Privacy Policy
Last updated: 2026-08-06
1. Data controller
Studroof (Benhmid Oualid). Contact: support@studroof.com.
2. Data we collect
Account: email, name, photo, university, dates, city. Student profile: budget, flatmate preferences, lifestyle. Listings: address, photos, price. Messages. Payments via Stripe — Studroof never stores card numbers. Erasmus cohorts (cohorts): city, season, capacity — technical reference data, not personal. Cohort memberships (cohort_memberships): user_id, cohort_id, role (student/host), Roofer status, membership status (active/graduated/dropped), join date. Semester payments (season_payments): user_id, cohort_id, amount, currency, Stripe session and payment intent identifiers, status, payment date. Erasmus Squads (squad_memberships): user_id, squad_id, pre-arrival/active/graduated state, last-seen timestamp. Discussion topics (squad_topics): technical identifiers (i18n keys), no personal data. Posts published between students (squad_posts): author, text content, original locale, creation/edit dates, hidden status (moderation). Emoji reactions to posts (squad_post_reactions): author, reaction type. Squad notifications log (squad_notification_log): user_id, squad_id, digest kind sent (J-7 / J-1 / arrival), send date. Guide reminders log (guide_notification_log): user_id, reminder kind sent (pre-arrival J-30 / post-arrival J+7), send date. Cookieless audience measurement (Vercel Web Analytics), see section 15. Where applicable, audience-measurement tools subject to consent (see section 7): Plausible (cookieless page counting) and Microsoft Clarity, a session-recording ("session replay") and heatmap tool — a more intrusive processing than Plausible, which sets cookies and records your browsing interactions (mouse movements, clicks, scrolling); the sensitive content you type is masked by default before it is sent (see section 5). Advertising and retargeting (Meta Pixel): if you separately consent to it (an advertising consent distinct from the analytics consent — see section 7), Studroof loads the Meta Pixel (Facebook/Instagram), which sends Meta browsing events (page views, interactions) to measure the effectiveness of our ads and to show you retargeted ads on Facebook and Instagram. This is cross-site advertising profiling, a purpose distinct from plain audience measurement; it is never activated under the analytics consent alone. Server logs: IP address, user-agent, date. Conversation attachments: images you send to your correspondent in a conversation, stored in a private space (file name, type, size). Shared location: when you choose to share your location in a conversation, one-off geolocation coordinates (latitude and longitude at the moment of sharing) and the date of sharing. Studroof does not track your movements and does not derive an address from these coordinates. City search (autocomplete): when you type a city name, the text you enter is relayed by Studroof’s server to our geocoding provider to suggest matches; Studroof does not send your IP address to that provider and keeps from your search only the city you select and its country code. Introductions usage counter (contact_usage_total): your identifier, the total number of landlords and flatmates you have contacted since you created your account, and the date it was last updated. This counter is used only to apply your free introductions and then, if you take a Pass, to give you unlimited contacts. Notification preferences (notification_preferences): your identifier and your email reception choices (requests, messages, weekly digest, your squad’s arrival updates, Guide reminders), with the date they were last changed.
3. Legal basis
Consent (account creation, posting in a Squad), performance of contract (any paid services (prior Studroof+ subscriptions and Studroof Passes), Roofers Programme enrolment, exchanging the information you need for your housing including conversation attachments), legitimate interest (fraud prevention, community safety including the removal of reported illegal content, animating the pre-arrival community so students of the same cohort can help each other and meet before landing), legal obligation (accounting retention of payments). For location sharing: your explicit consent, collected at the precise moment you decide to share your location (GDPR article 6(1)(a)); you can withdraw this consent at any time by deleting the location message, as easily as you gave it (article 7(3)). For the pre-arrival community animation (J-7 / J-1 / arrival-day emails), you can object at any time and without giving a reason from /settings, Notifications tab (GDPR article 21). The objection takes effect immediately: subsequent sends are filtered at the source. The same applies to the Guide reminders (admin-step emails triggered by your arrival date, at J-30 before and J+7 after): sent on the basis of our legitimate interest in helping you settle in, you can object at any time from /settings, Notifications tab (GDPR article 21), the objection likewise being filtered at the source.
4. Retention
While the account is active, then 30 days after a deletion request. Server logs: 12 months. Stripe data: per their retention policy. Semester payments (season_payments): 5 years from the payment date, in accordance with Article L102B of the French Tax Procedure Code. Posts published in a Squad (squad_posts) and reactions (squad_post_reactions): kept until the author’s account is hard-deleted, then cascade-deleted. Squad notifications log (squad_notification_log): cascade-deleted when the recipient’s account is hard-deleted. Notification preferences (notification_preferences): kept for as long as your account exists, then cascade-deleted when your account is permanently deleted (hard-delete).
