ROMP
Home

Privacy Policy (Datenschutzerklärung)

Effective: 1 July 2026 | Last updated: 27 July 2026

This Privacy Policy explains how Romp Network ("we", "us", "Romp") collects, uses, and protects personal data in accordance with the Swiss Federal Act on Data Protection (revDSG, in force since 1 September 2023).

1. Controller

Data controller: Romp Network
Contact: privacy@romp.network
(You may contact us in English, German, or French.)

2. Personal Data We Collect

CategoryDataPurposeLegal basis
Account Username, password (hashed), email (optional), profile text, avatar image Account creation and management Contract (DSG Art. 31 lit. b)
Marketplace activity Listings, offers, deals, ratings, comments, direct messages Operating the marketplace Contract
Payments Payment method data (processed by Stripe / GNU Taler), transaction amounts and timestamps Processing payments and fulfilling legal accounting obligations Contract; Legal obligation (CO Art. 962)
Content moderation Content flagged by automated review, moderation decisions and timestamps Enforcing community guidelines; preventing fraud Legitimate interest (DSG Art. 31 lit. d)
Technical logs IP address, HTTP request logs, error traces Security, debugging, rate limiting Legitimate interest

3. Data Retention

Data categoryRetention period
Active user accountUntil deletion request or 2 years of inactivity
Inactive accounts (no login)2 years, then anonymised
Transaction records (amounts, dates)10 years (CO Art. 962)
Direct messages1 year after conversation ends
IP address / access logs6 months
Moderation decisions3 years
Uploaded files (digital goods)Until listing deleted + 30 days
Payment dataPer Stripe / GNU Taler processor terms

4. Recipients and Third-Party Processors

  • Stripe, Inc. (USA) — payment processing. Transfer safeguard: EU Standard Contractual Clauses (SCCs). See stripe.com/privacy.
  • GNU Taler — privacy-preserving payment protocol operated on-premise. No personal data is shared with external Taler nodes.
  • OpenSearch / Grafana / Loki — observability stack operated on-premise within the cluster. No data leaves the cluster.

We do not sell personal data to third parties.

5. Your Rights (DSG Art. 25–27)

You have the right to:

  • Access — request a copy of all personal data we hold about you
  • Rectification — correct inaccurate data via your profile settings
  • Deletion — delete your account via DELETE /api/userprofiles/me/ or by contacting us. Personal data is anonymised; transaction records are retained for 10 years as required by CO Art. 962.
  • Portability — request a machine-readable export of your data
  • Objection to automated decisions — if your content is flagged by our automated moderation system, you may request human review

To exercise any of the above rights, email privacy@romp.network. We will respond within 30 days.

6. Automated Decision-Making

We use an automated content moderation system to review marketplace listings and offers. If your content is flagged by this system, you will receive a notification and may request human review. We will respond to human review requests within 7 days. (DSG Art. 21)

7. Data Breach Notification

In the event of a data breach that poses a risk to you, we will notify you and the Federal Data Protection and Information Commissioner (FDPIC) as quickly as possible and within 72 hours of becoming aware of the breach (DSG Art. 24).

8. Supervisory Authority

You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).

9. Changes to this Policy

We may update this policy to reflect changes in our practices or applicable law. We will post the updated policy on this page with a new effective date. Continued use of Romp after the effective date constitutes acceptance.

© 2026 Romp Network. All rights reserved.  |  Privacy Policy