1. Who this policy covers
This policy applies to the RoamID service available at roamid.app and to people whose information RoamID handles through that service. This includes account holders, authorised managers and Account Stewards, people represented by Emergency Profiles, nominated in-case-of-emergency (ICE) contacts, and people who use an active tag URL.
RoamID is the registered business name used by Nicholas C. Gleeson (ABN 78 486 967 639) as the Founding sole-trader operator. In this document, “RoamID”, “we”, “us” and “our” mean that operator of the RoamID service available at roamid.app.
This policy describes the current Founding Release application. It does not describe an unimplemented checkout, marketing-signup, general contact-form or support-ticket system.
2. Emergency Profiles are intentionally public
An Emergency Profile connected to a qualifying active tag may show the person’s full or preferred name, year of birth, blood type, conditions and related notes or critical flags, medications and dosage information, allergies and reactions, emergency instructions, ICE contact names, relationships and telephone numbers, disclosure choices, and last-verification information.
This is sensitive personal and emergency information even though publishing it is deliberate. Possessing the tag or URL does not prove that a viewer is an emergency responder, and RoamID does not restrict access to responders.
Unknown, unassigned, PENDING, disabled, lost, replaced, retired, unavailable or invalidly contained tags do not disclose customer Emergency Profile information. Profiles controlled by an account in the account-closure grace period are also non-disclosing. These controls reduce unintended disclosure, but they cannot recall information already seen or copied while a tag was active.
3. Information RoamID collects
Account and identity information
RoamID handles account email address, display name, sign-in identity, role and status, onboarding state, adult-controller acknowledgement, and account ownership or delegated-management relationships. Authentication services may also generate security and access information.
Emergency Profile and ICE information
Customers and authorised managers may provide names, year of birth, blood type, conditions, medications, allergies, emergency notes, disclosure settings, verification information and ICE contact details. An Emergency Profile may represent an adult or a minor; a minor is represented through a managed profile controlled by an authorised adult account controller. RoamID stores year of birth rather than a full date of birth to minimise the personal information held for an Emergency Profile. Year of birth alone is not represented as sufficient for every legal, identity or medical purpose. RoamID records when profile information is changed or expressly confirmed as current. Customer confirmation is not independent medical verification by RoamID.
Founding eligibility evidence
Where it applies, RoamID records a controller’s confirmation that a person in the current-year-18 cohort has actually turned 18. For a managed profile, it records the applicable adult or minor authority and publication confirmation. This bounded evidence includes the applicable year of birth and represented-person revision, the controlling owner and acting controller, and the time and version of the confirmation. These are product attestations, not independent identity, signature, age, consent, guardianship or capacity verification.
Tags, activation and lifecycle
RoamID handles physical tag type, internal and provisioning identifiers, the permanent opaque public URL, customer tag labels, assignment and activation state, replacement relationships, and relevant lifecycle timestamps. Activation and claim controls also use security credentials, digests, attempt controls and audit records. Claim-code plaintext is handled transiently and is not stored in the application database.
Authority and support
RoamID records which people may manage an account or profile, invitation and acceptance state, relationship labels, Account Steward authority, temporary support grants and their grant, expiry or revocation details, and privacy-minimised support audit information.
Operations, security and communications
RoamID handles bounded operational and audit information needed to secure, troubleshoot, recover and operate the service. It also processes the account or invited-manager identity needed to send current transactional welcome and invitation messages, together with delivery state. Cloudflare and network or email providers may independently generate request, security, authentication, delivery and service telemetry.
4. Why RoamID handles information
RoamID handles information only for purposes connected with the current service, including to:
- publish the selected Emergency Profile through an operational active tag;
- let authenticated and authorised people create, maintain, verify and manage profiles, ICE contacts, tags and account relationships;
- authenticate users and enforce account, profile, support and administrator authority;
- claim, activate, disable, replace, retire and protect physical tags and permanent identifiers;
- calculate profile readiness, profile verification/currentness and Founding eligibility without treating any of them as a clinical assessment;
- send implemented transactional account and invitation messages;
- provide temporary customer-authorised support;
- prevent misuse, preserve integrity, investigate faults and security events, maintain audit history, and operate or recover the service; and
- respond to lawful requirements and protect the rights, safety and security of individuals, RoamID and others.
