Subprocessors
Roomiva · Version 2026-09-06.1 · Effective 6 September 2026
The companies that process personal data on our behalf to run Roomiva, what each one receives, and why. This list is compiled from the software's dependencies and configuration; a company that does not appear in the code is not on it. The operator ("we") is identified in the Operator details at the end of this document.
| Subprocessor | Service | What it processes | Location and transfer mechanism |
|---|---|---|---|
| Supabase, Inc. | Authentication, database (PostgreSQL), private file storage; delivery of the sign-in link email through the mailer configured in our Supabase project | Account identifiers, email address, sign-in links (transiently), session tokens, all database records listed in the Privacy Policy, uploaded photos and generated designs | The project region and the mailer are stated in the Operator details |
| Resend, Inc. | Delivery of the sign-in link email, as the custom SMTP provider configured in our Supabase project | Your email address and the sign-in email (which contains the one-time link), transiently, for delivery and delivery logs | Sending region Tokyo (ap-northeast-1), from the verified sending domain send.roomivaapp.com; Resend's data-processing terms |
| Google LLC (Gemini API) | Artificial-intelligence analysis of the photo, planning of each design, and the structural review of each generated design. Google does not draw the designs. | The re-encoded photo, the design choices and the optional request text, and the generated designs for the structural review. No account identifier, email or device identifier. | Google's API processing locations; the service tier and its data-use terms are stated in the Operator details |
| OpenAI (Images API) | Artificial-intelligence image generation of the design renders: the one call that draws each design | The re-encoded photo (and, for a refinement, the previously generated design together with the photo) and the render instruction text, which contains the design choices and the optional request text. No account identifier, email or device identifier. | United States by default (OpenAI's regional processing is not configured for our account). Processed under OpenAI's API data-usage terms: content sent to the API is not used to train or improve OpenAI's models unless the customer opts in, and we have not; logs kept for abuse monitoring, which may contain the photo and the instruction text, are retained for up to 30 days unless a longer period is required by law; an image OpenAI's classifier flags as child sexual abuse material is retained for manual review. OpenAI offers zero data retention only on prior approval, which we have not applied for. The contracting entity and the agreement status are stated in the Operator details |
| RevenueCat, Inc. | Subscription management: receiving purchase events from the stores and reporting entitlement status | Your app user identifier (the same random identifier as your account), purchase and subscription events from the store | RevenueCat's regions; see RevenueCat's privacy documentation |
| Apple Inc. (App Store) | Distribution, payment and subscription billing on iOS | Your Apple account and payment details, under Apple's terms — none of which reach us | Apple's regions |
| Google LLC (Google Play) | Distribution, payment and subscription billing on Android | Your Google account and payment details, under Google's terms — none of which reach us | Google's regions |
| Render Services, Inc. | Runs the API server, the background worker and the daily retention job (render.yaml: three services in the Frankfurt region); holds the server request logs | Request logs (request id, route, status, timing, network address, credentials redacted); data in transit | Frankfurt, Germany (EU). Log retention is stated in the Operator details |
| Expo (650 Industries, Inc.) | Build tooling for the app binaries (EAS Build) | No user data. The build service compiles the app; the app does not send data to Expo at runtime, and no over-the-air update service is installed. | — |
Not used: no content-delivery network, no analytics provider, no crash-reporting provider, no advertising network, no customer-messaging or marketing-email provider, no data broker.
Changes
When we add or replace a subprocessor we update this document, bump the version at the top, and show the new version in the app. Where the law where you live requires us to give you a chance to object to a new subprocessor, we will do so by the notice methods described in the Privacy Policy.
Operator details
The Supabase project region, the server log retention period, the AI providers' terms and data use (the Gemini API service tier and its data-use terms; the OpenAI API terms and contracting entity that apply to our account), and the status of our data-processing agreements are published below.
- Operator: iClick Solutions Inc.
- Registration: State of Delaware, Secretary of State, Division of Corporations — File Number 6657647; filed March 7, 2022.
- Address: 651 N Broad St, Suite 201, Middletown, Delaware 19709, United States
- Country: United States
- Governing law and courts: The laws of the State of Delaware, United States; the state and federal courts located in Delaware
- Support: support@roomivaapp.com
- Privacy contact: support@roomivaapp.com
- Grievance officer / DPO: Viren Makkar, vmakkar@iclicksolutions.us
- EU / UK representative: Viren Makkar, vmakkar@iclicksolutions.us (for the EU and the UK)
- Database and storage region (Supabase): us-east-1 (North Virginia)
- API hosting: Render Services, Inc. — Frankfurt (EU) region, for the API, the worker and the retention job (render.yaml)
- Server log retention: Server request logs are held by Render Services, Inc. in its log store for the retention period of the Render workspace tier in use (7 days on the Hobby tier, 14 days on Pro), then deleted. No log stream to any other provider is configured.
- Sign-in email delivery: Custom SMTP via Resend (Resend, Inc.), Tokyo (ap-northeast-1) sending region; sender no-reply@send.roomivaapp.com
- AI provider terms and data use (Google Gemini API; OpenAI API): Google Gemini API, paid tier (billing enabled): under the Gemini API Additional Terms for paid services, Google does not use prompts or responses to improve its products. OpenAI API, standard paid access: under the OpenAI API data-usage terms, content sent to the API is not used to train or improve OpenAI models unless the customer opts in, which we have not; abuse-monitoring logs are retained for up to 30 days.
- Data-processing agreements: OpenAI: Data Processing Addendum executed by iClick Solutions Inc. on 2026-09-20 (DocuSign envelope E6FAD23DD4D288A181516FF270372C69); the countersigned copy is held by the operator. Supabase, Render, Resend, Google (Gemini API) and RevenueCat: the data-processing terms of each form part of the agreement accepted when the account was created and require no separate signature.