Legal · Roots Business

Business Privacy Policy

Last updated: 19 July 2026 · Effective from: 19 July 2026

This Privacy Policy explains what personal data we hold about the people who use Roots Business, the venue management app for Albanian tourism businesses, why we hold it, how long we keep it, where it is stored, and what rights you have. It is written in plain language. If anything is unclear, email us at hello@rootsalbania.com.

Roots Business is the authoring tool for our consumer travel guide Roots Albania. Verified local venues use it to publish events and activities that appear to travelers inside the Roots Albania app. This policy covers the business owners, managers, and staff who log in to Roots Business. The separate Roots Albania privacy policy covers travelers who use the consumer app.

1. Who we are (Data Controller)

Roots Business is operated by ROOTS SHPK, a limited liability company registered in Albania with the National Business Centre (Qendra Kombëtare e Biznesit), unique identification number (NUIS) M61803028A. We are the data controller under EU Regulation 2016/679 (GDPR) and Albanian Law no. 9887/2008 on Personal Data Protection (as amended).

  • Product name: Roots Business
  • Registered seat: Rruga Zef Jubani, Nd. 4, H. 1, Ap. 3, Njësia Administrative Nr. 5, 1000 Tiranë, Albania
  • NUIS: M61803028A
  • Contact email: hello@rootsalbania.com
  • Phone: +355 69 443 8348

2. The data we collect

Roots Business uses a proprietary username and password login. It does not use Apple, Google, or Facebook sign in, and it contains no advertising SDKs, no analytics SDKs, and no third-party trackers. The data we hold is the minimum needed to run your account and to publish your content.

2.1 Account data

  • Username. A short login name you choose. No email address is required to create a staff account.
  • Display name. The name shown inside the app.
  • Email address (managers only). Used to send password reset codes and important account notices. Staff accounts do not require an email at all (data minimization by design).
  • Password. Stored only as a one-way bcrypt hash. We never store or can read your actual password.
  • Security metadata. Login and lockout timestamps, failed-login counts, and hashed session (refresh) tokens with basic device information, used to keep your account secure.

2.2 Business profile (published by design)

So travelers can find you, the profile you create is public by design inside the Roots Albania app: business name, category, description, address, city, map coordinates, phone and WhatsApp number, website, social links, and your logo and cover image.

2.3 Content you publish (published by design)

The event and activity content you create, including titles, descriptions, and the images or video you upload, is displayed publicly to travelers. When you upload an image or video, our server re-encodes it and strips embedded location (EXIF/GPS) and metadata before it is shown, so staff phone locations are not leaked.

2.4 Support correspondence

If you email us, we keep your message and contact details to answer you and to keep a record of the request.

2.5 What we do NOT collect

  • No advertising identifiers and no cross-app tracking.
  • No analytics profiles of you.
  • No location permission is requested by the Roots Business app.
  • No payment or card data (the service is free; there are no in-app purchases).

3. Why we use this data (purpose & legal basis)

DataPurposeLegal basis (GDPR Art. 6)
Username, display name, password hashOperate your account and log you inContract performance (6(1)(b))
Business profilePublish your venue to travelers in Roots AlbaniaContract performance (6(1)(b))
Event and activity content and mediaPublish your events and activities to travelersContract performance (6(1)(b))
Manager emailPassword resets and account noticesContract performance (6(1)(b))
Login, lockout and session-token metadataKeep your account and our platform secureLegitimate interest (6(1)(f))
Content-moderation recordsHandle reports and keep the platform safeLegitimate interest (6(1)(f))
Records required by lawComply with tax, accounting and legal dutiesLegal obligation (6(1)(c))

4. Where your data is stored (hosting & processors)

All account data and all uploaded media are stored on servers inside the European Union. We use a small, fixed set of processors that act only on our instructions under written data-processing agreements. We do not sell your data and we run no advertising.

ProviderWhat they do for usWhere
Hetzner Online GmbHHosts our database and all uploaded images and video (server and storage)Germany, EU
Resend, Inc.Sends transactional email only (password reset codes to managers, and content-report alerts to our team)USA, under a data-processing agreement with EU Standard Contractual Clauses
Apple and GoogleApp distribution and crash reporting for the appUnder their own developer terms

We do not share your data with advertisers or data brokers, and we never sell it.

5. How long we keep data (retention)

  • Account data: for the life of your account. On an erasure request we anonymize the account so that audit records stay intact but your personal data is removed.
  • Session (refresh) tokens: pruned after they expire or are revoked, and in any case within 90 days.
  • Password reset codes: deleted after 30 days.
  • Event and activity media: automatically deleted about 90 days after the event or activity ends.
  • Support emails: kept for up to 24 months.

6. Your rights

Under GDPR and Albanian data-protection law you have the right to access, rectify, erase, restrict, and port your data, to object to processing based on legitimate interest, and to lodge a complaint with a supervisory authority.

To exercise any of these rights, email hello@rootsalbania.com. We acknowledge requests within 72 hours and fulfil them within 30 days. You may also complain to the Albanian Information and Data Protection Commissioner (idp.al) or your local EU supervisory authority.

Please note that your business profile and content are public by design; erasing your account removes it from public display.

7. Security

  • All traffic uses TLS 1.2 or higher.
  • Passwords are stored only as bcrypt hashes; no one, including us, can read them.
  • Data at rest is protected on EU infrastructure.
  • Access to production systems is restricted to a minimum number of authorised people.
  • In the unlikely event of a personal-data breach we will notify the relevant authority within 72 hours and inform affected users where the law requires it.

8. Children

Roots Business is a tool for businesses and is not directed at children. You must be an adult and authorised to act for the business to use it.

9. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date above and, where the change is material, notify managers by email or in the app.

10. Contact

For any privacy question, request, or complaint:

ROOTS SHPK · Roots BusinessRruga Zef Jubani, Nd. 4, H. 1, Ap. 3, 1000 Tiranë, Albania · NUIS M61803028AEmail: hello@rootsalbania.com