Profile readiness concerns whether required emergency content is present. Profile verification/currentness records a customer’s review of that content. Founding eligibility is separate from readiness: self-managed profiles retain their adult-age rules, while a managed adult or minor profile requires the applicable current authority and publication evidence. Activation and eligible recovery require both readiness and Founding eligibility. RoamID does not use Emergency Profile information for marketing in the current Founding Release. A materially different purpose requires a fresh product, privacy and legal assessment and, where appropriate, further notice or consent.
5. Who can access or receive information
Public Emergency Profile information
Anyone possessing an operational active tag URL may receive the published fields described above. This is the service’s central disclosure, not an accidental exception.
Authorised customer access
An account owner and people with current, server-verified delegated authority can access information within their actual account or profile scope. An Account Steward has only the narrow lifecycle and support-authorisation powers granted by the product; Steward status is not co-ownership or unrestricted account administration.
Administration and support
Ordinary administrators handle account, tag, readiness, lifecycle and other administrative information. To calculate readiness or administrative summaries, their normal tools may internally process limited profile-derived facts, including profile names, record counts, disclosure states, readiness reasons, verification freshness, ICE telephone arrays and year of birth. The normal administrator interface does not ordinarily render or display the underlying raw medical entries, emergency notes, year of birth or ICE telephone numbers.
A real administrator may inspect the broader exact-account support view only during a current customer-authorised support grant, as explained below.
Providers and lawful recipients
RoamID makes information available to service providers to the extent needed for hosting, storage, authentication, security, logging, status and transactional email. RoamID may also use or disclose information where required or authorised by law, or where reasonably necessary to establish, exercise or defend legal rights or address a serious safety or security concern, subject to applicable law.
7. Customer-authorised support
An account owner or current accepted Account Steward may deliberately enable read-only administrator support for exactly 1, 4 or 24 hours. The grant applies only to the exact account and can allow a real, authenticated administrator to inspect support-relevant account, Emergency Profile, medical, ICE, readiness and tag information for troubleshooting.
Support mode does not impersonate the customer and does not allow profile, ICE, verification, authority or tag changes. The administrator remains identified and support use is audited without copying medical or ICE content into the grant or audit metadata.
The grant ends on expiry or revocation. It also ends if the account closes or the administrator loses authority, with access denied on the next protected request. Closing and later reinstating an account does not restore an old grant. Enabling support does not change what an active Emergency Profile publicly displays.
8. Service providers and overseas handling
The current application uses Cloudflare services to run and serve the Worker and static assets, store application data in D1, authenticate customers and administrators through Access, send transactional email through an email binding, retain bounded Workers Logs, and operate status-service components. The application makes information available to those services for those technical roles. Transactional email providers may process message content and delivery information as needed to send, secure, troubleshoot and operate those communications. Providers may independently handle service, network, security, authentication or delivery data.
Cloudflare is a global provider. Provider processing or access may occur outside Australia, and RoamID does not promise Australia-only storage or processing. Provider security, recovery, access, authentication, delivery and other operational records may be retained for provider-dependent periods that differ from active RoamID application data. Provider arrangements and retention can change; RoamID reviews them as appropriate and will update this policy where needed.
Before relying on an overseas provider arrangement, RoamID will assess the available provider, contractual and security information and take reasonable steps appropriate to the information and applicable Australian requirements. Any materially different provider or transfer arrangement must be assessed and this policy updated where needed.
