Legal · Roots Business

Business Privacy Policy

Last updated: 4 August 2026 · Effective from: 4 August 2026

This Privacy Policy explains what personal data we hold about the people who use Roots Business, the venue-management console for local tourism businesses in the cities Roots Earth covers, why we hold it, how long we keep it, where it is stored, and what rights you have. It is written in plain language. If anything is unclear, email us at hello@rootsearth.com.

Roots Business is the authoring tool for our consumer travel guide Roots Earth. Verified local venues use it to publish events and activities that appear to travelers inside the Roots Earth app. This policy covers the business owners, managers, and staff who log in to Roots Business. The separate Roots Earth privacy policy covers travelers who use the consumer app.

1. Who we are (Data Controller)

Roots Business is operated by ROOTS SHPK, a limited liability company registered in Albania with the National Business Centre (Qendra Kombëtare e Biznesit), unique identification number (NUIS) M61803028A. We are the data controller under EU Regulation 2016/679 (GDPR) and Albanian Law no. 9887/2008 on Personal Data Protection (as amended).

  • Product name: Roots Business
  • Registered seat: Rruga Zef Jubani, Nd. 4, H. 1, Ap. 3, Njësia Administrative Nr. 5, 1000 Tiranë, Albania
  • NUIS: M61803028A
  • Contact email: hello@rootsearth.com
  • Phone: +355 69 443 8348

2. The data we collect

Roots Business uses a proprietary username and password login. It does not use Apple, Google, or Facebook sign in, and it contains no advertising SDKs, no analytics SDKs, and no third-party trackers. The data we hold is the minimum needed to run your account and to publish your content.

2.1 Account data

  • Username. A short login name for your account. No email address is required to create a staff account.
  • Display name. The name shown inside the app.
  • Email address (managers only). Used to send your secure sign-in link, password reset codes, and important account notices. Staff accounts do not require an email at all (data minimization by design).
  • Password. Stored only as a one-way bcrypt hash. We never store or can read your actual password.
  • Security metadata. Login and lockout timestamps, failed-login counts, and hashed session (refresh) tokens with basic device information, used to keep your account secure.

2.2 Account request data

When you request an account through our website, we collect the business name, your name, email, city, country, and any phone, website, or note you provide, so we can review and set up your account. We store a salted hash of your network address (never a raw IP) to prevent abuse of the request form.

2.3 Business profile (published by design)

So travelers can find you, the profile you create is public by design inside the Roots Earth app: business name, category, description, address, city, map coordinates, phone and WhatsApp number, website, social links, and your logo and cover image.

2.4 Content you publish (published by design)

The event and activity content you create, including titles, descriptions, and the images or video you upload, is displayed publicly to travelers. When you upload an image or video, our server re-encodes it and strips embedded location (EXIF/GPS) and metadata before it is shown, so staff phone locations are not leaked.

2.5 Support correspondence

If you email us, we keep your message and contact details to answer you and to keep a record of the request.

2.6 What we do NOT collect

  • No advertising identifiers and no cross-app tracking.
  • No analytics profiles of you.
  • No location permission is requested by the Roots Business app.
  • No payment or card data (the service is free; there are no in-app purchases).

3. Why we use this data (purpose & legal basis)

DataPurposeLegal basis (GDPR Art. 6)
Username, display name, password hashOperate your account and log you inContract performance (6(1)(b))
Account request detailsReview your request and set up your accountSteps prior to a contract (6(1)(b))
Business profilePublish your venue to travelers in Roots EarthContract performance (6(1)(b))
Event and activity content and mediaPublish your events and activities to travelersContract performance (6(1)(b))
Manager emailSign-in links, password resets and account noticesContract performance (6(1)(b))
Login, lockout and session-token metadataKeep your account and our platform secureLegitimate interest (6(1)(f))
Content-moderation recordsHandle reports and keep the platform safeLegitimate interest (6(1)(f))
Records required by lawComply with tax, accounting and legal dutiesLegal obligation (6(1)(c))

4. Where your data is stored (hosting & processors)

All account data and all uploaded media are stored on servers inside the European Union. We use a small, fixed set of processors that act only on our instructions under written data-processing agreements. We do not sell your data and we run no advertising.

ProviderWhat they do for usWhere
Hetzner Online GmbHHosts our database and all uploaded images and video (server and storage)Germany, EU
Resend, Inc.Sends transactional email only (sign-in links and password reset codes to managers, and content-report alerts to our team)USA, under a data-processing agreement with EU Standard Contractual Clauses
Apple and GoogleApp distribution and crash reporting for the appUnder their own developer terms

We do not share your data with advertisers or data brokers, and we never sell it.

5. How long we keep data (retention)

  • Account data: for the life of your account. On an erasure request we anonymize the account so that audit records stay intact but your personal data is removed.
  • Account requests: a pending request expires after 7 days; declined requests are kept only as long as needed to prevent repeat abuse and are then removed.
  • Session (refresh) tokens: pruned after they expire or are revoked, and in any case within 90 days.
  • Password reset codes: deleted after 30 days.
  • Event and activity media: automatically deleted about 90 days after the event or activity ends.
  • Support emails: kept for up to 24 months.

6. Your rights

Under GDPR and Albanian data-protection law you have the right to access, rectify, erase, restrict, and port your data, to object to processing based on legitimate interest, and to lodge a complaint with a supervisory authority.

To exercise any of these rights, email hello@rootsearth.com. We acknowledge requests within 72 hours and fulfil them within 30 days. You may also complain to the Albanian Information and Data Protection Commissioner (idp.al) or your local EU supervisory authority.

Please note that your business profile and content are public by design; erasing your account removes it from public display.

7. Security

  • All traffic uses TLS 1.2 or higher.
  • Passwords are stored only as bcrypt hashes; no one, including us, can read them.
  • Data at rest is protected on EU infrastructure.
  • Access to production systems is restricted to a minimum number of authorised people.
  • In the unlikely event of a personal-data breach we will notify the relevant authority within 72 hours and inform affected users where the law requires it.

8. Children

Roots Business is a tool for businesses and is not directed at children. You must be an adult and authorised to act for the business to use it.

9. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date above and, where the change is material, notify managers by email or in the app.

10. Contact

For any privacy question, request, or complaint:

ROOTS SHPK · Roots BusinessRruga Zef Jubani, Nd. 4, H. 1, Ap. 3, 1000 Tiranë, Albania · NUIS M61803028AEmail: hello@rootsearth.com