Skip to content
How It WorksTagsGetting StartedHelpEmergency ProfilesStatusManage Tag
How It WorksTagsGetting StartedHelpEmergency ProfilesStatusManage Tag

Privacy

Privacy Policy

This policy explains how RoamID handles personal information in the controlled Founding Release, including the sensitive emergency information that authorised adult account controllers deliberately publish through an active tag.

Effective
21 September 2026
Version
Founding Release 1.0

On this page

  1. Who this policy covers
  2. Emergency Profiles are public
  3. Information we collect
  4. Why we handle information
  5. Who can access information
  6. Profiles about other people and ICE contacts
  7. Customer-authorised support
  8. Service providers and overseas handling
  9. Security, tracking and automated use
  10. Retention and account closure
  11. Access and correction
  12. Questions, complaints and data breaches
  13. Changes to this policy

The most important privacy point

An active Emergency Profile is public by design.

Anyone who possesses the NFC or QR URL for an operational ACTIVE tag can open the associated Emergency Profile without signing in. The opaque URL makes guessing difficult, but it is a locator—not authentication or a promise of privacy. A person can copy, photograph, forward or otherwise obtain it.

Only enter information that is useful and appropriate for emergency disclosure. Do not include passwords, financial details, identity-document numbers or unrelated sensitive information.

1. Who this policy covers

This policy applies to the RoamID service available at roamid.app and to people whose information RoamID handles through that service. This includes account holders, authorised managers and Account Stewards, people represented by Emergency Profiles, nominated in-case-of-emergency (ICE) contacts, and people who use an active tag URL.

RoamID is the registered business name used by Nicholas C. Gleeson (ABN 78 486 967 639) as the Founding sole-trader operator. In this document, “RoamID”, “we”, “us” and “our” mean that operator of the RoamID service available at roamid.app.

This policy describes the current Founding Release application. It does not describe an unimplemented checkout, marketing-signup, general contact-form or support-ticket system.

2. Emergency Profiles are intentionally public

An Emergency Profile connected to a qualifying active tag may show the person’s full or preferred name, year of birth, blood type, conditions and related notes or critical flags, medications and dosage information, allergies and reactions, emergency instructions, ICE contact names, relationships and telephone numbers, disclosure choices, and last-verification information.

This is sensitive personal and emergency information even though publishing it is deliberate. Possessing the tag or URL does not prove that a viewer is an emergency responder, and RoamID does not restrict access to responders.

Unknown, unassigned, PENDING, disabled, lost, replaced, retired, unavailable or invalidly contained tags do not disclose customer Emergency Profile information. Profiles controlled by an account in the account-closure grace period are also non-disclosing. These controls reduce unintended disclosure, but they cannot recall information already seen or copied while a tag was active.

3. Information RoamID collects

Account and identity information

RoamID handles account email address, display name, sign-in identity, role and status, onboarding state, adult-controller acknowledgement, and account ownership or delegated-management relationships. Authentication services may also generate security and access information.

Emergency Profile and ICE information

Customers and authorised managers may provide names, year of birth, blood type, conditions, medications, allergies, emergency notes, disclosure settings, verification information and ICE contact details. An Emergency Profile may represent an adult or a minor; a minor is represented through a managed profile controlled by an authorised adult account controller. RoamID stores year of birth rather than a full date of birth to minimise the personal information held for an Emergency Profile. Year of birth alone is not represented as sufficient for every legal, identity or medical purpose. RoamID records when profile information is changed or expressly confirmed as current. Customer confirmation is not independent medical verification by RoamID.

Founding eligibility evidence

Where it applies, RoamID records a controller’s confirmation that a person in the current-year-18 cohort has actually turned 18. For a managed profile, it records the applicable adult or minor authority and publication confirmation. This bounded evidence includes the applicable year of birth and represented-person revision, the controlling owner and acting controller, and the time and version of the confirmation. These are product attestations, not independent identity, signature, age, consent, guardianship or capacity verification.

Tags, activation and lifecycle

RoamID handles physical tag type, internal and provisioning identifiers, the permanent opaque public URL, customer tag labels, assignment and activation state, replacement relationships, and relevant lifecycle timestamps. Activation and claim controls also use security credentials, digests, attempt controls and audit records. Claim-code plaintext is handled transiently and is not stored in the application database.

Authority and support

RoamID records which people may manage an account or profile, invitation and acceptance state, relationship labels, Account Steward authority, temporary support grants and their grant, expiry or revocation details, and privacy-minimised support audit information.

Operations, security and communications

RoamID handles bounded operational and audit information needed to secure, troubleshoot, recover and operate the service. It also processes the account or invited-manager identity needed to send current transactional welcome and invitation messages, together with delivery state. Cloudflare and network or email providers may independently generate request, security, authentication, delivery and service telemetry.

