Privacy Policy
Last Updated and Effective Date: May 26, 2026
1. Welcome
At ROKO, we believe your home should feel like an extension of who you are — and the same goes for how we handle your data. This Privacy Policy explains what information we collect when you visit rokohome.com or purchase a ROKO Product, why we collect it, and the choices you have.
We've written this in plain language. Where legal terms are necessary, we explain them.
2. Who we are
rokohome.com is owned and operated by ModaTrends, LLC, doing business as ROKO, a limited liability company organized under the laws of Wisconsin, United States.
| Legal entity | ModaTrends, LLC (DBA ROKO) |
| Mailing address | 2800 E Enterprise Ave., Ste. 333, Appleton, WI 54913, USA |
| Privacy contact | [email protected] |
| Contact form | rokohome.com/contact |
Throughout this policy, "ROKO," "we," "us," and "our" refer to ModaTrends, LLC.
For data protection purposes, ModaTrends, LLC is the data controller of the personal information we collect about you.
3. Scope of this policy
This Privacy Policy applies to personal information we collect through:
- rokohome.com and any subdomain we operate for customer-facing purposes
- Your ROKO Home Profile, including both the ROKO Discovery (our interactive home profiling experience) and the personalized report delivered to your email upon completion
- Email correspondence with our team
- Forms, newsletters, and surveys you submit to us
It does not apply to websites, apps, or services operated by third parties, even if we link to them. Their privacy practices are their own.
What we mean by "ROKO Products"
Throughout this policy, "ROKO Products" means the goods and services we offer through rokohome.com, including but not limited to:
- The ROKO Home Profile, our flagship product, available in four variants (Essential Individual, Premium Individual, Essential Couple, Premium Couple). Each purchase includes the ROKO Discovery (interactive experience) and the personalized report delivered upon completion.
- Together Edition — the experience that joins two existing Home Profiles
- Upgrades between variants
- Gift cards redeemable for any of the above
- Additional digital products and services we may launch in the future
When we say "your purchase," we mean any ROKO Product.
4. Information we collect
4.1 Information you give us directly
When you purchase a ROKO Product, take the Discovery, redeem a gift card, or contact us, we collect:
| Category | Examples | Purpose |
|---|---|---|
| Identity | First name, last name | Personalize your Home Profile; address you correctly in communications |
| Contact | Email address | Deliver your access link, Home Profile, support, satisfaction surveys |
| Discovery responses | Your answers to the questions in the Discovery | Generate your personalized Home Profile |
| Optional demographic data | Age range, household composition, moving plans, profession | Improve our psychological profiling; optional and can be skipped |
| Communications | Messages you send us, survey responses | Customer support; product improvement |
4.2 Information collected by our payment processor
We do not collect, store, or process your payment card information. When you make a purchase on rokohome.com, you are redirected to Stripe, our payment processor. Stripe collects directly from you:
- Full name as it appears on your card
- Card number, expiration date, and security code
- Billing address and postal code
- Country
- Phone number (when required)
Stripe shares with us only what we need to fulfill your order: your email, name, country, and a confirmation that payment succeeded. We never see your card number.
Stripe's handling of your payment data is governed by Stripe's own privacy policy: stripe.com/privacy.
4.3 Information collected automatically
When you visit rokohome.com, we automatically collect limited technical information:
- IP address (anonymized after collection where applicable)
- Browser type and version
- Device type and operating system
- Pages visited, time spent, referring URL
- Language preference
- General location inferred from IP (country and region, not precise address)
We use Google Analytics 4 (provided by Google LLC) to understand aggregate usage of rokohome.com. Google Analytics is configured with Consent Mode v2: until you consent to analytics cookies in our cookie banner, Google receives only an anonymized signal that does not identify you, does not set cookies, and does not allow Google to build a profile of you. If your browser sends a Global Privacy Control (GPC) signal, Google Analytics is disabled automatically.
This information is collected through essential cookies and, with your consent, analytics cookies. See our Cookie Policy for full details.
