Privacy policy
The short version: we run no ad trackers, we don't know your name unless you tell us, and we couldn't sell your data if we wanted to — we barely have any.
Last updated: September 2026
What we collect (all of it)
Anonymous click IDs. When you click 'Get plan' and we send you to a provider, we generate a random ID (a 'subid') for that click and store which plan, which country page, what kind of device (just 'mobile', 'desktop', or 'bot' — nothing more specific), the page you came from, and the time. This is how we find out whether our recommendations actually lead to purchases, and it's how we get paid. None of it identifies you.
A session cookie. On your first visit we set a random ID in a cookie so we can tell that two clicks came from the same browser. It contains no personal information — it's a coin flip with 122 bits.
Contact form submissions. If you write to us, we store the name, email address, and message you typed, because replying to you without them would be a magic trick we haven't mastered. We use them only to reply. Cloudflare stores your enquiry, and Emailit processes those details to deliver it to our team by email. Your email is used as the reply address. Open and click tracking are disabled for these messages, and contacting us does not subscribe you to marketing.
App launch list. If you opt in, we store your email, preferred phone platform and timestamped consent in Cloudflare D1, solely for RoamSonar app launch updates. These addresses are not added to our deals or review lists. We retain them until launch communications finish or you ask for removal through our contact form. Launch emails include a personal opt-out link. Temporary daily secret-keyed network hashes and request counters limit signup abuse; no raw IP is stored with your subscription. Expired counters are removed during subsequent signup admission.
Optional price alerts and verified reviews. If you ask for a country price-drop alert, we store the email address, country and anonymous session you submitted it from. We use it for the alert or digest you requested and may send a one-use review or speed-report invitation after that anonymous session clicks a provider. Review submissions store the rating and words you provide; your email is used to enforce one review per provider and is never shown publicly. Every email includes an unsubscribe path, and we do not add it to unrelated marketing.
Your currency preference. If you switch the display currency, we remember it in a cookie so you don't have to switch it again.
Your language preference. If you choose English, French, or Simplified Chinese, we remember that choice in a cookie. The language itself is also explicit in the page URL, so we never infer it from your identity or browsing history.
Admin cookies. Our own staff logins use an authentication cookie. Unless you work here, this one's not about you.
Developer API and MCP protection. Cloudflare supplies the connecting network address. We derive a daily, secret-keyed hash of the IPv4 address or IPv6 /64 network and keep short-lived request counters in Cloudflare Durable Object storage, separate from the catalogue. These counters contain no raw IP, prompt, trip, response or contact details. Counter cleanup is scheduled within 48 hours; Cloudflare’s infrastructure logs and recovery retention are separate. Shared networks share an allowance. Our read-only MCP service does not call an AI model; your chosen assistant handles its own processing under its own privacy policy.
Saved-search links contain only validated trip filters, never your paragraph. Anyone with the link can see those filters; your browser history and hosting request logs may retain the URL. Reopening a link checks current catalogue prices without AI. We store one anonymous daily request counter to enforce the AI budget, not individual search records.
Optional AI destination search
When you submit a trip paragraph, we send that text and eligible country codes to OpenRouter to interpret your search. Do not include names, email addresses, payment details or other personal information in the paragraph. We do not attach your IP address or browser cookies to the AI request. The manual country form does not use AI.
RoamSonar does not save your paragraph, trip choices or AI reply in its database or application logs. We request zero-data-retention routing and prohibit provider data collection for inference. OpenRouter and its model providers process the request under their own policies; this does not assert that every account-level logging setting has been independently audited. Read OpenRouter’s data policy.
Cloudflare processes requests to host this feature. A temporary hash derived from the connecting IP helps limit abuse; it is not added to our catalogue or contact database. If AI is unavailable or a limit is reached, use the normal country selector. We do not use these searches to train a RoamSonar model.
What we deliberately don't collect
No Google Analytics, Meta pixel, fingerprinting or heatmaps. We do not store your IP address with affiliate clicks; we reduce the user-agent to a broad device class. We do not buy, sell or rent your personal information, or add you to unsolicited marketing. Service-provider processing and optional features are described in this policy.
Cookies we set
| Cookie | Purpose | Lifetime |
|---|---|---|
sid | Anonymous session ID (random UUID) so clicks from the same browser can be grouped. HttpOnly, SameSite=Lax. | 1 year |
cur | Remembers your chosen display currency (e.g. EUR). | 1 year |
lang | Remembers your chosen site language (English, French, or Simplified Chinese). | 1 year |
cur_toast | Shows the one-time automatic-currency notice. | 5 minutes |
price_alert_seen | Stops the country price-alert prompt repeating during the same browser session. | Session |
sess | Keeps RoamSonar staff logged in to the admin panel. HttpOnly, SameSite=Strict. Only set if you log in as an admin. | 7 days |
That's the whole list. No third-party cookies are set by this site.
When you click out to a provider
RoamSonar is a comparison site, and we earn a commission from affiliate links. When you click through to a provider, the link tells them you arrived via RoamSonar, along with our anonymous click ID. If you buy, the provider may report that a sale happened for that click ID — that's how we get paid, and it's the entire transaction between us and them. The provider never sends us your name, email, payment details, or anything else about you, and we never send them anything about you beyond that random ID. Once you're on their site, their privacy policy applies — worth a skim, as always.
How long we keep things
Click records: 18 months, then automatically deleted (a weekly job removes anything older). Contact messages: until resolved, then periodically cleared. Price-alert subscriptions and review invitations: until you unsubscribe, use the invitation, or ask us to delete them. Published reviews remain until withdrawn or removed through moderation. Session, language, and currency cookies expire as listed above, and you can delete them anytime in your browser. Server logs at our host (Cloudflare) are governed by Cloudflare's own retention and are not something we mine.
Your rights
Depending on where you live, you may have rights to access, correct, delete or export your personal information. This can include messages, optional price-alert subscriptions and review information you have provided. Use our contact form and start your message with PRIVACY; we aim to respond within 30 days. You may also contact your local data-protection authority.
Changes to this policy
If we change what we collect — for example, if we ever add privacy-respecting analytics — we'll update this page and change the 'Last updated' date at the top before the change takes effect. We won't retroactively do anything sneaky with data collected under an older, stricter policy.