What is collected, why, and what you can do about it. PointRoost is built to hold as little as it can get away with — this page is specific about what that means in practice.
1. Who is responsible
PointRoost decides what is collected here and why. Questions go to support@pointroost.app.
2. What is collected
What you give directly
- Account: your email address and display name. Sign-in happens through Apple, Google, or email — passwords are never held by PointRoost.
- Profile: an optional city, and your notification preferences.
- Listings and wanted posts: resorts, use year, points, dates, and price.
- Messages: what you send other members.
- Verification documents: what you upload to prove identity or ownership.
What is generated by using the service
- Which listings you viewed and searched for, so Skipper can match you.
- Your verification and Founding Owner status.
- Purchase records for paid features — what was bought and when, never card numbers.
- A device token, if you turn on push notifications.
3. What is deliberately not collected
These are design constraints, not aspirations, and the code enforces them:
- No payment details. Rental money never passes through PointRoost. Paid features are charged by Apple, Google, or Stripe, who handle the card — PointRoost receives a confirmation, never a number.
- No home address. City only, and only if you choose to show it.
- No identity document contents in analytics. Document numbers, legal names, Disney confirmation numbers, and private price limits are excluded from the analytics pipeline by a typed schema that has no field they could occupy.
- No exact prices in analytics. Prices are bucketed into bands on the server first.
4. Why
| Purpose | What it uses | Basis |
|---|
| Running your account | Email, display name | Performing our contract with you |
| Showing your listings to others | Listing contents, display name, badges | Performing our contract with you |
| Matching (Skipper) | Your saved searches, new listings | Performing our contract with you |
| Verification | Documents you upload | Your consent, and our interest in a marketplace that is not full of fraud |
| Notifications | Device token, preferences | Your consent — off until you turn it on |
| Fraud prevention and safety | Account and listing activity | Our legitimate interest in protecting members |
5. What other members see
Your display name, member-since date, verification badges, listings, and any reviews written about you are public. Your city is shown only if you switched it on.
Your email address is never shown to another member. Neither is your exact location, or the private floor or ceiling you may have set on a listing.
6. Who else receives it
PointRoost does not sell personal information, and does not share it for advertising.
- Google (Firebase): hosting, database, authentication, push delivery, file storage.
- Vercel: serves the website.
- Stripe: processes payments made on the web. Stripe receives what it needs to take a payment; PointRoost receives confirmation that one happened.
- Apple and Google: process in-app purchases and confirm them back.
- Law enforcement, where there is a valid legal obligation.
7. How long it is kept
- Account and profile: until you delete the account.
- Listings: until you remove them, or shortly after they expire.
- Messages: for as long as both sides have an account, since a conversation belongs to two people.
- Verification documents: removed once a decision has been recorded. The decision is kept; the document is not.
- Purchase records: kept as long as tax and accounting law requires.
8. Your rights
Depending on where you live you may have the right to access, correct, delete, or port your information, and to object to some processing. Two of these are built in rather than being a request queue:
- Export. Settings gives you a copy of your data directly.
- Deletion. Settings closes your account. Your profile is replaced with a placeholder and your listings go. Reviews you wrote about other members stay, with your name removed, because deleting them would rewrite someone else’s record.
Anything else, or a complaint, goes to support@pointroost.app. If you are in the EEA or UK you may also complain to your local data protection authority.
9. Security
Traffic is encrypted in transit. Verification documents are stored privately and are reachable only through short-lived links issued to a reviewer. Access rules are enforced by the database itself rather than by the app asking nicely.
No service can promise to be unbreachable, and this one does not.
10. Children
PointRoost is for adults. It is not directed at anyone under 18 and does not knowingly collect their information.
11. International transfers
Data is processed on servers in the United States. If you are elsewhere, using PointRoost means it is transferred there, protected by the safeguards our providers have in place.
12. Changes
Material changes will be notified before they take effect, and the date at the top of this page will move.
See also the Cookie Policy.