Effective date : July 20, 2026

Privacy policy

Roma processes account, business, financial-operations and integration data only as needed to provide, secure and support the Services. We do not sell customer, Google or Microsoft user data. The Google-specific disclosures in this Policy apply when a user chooses Google Login or separately enables the optional read-only Gmail integration. Microsoft-specific disclosures apply when a user chooses Microsoft Login or separately enables the optional Microsoft email integration, which may read and send mail only for enabled Roma features authorized by the user or the user's organization.

1. About this Privacy Policy 


This Privacy Policy explains how AlphaStar Technologies Private Limited ("AlphaStar", "Roma", "we", "us" or "our") collects, accesses, uses, stores, discloses, protects, retains and deletes information when you visit https://www.runroma.com, use the Roma platform, upload or provide information, or connect email, accounting, ERP, cloud-storage, retailer, distributor, collaboration or other third-party services (collectively, the "Services"). 


AlphaStar Technologies Private Limited is incorporated under the Companies Act, 2013 (CIN: U72900DL2021PTC389698) and has its registered office at Plot No. 27, 3rd Floor, Community Centre, Naraina Vihar, Phase-I, Delhi, South West Delhi, India 110028. 


This Policy is an electronic record under the Information Technology Act, 2000 and applicable rules, together with other applicable privacy and data-protection laws. It is generated by a computer system and does not require a physical or digital signature. 


This Policy applies to visitors, prospective customers, customers, authorized users and individuals whose information is processed through the Services. If Roma processes information on behalf of an organizational customer, that customer may determine the purposes and means of processing and its agreement with Roma may contain additional terms. Where there is a conflict, the applicable customer agreement or data processing agreement controls to the extent permitted by law. 


2. Information We Collect or Access 


2.1 Information provided by you or your organization 


  • Account and contact information. Name, business email address, phone number, organization, role, account identifiers and support communications. 


  • Business and financial operations data. Invoices, remittance advice, debit or credit notes, deductions, claims, backup documents, purchase or sales records, ledgers, retailer or distributor data, payment and reconciliation information, and other documents uploaded or connected by an authorized user. 


  • Configuration and integration information. Integration settings, connection status, search rules, mappings and other instructions that you or your organization configure. 


  • Authentication information. Roma may process credentials or tokens required to authenticate an account. Roma does not receive or store your Google or Microsoft password. Passwords used for a Roma local account are stored using one-way cryptographic hashing, not in readable form. 


2.2 Information from customer systems and connected services 


At the direction of a customer or authorized user, Roma may receive information from connected email accounts, accounting or ERP systems, cloud-storage services, retailer or distributor portals, collaboration tools and other integrations. The information received depends on the integration, permissions granted, customer configuration and enabled features. It may include account identifiers, documents, communications, transaction records, ledgers, invoices, remittances, deductions, claims, statements, payment information and related metadata. Not every customer uses every integration. 


Roma uses information from connected services only to provide the customer-requested features, such as document ingestion, classification, extraction, reconciliation, analytics, exception management, supporting-document retrieval and workflow automation. Customers are responsible for authorizing integrations and configuring appropriate user access. 


2.3 Google Login data 


Roma offers Google Login as one method of signing in. When a user selects Continue with Google, the login flow requests https://www.googleapis.com/auth/userinfo.email and https://www.googleapis.com/auth/userinfo.profile. Roma may receive the user's primary Google Account email address, name, profile image and basic account identifier. 


Roma uses this information only to authenticate the user, create or identify the corresponding Roma account, associate the user with the appropriate organization, and display basic account information within Roma. The Google Login flow does not provide Roma with access to Gmail messages, attachments, mailbox settings or other email content. 


2.4 Optional Gmail email integration 


After signing in to Roma, an authorized user may separately choose to connect a Gmail account to Roma's email integration. This integration is optional, is not required to use Google Login, and requests only https://www.googleapis.com/auth/gmail.readonly, a restricted, read-only Gmail scope. Depending on the features enabled and the authorized mailbox, Roma may access: 



  • message and thread identifiers, labels, sender, recipients, subject, timestamps and other message headers or metadata; 


  • message bodies and attachments, including remittance advice, deduction notices, debit or credit memos, invoices, claims, statements and supporting documents; and 


  • information extracted or derived from relevant messages and attachments, such as deduction type, amount, invoice number, retailer or distributor, dates, status and reconciliation results. 


Roma uses Gmail read-only access to search for and retrieve relevant business messages and supporting documents, classify and extract information from them, associate that information with deductions or transactions, and display the resulting records, documents, exceptions, dashboards and workflow status to the authorized user and permitted members of the user's organization. 