4. Why RoamID handles information

RoamID handles information only for purposes connected with the current service, including to:

  • publish the selected Emergency Profile through an operational active tag;
  • let authenticated and authorised people create, maintain, verify and manage profiles, ICE contacts, tags and account relationships;
  • authenticate users and enforce account, profile, support and administrator authority;
  • claim, activate, disable, replace, retire and protect physical tags and permanent identifiers;
  • calculate profile readiness, profile verification/currentness and Founding eligibility without treating any of them as a clinical assessment;
  • send implemented transactional account and invitation messages;
  • provide temporary customer-authorised support;
  • prevent misuse, preserve integrity, investigate faults and security events, maintain audit history, and operate or recover the service; and
  • respond to lawful requirements and protect the rights, safety and security of individuals, RoamID and others.

Profile readiness concerns whether required emergency content is present. Profile verification/currentness records a customer’s review of that content. Founding eligibility is separate from readiness: self-managed profiles retain their adult-age rules, while a managed adult or minor profile requires the applicable current authority and publication evidence. Activation and eligible recovery require both readiness and Founding eligibility. RoamID does not use Emergency Profile information for marketing in the current Founding Release. A materially different purpose requires a fresh product, privacy and legal assessment and, where appropriate, further notice or consent.

5. Who can access or receive information

Public Emergency Profile information

Anyone possessing an operational active tag URL may receive the published fields described above. This is the service’s central disclosure, not an accidental exception.

Authorised customer access

An account owner and people with current, server-verified delegated authority can access information within their actual account or profile scope. An Account Steward has only the narrow lifecycle and support-authorisation powers granted by the product; Steward status is not co-ownership or unrestricted account administration.

Administration and support

Ordinary administrators handle account, tag, readiness, lifecycle and other administrative information. To calculate readiness or administrative summaries, their normal tools may internally process limited profile-derived facts, including profile names, record counts, disclosure states, readiness reasons, verification freshness, ICE telephone arrays and year of birth. The normal administrator interface does not ordinarily render or display the underlying raw medical entries, emergency notes, year of birth or ICE telephone numbers.

A real administrator may inspect the broader exact-account support view only during a current customer-authorised support grant, as explained below.

Providers and lawful recipients

RoamID makes information available to service providers to the extent needed for hosting, storage, authentication, security, logging, status and transactional email. RoamID may also use or disclose information where required or authorised by law, or where reasonably necessary to establish, exercise or defend legal rights or address a serious safety or security concern, subject to applicable law.

6. Profiles about other people and ICE contacts

RoamID account controllers must be adults aged 18 or over. An Emergency Profile may represent an adult or a minor. A minor’s profile must be created and managed by an authorised adult account controller; RoamID does not independently verify guardianship, identity, consent, capacity or documentary authority. Relationship labels are descriptive only and do not establish authority.

If you provide another person’s information, you are responsible for making the public nature and intended uses clear to them where appropriate, respecting any limits on your authority, and keeping the information accurate. Do not use delegated access to exceed the authority given to you.

ICE details are information about another person. Before adding an ICE contact, obtain an appropriate basis to provide and publicly display their name, relationship and telephone number. Tell them that anyone possessing an active tag URL may see and use those details for emergency contact. Remove or correct the details if the contact withdraws agreement or the information changes.

7. Customer-authorised support

An account owner or current accepted Account Steward may deliberately enable read-only administrator support for exactly 1, 4 or 24 hours. The grant applies only to the exact account and can allow a real, authenticated administrator to inspect support-relevant account, Emergency Profile, medical, ICE, readiness and tag information for troubleshooting.

Support mode does not impersonate the customer and does not allow profile, ICE, verification, authority or tag changes. The administrator remains identified and support use is audited without copying medical or ICE content into the grant or audit metadata.

The grant ends on expiry or revocation. It also ends if the account closes or the administrator loses authority, with access denied on the next protected request. Closing and later reinstating an account does not restore an old grant. Enabling support does not change what an active Emergency Profile publicly displays.

8. Service providers and overseas handling

The current application uses Cloudflare services to run and serve the Worker and static assets, store application data in D1, authenticate customers and administrators through Access, send transactional email through an email binding, retain bounded Workers Logs, and operate status-service components. The application makes information available to those services for those technical roles. Transactional email providers may process message content and delivery information as needed to send, secure, troubleshoot and operate those communications. Providers may independently handle service, network, security, authentication or delivery data.

Cloudflare is a global provider. Provider processing or access may occur outside Australia, and RoamID does not promise Australia-only storage or processing. Provider security, recovery, access, authentication, delivery and other operational records may be retained for provider-dependent periods that differ from active RoamID application data. Provider arrangements and retention can change; RoamID reviews them as appropriate and will update this policy where needed.

