Privacy Policy

Last updated

1. Who we are

1.1 This Privacy Policy explains how RoundTrips LTD, a company registered in Israel under company number 517410148 with its registered office at Nahal Shilo 25, Beer Sheva 8485867, Israel (we, us, our), collects and uses personal data.

1.2 We are the data controller for the personal data described in this policy, except where we act as a processor on your behalf as described in section 5.

1.3 You can contact us about anything in this policy at admin@roundtrips.io.

2. What this policy covers

2.1 This policy covers personal data we handle when you visit https://www.roundtrips.io, request or download a trial of RoundTrips, ask us to contact you about pricing, buy or use a Subscription, contact our support team, or receive marketing from us.

2.2 It does not cover the practices of third parties whose services you connect to RoundTrips, such as Autodesk Construction Cloud, Microsoft OneDrive or Dropbox. Those services handle your data under their own privacy policies.

2.3 This policy forms part of our Terms of Service.

3. What we do not collect

3.1 We think this is the most important section, so it comes first.

3.2 We do not collect or store the contents of your models, drawings or documents. RoundTrips processes files locally on your machine. When a Task moves or builds files, the contents travel directly between your machine and the storage locations you have authorised. They do not pass through our servers and we keep no copies.

3.3 We do not have access to your project files in a Connected Service. We hold an access token that lets the Software act on your instructions from your machine; we do not use it to browse, read or retrieve your files ourselves.

3.4 We do not sell personal data, and we do not share it with advertisers or data brokers.

4. Personal data we collect

4.1 Account and billing data. Your name, work email address, company name, job role, country, billing address, VAT or tax number, and purchase history. We take payment by bank transfer against an invoice and hold no payment card details.

4.2 Licence and activation data. Your licence key, the number of Seats assigned, the individuals assigned to them, activation records, machine identifiers used to enforce Seat limits, and the software version installed.

4.3 Operational data from the Software. Task configuration metadata such as Task names, project names, folder paths, file names, file types and file counts; Run outcomes, timings and stage durations; data volumes moved; error diagnostics; and application logs. Folder paths and file names can contain personal data if you name files after people, so we treat this category as personal data.

4.4 Connected Service authorisation data. Access and refresh tokens issued when you authorise a Connected Service, the account identifier associated with that authorisation, and the scopes granted.

4.5 Support data. The content of emails and support tickets you send us, and any logs or files you choose to attach.

4.6 Website data. IP address, browser and device type, pages viewed and referring site.

4.7 Trial request form. When you ask for a trial we collect your first name, last name, work email address and, if you give it, your company name. We record the trial licence issued in response: its key, its identifier, its expiry date, and when it was sent to you.

4.8 Contact sales form. When you ask us to contact you about pricing we collect your name, work email address, your message, your company size if you select one, and which pricing plan's button you pressed. We record whether the notification to our sales inbox succeeded, so that an enquiry cannot be lost silently.

4.9 Anti-abuse data for both forms. We store a salted one-way hash of your IP address rather than the address itself, and use it only to limit how many submissions come from one place in an hour. The hash cannot be turned back into your address. Each form also carries a field hidden from people and visible to automated scripts; we discard anything that fills it in.

4.10 Trial activation on your machine. When RoundTrips starts its own trial on first launch it sends a machine fingerprint, which is a value derived from the computer, so that one computer receives one trial. No name or email address is attached to it.

4.11 Downloading the Software. The installer is hosted on GitHub Releases. Downloading it is a request to GitHub, who will see your IP address under their own privacy policy. We do not receive a record of individual downloads.

5. Where we act as a processor

5.1 Some of the data the Software handles is personal data belonging to your own clients, staff or project participants. Where that is the case you are the controller and we act as a processor, handling it only on your documented instructions.

5.2 If you require a data processing agreement, ours is available on request from admin@roundtrips.io. Where we act as processor, our commitments in that agreement take precedence over this policy for the data it covers.

6. Why we use your data, and our legal basis

6.1 To provide the Software and your Subscription — creating your account, issuing and validating licence keys, enforcing Seat and tier limits, and running the Tasks you configure. Legal basis: performance of a contract.

6.2 To answer a sales enquiry — replying to you, understanding what your team needs, and preparing a quote. Legal basis: taking steps at your request before entering a contract, and our legitimate interest in responding to people who ask to hear from us.

6.3 To provide support — investigating problems you report, reproducing errors, and responding to you. Legal basis: performance of a contract, and our legitimate interest in supporting our customers.

6.4 To keep the Software and the website secure and working — detecting failures, diagnosing errors, preventing abuse of licence keys, stopping automated and repeated form submissions, and protecting our systems. Legal basis: our legitimate interest in the security and integrity of our service.

6.5 To improve the product — understanding which Tasks fail, how long Runs take, and where performance problems occur, so we can fix and improve them. Legal basis: our legitimate interest in improving a product our customers rely on. We use aggregated data for this wherever it is sufficient.

6.6 To take payment and meet our accounting obligations — invoicing, collecting payment, and keeping financial records. Legal basis: performance of a contract, and compliance with a legal obligation.