Roma does not use this scope to send, edit, label, archive, move or delete Gmail messages. Roma applies application-level filters—such as configured sender addresses, domains, subjects, labels, keywords and date ranges—to limit processing to messages reasonably relevant to the enabled Roma features. Because Gmail does not provide an OAuth scope limited to selected senders, subjects or attachments, the authorization screen describes mailbox-wide read access even though Roma limits its actual processing in this manner. 


2.5 Microsoft Login data 


Roma also offers Microsoft Login as a sign-in method. When a user selects the Microsoft sign-in option, the authentication flow requests the OpenID Connect scopes openid, profile and email. Roma may receive a unique account identifier, primary email address where available, name, preferred username and other basic profile claims provided by Microsoft. 


Roma uses this information only to authenticate the user, create or identify the corresponding Roma account, associate the user with the appropriate organization, and display basic account information within Roma. Microsoft Login by itself does not give Roma access to the user's mailbox or email content. 


2.6 Optional Microsoft email integration 


After signing in to Roma, an authorized user may separately choose to connect a Microsoft email account. This optional integration is distinct from Microsoft Login and requests delegated Microsoft permissions User.Read, Mail.Read, Mail.Send and offline_access. Roma uses these permissions as follows: 


  • User.Read. Read the signed-in user's basic profile to identify the connected Microsoft account and associate it with the correct Roma user and organization. 


  • Mail.Read. Read mailbox messages, message bodies, attachments and related metadata to retrieve and process relevant business communications and supporting documents for enabled deduction-management and finance-operations workflows. 


  • Mail.Send. Send email from the connected Microsoft account on the user's behalf only when an authorized user initiates or configures an enabled Roma email-sending workflow. This permission does not authorize Roma to send unrelated marketing or unsolicited email. 


  • offline_access. Receive and use refresh tokens so the authorized integration can continue background synchronization and enabled workflows without requiring the user to sign in again each time. 


Google and Microsoft email permissions are not identical. Roma's Gmail integration is read-only and cannot send email through Gmail. The Microsoft email integration can send email through the connected Microsoft account because it requests Mail.Send, but only for a user-authorized, enabled Roma feature. Users can review the Microsoft consent screen before granting access and can disconnect or revoke the integration at any time. 


2.7 Technical and usage information 


  • IP address, browser and device information, operating system, referral URL, date and time of access and cookie or similar identifiers; 


  • feature usage, page interactions, performance metrics, error events, audit logs and security events; and 


  • information required to diagnose issues, prevent abuse and maintain availability and security. 


3. How We Use Information 



  • provide, operate and support the Services and authenticate authorized users; 


  • ingest, classify, extract and organize finance documents and data; 


  • reconcile transactions, identify exceptions, validate deductions and support dispute workflows; 


  • retrieve supporting documents and present results in user-facing dashboards, reports, audit trails and workflows; 


  • maintain integrations requested by you or your organization; 


  • secure the Services, detect and prevent fraud or abuse, troubleshoot issues and monitor reliability; 


  • communicate about the Services, respond to support requests and administer our relationship with your organization; 


  • comply with law, enforce agreements and establish, exercise or defend legal claims; and 


  • improve the Services using service telemetry, feedback and aggregated or de-identified information, but not by training general-purpose AI or machine-learning models on Google user data. 


We do not use Google user data for advertising, retargeting, personalized marketing, credit scoring, lending or determining creditworthiness. 


4. Provider-Specific API Commitments 


4.1 Google API Services and Limited Use 


LIMITED USE COMMITMENT 
Roma's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. 



 


Consistent with those requirements: 


  • Google user data is used only to provide or improve user-facing features that are prominent in Roma's interface and that the user or the user's organization has enabled. 


  • We do not sell Google user data or transfer it to advertising platforms, data brokers or information resellers. 


  • We do not use or transfer Google user data for serving advertisements, including retargeted, personalized or interest-based advertising. 


  • We do not use or transfer Google user data to determine creditworthiness or for lending purposes. 


  • We do not use Google user data to develop, improve or train generalized or non-personalized artificial-intelligence or machine-learning models. 


  • Human access to Google user data is prohibited except when the user gives affirmative permission to view specific data; when access is necessary for security, fraud or abuse investigation; when required by applicable law; or when data is aggregated and used for internal operations in compliance with applicable privacy law. 


  • We transfer Google user data only to contracted service providers acting on our instructions where necessary to provide or secure the user-facing features, with the user's authorization and appropriate confidentiality and security protections; to comply with applicable law; or as otherwise expressly permitted by Google's Limited Use requirements. 


  • We will not transfer Google user data as part of a merger, acquisition or sale of assets without obtaining the user's explicit prior consent as required by Google's policy. 


