Roam Moon Cloud

Privacy Policy

1. Scope

This policy covers the Roam Moon Cloud console at cloud.roammoon.com and the API at core.roammoon.com, both operated by ROAM MOON COMPANY LIMITED.

2. What we collect

  • Account data: your email address, and your name and avatar if you choose to sign in with Google or GitHub.
  • Workspace data: workspace name, members and their roles.
  • Request logs: the time of each API call, its request id, the endpoint, the HTTP status, how long it took, the request and response size, and which API key was used.
  • Technical data: IP address and user agent, used for security and for enforcing rate limits.
  • Billing data: your plan, invoices and transaction identifiers. Card details are handled by our merchant of record and never reach us.

3. Images you send to the API

An image you upload is passed straight through to the recognition service and is not stored on our gateway.

Neither the image nor the recognised plate text is written to our request logs. Those logs hold only the metadata listed above, which is what we need in order to bill accurately and to investigate a problem you report.

An image is processed for the sole purpose of producing the result for that one request.

4. Why we collect it

  • To operate the service and authenticate your requests.
  • To measure usage and bill it accurately.
  • To detect and prevent abuse, fraud and attacks.
  • To answer your support requests.
  • To meet accounting, tax and other legal obligations.

5. Who else processes your data

We do not sell personal data. We share it only with the providers needed to run the service, and only to the extent each one needs.

  • Cloudflare, for hosting, database and content delivery.
  • Polar, for payment processing as merchant of record, including invoicing and tax. We may also use Paddle in the same role.
  • Resend, for sending transactional email such as verification codes.
  • Google and GitHub, but only if you choose to sign in with one of them.
  • Competent authorities, where the law requires it.

6. How long we keep it

  • Request logs: 3 days on Hobby, 7 days on Pro, 30 days on Scale. They are deleted automatically after that.
  • Account and workspace data: for as long as the account exists.
  • Billing records: for as long as accounting and tax law requires them to be kept.

7. How we protect it

  • All traffic runs over HTTPS.
  • API keys are stored only as a keyed hash. The key itself is shown once and never stored.
  • Passwords are hashed with PBKDF2 at 600,000 iterations.
  • Session cookies are HttpOnly and use the __Host- prefix, with CSRF protection on state-changing requests.
  • Credentials are never written to logs.

8. Your rights

You may ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. Write to the email address below from the address on the account. We answer within 30 days.

Deleting an account removes its data, except records we are required by law to keep, such as invoices.

9. International transfers

Our infrastructure and payment providers operate globally, so your data may be processed outside Vietnam. Where that happens we rely on the safeguards those providers offer, including the standard contractual clauses approved by the European Commission.

10. Cookies

The console sets cookies that are needed to keep you signed in and to protect against cross-site request forgery. It does not set advertising cookies. Blocking these cookies will prevent you from signing in.

11. Children

This is a product for businesses and developers. It is not directed at children, and we do not knowingly collect data from anyone under 16.

12. Changes to this policy

We may update this policy. A material change is announced by email or in the console before it takes effect.