Privacy Policy

Last updated: February 2026

Effective for all users, including corporate employees: This policy applies to all personal data processed through Roadmap Lodging's services.

Privacy Commitment for Corporate Users

Roadmap Lodging is committed to protecting personal data in compliance with CCPA, GDPR, HIPAA (where applicable), and other regulatory requirements. This policy details how we collect, use, secure, and protect information provided by individuals and corporate entities.

1. Personal Data Collection

We collect personal information necessary to provide housing services and fulfill business obligations:

  • Identity Information: Name, email, phone, date of birth (if applicable)
  • Location Data: Residential address, preferred markets, office locations (for corporate accounts)
  • Housing Preferences: Move dates, bedroom/bathroom requirements, budget, special accommodations
  • Financial Data: Payment method, billing information (processed securely; we do not store card numbers)
  • Employment Information: Company name, job title, employer contact (for corporate requests)
  • Communication Data: Call logs, emails, messages with our team and property hosts
  • Device Information: IP address, browser type, cookies, analytics (for service improvement)
  • Health/Accessibility Data: Only when necessary for accessibility accommodations (processed with heightened care)

Corporate Transparency Note: If submitted through a corporate account, your employer may be notified of request status as part of business arrangements. Individual privacy is maintained throughout.

2. Legal Basis for Data Processing

We process your data on the following lawful grounds:

  • Contractual Necessity: Fulfilling housing service agreements and bookings
  • Legitimate Business Interest: Fraud prevention, security, service improvements, analytics
  • Legal Compliance: Tax reporting, regulatory requirements, anti-money laundering
  • Consent: Marketing communications, optional surveys, additional features (always opt-in)
  • Employment Relationship: For corporate users, coordinating with authorized company representatives

3. Data Security & Protection Measures

Roadmap Lodging implements enterprise-grade security controls aligned with NIST Cybersecurity Framework and ISO 27001 standards:

Technical Safeguards

  • Encryption in Transit: TLS 1.3/SSL for all data transmission; enforced HTTPS on all endpoints
  • Encryption at Rest: AES-256-GCM for sensitive data; keys managed via HSM (Hardware Security Module)
  • Database Security: Row-level security, encrypted backups, automated replication across secure data centers
  • API Security: OAuth 2.0, JWT tokens, rate limiting, API key rotation policies
  • Network Security: VPC isolation, WAF (Web Application Firewall), DDoS mitigation, intrusion detection
  • Zero Trust Architecture: Continuous authentication, micro-segmentation, endpoint monitoring

Administrative & Operational Safeguards

  • Access Controls: Role-based access control (RBAC) with principle of least privilege; multi-factor authentication for all staff
  • Personnel Security: Background checks, confidentiality agreements, annual privacy/security training
  • Audit Logging: Immutable logs of all data access; retained for 2 years; reviewed quarterly for anomalies
  • Change Management: Code review processes, staging environments, automated testing before production deployment
  • Vendor Management: Annual security assessments, signed Data Processing Agreements (DPAs), audit rights
  • Incident Response Plan: Documented procedures, 24/7 monitoring, 72-hour breach notification requirement

Compliance Certifications

  • ISO 27001:2022 – Information Security Management System certification
  • SOC 2 Type II – Security, Availability, Processing Integrity audit completed annually
  • PCI DSS 4.0 – Payment Card Industry compliance; quarterly vulnerability assessments
  • HIPAA Business Associate Agreement (BAA) – For housing requests involving health information
  • GDPR Data Protection Impact Assessment (DPIA) – Completed for processing EU resident data
  • CCPA Compliance – Consumer rights implementation for California residents

Despite robust safeguards, no system is 100% secure. We recommend users employ strong passwords (12+ characters), enable two-factor authentication, and avoid sharing sensitive information via unsecured channels.

4. Who We Share Your Data With

Your information is shared only when necessary and with appropriate safeguards:

  • Property Hosts/Landlords: Contact info, housing preferences, and dates needed for bookings
  • Corporate Partners: For business accounts, authorized company contacts only (with proper authorization)
  • Payment Processors: Limited to transaction information (Stripe, PayPal); PCI-compliant and encrypted
  • CRM Systems: Lead and booking information (GoHighLevel, with DPA in place)
  • Service Providers: Email, SMS, analytics, and hosting providers (all under written agreements)
  • Legal/Government: Only when required by law, court order, or regulatory investigation; we notify users unless prohibited
  • Business Transfers: In event of merger/acquisition, data transfers with same protections; users notified

Corporate Employees: Your company may receive aggregated reporting (housing requests submitted, placements made); individual personal data shared only with designated HR/Relocation contacts.

5. Cookies, Tracking & Analytics

We use technologies to enhance user experience and understand platform usage:

  • Essential Cookies: Required for login, security, and session management (cannot be disabled)
  • Functional Cookies: Remember preferences, language settings (can be disabled; service degradation expected)
  • Analytics: Google Analytics for anonymous usage patterns; no personally identifiable tracking
  • Advertising and measurement: The Meta (Facebook) pixel runs on our public marketing pages, including our free operator tools. It sets the _fbc and _fbp cookies and reports page views and free-tool signups to Meta so we can measure which ads bring people here. It does not run on the host, guest, or admin areas of the platform.
  • Marketing/Retargeting: Used to show relevant housing options and operator tools. You can opt out through your browser or device advertising controls, and through Meta's own ad preferences.

See our Cookie Policy for detailed management instructions.