Google's policy is available at Google API Services User Data Policy


4.2 Microsoft identity and Microsoft Graph data 


Roma uses information received through Microsoft identity services and Microsoft Graph only to provide, secure and support the sign-in and email-integration features enabled by the user or the user's organization. Roma does not sell Microsoft user data or use it for third-party advertising. Access is limited to authorized personnel and contracted service providers with a need to provide or secure the Services, subject to confidentiality, data-protection and use restrictions. Any use of Mail.Send is limited to an email-sending action or workflow authorized through Roma; it is not used for unrelated marketing or unsolicited messages. 


5. Legal Bases and Authorization 


We process information as necessary to provide the Services requested by you or your organization, perform our contractual obligations, comply with legal obligations, protect legitimate business and security interests, and obtain consent where required. An organizational customer is responsible for ensuring that it has authority to connect accounts and provide data to Roma, and for giving any notices or obtaining any consents required for its users, personnel, customers or counterparties. 


Google and Microsoft account access is optional and begins only after an authorized user initiates the applicable connection and grants permission through the provider's consent flow. A user may decline or revoke access, although features dependent on the disconnected integration will then stop working. 


6. How We Disclose Information 


We do not sell personal information or Google user data. We may disclose information only in the following circumstances: 


  • Within the customer's organization. To authorized administrators and users according to the customer's access settings. 


  • Service providers. To cloud hosting, storage, security, monitoring, support, communication, document-processing and similar providers that process information on our behalf under contractual confidentiality, data-protection and use restrictions. 



  • At your direction. To an integration partner or recipient when an authorized user instructs Roma to transmit or export data. 


  • Legal and safety reasons. When reasonably necessary to comply with law or valid legal process, protect rights or safety, investigate fraud or abuse, or enforce agreements. 


  • Corporate transactions. In connection with a financing, merger, acquisition, restructuring or sale of assets, subject to applicable law and appropriate confidentiality. Google user data will be handled only as permitted in Section 4, including explicit prior consent where required. 


  • Aggregated or de-identified information. Where information cannot reasonably identify an individual or organization and its use is permitted by law and applicable contract. 


7. Data Protection and Security 


Roma maintains administrative, technical and organizational safeguards designed to protect personal information and Google user data against unauthorized or unlawful access, use, alteration, disclosure, loss or destruction. These safeguards include: 


  • encryption in transit using HTTPS/TLS and encryption at rest using industry-standard encryption; 


  • encryption and restricted storage of OAuth access and refresh tokens, with credentials and secrets managed separately from application code; 


  • role-based and least-privilege access controls, multi-factor authentication for privileged access and periodic access reviews; 


  • tenant and network access controls, logging and audit trails, monitoring and alerting for suspicious activity; 


  • secure software-development practices, vulnerability management, patching, change management and incident-response procedures; 


  • business-continuity, backup and disaster-recovery controls; and 


  • contractual confidentiality and security obligations for personnel and service providers with authorized access. 


Roma maintains a SOC 2 Type II attestation and ISO/IEC 27001 certification. No security method is completely risk-free, but we continually review and improve our safeguards based on the nature of the information and relevant risks. 


8. Retention and Deletion 


We retain information only for as long as reasonably necessary to provide the Services, meet the purposes described in this Policy, comply with contractual or legal obligations, resolve disputes and enforce agreements. Customer-specific retention settings or a written customer agreement may establish a shorter or different period. The following rules describe our general approach and the additional treatment of Google and Microsoft user data: 






Data category 



Retention rule 



Deletion process 



Roma account, contact and configuration data 



Retained while the account or customer relationship is active and thereafter only as needed for legitimate business, security, contractual or legal purposes. 



Deleted or de-identified within 30 days after a verified account-deletion request or applicable termination, subject to legal retention requirements. 



Customer Data from uploads or non-Google integrations 



Retained for active customer workflows and the customer-configured or contractually agreed retention period. 



Deleted from active systems within 30 days after a verified applicable request or termination, unless the customer requests retention or law requires it. 



Google Login profile information 



Retained while the corresponding Roma account remains active and as otherwise required for account security or legal compliance. 



Deleted or de-identified within 30 days after verified deletion of the corresponding Roma account, subject to legal retention requirements. 



Gmail OAuth tokens and connection details 



Retained while the optional Gmail integration is connected and required to provide the enabled feature. 



When the Gmail integration is disconnected, permission is revoked or the account is terminated, tokens are revoked where technically available and deleted from active systems within 7 days. 



Gmail messages, attachments and metadata imported into Roma 



Retained while needed for the customer's active Roma workflows and for the customer-configured or contractually agreed retention period. 



Deleted from active systems within 30 days after a verified deletion request or termination, unless the customer expressly asks to retain imported business records or law requires retention. 