Student verification: supporting documents are deleted as soon as a decision is made; submission metadata and the verification audit log are kept for as long as your account is active, and deleted or anonymised when you delete your account.
Conversation attachments: kept while the message exists; removed from our storage when you delete the message or when your account is permanently deleted (hard-delete).
Shared locations: kept while the message exists; the coordinates are erased when you delete the message or when your account is permanently deleted (hard-delete).
Introductions usage counter (contact_usage_total): kept for as long as your account exists, then cascade-deleted when your account is permanently deleted (hard-delete).
5. Recipients
Vercel (hosting and audience measurement), Supabase (database), Stripe (payments), Resend (emails), Plausible (analytics), Microsoft Clarity (session recording and heatmaps) — each under a GDPR-compliant Data Processing Agreement.
Microsoft Clarity is a Microsoft Corporation (United States) session-recording ("session replay") and heatmap tool, loaded only after your analytics consent (the same cookie banner as Plausible). Microsoft receives your browsing interactions (mouse movements, clicks, scrolling, pages viewed) to produce session replays and aggregated heatmaps. This is more intrusive than plain page counting: Clarity sets cookies. As a safeguard, Clarity masks sensitive content by default — input fields, email addresses and numbers — directly in your browser, before anything is sent to Microsoft (Microsoft "Masking content" documentation, learn.microsoft.com/en-us/clarity/setup-and-installation/clarity-masking). This transfer outside the EU is governed by the European Commission’s Standard Contractual Clauses set out in the Microsoft Data Protection Addendum; Microsoft is also certified under the EU-US Data Privacy Framework. Microsoft processes this data under its own privacy statement (privacy.microsoft.com).
Meta Pixel (advertising): when you separately consent, Studroof activates the Meta Pixel, an advertising tool from Meta. For this processing, Studroof and Meta Platforms Ireland Limited (Ireland) act as joint controllers within the meaning of Article 26 GDPR, for the collection and transmission to Meta of browsing events (Meta joint-controller "Controller Addendum"); this joint controllership was established by the Court of Justice of the European Union for third-party social plug-ins (Fashion ID judgment, C-40/17). Meta then uses this data for its own advertising purposes (conversion measurement, retargeting audiences and lookalike audiences), under its own privacy policy (facebook.com/privacy/policy). Meta sets cookies (for example _fbp). The transfer to the United States is governed by the European Commission’s Standard Contractual Clauses set out in the Meta European Data Transfer Addendum; Meta Platforms, Inc. (United States) is moreover certified under the EU-US Data Privacy Framework. You can withdraw your advertising consent at any time from /account/cookies.
komoot GmbH (Germany, "Photon" geocoding service, based on OpenStreetMap data) only receives the city text you search for, in order to return autocomplete suggestions; Studroof relays this search from its server, so your IP address is never sent to komoot, and the query is tied to no cookie or tracker. komoot processes this query under its own privacy policy (komoot.com/privacy).
The OpenStreetMap Foundation (United Kingdom — a country covered by a European Commission adequacy decision —, "Nominatim" geocoding service) only receives the public OpenStreetMap identifier of the city you select (osm_id) — never your IP address or the text you typed — so that Studroof can retrieve that city’s name in your language; Studroof relays this request from its server, so your IP address is never sent to the Foundation, and the request is tied to no cookie or tracker. The OpenStreetMap Foundation processes this request under its own privacy policy (osmfoundation.org/wiki/Privacy_Policy).
6. Your rights
Access, rectification, erasure (via /account/danger-zone), objection and portability (JSON export). You can also delete a message, an attachment or a shared location yourself from the conversation; deleting it erases the corresponding data from our systems (and purges the file from our storage if it is an attachment). Data protection contact: support@studroof.com. To object to your squad’s arrival emails: /settings, Notifications tab. To object to the Guide reminders: /settings, Notifications tab.
7. Cookies
See the Cookie Policy: /legal/cookies. Vercel’s audience measurement (Vercel Web Analytics) works without cookies and therefore does not appear in the cookie list (see section 15).
8. Security
Encryption in transit (TLS), Supabase Row-Level Security, encryption at rest.
