HomeFavoritesLogoLogoHelpSettings

Notifications

All caught up!

No new notifications to display right now. Check back later!

Sri Lanka PDPA (2022) & GDPR Certified Compliancev2.3

Privacy Policy

Learn how RoamLK collects, protects, and handles your personal data, booking details, and privacy rights across our Sri Lanka travel platform.

Last Updated: March 1, 2026Effective: March 15, 2026Reading Time: ~9 min
Terms and conditions

No Data Selling

We never sell or monetize your personal data or travel search habits to advertisers.

TLS 1.3 & AES-256

Full end-to-end cryptographic encryption across all user communications and stored records.

Right to Erasure

Full control to export your booking records or delete your account at any time.

DPO Oversight

Direct access to our dedicated Data Protection Officer via support@roam.lk.

Section 1

Introduction & Data Controller Information

Summary: RoamLK values your trust and is committed to protecting your personal information under the Sri Lanka Personal Data Protection Act No. 9 of 2022 and GDPR.

This Privacy Policy explains how RoamLK Private Limited ("RoamLK", "we", "us", or "our") collects, uses, stores, shares, and protects your personal data when you visit our website (roam.lk), use our mobile services, make lodging bookings, or partner with us as a property host.

Under the Personal Data Protection Act (PDPA) No. 9 of 2022 of Sri Lanka and applicable international data protection standards (such as the EU General Data Protection Regulation (GDPR) for our international guests), RoamLK acts as the Data Controller responsible for your personal information.

Designated Data Protection Officer (DPO): For any privacy-related requests, data subject access queries, or rights exercise, contact our DPO at support@roam.lk.
Section 2

Categories of Personal Data We Collect

Summary: We collect information provided directly by guests and hosts, automated device logs, and lodging verification records required by Sri Lankan regulations.

We collect personal information across three main categories:

A. Guest Information

Account & Contact: Full name, email address, mobile phone number, nationality, residential address.
Statutory Lodging Records: Passport number or National Identity Card (NIC) number (mandated by Sri Lankan tourist accommodation regulations for guest registration registers).
Booking Details: Check-in/check-out dates, guest counts, room preferences, special dietary or accessibility notes.

B. Host & Partner Information

Partner Identity: Business name, owner/manager name, contact details, official Business Registration (BR) certificate, tax identification.
Payout Data: Bank account name, account number, bank code, and branch details for payout disbursements.
Listing Information: Property address, GPS coordinates, photos, amenities, house rules, pricing models.

C. Automated & Technical Data

Device & Browsing: IP address, device model, operating system, browser type, referring URLs, access timestamps.
Location Information: Approximate geolocation inferred from IP or precise GPS coordinates (when explicitly authorized for "stays near me" searches).
Payment Tokenization: Credit/debit card numbers are tokenized directly by our PCI-DSS Level 1 certified payment processors (e.g., PayHere, Stripe). RoamLK never stores raw card details on its servers.

Section 4

Third-Party Data Sharing & Disclosures

Summary: We share personal data strictly on a need-to-know basis with property hosts, certified payment gateways, and cloud service providers.

We do not sell, rent, or trade your personal information to third parties. We only disclose personal information under the following limited circumstances:

  • Property Hosts / Accommodations: When a booking is confirmed, we share the guest's full name, phone number, arrival schedule, and special requests with the host to prepare the stay and fulfill check-in.
  • Payment Service Providers: Encrypted transaction data is transmitted to authorized payment gateways (e.g., PayHere, Stripe) for secure authorization and fraud screening.
  • Infrastructure & IT Providers: Trusted cloud hosting, database hosting (MongoDB / AWS / GCP), transactional email (SendGrid/Resend), and SMS dispatch services operating under strict Data Processing Agreements (DPAs).
  • Statutory & Law Enforcement Bodies: When legally mandated by a valid court order, warrant, or regulatory requirement issued by Sri Lankan law enforcement or tourism authorities.
Section 5

International Data Transfers

Summary: Personal data may be processed in secure international cloud regions with encryption and standard contractual clauses.

To maintain 24/7 reliability, fast asset delivery, and encrypted backups, your data may be processed and stored on cloud servers located outside of Sri Lanka (e.g., in AWS/GCP regions in Singapore or Europe).

