Privacy Policy
Last updated: 1 May 2026
1. Who we are
SisterRoam is a verified hospitality-exchange community for female solo travellers, operated by Sym Healthtech. When this policy says “SisterRoam”, “we”, “us”, or “our”, it refers to Sym Healthtech and the SisterRoam platform.
For privacy questions contact us at admin.sisterroam@gmail.com.
2. Information we collect
We collect information you provide directly, including:
- Account details: name, email address, password (hashed)
- Profile information: photo, bio, city, country, languages, travel style
- Identity documents submitted for verification (stored securely via Cloudinary)
- Emergency contact details you provide when making or accepting hosting requests
- Content you create: community posts, stories, recommendations, messages
- Payment information processed securely by our payment provider — we do not store card details
We also collect usage data automatically, including device type, browser, pages visited, and IP address.
3. How we use your information
- To operate, maintain, and improve the platform
- To verify your identity and grant the verified member badge
- To facilitate hosting requests, co-traveller matching, and messaging
- To send safety check-ins during active stays
- To notify emergency contacts only in a genuine emergency
- To send transactional emails (request notifications, verification updates)
- To detect fraud, abuse, and safety violations
- To comply with legal obligations
4. Who we share your data with
We do not sell your personal data. We share it only with:
- Other members — your public profile (name, photo, city, bio, verification badge) is visible to logged-in members.
- Service providers — Cloudinary (media storage), Resend (transactional email), Pusher (real-time messaging), Vercel (hosting), MongoDB Atlas (database).
- Law enforcement — only when required by law or to protect safety.
5. Data retention
We retain your account data for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is required by law or to resolve disputes.
Identity documents submitted for verification are deleted from our systems within 90 days of a decision being made.
6. Security
We use industry-standard security measures including HTTPS everywhere, bcrypt password hashing, strict CORS headers, and role-based access controls. No method of transmission over the internet is 100% secure, but we take all reasonable precautions.
7. Your rights
Depending on your location you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Data portability
To exercise any of these rights email admin.sisterroam@gmail.com.
8. Cookies
We use essential cookies to keep you logged in and a session cookie for CSRF protection. We do not use advertising or tracking cookies. You can disable cookies in your browser settings, but this will prevent you from logging in.
9. Children
SisterRoam is not directed at children under 18. If we become aware that a child has created an account, we will delete it promptly.
10. Changes to this policy
We may update this policy occasionally. We will notify you by email or in-app banner for material changes. Continued use of the platform after changes take effect constitutes acceptance.