9. Transfers outside the EU
Stripe (USA) and Resend (USA, email delivery), under the European Commission’s Standard Contractual Clauses (and, where applicable, the EU-US Data Privacy Framework). Vercel (USA, hosting and audience measurement), under the Standard Contractual Clauses set out in Vercel’s Data Processing Agreement (DPA). Microsoft Corporation (USA, the Microsoft Clarity analytics tool, with consent — see section 5), under the Standard Contractual Clauses set out in the Microsoft Data Protection Addendum, Microsoft also being certified under the EU-US Data Privacy Framework. Meta Platforms, Inc. (USA, the Meta advertising pixel, with a separate advertising consent — see section 5), under the Standard Contractual Clauses set out in the Meta European Data Transfer Addendum, Meta Platforms, Inc. also being certified under the EU-US Data Privacy Framework.
10. Changes
Any change to this policy is published on this page.
11. Complaints
You may lodge a complaint with the CNIL (www.cnil.fr) or your local data protection authority.
12. Partner affiliations
On some editorial pages, Studroof displays recommendations to selected partners (for example Garantme for rental guarantees, Uniplaces / Spotahome / HousingAnywhere for housing search). Data collected when you click an affiliate link (affiliate_clicks table): timestamp, clicked partner identifier, source URL on Studroof, anonymous session identifier (from the analytics cookie), user identifier (only if you are signed in — otherwise NULL), SHA-256 hashed IP address (never the raw IP, with a monthly-rotated salt) and SHA-256 hashed user-agent. Conversions reported by partners (affiliate_conversions table): timestamp, partner identifier, B2B commission amount (internal accounting information, never shown to another user). Legal bases (GDPR art. 6): (a) your consent, collected via the cookie banner, for individualised analytics tracking (art. 6(1)(a)); (b) Studroof’s legitimate interest in anonymised audience measurement of editorial recommendations and in calculating the B2B commission owed by the partner (art. 6(1)(f)). Purposes: measure the editorial effectiveness of recommendations, calculate the B2B commission owed by the partner, improve the relevance of displayed recommendations. Studroof does no commercial profiling, no data resale and no ad retargeting. Recipients: Studroof (data controller); affiliate partners (Garantme, Uniplaces, Spotahome, HousingAnywhere) — only when you click on the partner link and your browser is redirected to their website, subject to their own privacy policy (partner terms link shown on each card); Studroof’s technical sub-processors: Supabase (database hosting, EU), Sentry (monitoring), Upstash (rate-limit). No transfer outside the EU is performed without the European Commission’s Standard Contractual Clauses. Retention: affiliate clicks 24 months maximum (editorial audit + recommendations); conversions 5 years (accounting obligations, Article L102B of the French Tax Procedure Code). If your account is permanently deleted (hard-delete), the user_id field of the clicks is set to NULL — the editorial statistic is preserved but is no longer linked to you. Your rights (GDPR art. 13, 15, 17 and 20): you can access your affiliate clicks via the JSON export (affiliateClicks[] included in the /account export), request their erasure via /account/danger-zone (anonymisation user_id → NULL), and disable analytics tracking at any time from /account/cookies. Commission disclosure (DSA art. 26 and French Consumer Code L. 121-1): Studroof gets a commission from the partner if you book or sign up through an affiliate link. It has no impact on the price you pay. Studroof does not take part in the contract concluded between you and the partner, does not negotiate the price and earns no commission on your rent.