4.4 Information from third parties
We may receive limited information from:
- Stripe — payment confirmation, transaction identifiers
- Email service providers — bounce reports, delivery status
- Hosting infrastructure — security logs, traffic anomalies
We do not purchase personal information from data brokers, and we do not receive lists of customers from other companies.
4.5 Pre-launch list and newsletter subscription
Before ROKO's public launch, we offer a pre-launch notification list. After launch, we offer an optional newsletter. In both cases, we collect:
| Category | Examples | Purpose |
|---|---|---|
| Contact | Email address | Send you a single launch notification (transactional) and, if you give your explicit consent, occasional design ideas and ROKO updates |
| Language preference | ES or EN | Communicate with you in the right language |
| Consent metadata | Date and version of the consent text | Meet our audit obligations under GDPR/LGPD |
The launch email is transactional — sent once to everyone on the list, because subscribing to the list is the explicit request for that email.
Consent for any further communications (design ideas, updates, offers) is optional, granular, and separate from the launch notification. You can withdraw it at any time using the unsubscribe link in any marketing email or by writing to [email protected].
5. How we use your information
We use your information to:
Deliver the service you purchased
- Generate your personalized Home Profile
- Send you access links, the Home Profile PDF, and related communications
- Provide customer support when you write to us
Operate and improve ROKO
- Maintain and secure our website and systems
- Analyze aggregate usage patterns (with consent for non-essential analytics)
- Improve our Discovery methodology and the quality of our Home Profiles
- Validate and refine the six psychological profiles that power ROKO
Communicate with you
- Send transactional emails (access links, your Home Profile, satisfaction surveys, account-related notices)
- Send marketing emails only if you opt in via our newsletter subscription
- Respond to inquiries, complaints, and privacy requests
Comply with the law
- Meet tax, accounting, and recordkeeping obligations
- Respond to lawful requests from authorities
- Protect our rights, property, and the safety of our users
Improve our artificial intelligence systems — with important limits explained in Section 10
6. Legal bases for processing (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR:
| Purpose | Legal basis |
|---|---|
| Deliver the ROKO Home Profile you purchased | Contract (Art. 6(1)(b) GDPR) |
| Send transactional emails related to your purchase | Contract (Art. 6(1)(b) GDPR) |
| Comply with tax and accounting obligations | Legal obligation (Art. 6(1)(c) GDPR) |
| Operate and secure our website; prevent fraud | Legitimate interests (Art. 6(1)(f) GDPR) |
| Improve our methodology using anonymized data | Legitimate interests (Art. 6(1)(f) GDPR) |
| Analytics cookies | Consent (Art. 6(1)(a) GDPR) |
| Marketing emails | Consent (Art. 6(1)(a) GDPR) |
| Optional demographic data collection | Consent (Art. 6(1)(a) GDPR) |
You can withdraw consent at any time by contacting us at [email protected] or using the unsubscribe link in any marketing email.
7. Who we share your information with
We do not sell your personal information. We do not share it for cross-context behavioral advertising. We share it only with the service providers listed below, each bound by contractual confidentiality and data protection obligations.
| Provider | Role | Location | Data shared |
|---|---|---|---|
| Stripe, Inc. | Payment processing | United States | Payment data (collected directly by Stripe) |
| ZeptoMail (Zoho Corporation Pvt. Ltd.) | Transactional email delivery | India, United States | Name, email, Home Profile content |
| Cloudflare, Inc. | Content delivery network, security, DDoS protection | United States, global edge network | IP address, technical metadata |
| Hetzner Online GmbH | Hosting infrastructure (servers) | Germany (European Union) | All data stored on our servers |
| Google LLC (Google Analytics 4) | Aggregate website analytics | United States | Anonymized IP, browsing patterns, device type — only when you consent to analytics cookies |
| Zoho Corporation | Corporate email (support, administration) | India, United States | Correspondence sent to our support addresses |
Encrypted archive storage in Cloudflare R2. We use Cloudflare R2 as long-term encrypted archive storage for communications audit logs (delivery records for transactional emails), subject to the timeframes detailed in Section 9. Content is end-to-end encrypted before transfer; Cloudflare never has access to plaintext.