Before relying on an overseas provider arrangement, RoamID will assess the available provider, contractual and security information and take reasonable steps appropriate to the information and applicable Australian requirements. Any materially different provider or transfer arrangement must be assessed and this policy updated where needed.

9. Security, tracking and automated use

RoamID uses technical and organisational safeguards intended to be proportionate to the sensitivity of the information. Current measures include authenticated management and administration boundaries, server-side authority checks, high-entropy opaque tag URLs, non-indexing directives, input validation and escaping, lifecycle non-disclosure rules, restricted support scope, privacy-minimised application logs and recovery procedures. No internet service or physical tag can guarantee absolute security.

The RoamID application does not create responder scan, emergency-access, page-view or profile-view analytics events. It does not record a responder’s IP address, User-Agent, geolocation or coordinates in its operational logs, and it does not record responder scan location or perform responder tracking. This application-level statement does not mean infrastructure, network or device providers generate no service or security data.

RoamID does not provide medical diagnosis or advice and does not use artificial intelligence to interpret, rewrite, diagnose, prioritise or generate Emergency Profile information.

10. Retention and account closure

RoamID keeps active account and profile information while it is needed to provide and protect the service. Different security, lifecycle, audit and provider records may need different retention periods; RoamID does not apply or promise one blanket statutory period.

The 30-day account-closure process

A valid closure request immediately places the account into PENDING_DELETION. Responder disclosure from every tag controlled by that account stops immediately and normal management is suspended. The account, profiles, ICE contacts, authority relationships and tag state are preserved during a fixed 30-day grace period solely so an authorised person can reinstate the account before the persisted deadline.

At the deadline, reinstatement is unavailable. When hard deletion runs, it permanently removes Emergency Profile, medical and ICE information from the active application store and removes ordinary account and profile authority. Physical tags are permanently retired and cannot be reused, even if the same email later registers a new account.

What remains

RoamID retains the permanent tag identifiers and limited lifecycle, credential-digest, security, audit and provenance history needed to prevent physical identifier reuse, maintain system integrity and evidence terminal events. The retained application records are designed not to contain Emergency Profile, medical or ICE content, and identifying references are removed, nulled or minimised where the implemented deletion rules require it.

Deletion from the active application store may not immediately remove information from provider-controlled recovery history, operational systems or transactional-email records. Those records can persist for provider-dependent periods that are separate from active RoamID application data. Any deliberate recovery export must be protected and removed when its defined recovery purpose ends.

11. Access and correction

You can view and correct much of the Emergency Profile and ICE information within the authorised management service. You should correct inaccurate information promptly and expressly verify it again when current. Changing or confirming customer information does not mean RoamID has medically verified it.

You may also ask for access to, or correction of, other personal information RoamID holds about you. RoamID may need to verify your identity and authority, particularly where a request concerns another person, an ICE contact, audit or security information, or a closed account. Applicable law may permit or require RoamID to withhold some information, protect another person’s information, or preserve security controls. If a request is refused, RoamID will explain the basis to the extent required and permitted.

Use the contact path in section 12. State whether you seek access or correction, describe the relevant information, and do not send medical details, passwords, activation codes or tag URLs in the initial message.

12. Questions, complaints and data breaches

For privacy questions or complaints, email privacy@roamid.app. For normal customer or service support, email support@roamid.app.

For a privacy question or complaint, explain the issue and the outcome you seek without including unnecessary sensitive information. RoamID will acknowledge and investigate the matter, may ask for information needed to verify identity or authority, and will respond within a reasonable period having regard to the issue and any applicable legal timeframe.

If you remain dissatisfied, you may have a right to complain to an applicable privacy regulator, including the Office of the Australian Information Commissioner or a state or territory health privacy regulator. Which regulator and process applies can depend on the operator, information and circumstances.

RoamID will assess suspected loss, unauthorised access or unauthorised disclosure, take reasonable containment and remedial steps, and notify affected people and a regulator where an applicable data-breach notification law requires it. This statement does not assert that a particular statutory scheme applies in every case.

13. Changes to this policy

RoamID may update this policy when the service, provider arrangements, law or information-handling practices change. The current version and effective date will remain on this page. A material change will not retrospectively authorise a new use or disclosure where further notice, agreement or consent is required.

RoamID

One tag. Wherever you may roam

ProductHow It WorksTagsSample ProfileAbout
SupportGetting StartedHelpService StatusManage Tag
LegalPrivacyTerms
© 2026 RoamIDEmergency profiles are public by design. Only share information appropriate for emergency access.