6.7 To send you service messages — trial expiry, renewal, security and availability notices, and material changes to our terms. Legal basis: performance of a contract. You cannot opt out of these while you hold a Subscription.

6.8 To send you marketing — product updates and occasional announcements, where you have opted in or where you are an existing customer and we are permitted to contact you about similar products. Legal basis: consent, or our legitimate interest in marketing to existing customers. You can unsubscribe from any marketing email, at any time, using the link in it.

7. Who we share data with

7.1 We share personal data only with service providers who help us operate, and only as far as they need it. Our sub-processors are:

• Vercel — hosting the website and the code behind its forms

• Supabase — the database holding trial requests, sales enquiries and trial records

• Resend — sending transactional email, including the trial email and the notification of your enquiry to our sales inbox

• Cloudflare — the anti-spam check on our forms, which receives your IP address and browser signals to decide whether a submission is automated

• Keygen — issuing and validating licence keys, including trial keys

• GitHub — hosting the installer download

7.2 The list in clause 7.1 is the current list of sub-processors, and this policy is updated whenever it changes. Where we act as processor, we will give you notice of changes to this list as set out in our data processing agreement.

7.3 We may also disclose personal data where we are legally required to, to establish or defend legal claims, or to a buyer or successor in connection with a merger, acquisition or sale of assets — in which case we will notify you before your data becomes subject to a different privacy policy.

8. International transfers

8.1 We are based in Israel and some of our service providers are located outside it, including in the United States.

8.2 Where we transfer personal data outside the UK or the European Economic Area, we rely on an adequacy decision where one applies, or otherwise on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, together with any additional safeguards the transfer requires.

8.3 You can request a copy of the safeguards we rely on by writing to admin@roundtrips.io.

9. How long we keep data

9.1 Account and billing data — for the life of your account, and then for [7] years to meet accounting and tax obligations.

9.2 Licence and activation data — for the life of your Subscription, and then for [24] months to handle renewals, disputes and licence misuse.

9.3 Operational data and application logs — for [12] months, after which it is deleted or irreversibly aggregated.

9.4 Connected Service tokens — until you disconnect the service, revoke access from within that service, or your Subscription ends. Tokens are then deleted.

9.5 Support correspondence — for [24] months after the ticket is closed.

9.6 Trial requests and the trial licences issued from them — for [24] months from the request, so that we can answer questions about a trial and recognise a repeat request.

9.7 Sales enquiries — for [24] months from the enquiry, or for the life of your account if you become a customer.

9.8 The hashed IP address attached to either — deleted with the record it belongs to.

9.9 We may keep data for longer where we are legally required to, or where it is needed for a legal claim that is active or reasonably anticipated.

10. How we protect data

10.1 We use encryption in transit for all connections between the Software, our services and Connected Services, and encryption at rest for stored credentials and tokens.

10.2 Access to personal data within our organisation is restricted to staff who need it, and is logged.

10.3 We keep the fact that model and document contents never reach our systems as a deliberate design decision — it is the strongest protection we can offer for the data you care most about.

10.4 No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay where the risk is high.

11. Your rights

11.1 Depending on where you live, you have some or all of the following rights over your personal data: to access it; to have it corrected; to have it erased; to restrict or object to our use of it; to receive it in a portable format; and to withdraw consent where our use relies on consent.

11.2 Where we rely on legitimate interests, you may object at any time and we will stop unless we have compelling grounds to continue.

11.3 To exercise any right, write to admin@roundtrips.io. We will respond within one month, and will tell you if we need longer because the request is complex.

11.4 We will not charge you for exercising your rights, or treat you differently for doing so.

11.5 If you are unhappy with how we have handled your data you may complain to your local supervisory authority. In the UK this is the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to address your concern first.

12. Cookies and website analytics

12.1 We set no cookies of our own, and we use no website analytics. Nothing on the site records which pages you viewed or follows you between visits.

12.2 Two of our providers may store data in your browser where it is strictly necessary for the page to work: Cloudflare, for the anti-spam check on our forms, so that you are not asked to prove you are human twice; and Vercel, our host, where it protects the site from automated traffic. Neither is used to profile you or to measure your visit.

12.3 We do not use advertising or cross-site tracking cookies.

12.4 If we add analytics in future we will update this policy and ask for your consent before setting anything that is not strictly necessary.

13. Children

13.1 RoundTrips is a tool for construction and design professionals. It is not directed at children, and we do not market it to them.

13.2 We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to admin@roundtrips.io and we will delete it.

14. Changes to this policy

14.1 We may update this policy. When we make a material change we will update the effective date at the top, and where the change affects how we use data you have already given us we will notify you by email or in the Software before it takes effect.

14.2 Previous versions are available on request.

15. Contact us

15.1 For any question about this policy, or to exercise your rights:

• RoundTrips LTD

• Nahal Shilo 25, Beer Sheva 8485867, Israel

• admin@roundtrips.io

15.2 We are not currently required to appoint a data protection officer or an EU representative. Questions that would go to one go to admin@roundtrips.io.

30 Days free trial

To download and start the free trial, please submit the form.

Contact sales