We may also share information:
- With legal authorities, when required by valid legal process or to protect our rights or the safety of others
- In a business transaction, such as a merger, acquisition, or asset sale, in which case the acquiring entity will be bound by this policy or provide notice of changes
- With your consent, for any other purpose we disclose to you at the time
When we engage new service providers, we update this policy accordingly.
8. International data transfers
ROKO operates from the United States. Our hosting infrastructure is in the European Union (Germany). Some of our service providers operate globally.
When we transfer personal information outside your country of residence:
- Transfers to the United States are covered by Standard Contractual Clauses (SCCs) approved by the European Commission, or by our service providers' participation in recognized adequacy frameworks where applicable.
- Transfers within the European Economic Area are subject to GDPR-level protection by default.
- Transfers to India (ZeptoMail, Zoho) are covered by Standard Contractual Clauses and supplementary security measures.
You can request a copy of the safeguards applied to transfers of your personal data by emailing [email protected].
9. How long we keep your information
We keep your personal information only as long as necessary for the purposes described in this policy.
| Data category | Retention period |
|---|---|
| Account information and your Home Profile (including Discovery responses) | Retained for as long as your relationship with ROKO continues, plus 24 months after your last interaction. You can request deletion at any time. |
| Home Profile PDF (direct access link) | Active for 365 days from delivery. The PDF is also delivered to your email, where it remains under your control. After 365 days, you can request a copy from support. |
| Home Profile PDF (archived copy) | Retained alongside your account information and recoverable upon request through support |
| Order and billing records | 7 years (tax and accounting obligations under US law) |
| Customer support correspondence | 3 years after last interaction |
| Marketing email subscription | Until you unsubscribe, plus 30 days for processing |
| Pre-launch list subscription (without marketing opt-in) | 90 days after launch or after your unsubscribe request, whichever comes first |
| Website analytics (if consented) | 14 months |
| Security logs | 12 months |
| Communications audit logs (delivery records for transactional emails) | 90 days in the operational database; from day 90 to day 730, in long-term encrypted archive; irreversibly deleted at 2 years |
| Anonymized Discovery data (for methodology improvement) | Indefinite, with no way to link back to you |
A note on staying current. Personal preferences evolve over time. We recommend retaking the Discovery every 5 years to keep your Home Profile aligned with how you actually live now. Your earlier Profiles remain in your account history.
When the retention period ends, we delete or irreversibly anonymize your personal information. "Last interaction" means any of the following: making a purchase, logging into your account, opening a transactional email, contacting support, or another action that signals an active relationship.
10. Artificial intelligence and automated processing
ROKO uses proprietary algorithms to generate your Home Profile. This is automated processing, but it is not "automated decision-making with legal or similarly significant effects" under Article 22 of the GDPR — your Home Profile is a creative recommendation, not a legal determination about you.
How we use data to improve our AI systems
We use anonymized and aggregated Discovery responses to:
- Validate and refine our six psychological profiles
- Improve the accuracy of our color, material, and plant recommendations
- Train our proprietary AI systems (ROKO does not use OpenAI, Anthropic, or other third-party AI models for this purpose)
Before data is used for these purposes, we irreversibly remove:
- Your name, email, and any direct identifiers
- IP addresses, device identifiers, and session tokens
- Billing information
- Exact timestamps (replaced with coarse time windows)
- Unique demographic combinations that could re-identify you
The result is aggregate data that cannot be linked back to you.
Your right to object
You can object to your Discovery responses being used in this way, even in anonymized form. We will honor your objection by excluding your data from our training datasets within 30 days.
To object:
- Email [email protected] with the subject "AI Training Opt-Out" and include the email used for your purchase
- Or submit a request through the contact form at rokohome.com/contact, selecting "Privacy Request" as the category
We will confirm receipt and completion by email.