6. Data Retention & Deletion

We retain data only as long as necessary:

  • Active Users: Data retained while account is active and for 2 years post-completion
  • Transaction Records: 7 years (tax/legal compliance)
  • Marketing Opt-Outs: Retained indefinitely to honor unsubscribe requests
  • Deleted Account Data: Purged within 30 days (except legally required records)
  • Corporate Accounts: Data retained per contract terms; notification given before deletion

Request Your Data: Submit deletion requests to privacy@roadmaplodging.com with proof of identity. Requests processed within 30 days per CCPA/GDPR.

7. Your Privacy Rights

You have the following rights under applicable law:

  • Right to Access: Request a copy of all personal data we hold (ISO format provided)
  • Right to Correction: Update or correct inaccurate information in your profile
  • Right to Deletion: Request removal of your data ("Right to be Forgotten") in most cases
  • Right to Portability: Receive your data in machine-readable format to transfer to competitors
  • Right to Object: Opt out of marketing, analytics, or certain processing activities
  • Right to Restrict Processing: Limit how your data is used while we investigate disputes
  • Right to Not Be Profiled: Automated decision-making with significant effects requires human review

To exercise any right, email privacy@roadmaplodging.com with "DATA REQUEST" in the subject line. Include your full name, email, and specify the right you're invoking. We'll respond within 30 days.

8. International Data Transfers (GDPR/International)

Roadmap Lodging operates primarily in the United States. If you're in the EU/EEA or other regions with strict data protection laws:

  • Data transfers are covered by Standard Contractual Clauses (SCCs) approved by authorities
  • We have Data Processing Agreements (DPAs) with all sub-processors
  • GDPR Article 44+ compliance is verified annually by external auditors
  • You retain all rights under GDPR regardless of storage location

9. Children's Privacy

Roadmap Lodging is not intended for users under 18. We do not knowingly collect data from minors. If we discover a user is under 18, we will delete their data immediately. Parents/guardians concerned about a minor's data should contact privacy@roadmaplodging.com.

10. Corporate Account & Employee Privacy

For companies using Roadmap Lodging for employee relocation/temporary housing:

  • Business Agreement: Separate DPA governs corporate data handling; employer acts as Data Controller
  • Employee Notification: Employees must be informed that employer may access housing request status
  • Authorized Contacts: Only designated HR/Relocation managers receive employee personal data
  • Data Minimization: Employees retain rights to personal data independent of employer relationship
  • Third-Country Considerations: If employee works internationally, additional protections apply
  • Separation of Duties: Roadmap Lodging is not a party to employer-employee disputes regarding housing data

11. Policy Updates

We may update this policy to reflect legal changes or operational improvements. Material changes will be announced via email to registered accounts at least 30 days before taking effect. Continued use constitutes acceptance.

For corporate accounts, changes affecting employee data handling will be communicated directly to authorized contacts.

12. Security Recommendations for Users

While we maintain robust security, users should follow these best practices:

  • Strong Passwords: Use 12+ characters combining uppercase, lowercase, numbers, and symbols. Never reuse passwords across sites.
  • Multi-Factor Authentication (MFA): Enable MFA on your account. Use authenticator apps over SMS when available.
  • Device Security: Keep devices updated with latest security patches. Use antivirus software.
  • Network Safety: Avoid public Wi-Fi for sensitive transactions. Use VPN if needed.
  • Phishing Awareness: Never click links in unsolicited emails. Verify URLs before entering credentials.
  • Privacy Settings: Review your account privacy settings regularly. Limit visibility of personal information.
  • Credential Monitoring: Consider using identity theft monitoring services for high-risk roles.

13. Third-Party Services & External Links

Our platform may integrate with or link to third-party services:

  • No Endorsement: Roadmap Lodging is not responsible for third-party privacy practices
  • Data Sharing: Data shared with third parties is governed by their privacy policies
  • Integrated Services: Payment processors, CRM tools, and analytics platforms operate under their own terms
  • External Links: We are not responsible for content or policies on external websites
  • Vendor DPAs: Roadmap Lodging maintains Data Processing Agreements with all major vendors

14. Data Breach & Incident Response

In the unlikely event of a confirmed data breach:

  • Investigation: Roadmap Lodging will immediately investigate the scope and cause
  • Notification: Affected users notified within 72 hours (GDPR requirement) or per state law (max 30 days for CCPA)
  • Transparency: Breach details, affected data, and steps taken will be communicated clearly
  • Credit Monitoring: Complimentary credit monitoring offered to those affected by financial data exposure
  • Regulatory Reporting: Appropriate authorities notified per legal requirements
  • Remediation: Root cause analysis published; security enhancements implemented

15. Privacy Contact & Regulatory Compliance

Questions or Requests:

Email: info@roadmaplodging.com

Phone: (855) 552-9155

Mailing Address: Roadmap Lodging, Attn: Privacy Officer, 2261 Indiana Ave., Columbus, IN 47201

Response Time: 30 days for all privacy requests

Regulatory Authorities (if applicable):

  • CCPA/CPRA: California Attorney General (for California residents)
  • GDPR: European Data Protection Board (for EU/EEA residents)
  • HIPAA: HHS Office for Civil Rights (if health data involved)
  • Users have the right to lodge complaints with regulatory authorities

Legal Disclaimer & Recommendations: This Privacy Policy is provided as-is and does not constitute legal advice. Organizations using Roadmap Lodging for employee housing should:

  • Have their legal team review this policy before sharing with employees
  • Maintain their own privacy policies that reference Roadmap Lodging's data handling
  • Execute a Data Processing Agreement with Roadmap Lodging prior to use
  • Establish clear employee communication regarding data sharing practices