Your data,
clearly handled.

PRIVACYUseful data.
Limited purpose.
Community features use only the information needed to verify, notify and protect the service.

01 / WHAT WE COLLECT

Only what
the feature needs.

Public Passport Roam pages can be browsed without an account. Community questions require an email address for one-time verification. The email is kept private and is not displayed as part of a question or answer.

Community content may include the text, links and optional display name that a visitor submits. Technical information such as request time, IP-derived abuse-prevention hashes and service logs may be processed to protect the service.

02 / HOW WE USE IT

Verification,
notifications and safety.

Community email is used to send a one-time verification link, identify the verified question author, create a trusted-device session and send notifications for new answers to that author’s question.

Answer notifications contain the question title, a link back to the website and a single-question unsubscribe link. They do not include the answer text.

Submitted content and technical signals are also used for duplicate detection, rate limiting and basic automated abuse prevention.

03 / COOKIES

Small cookies,
specific jobs.

Community uses secure, HttpOnly cookies for verified question-author sessions and anonymous answer edit/delete capability. These cookies are not used to display the user’s email publicly.

Temporary browser storage may preserve an unfinished question draft for a short period so that a visitor can return from the verification email without losing their work. Authentication and content ownership do not rely on browser storage.

04 / SERVICE PROVIDERS

Specialist services
behind the site.

Bluehost hosts the static website and the small PHP API proxy. Supabase provides the Community PostgreSQL database and Edge Function API. Resend sends verification and answer notification emails.

These services receive only the information required for their respective jobs. Passport Roam does not sell Community email addresses or use them for unrelated marketing.

05 / RETENTION AND CONTROL

Keep what is useful.
Remove what is not.

Published Community questions and answers remain available while they are useful and consistent with the site’s content rules. Hidden or deleted content is removed from public views; operational backups and logs may retain limited records for a reasonable recovery or security period.

Answer notifications can be stopped at any time through the single-question unsubscribe link. To request correction or deletion of Community content or associated email data, use the Contact page and identify the relevant question URL.

06 / AUTOMATION

Human content,
careful automation.

At the current stage, Passport Roam does not use AI to make visa decisions or automatically judge the value of a traveller’s advice. Basic automated checks help prevent repeated and abusive submissions.

If automated AI content screening is introduced later, this policy and the relevant processing details will be updated before that feature is enabled.

Read the content disclaimer