Trust Signal

Privacy & Cookie Notice

How Rooni handles personal data and cookies in connection with our website and Trust Signal.

This Privacy & Cookie Notice explains how Rooni ("we", "us") collects, uses, stores, and protects personal data in connection with our website, our business, and Rooni Trust Signal. It also explains how we use cookies and similar technologies.

1. Who we are

Rooni provides Trust Signal, a consent management platform for websites, apps, and digital services.

  • Company name: Rooni
  • Product name: Trust Signal
  • Website: rooni.io
  • Contact email: [email protected]
  • Data Protection Officer: We have not appointed a Data Protection Officer. Privacy enquiries can be sent to the contact above.

2. When this notice applies

This notice applies when you visit our website; create a Trust Signal account; request a demo; contact us; subscribe to our service; use our dashboard or platform; interact with our support, sales, marketing, or billing processes; or receive communications from us. It also explains, at a high level, how we process end-user consent data on behalf of our Customers.

3. Our role: controller and processor

When Rooni acts as controller. Rooni acts as controller when we decide why and how personal data is processed. This includes data relating to website visitors to rooni.io, account owners and authorised users, demo requests, billing contacts, support enquiries, marketing communications, security monitoring, and service improvement.

When Rooni acts as processor. Rooni generally acts as processor when we process consent records, preference data, and related technical data on behalf of our Customers using Trust Signal. In that case, the Customer is usually the controller and is responsible for explaining the processing to its own website or app users. If you are an end user of a website that uses Trust Signal, you should contact the owner of that website to exercise privacy rights relating to that website's use of your data.

4. Personal data we collect

Account and user data: name, email address, company name, job title, login details, account settings, team membership, authentication information, user role and permission settings.

Billing and subscription data: billing contact details, company details, billing address, tax information, subscription plan, payment status, invoices and transaction references. Payment card details are processed by our payment provider (Paddle) and are not stored directly by Rooni.

Website and device data: IP address, browser type, device type, operating system, pages viewed, referral source, approximate location, interaction events, cookie identifiers, consent preferences.

Support and communication data: emails and messages you send us, support tickets, chat messages, call notes, feedback, uploaded files or screenshots, technical diagnostic information.

Product usage data: login events, dashboard usage, websites or domains added to your account, configuration changes, scan history, consent banner settings, consent categories, integration settings, API usage, error logs, audit logs.

Consent and preference data processed for Customers: consent choices, consent category status, consent signal values, timestamps, banner version, policy version, preference centre interactions, user region or jurisdiction, device or browser information, anonymous or pseudonymous identifiers, proof-of-consent records.

5. How we collect personal data

We collect personal data directly from you when you submit forms, create accounts, or contact us; automatically through our website, platform, cookies, logs, and analytics tools; from payment, authentication, support, and infrastructure providers; from Customers who configure and use Trust Signal; and from public sources where relevant for business contact or security purposes.

6. Why we use personal data

PurposeExamplesLikely lawful basis
Provide Trust SignalAccount access, dashboard, consent tools, scans, scripts, supportContract
Manage subscriptions and billingPlans, invoices, payment status, tax recordsContract / legal obligation
Support CustomersTroubleshooting, tickets, diagnosticsContract / legitimate interests
Secure the serviceFraud prevention, logs, access controls, abuse detectionLegitimate interests / legal obligation
Improve the productUsage analytics, error monitoring, feature improvementLegitimate interests
Service communicationsAccount notices, security alerts, product updatesContract / legitimate interests
MarketingNewsletters, product updates, demo follow-upConsent / legitimate interests depending on context
Comply with lawAccounting, tax, regulatory requests, legal claimsLegal obligation / legitimate interests
Process Customer consent recordsStore and manage consent choices for Customer websitesCustomer instructions / processor role

7. Cookies and similar technologies

Cookies and similar technologies may store or access information on a user's device. We may use cookies, pixels, local storage, scripts, tags, and similar technologies on our website and platform.

8. Types of cookies we use

Strictly necessary cookies. Required for our website or platform to function. They may support security, login, session management, load balancing, consent storage, fraud prevention, and core service functionality. These cannot usually be disabled.

Functional cookies. Help remember choices such as language, region, interface settings, or saved preferences.

Analytics cookies. Help us understand how users interact with our website and platform, such as which pages are visited, which features are used, and where errors occur.

Marketing cookies. May help us measure campaigns, understand referrals, or show relevant advertising.

Consent management cookies. Trust Signal may set or read cookies or local storage to remember consent preferences and ensure the correct consent state is applied.

9. Cookie consent

Where required, we ask for consent before setting non-essential cookies. You can update your choices using our cookie banner or preference centre at any time — Trust Signal itself is the consent layer on rooni.io.

10. Managing cookies

You can manage cookies through our consent banner or preference centre, your browser settings, your device privacy settings, and third-party opt-out tools where available. Blocking some cookies may affect website or platform functionality.

11. How long we keep personal data

We keep personal data only as long as reasonably necessary for the purposes described in this notice.

Data typeTypical retention
Account dataFor the life of the account, then deleted or anonymised within 90 days
Billing recordsRetained for legal, accounting, and tax periods (typically up to 10 years)
Support recordsRetained for 24 months after closure
Security and audit logsRetained per workspace configuration (12–120 months; default 24 months)
Marketing contactsUntil unsubscribed or inactive for 24 months
Consent records processed for CustomersRetained per Customer configuration (12–120 months) and the DPA
Website analyticsRetained for 14 months

12. Who we share personal data with

We may share personal data with hosting and infrastructure providers, database and storage providers, payment processors, authentication providers, analytics providers, email and communication providers, customer support tools, professional advisers, regulators, courts, or public authorities where required, and buyers or successors in connection with a business sale, merger, or restructuring. We do not sell personal data.