13. Alumni & Ambassadors Programme
Alumni & Ambassadors Programme (starting at the end of your Erasmus stay): alumni status (upcoming / active / graduated / alumni / dormant), alumni opt-in date, Erasmus home city, per-stay arrival and departure dates (student_stays table), alumni consent audit log (alumni_consent_log table: id of the affected stay, action — opt-in / opt-out / purge —, purpose — alumni retention or right to erasure —, SHA-256 hashed IP address captured at the moment you clicked the J+0 email, timestamp, source — email_link). No sensitive data (GDPR Art. 9) is collected as part of the programme. Legal bases (GDPR Art. 6): (a) your consent, collected explicitly when you click the "Become Alumni Studroof" button in the J+0 email sent at the end of your stay, for the active retention of your alumni account and the sending of post-stay communications (Art. 6 §1.a); (b) Studroof’s legitimate interest in keeping your Erasmus passport data after your stay, so that you can reactivate it or add future stays, and for the continuity of the alumni network — with no active processing until you act (no ambassador emails, no profiling) (Art. 6 §1.f, balancing test documented internally). Purposes: keep your multi-stay Erasmus passport, share cross-city recommendations with incoming students, send post-stay communications, animate the alumni network. Studroof does no commercial profiling, no data resale, no ad retargeting from your alumni data. Recipients: Studroof (data controller); Studroof’s technical sub-processors: Supabase (database hosting, EU), Resend (alumni email delivery), Sentry (monitoring). No transfer outside the EU is performed without the European Commission’s Standard Contractual Clauses. Retention: at the end of your Erasmus stay, if you do not activate the Alumni programme via the "Become Alumni Studroof" button in the J+0 email within 30 days, the stay is set to dormant (dormant status: read-only, no more notifications). As of today, Studroof does not yet automatically delete the data of a dormant stay: it is kept until you delete it yourself. If you activate the Alumni programme, your passport for that stay is kept as long as your account exists (no inactivity-based deletion is applied to date). The only permanent erasures available today are the ones you trigger yourself: deleting a stay from /me/alumni, which deletes the corresponding student_stays row; and deleting your account via /account/danger-zone, which deletes your stays (student_stays table) as well as your alumni_consent_log, both linked to your profile by an ON DELETE CASCADE foreign key. Studroof has not yet settled on a storage-limitation policy (GDPR Art. 5 §1.e) for this data: until one is adopted, no automatic deletion takes place. The periods will be stated on this page as soon as they are adopted. Your rights (GDPR Art. 7 §3, 13, 15, 17 and 20): you can withdraw your consent to the Alumni & Ambassadors Programme at any time from /me/alumni — with exactly the same simplicity as opting in, with no justification (Art. 7 §3, anti-dark-pattern aligned with the CNIL ruling SAN-2022-009). Withdrawing either pauses your account or permanently deletes it — you choose. You can access your alumni consent log via the JSON export (alumni_consent_log filtered on your id), and request the full deletion of your passport via /account/danger-zone: deleting your account erases both your stays and your consent log, each linked to your profile by an ON DELETE CASCADE foreign key. Deleting a single stay, by contrast, KEEPS the corresponding log row, whose stay identifier is simply set to NULL — that is the record, required by Article 5(2), showing that your erasure request was received and carried out.
14. Student status verification
To protect the community against fake profiles, Studroof lets students prove their Erasmus student status to obtain a "Verified student" badge, using either a university email (one-time code) or a supporting document.
Data we process for this purpose: (university-email method) the university email address you enter, a one-time code (stored only as a salted SHA-256 hash, valid 15 minutes, single-use), and the date it was verified; (document method) the document you upload (Erasmus attestation, enrolment certificate, student card, or "other") — we ask you to redact any information that is not needed to prove your student status. Files are stored in a PRIVATE bucket (verification-docs); they are never public, are accessible only to authorised Studroof staff through short-lived signed links, and are DELETED as soon as a decision is made (approved, rejected or resubmission requested), as well as when a newer submission replaces an older one; (submission metadata and audit log) method used, document type, submission status, decision date, the deciding staff member, and the rejection reason where applicable.
We do NOT request or knowingly process special-category data (GDPR Art. 9). A photo on a student card is reviewed visually by a human and is never used for biometric identification.
Legal basis: Studroof’s legitimate interest in preventing fraud and keeping the community safe (GDPR Art. 6(1)(f); see Recital 47, which recognises fraud prevention as a legitimate interest). A balancing test is documented internally.
Recipients: authorised Studroof staff (review); Supabase (private storage and database); Resend (delivery of the one-time-code email). See section 9 for transfers outside the EU.
Retention: verification documents are deleted as soon as a decision is made. Submission metadata and the audit log are kept for as long as your account is active, and deleted or anonymised when you delete your account, so that we can demonstrate why a decision was taken and detect repeated fraud attempts while you use Studroof.
Your rights: you can access and export your verification data via the JSON export (/account), ask for rectification, and obtain erasure (via /account/danger-zone, or by withdrawing a pending request). While a request is pending, you cannot delete the proof yourself so that it cannot be tampered with before review; the document is deleted automatically once the decision is made.
⚠️ Draft — lawyer review required.
15. Audience measurement (Vercel Web Analytics)
Studroof measures the audience of its site with Vercel Web Analytics, a cookieless tool. No cookie, no advertising identifier and no tracker is stored or read on your device, and no advertising profile is built. For each page view, the following information is processed in aggregate form: the page viewed, the originating site or link (referrer), the campaign parameters (UTM), the country, region and city estimated from your IP address, the device type, the operating system and the browser. Your IP address is not retained: it is used only, at the time of the visit, to generate a hashed technical identifier that Vercel automatically deletes after 24 hours; the statistics remain aggregated and cannot re-identify you.
