securely in cloud storage for 30 days, after which they are automatically and permanently deleted. If you delete your account before the 30 days are up, your photos are deleted immediately. Question text is transient and not retained.

4.4 Purchase and transaction data

All payments are processed by Apple (App Store) or Google (Play Store). We never receive or store your credit card details. What we receive and store is the history of the individual tours, Columbus Passes, or Marco Polo Passes you acquired, the price paid, currency, timestamp, payment status, and the transaction token from Apple or Google.

Legal basis: Contract performance and legal obligation (required by the Indian Companies Act, 2013, and EU tax frameworks to retain institutional financial records).

Retention: 8 years. This data survives account deletion and is retained in anonymized form.

4.5 Device, technical, and accessibility preferences

We collect your device model, operating system version, app version, and network connection type. Your IP address is collected, but the last octet is immediately zeroed out upon arrival at our gateway to preserve anonymity. Settings for accessibility features (haptic feedback, greyscale mode, and text size adjustments) are stored entirely locally on your device hardware and are never transmitted to our cloud or tracked across platforms.

Legal basis: Legitimate interest (system optimization).

Retention: 180 days for truncated technical logs.

4.6 App usage metrics (behavioral data)

We track how you interact with the app to improve the experience, but only if you give us permission to do so. If you consent, we collect screen views, navigation paths, and tour engagement metrics. All analytics data is pseudonymized.

Legal basis: Consent. You can withdraw it at any time in the settings.

Retention: 6 months.

4.7 Crash reports and errors

If the app crashes, we collect crash reports and stack traces via Firebase Crashlytics. We log API errors, empty states, and offline mode triggers.

Legal basis: Legitimate interest (maintaining safety and stability).

Retention: 180 days.

4.8 Push notifications

We use Firebase Cloud Messaging to send you push notifications. When you grant notification permission, Firebase generates a token specific to your device. If you deny permission, no token is stored.

Legal basis: Consent for promotional notifications; Legitimate interest for transactional notifications.

Retention: Life of your account, deleted immediately on account deletion.

4.9 Consent records

We log your consent decisions, including what you consented to and when.

Legal basis: Legal obligation (GDPR requires us to demonstrate valid consent).

Retention: The duration of the active consent, plus a period of 3 years after consent is withdrawn or the account is deleted.


5. Data Deletion and Backup Protection Timeline

When an account deletion request is finalized, data disappears from your active application panel and functional processing nodes immediately. However, you acknowledge that under standard data infrastructure management routines, this information remains resident within our secure, encrypted backup volumes, server caches, and archival tapes until they are naturally overwritten. Our complete system clearance cycle operates under the following milestones:


6. Data collected on the marketing website

Cookies: We use a strict consent management platform. No analytics cookies or tracking scripts load on www.voiceroam.com until you actively choose to accept them.

Feedback and Comments: If you submit feedback through our site, we collect your email address and message text. This data is managed through Brevo exclusively to resolve your inquiry and is not fed into marketing email sequences.

Legal basis: Consent or Legitimate interest.

Retention: Until the inquiry is resolved or you request deletion.


7. How we use AI

VoiceRoam uses artificial intelligence in three ways:

We do not use your personal data, including your questions, photos, or location data, to train any AI model.


8. Third-Party Data Processors

We do not sell your personal data. We share it only with service providers who help us run VoiceRoam. We engage the following processors:

Google LLC (Google Cloud Platform & Firebase)

Provides backend hosting, text-to-speech (TTS), AI processing (Gemini), database storage, and security firewalls.
Safeguards: Certified under the EU-U.S. Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs) in place for international transfers.

Brevo (Sendinblue SAS)

Managing user comments and feedback submitted via the marketing website.
Safeguards: EU-based processor (France); fully GDPR-compliant.

Unsplash (Unsplash Inc.)

Independent Data Controller handling visual content delivery for images displayed on the site. When your browser requests these images, Unsplash receives your IP address and standard request headers.
Safeguards: Canada is recognized by the European Commission as providing an adequate level of data protection.


9. Where your data goes

All customer data resides in Google Cloud Platform (GCP) buckets located strictly in Europe.

Because Travelfall Technologies Private Limited is a Data Controller based in India, our operational team accesses this Europe-hosted data directly from India for purposes including customer support, system administration, and product operations. India does not have an adequacy decision from the European Commission. We have implemented appropriate technical and organizational measures, including strict access controls, encryption at rest and in transit, and role-based data limitations, to ensure your data remains protected when accessed by our internal team.


10. Consent Logging and Right of Withdrawal

Under EU law, digital content purchases come with a 14-day right of withdrawal. Because our content is delivered instantly, you must waive this right to access the tours. When you successfully initiate and start an acquired tour within the application, our systems automatically capture this structural activity within our telemetry logs as your explicit consent for immediate digital delivery and your accompanying waiver of the 14-day right of withdrawal.


11. Your rights (GDPR)

If you reside in the EU, you have the rights to Access, Rectification, Erasure, Restriction, Portability, Objection, and to Withdraw Consent. You can exercise any of them by emailing us at dhruv.pant@voiceroam.com. We will respond within 30 days. If you are unsatisfied, you have the right to lodge a complaint with a supervisory authority (such as the AEPD in Spain).


12. Security

All data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher, via Google Cloud Platform's default encryption infrastructure. Photos are stored in private Cloud Storage buckets with access limited to authenticated backend services. We take reasonable and appropriate technical measures to protect your data.


13. Third-party links

The VoiceRoam app contains links to partner websites, including museums and attractions. When you tap a partner listing, you leave VoiceRoam and enter a site operated by that partner under their own privacy policy. We are not responsible for the privacy practices of third-party sites.


14. Changes to this policy

If we make material changes to this policy, we will notify you via email (if you have an account) or through an in-app notification before the changes take effect. We will never retroactively reduce your rights without your consent.


15. For California residents

VoiceRoam does not target the United States market. However, if you access the app from California, the following applies under the CCPA/CPRA: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. You have the right to know what data we collect and to request its deletion. To exercise these rights, contact us at dhruv.pant@voiceroam.com.


16. Geo restrictions and intended markets

VoiceRoam is designed for and marketed to users in the European Union, beginning with Spain. Our services might not be available in a few countries, and we do not actively market or provide support in those jurisdictions.