11. Your privacy rights
Regardless of where you live, you have the following rights with respect to the personal information we hold about you:
- Right to access — request a copy of the personal information we hold about you
- Right to correct — request that inaccurate or outdated information be corrected
- Right to delete — request that we delete your personal information, subject to legal exceptions
- Right to object — object to certain uses of your data, including AI training as described above
- Right to withdraw consent — where we rely on your consent, you can withdraw it at any time
- Right to portability — receive your data in a commonly used, machine-readable format
- Right to complain — lodge a complaint with a data protection authority
Scope of the right to delete. Your right to delete applies to both our operational database and the long-term encrypted archive, subject to reasonable technical limitations involved in locating, decrypting and modifying encrypted archives. The procedure is documented in our internal processes and we execute it within applicable legal timeframes.
How to exercise your rights
- Email: [email protected]
- Contact form: rokohome.com/contact (select "Privacy Request")
We will respond within 30 days. If your request is complex, we may extend this period by up to 60 additional days and notify you. There is no charge for reasonable requests.
To protect your information, we may ask you to verify your identity before fulfilling a request. We will use the least invasive method possible (typically, confirming the request from the email address associated with your purchase).
12. Additional rights for residents of the EEA, UK, and Switzerland
If you are a resident of the European Economic Area, the United Kingdom, or Switzerland, you have the rights described in Section 11 under the GDPR, UK GDPR, and Swiss FADP.
Right to complain to a supervisory authority
If you believe our processing violates data protection law, you can lodge a complaint with your local data protection authority:
- EEA residents: edpb.europa.eu/about-edpb/board/members_en
- UK residents: Information Commissioner's Office — ico.org.uk
- Swiss residents: Federal Data Protection and Information Commissioner — edoeb.admin.ch
EU Representative
ROKO currently does not have an Article 27 GDPR representative designated in the European Union. If our user base in the EEA grows to a level that requires one, we will appoint a representative and update this policy.
In the meantime, EEA residents can exercise their rights by contacting us directly at [email protected]. We commit to responding within GDPR-mandated timeframes.
Right of withdrawal (14 days)
EU consumer law grants a 14-day right of withdrawal for online purchases. At checkout, you expressly consent to immediate access to your Discovery and waive this right, as permitted by Article 16(m) of EU Directive 2011/83/EU. See our Terms & Conditions for full details.
13. Additional rights for California residents
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you additional rights over your personal information.
Categories of personal information we collect
In the past 12 months, we have collected the following categories of personal information (as defined by CCPA):
| CCPA category | Do we collect? | Examples |
|---|---|---|
| Identifiers | Yes | Name, email, IP address |
| Customer records | Yes | Name, payment information (collected by Stripe) |
| Commercial information | Yes | Purchase history |
| Internet activity | Yes | Browsing on rokohome.com, Discovery responses |
| Geolocation (general) | Yes | Country and region inferred from IP |
| Geolocation (precise) | No | We do not collect precise location |
| Biometric information | No | |
| Sensory information | No | |
| Professional information | Yes (optional) | Profession (if you share in optional demographic form) |
| Education information | No | |
| Inferences | Yes | Your ROKO profile (e.g., Refugio Sereno) derived from Discovery responses |
| Sensitive personal information | Limited | Account credentials (if any); we do not collect race, religion, health, precise location, or other sensitive categories |
Your California rights
- Right to know — what personal information we collect, use, disclose, and the sources
- Right to access — a copy of your personal information
- Right to delete — request deletion, subject to legal exceptions (e.g., fraud prevention, tax records)
- Right to correct — request correction of inaccurate information
- Right to opt out of sale or sharing — see below
- Right to limit use of sensitive personal information — see below
- Right to non-discrimination — we will not charge you more or provide a lower-quality service for exercising your rights
Sale and sharing of personal information
ROKO does not sell your personal information. ROKO does not share your personal information for cross-context behavioral advertising.