We also track a "waitlist sign-up" conversion event, to which only non-identifying information is attached: your role (student or landlord), the arrival source and channel (from the UTM parameters or the originating site, otherwise "direct") and an indication of whether a city was provided (yes/no). Neither your email address, nor your name, nor the name of your city or university is sent to Vercel; your waitlist sign-up email is stored separately in our database and covered by sections 2 to 6.
Legal basis: Studroof’s legitimate interest in understanding the audience of its site and improving its service (GDPR article 6(1)(f)). Because this measurement neither writes to nor reads any information on your terminal equipment, it does not require prior consent; it is distinct from the consent-based analytics cookies mentioned in section 7. You can object to this processing at any time (GDPR article 21) by writing to support@studroof.com.
Sub-processor and transfer outside the European Union: Vercel Inc. (United States), which also hosts the site. This transfer is governed by the European Commission’s Standard Contractual Clauses set out in Vercel’s Data Processing Agreement (DPA).
16. Hosts and housing listings
When you publish a housing listing as a host (private individual, residence or agency), Studroof processes the data described below, in accordance with Article 13 GDPR.
Data we collect: your identity and contact details (name, email address, and phone number if you provide one); the address and location of the property (street, city, geolocation coordinates derived from the address you enter); the photos of the property you upload; the property’s characteristics (type, floor area, number of rooms, amenities, rent, charges, availability); and, for professional hosts (residences, agencies), the company name and SIRET number.
Purposes: to publish and display your listing, let interested students contact you, keep the community safe and prevent fraud.
Legal basis: performance of the contract between you and Studroof when you request the publication of your listing and the introduction to students (GDPR article 6(1)(b)); for professional hosts, compliance with our legal obligations, notably accounting ones (GDPR article 6(1)(c)); fraud prevention relies on our legitimate interest (article 6(1)(f)).
Public display: when a listing is published, your first name, your profile picture (avatar), the property location and the property photos are DISPLAYED PUBLICLY on the listing page, visible to anyone who views it. Only publish information and photos you are happy to make public and that you hold the rights to. Your email address and phone number are never displayed publicly: exchanges go through Studroof messaging. These public listings are also indexable by search engines: see section 17. The exposure of these pages to artificial-intelligence agents is described in section 18.
Address autocomplete: when you type the property address, the text you enter is relayed by Studroof’s server (never directly by your browser) to the public geocoding service of the French National Address Database, operated by the IGN — the French national mapping agency — through the Géoplateforme (data.geopf.fr), to suggest matching addresses. Your IP address is not sent to the IGN, the query is tied to no cookie or tracker, and this processing takes place in France (no transfer outside the European Union).
Recipients: the students who view your listing (only for the public data above); Studroof’s technical sub-processors (Vercel for hosting, Supabase for the database and photo storage, in the European Union); the IGN for address autocomplete. See sections 5 and 9.
Retention: your listings are kept for as long as your account exists; you can remove a listing at any time. When your account is permanently deleted (hard-delete), your listings and their photos are deleted.
Your rights: access, rectification, erasure, objection and portability (see section 6). You can edit or remove a listing at any time from your host area.
⚠️ Draft — lawyer review required.
17. Public listings: marketplace, handovers and search-engine indexing
In addition to host listings (section 16), other content you publish is displayed publicly on Studroof, viewable without an account by any visitor. Studroof processes this data to perform the service you request — publishing a viewable listing (GDPR article 6(1)(b)) — exposing only the minimum necessary (article 5(1)(c)).
Student-to-student item listings (/marketplace): your first name, your profile photo (avatar) and the pickup neighbourhood of the item are displayed publicly, in addition to the item’s title, description, price and photos.
Student handovers (/rooms): when a departing student hands over their home, their first name, their profile photo, their city, their neighbourhood and the home’s availability date are displayed publicly.
In every case, the following are never displayed publicly: your last name, your email address, your phone number, your exact departure date, your nationality or country of origin, and the exact address. Getting in touch always goes through an account: a visitor must sign in to contact you.
Search-engine indexing: because these pages are public, all listings published on Studroof — host listings (section 16), handovers and marketplace items — can be crawled and indexed by search engines (for example Google), which may show them in their results, keep a cached copy and present them outside the Studroof context. For that indexing, a search engine acts as an independent controller (Court of Justice of the European Union, Google Spain judgment, C-131/12).