9. Security, tracking and automated use
RoamID uses technical and organisational safeguards intended to be proportionate to the sensitivity of the information. Current measures include authenticated management and administration boundaries, server-side authority checks, high-entropy opaque tag URLs, non-indexing directives, input validation and escaping, lifecycle non-disclosure rules, restricted support scope, privacy-minimised application logs and recovery procedures. No internet service or physical tag can guarantee absolute security.
The RoamID application does not create responder scan, emergency-access, page-view or profile-view analytics events. It does not record a responder’s IP address, User-Agent, geolocation or coordinates in its operational logs, and it does not record responder scan location or perform responder tracking. This application-level statement does not mean infrastructure, network or device providers generate no service or security data.
RoamID does not provide medical diagnosis or advice and does not use artificial intelligence to interpret, rewrite, diagnose, prioritise or generate Emergency Profile information.
10. Retention and account closure
RoamID keeps active account and profile information while it is needed to provide and protect the service. Different security, lifecycle, audit and provider records may need different retention periods; RoamID does not apply or promise one blanket statutory period.
The 30-day account-closure process
A valid closure request immediately places the account into PENDING_DELETION. Responder disclosure from every tag controlled by that account stops immediately and normal management is suspended. The account, profiles, ICE contacts, authority relationships and tag state are preserved during a fixed 30-day grace period solely so an authorised person can reinstate the account before the persisted deadline.
At the deadline, reinstatement is unavailable. When hard deletion runs, it permanently removes Emergency Profile, medical and ICE information from the active application store and removes ordinary account and profile authority. Physical tags are permanently retired and cannot be reused, even if the same email later registers a new account.
What remains
RoamID retains the permanent tag identifiers and limited lifecycle, credential-digest, security, audit and provenance history needed to prevent physical identifier reuse, maintain system integrity and evidence terminal events. The retained application records are designed not to contain Emergency Profile, medical or ICE content, and identifying references are removed, nulled or minimised where the implemented deletion rules require it.
Deletion from the active application store may not immediately remove information from provider-controlled recovery history, operational systems or transactional-email records. Those records can persist for provider-dependent periods that are separate from active RoamID application data. Any deliberate recovery export must be protected and removed when its defined recovery purpose ends.
11. Access and correction
You can view and correct much of the Emergency Profile and ICE information within the authorised management service. You should correct inaccurate information promptly and expressly verify it again when current. Changing or confirming customer information does not mean RoamID has medically verified it.
You may also ask for access to, or correction of, other personal information RoamID holds about you. RoamID may need to verify your identity and authority, particularly where a request concerns another person, an ICE contact, audit or security information, or a closed account. Applicable law may permit or require RoamID to withhold some information, protect another person’s information, or preserve security controls. If a request is refused, RoamID will explain the basis to the extent required and permitted.
Use the contact path in section 12. State whether you seek access or correction, describe the relevant information, and do not send medical details, passwords, activation codes or tag URLs in the initial message.
12. Questions, complaints and data breaches
For privacy questions or complaints, email privacy@roamid.app. For normal customer or service support, email support@roamid.app.
For a privacy question or complaint, explain the issue and the outcome you seek without including unnecessary sensitive information. RoamID will acknowledge and investigate the matter, may ask for information needed to verify identity or authority, and will respond within a reasonable period having regard to the issue and any applicable legal timeframe.
If you remain dissatisfied, you may have a right to complain to an applicable privacy regulator, including the Office of the Australian Information Commissioner or a state or territory health privacy regulator. Which regulator and process applies can depend on the operator, information and circumstances.
RoamID will assess suspected loss, unauthorised access or unauthorised disclosure, take reasonable containment and remedial steps, and notify affected people and a regulator where an applicable data-breach notification law requires it. This statement does not assert that a particular statutory scheme applies in every case.
13. Changes to this policy
RoamID may update this policy when the service, provider arrangements, law or information-handling practices change. The current version and effective date will remain on this page. A material change will not retrospectively authorise a new use or disclosure where further notice, agreement or consent is required.