Privacy Policy
Last updated: June 2026
This policy explains what information RoomPin collects, how we use it, and the choices you have. It applies to the RoomPin website at roompin.in and the RoomPin Android app, which share the same accounts and backend.
RoomPin is a flat-hunting platform for India that connects people looking for rooms, flats, and flatmates with the owners and brokers who list them. It is operated from India and free to use. We try to collect only what we need to make that matching work, and to keep the language here plain.
1. Information we collect
Information you give us
- Account details — your name, email address, phone number, and whether you are listing a place or searching for one. Your password is stored only as a secure one-way hash; we never store it in readable form.
- Profile photo — optional; only if you add one.
- Listing details — if you post a listing or a search, the location you choose on the map (coordinates and an area label), rent or budget, deposit, move-in date, property size, furnishing, and your gender and meal preferences for matching. Owners and brokers also upload property photos.
- Roommate compatibility profile ("your vibe") — if you are searching for a flatmate, optional lifestyle details you choose to share so we can suggest roommates you are likely to get along with: your sleep schedule, how tidy you keep your space, whether you smoke or drink, your work style (home, hybrid, or office), how often you have guests, your stance on pets, and a short free-text note about yourself. Every field is optional, and you can edit or remove them anytime from your Profile.
- Messages — the chat messages you send to other users through RoomPin, and any intro note you send when you start a conversation.
- Reports, blocks, and feedback — if you report a user or listing, block someone, request a new area, or send us feedback, we keep what you submit.
Information we collect automatically
- Device and connection data — your IP address, an approximate network range derived from it, and your browser/device user-agent string. We record these when you sign up and on sensitive actions, to prevent fraud, spam, and abuse.
- Activity data — a "last active" timestamp, and basic product-analytics events (such as page views and feature taps) so we can understand how RoomPin is used and improve it.
- Diagnostics — if something errors or crashes, we collect technical error reports to help us fix it.
- Cookies (website) — a secure, http-only session cookie that keeps you logged in for up to 7 days, and a separate cookie that protects against cross-site request forgery. We do not use third-party advertising cookies.
App push notifications (Android app only)
If you use the RoomPin Android app and allow notifications, the app registers a device push token with us (via Google Firebase Cloud Messaging) so we can notify you about new messages and matches — even when the app is closed. The token identifies the device, not you personally. You can turn notifications off at any time in your device settings, and logging out removes your device tokens from our servers.
2. How we use your information
- To run the core service — show listings, match owners and searchers, power your chat and inbox, and send you notifications you ask for.
- To send account and service emails (sign-up verification, password resets, and match/message/connection alerts) and app push notifications.
- To keep RoomPin safe — verify accounts by email one-time code, rate-limit requests, and detect and prevent fraud, spam, impersonation, and abuse.
- To understand and improve the product, and to diagnose and fix errors.
We do not sell your personal data, and we do not use it for third-party advertising.
3. What other users can see
RoomPin only works if people can find and contact each other, so some of your information is visible to other users:
- Visible to others: your name, your profile photo (if added), your listing or search details (including the location pin and area), the messages you send them, and a coarse "last active" indicator. When you appear as a potential roommate match, we may also show that person a few compatibility highlights you have in common (for example, "both non-smokers"); your free-text note and your individual lifestyle answers are not shown.
- Your email address is never shown to other users.
Your phone number stays private by default. It is never shown on public listings. In a conversation, your number becomes visible to the other person only when both of you have replied in the chat, or when you choose to tap "Share my number" (which reveals only your own number, to that one person). Until then, it stays hidden.
4. Service providers we share data with
We use a small number of trusted companies to run RoomPin. They process data only to provide their service to us, under their own privacy and security terms — not for their own purposes:
| Provider | What it handles |
| Amazon Web Services (AWS), Mumbai region | Server hosting |
| MongoDB Atlas | Database hosting |
| Cloudinary | Hosting and delivery of profile and property photos |
| Google Maps Platform | Maps, place search, and geocoding for the location you enter |
| Google Firebase Cloud Messaging | Delivering app push notifications (device token) |
| Brevo (Sendinblue) | Sending account and notification emails |
| PostHog (EU) | Product analytics |
| Sentry | Error and crash diagnostics |
We may also disclose information if required by law, or where we believe in good faith it is necessary to protect the rights, property, or safety of RoomPin, our users, or the public.
5. How we protect your information
Passwords are stored as salted one-way hashes (bcrypt). Connections to RoomPin use HTTPS. Logins use a secure, http-only session token, and non-GET requests on the website are protected against cross-site request forgery. No system is perfectly secure, but we work to protect your data and limit who can access it.
6. Keeping and deleting your data
You can delete your account at any time from your Profile page, or by request — see our account-deletion page. Deleting your account permanently removes your account and personal details (name, email, phone), your listings or search and any photos, your saved preferences, and your registered device tokens. Conversations you had stay in the other person's chat history with your side anonymised ("Deleted user"). We may retain a limited amount of information — such as security and audit logs — for as long as needed to prevent abuse and to comply with our legal obligations.
7. Your choices
- Email notifications — every notification email includes a one-click unsubscribe link, and you can turn match/notification emails off in your account.
- Push notifications — controlled by your device's notification permission; turn them off any time in Android settings.
- Access and deletion — you can view and edit your details in the app, and delete your account as described above. To ask a privacy question or make a request, email us at the address below.
8. Children
RoomPin is intended for adults. You must be 18 or older to create an account or use the service. We do not knowingly collect information from anyone under 18.
9. Changes to this policy
We may update this policy as RoomPin evolves. When we do, we will change the "Last updated" date above, and for material changes we will give you notice within the app, by email, or on this page. Continuing to use RoomPin after a change means you accept the updated policy.
10. Contact us
If you have any questions about this policy or your data, email us at contact@roompin.in.