Erasure and third-party cache: when you remove a listing, it disappears from Studroof immediately, but a copy already cached by a third party (a search engine) may remain temporarily; we cannot erase it on your behalf on that third party. You can then ask the relevant search engine directly to delist the page (right to delisting, same C-131/12 judgment).
Artificial-intelligence agents: these same public pages can also be crawled by automated artificial-intelligence agents, whose effects and limits differ from those of a search engine. They are covered in section 18.
Your rights: you can remove a listing from your account at any time, which makes it non-public on Studroof immediately, and request erasure of your data via /account/danger-zone (GDPR article 17). Publication itself relies on performance of the contract you request (article 6(1)(b)): the direct levers are therefore removal of the listing and erasure. The right to object under article 21 applies to the exposure to artificial-intelligence agents, which relies on our legitimate interest (see section 18). See also section 6.
⚠️ Draft — lawyer review required.
18. Artificial-intelligence agents (crawling, citation and model training)
The public pages described in sections 16 and 17 are not only crawled by search engines: they can also be crawled by automated artificial-intelligence agents. Those agents are not equivalent, and the consequences for you differ depending on which family they belong to. The list of allowed and blocked agents is published in Studroof’s /robots.txt file, which is authoritative.
Search and citation agents — for example OAI-SearchBot and ChatGPT-User (ChatGPT), Claude-SearchBot and Claude-User (Claude), PerplexityBot and Perplexity-User (Perplexity). They fetch a public page at the moment someone asks a question, in order to answer it by citing the source and linking back to Studroof. The fetch is one-off and stays tied to the original page: if you remove your listing, the page is gone and the agent does not find it on its next pass. These agents are allowed.
Model-training agents — for example GPTBot, ClaudeBot and anthropic-ai, Google-Extended, Applebot-Extended. They collect public pages in order to train or enrich artificial-intelligence models. Here the collection is not one-off: the content may be incorporated into a model, detached from the original page and without any citation. These agents are not allowed on listing pages: the /rooms and /marketplace sections are closed to them. They may only access Studroof’s editorial pages (blog, information pages, landlord pages), which contain no user listings.
Redistributed corpora — the CCBot agent (Common Crawl) has been fully blocked since 29 July 2026. Such a corpus is a public archive of the web, redistributed to re-users we do not know: it cites no source, sends no visit, and a copy already distributed can never be recalled. We therefore chose to make nothing available to it.
Purpose and legal basis: this exposure pursues Studroof’s legitimate interest in making its service known and its public pages findable, including by the artificial-intelligence assistants students now use to prepare their arrival (GDPR article 6(1)(f)). It is distinct from the publication itself, which you request and which relies on performance of the contract (article 6(1)(b) — see sections 16 and 17).
A limit we owe you plainly: remedies do not work the same way across these families. For a search engine, delisting is possible (see section 17). For a model that has already been trained, it is not: if content has been collected and then incorporated into a model, neither you nor Studroof can have it extracted — we control neither those models nor the companies that release them. The measure the GDPR provides when data have been made public — informing other controllers of your erasure request (article 17(2)) — has no equivalent effect here to delisting. In other words: your right to erasure (article 17) and your right to object (article 21) take effect for the future, not retroactively on a model that has already been trained. We would rather tell you than promise a result we could not deliver.
What you can obtain at any time, and what we then do: (a) remove or unpublish your listing from your account — it immediately stops being public and is no longer collected on subsequent passes; (b) object to this exposure (GDPR article 21) by writing to support@studroof.com — we require no justification from you: we then exclude your pages from indexing and crawling by these agents, for the future; (c) request erasure of your data via /account/danger-zone (article 17); (d) ask a search engine to delist a page (see section 17). These requests are handled for the future, subject to the limit set out in the previous paragraph.
What is never exposed: the surfaces that are only reachable once signed in — your account, your profile, your messages and their attachments, your shared locations, your verification requests, the host area, the admin area — are excluded from all of these agents without exception, including the allowed ones, under the same rules applied to search engines. None of these agents receives your last name, your email address, your phone number or a home’s exact address: that information does not appear on public pages (see sections 16 and 17).
Finally, these rules are public instructions addressed to agents: they are followed by those that read and respect them, but they cannot technically prevent an actor that decides to ignore them. As with any online publication, only publish information and photos you are willing to make public.
⚠️ Draft — lawyer review required.