13. Sub-processors

To provide Rooni Trust Signal, we use trusted third-party service providers that may process personal data on our behalf. Where required, we enter into contracts with our sub-processors that impose data protection obligations designed to provide an appropriate level of protection for personal data. We remain responsible for our sub-processors where required by applicable data protection law and by our Data Processing Addendum.

Sub-processorServiceRegionData processed
SupabaseDatabase, authentication, storageEUAccount data, configuration, consent records, logs
CloudflareHosting, CDN, edge runtimeGlobalHTTP requests, IP address, configuration
PaddleBilling and subscriptions (Merchant of Record)UK / EUBilling contact, subscription, invoice and payment metadata
BrowserlessHeadless browser for website scansEUScanned website URLs, scan output
Google AI (Lovable AI Gateway)Script classification and translationsEU / USScript URLs, snippets, content to classify or translate
Google (Auth)Optional sign-in with GoogleGlobalName, email, authentication identifiers

We may update our sub-processors from time to time. Where Rooni acts as a processor for a Customer, we will provide notice of intended changes where required by our DPA. Customers may object to a new sub-processor where they have a reasonable data protection concern. Questions about our sub-processors can be sent to [email protected].

14. International transfers

Some service providers may process data outside your country, the UK, or the European Economic Area. Where required, we use appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, transfer risk assessments, or other lawful transfer mechanisms.

15. Security

We use reasonable technical and organisational measures to protect personal data, including access controls, encryption where appropriate, logging, monitoring, backups, and secure infrastructure practices. However, no system is completely secure.

16. Children

Trust Signal is not intended for children and should not be used by individuals under 16 years old. We do not knowingly collect personal data from children.

17. Automated decision-making

Rooni does not use personal data to make decisions that produce legal or similarly significant effects solely by automated means.

18. Your privacy rights

Depending on the law that applies, you may have the following rights in relation to personal data we process.

Who to contact. If you are a Rooni website visitor, account user, trial user, customer contact, or billing contact, contact Rooni directly at [email protected]. If you are a visitor to a website using Trust Signal, Rooni usually acts as a processor for that website owner — the website owner is normally responsible for responding to your privacy request, and you should contact the website or business where you submitted your consent choice. If you contact Rooni about a Customer website, we may redirect your request to the relevant Customer where appropriate.

Right to be informed. You have the right to receive clear information about how your personal data is collected, used, shared, and stored. This is why we provide this Privacy & Cookie Notice.

Right of access. You may request confirmation of whether we process your personal data and ask for a copy of that data.

Right to rectification. You may ask us to correct inaccurate or incomplete personal data.

Right to erasure. You may ask us to delete your personal data in certain circumstances. This right may not apply where we need to keep data for legal, security, contractual, accounting, or legitimate business reasons.

Right to restriction. You may ask us to restrict how we use your personal data in certain circumstances.

Right to data portability. Where applicable, you may ask to receive personal data you provided to us in a structured, commonly used, machine-readable format.

Right to object. You may object to processing based on legitimate interests or direct marketing. If you object to direct marketing, we will stop using your personal data for that purpose.

Right to withdraw consent. Where we rely on consent, you may withdraw that consent at any time. Withdrawing consent does not affect processing that took place before consent was withdrawn. For cookies, you can update your choices through our cookie banner or preference centre.

Rights relating to automated decision-making. You may have rights relating to decisions made solely by automated processing where those decisions have legal or similarly significant effects. Rooni does not currently use personal data for this type of automated decision-making.

How to submit a request. Email [email protected] with your name, your email address, the right you want to exercise, the account, website, or service your request relates to, and enough information for us to verify and process the request. We may need to verify your identity before responding.

Response times. We aim to respond within the timeframe required by applicable law. For GDPR and UK GDPR requests, this is usually within one month, although it may be extended where requests are complex or numerous.

When we may refuse or limit a request. We may refuse, limit, or delay a request where permitted by law, including where we cannot verify your identity; the request is manifestly unfounded or excessive; the data is required for legal claims; the data must be retained for legal, tax, accounting, or security reasons; or the request relates to data controlled by one of our Customers rather than Rooni.

Complaints. You may have the right to complain to a data protection authority. If you are in the UK, this may be the ICO. If you are in the EEA, you may contact your local supervisory authority (in France, this is the CNIL). We encourage you to contact us first so we can try to resolve the issue.

Cookie and consent choices. For Rooni's own website, you can manage cookie choices through our cookie banner or preference centre. For websites using Trust Signal, your consent choices are controlled by the relevant website owner — use that website's banner, preference centre, or privacy contact.

Customer website consent records. If Trust Signal is used on a Customer website, the Customer decides what technologies are used; what consent categories are shown; what lawful basis applies; how long consent records are retained; and how privacy requests are handled. Rooni processes those records according to the Customer's instructions and the Data Processing Addendum.

19. Changes to this notice

We may update this Privacy & Cookie Notice from time to time. If we make material changes, we will take reasonable steps to notify users, such as by posting a notice on our website or within the platform.

20. Contact us

For privacy questions, contact the Rooni Privacy Team at [email protected].

Effective date: 25 May 2026 · For questions, contact us at [email protected]

← Back to home