Security & privacy

Your department's data, kept private and safe

Here's the plain-English version first — what we do with your data, who can see it, and what happens to it if you leave. If you're on the IT side, the technical detail and our subprocessor list are further down.

The short version

What this means for your department

We never sell your data

We don't sell your data, run ads against it, or use it to train AI.

Customized visibility

Share only certain rooms with individual room links, or share a department-wide link.

Invite admins with granular permissions and visibility

Assign roles to admins and see activity history of room changes, booking confirmations, etc.

Your data is yours to take

Export everything to a spreadsheet whenever you want, and ask us to delete it whenever you're done. No lock-in contract.

Student data & the law

FERPA, GDPR, and what actually applies

Most departments never put regulated student data into Roomsked, because scheduling a room doesn't require any. A booking is a title, a time, a room, and the name and email of the person who booked it. Grades, student IDs, and enrollment records stay in your student information system, where they belong.

FERPA: Because we don't process student education records by default, FERPA-regulated data typically never touches Roomsked. We do offer a FERPA-compliant service if you need a deeper enterprise integration that syncs student data.

GDPR & privacy: What we collect, how long we keep it, and your rights over it are set out in our Privacy Policy and Terms of Service, which also list the subprocessors that handle data on our behalf. Customers in the EU or UK can request a Data Processing Agreement by emailing support@roomsked.com.

For your IT team

The technical detail

Roomsked is built on infrastructure used by thousands of organizations. Here are some details for your IT team.

Encryption in transit and at rest

All traffic is encrypted with TLS 1.2+, and data is encrypted at rest with AES-256 by our infrastructure providers.

Authentication

Sign-in is handled by Clerk (SOC 2 Type II), with support for multi-factor authentication and secure session management.

Tenant isolation

Every request is scoped to the department it belongs to. Users only ever load data for the departments for which they are a member.

Backups and durability

Automatic database backups, so a bad import or accidental deletion can be reversed.

Data residency and access

Primary data is stored in the United States.

Export, retention, and deletion

Export rooms, bookings, and users to CSV at any time. Delete your account and the associated data is removed within 30 days.

The full list of subprocessors that process data on our behalf lives in our Privacy Policy. Need a signed subprocessor list or a DPA for your review? Email us and we'll provide one.

Have a security question?

We're happy to answer IT-review questions, share our subprocessor agreements, or set up a call.