Where cross-border transfers occur, we implement appropriate safeguards in compliance with Part V of the Sri Lanka PDPA and international transfer frameworks, ensuring that recipient data centers maintain equivalent levels of data privacy and encryption.

Section 6

Data Retention & Archival Policies

Summary: Data is retained only as long as necessary for booking execution, statutory tax auditing, and legal dispute resolution.

We retain personal information in accordance with statutory retention schedules:

Account Profile Data

Retained for the lifetime of your active account, or until account deletion is requested.

Booking & Tax Invoices

Retained for 5–7 years to comply with Sri Lankan Inland Revenue and corporate audit laws.

Security & Analytics Logs

IP access logs and diagnostic telemetry are rotated and purged automatically after 90 days.

Section 7

Your Data Rights & Privacy Controls

Summary: You hold the right to access, rectify, export, and erase your personal data at any time.

Under the Sri Lanka PDPA and GDPR, you are entitled to the following fundamental rights:

1. Right to Access & Copy

Request confirmation and a portable digital copy of all personal data held about you.

2. Right to Rectification

Correct inaccurate or outdated profile details directly via your Settings page.

3. Right to Erasure ("Right to be Forgotten")

Request total deletion of your user account and associated personal data, subject to statutory tax record retention requirements.

4. Right to Withdraw Consent

Instantly opt-out of promotional communications via 1-click unsubscribe links or profile preferences.

How to Submit a Data Rights Request:Email support@roam.lk with your registered account email. We respond to verified requests within 21 business days.
Submit Request →
Section 8

Cookies & Tracking Technologies

Summary: We use essential session cookies for authentication, currency selection, and security, with optional analytical metrics.

Cookies are small text files stored on your browser to ensure seamless navigation, preserve active sessions, and save your currency preferences.

Cookie TypePurposeLifespan
Strictly Necessary CookiesUser login authentication token, CSRF security verification, and currency selection state.Session to 30 days
Functional CookiesRemembering search destination filters, recent views, and dark/light UI theme mode.Up to 1 year
Performance & AnalyticsAggregated anonymous page speed and checkout error telemetry to improve site usability.Up to 6 months

You can configure your browser settings to block or delete cookies. Note that disabling essential cookies may impact booking checkout functionality.

Section 9

Data Security & Technical Safeguards

Summary: Industry-standard cryptographic encryption (TLS 1.3, AES-256) and strict role-based access protect your data.

RoamLK enforces rigorous technical and organizational measures to safeguard personal information against accidental loss, unauthorized access, or tampering:

  • Encryption in Transit: All communication between your browser and our servers is secured via TLS 1.3 encryption with 256-bit keys.
  • Encryption at Rest: Database records and document archives are stored in encrypted cloud volumes with automated cryptographic key rotation.
  • Role-Based Access Controls (RBAC): Employee access to guest or host personal data is strictly restricted on a least-privilege, business-need basis.
  • Continuous Vulnerability Auditing: Regular automated security scanning and penetration testing on our API endpoints and server clusters.
Section 10

Children's Privacy (Under 18)

Summary: RoamLK services are exclusively for individuals aged 18 and older. We do not knowingly collect data from minors.

Our platform is intended strictly for adults of legal age (18+). We do not knowingly solicit or collect personal information from individuals under the age of 18.

If we discover that a minor under 18 has submitted personal data without verified parental consent, we will promptly delete the data and terminate the account. If you believe a minor has registered on RoamLK, please notify us immediately at support@roam.lk.

Section 11

Contact Our DPO & Grievance Redressal

Summary: Reach our dedicated privacy office for any questions, complaints, or regulatory inquiries.

If you have any questions about this Privacy Policy, wish to file a grievance, or request data erasure, our Data Protection Officer is ready to assist:

Data Protection & Privacy Office

RoamLK Private Limited
Attn: Data Protection Officer (DPO)
Colombo, Western Province, Sri Lanka
Email: support@roam.lk
General Inquiries: support@roam.lk

Under the Sri Lanka Personal Data Protection Act No. 9 of 2022, if you are unsatisfied with our response to your grievance, you hold the right to lodge a complaint with the Data Protection Authority of Sri Lanka.

This Privacy Policy is administered in compliance with the Personal Data Protection Act No. 9 of 2022 of Sri Lanka.

Inquiries & requests: support@roam.lk