Data extracted or derived from Gmail content 



Retained with the related deduction, transaction, reconciliation or audit record for the applicable customer retention period. 



Deleted or de-identified with the related record within 30 days after an applicable verified request or termination, subject to legal retention requirements. 



Microsoft Login profile information 



Retained while the corresponding Roma account remains active and as otherwise required for account security or legal compliance. 



Deleted or de-identified within 30 days after verified deletion of the corresponding Roma account, subject to legal retention requirements. 



Microsoft OAuth tokens and connection details 



Retained while the optional Microsoft integration is connected and required to provide enabled features. 



When the Microsoft integration is disconnected, permission is revoked or the account is terminated, tokens are revoked where technically available and deleted from active systems within 7 days. 



Microsoft mail, attachments, metadata and sent-workflow records imported into or generated through Roma 



Retained while needed for the customer's active Roma workflows and for the customer-configured or contractually agreed retention period. 



Deleted from active systems within 30 days after a verified deletion request or termination, unless the customer expressly asks to retain business records or law requires retention. 



Data extracted or derived from Microsoft mail 



Retained with the related deduction, transaction, reconciliation or audit record for the applicable customer retention period. 



Deleted or de-identified with the related record within 30 days after an applicable verified request or termination, subject to legal retention requirements. 



Backups containing deleted integration data 



Maintained for resilience on a rolling, access-restricted schedule. 



Deleted data expires from backups within 90 days and is not restored to production except for disaster recovery; if restored, the deletion request is reapplied. 



Security and audit logs 



Retained for up to 12 months, or longer where required by law or a binding customer security requirement. 



Automatically expired or de-identified at the end of the retention period. 



 


If applicable law requires us to retain particular information, we will isolate and restrict that information from ordinary use and delete it when the legal obligation ends. Aggregated or irreversibly de-identified information may be retained because it no longer identifies a user or customer. 


9. Your Controls and Deletion Requests 


  • Review, correct, export or request deletion of account information and Customer Data using available Roma controls or by contacting the Grievance Officer in Section 15. 


  • Disable a connected service using the applicable integration settings. Disabling an integration stops new retrieval but does not necessarily delete information already imported into Roma. 


  • Disconnect Gmail from Roma using the integration settings available to you or your organization administrator. 


  • Revoke Roma's Google access through your Google Account's third-party connections page at https://myaccount.google.com/connections. 


  • Request deletion of Google Login profile information, Gmail content or other Google user data by contacting the Grievance Officer in Section 15. Please identify the connected account and organization. We may verify identity and authority before acting. 


  • Disconnect the Microsoft email integration using Roma's integration settings, or revoke Roma's access through your Microsoft account or organization administrator. 


  • Request deletion of Microsoft Login profile information, Microsoft mail content or other Microsoft user data by contacting the Grievance Officer in Section 15. Please identify the connected account and organization. We may verify identity and authority before acting. 


  • A verified deletion request will be completed according to the timeframes in Section 8. We will confirm completion or explain any lawful exception. 


Revoking Google or Microsoft access stops new provider-data retrieval and any provider-dependent actions, but does not automatically delete data already imported into or generated through Roma. To delete previously imported or generated data, submit a deletion request or use an available customer-admin deletion control. 


10. Cookies and Similar Technologies 


We may use strictly necessary cookies and similar technologies for authentication, security, session management and preferences. We may also use limited analytics to understand Website and Service performance. Where required, we obtain consent for non-essential cookies. Browser controls may allow you to block cookies, but some features may not function correctly. 


11. International Processing 


Roma and its service providers may process information in countries other than the country where it was collected. Where required, we use appropriate contractual, organizational and technical safeguards for cross-border transfers and comply with applicable data-protection requirements. 


12. Children's Privacy 


The Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children through the Services. If you believe a child has provided information to us, contact us so that we can take appropriate action. 


13. Third-Party Services 


The Services may link to or integrate with third-party services. Their privacy practices are governed by their own terms and policies. This Policy governs Roma's handling of information received from those services, including Google user data received through Google APIs and Microsoft user data received through Microsoft identity services and Microsoft Graph. 


14. Changes to this Policy 


We may update this Policy to reflect changes in the Services, law or our practices. We will post the updated Policy with a revised effective date. If a change materially affects how we use Google user data or other personal information, we will provide prominent notice and obtain consent where required before applying the new use. 


15. Contact and Grievance Officer 


For questions, privacy requests or grievances, contact: 


Mr. Rocky DMary, Grievance Officer, AlphaStar Technologies Private Limited 
Email: rocky.dmary@nakad.co 
Registered office: Plot No. 27, 3rd Floor, Community Centre, Naraina Vihar, Phase-I, Delhi, South West Delhi, India 110028