We honor Global Privacy Control (GPC) signals automatically. If your browser sends a GPC signal, we treat it as a valid opt-out request for any future sharing.
Sensitive personal information
We do not use sensitive personal information for purposes other than those permitted by CCPA §7027(m) (delivering the service you requested, preventing fraud, ensuring security, and complying with law).
How to exercise your California rights
- Email: [email protected]
- Contact form: rokohome.com/contact (select "Privacy Request")
We will verify your identity using the email address associated with your account. An authorized agent may submit a request on your behalf with your written permission.
We will respond within 45 days. If your request is complex, we may extend by 45 additional days with notice.
Notice at collection
This Privacy Policy serves as our notice at collection under CCPA §1798.100(b). We collect the categories listed above for the purposes described in Sections 5 and 10. We retain each category for the periods described in Section 9.
14. Additional rights for Brazil residents (LGPD)
If you are a resident of Brazil, the Lei Geral de Proteção de Dados (LGPD) gives you rights similar to those in the GDPR. You have the right to:
- Confirm the existence of processing
- Access your data
- Correct incomplete, inaccurate, or outdated data
- Anonymize, block, or delete unnecessary or excessive data
- Port your data to another provider
- Delete data processed with consent
- Obtain information about entities with which we share your data
- Be informed about the possibility of denying consent and the consequences
- Revoke consent
Data Protection Officer (DPO) — Encarregado: For LGPD inquiries, contact [email protected] with the subject "LGPD Request."
You have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD): gov.br/anpd.
15. Additional rights for Mexico residents (LFPDPPP)
If you are a resident of Mexico, the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) recognizes your ARCO rights:
- Acceso — access your data
- Rectificación — correct your data
- Cancelación — cancel processing of your data
- Oposición — object to certain processing
To exercise ARCO rights, email [email protected]. Your request should include:
- Your full name and an email address where we can respond
- Documents proving your identity (or the identity and authority of your representative)
- A clear description of the data and the right you wish to exercise
- Any other elements that help us locate your data
We will respond within 20 business days.
You can also file a complaint with the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI): inai.org.mx.
16. Cookies and similar technologies
rokohome.com uses cookies and similar technologies (local storage, pixels) to operate the site and, with your consent, to understand how it's used.
Full details are in our Cookie Policy, including:
- Which cookies we use
- What each one does
- How long it lasts
- How to control or disable them
17. Children's privacy
ROKO is intended for adults aged 18 or older. We do not knowingly collect personal information from anyone under 18.
If you believe a minor has provided us with personal information, please contact [email protected] and we will delete it promptly.
18. Security
We use technical and organizational measures to protect your personal information, including:
- TLS encryption for all data in transit (HTTPS across rokohome.com)
- End-to-end encryption for archived communications audit logs
- Access controls and principle of least privilege for our team
- Regular security audits and backups
- Incident response procedures
Communications audit logs are end-to-end encrypted before being stored in long-term archive. The private decryption key never resides on our production servers: it is kept in a credential vault with offline physical backup. Column-level encryption at rest for personal data in our operational databases is on our technical roadmap.
No system is 100% secure. If a data breach affects your personal information, we will notify you and relevant authorities within the timeframes required by law.
19. Changes to this policy
ROKO reserves the right to modify, update, or replace this Privacy Policy at any time, in our sole discretion, to reflect changes in our practices, technology, legal requirements, or for any other reason.
When we make changes:
- We update the "Last updated" date at the top
- We post the revised version at rokohome.com/privacy-policy
- For material changes — meaning changes that significantly affect how we use your personal information — we will notify you by email at least 30 days before the change takes effect, where reasonably feasible
- For non-material changes (such as adding a new service provider or clarifying language), the change becomes effective when posted
Your continued use of rokohome.com or any ROKO Product after a change becomes effective constitutes acceptance of the revised policy, to the extent permitted by law. If you do not agree with the changes, you should stop using our services and may exercise your privacy rights as described in Section 11.
20. How to contact us
For any question about this Privacy Policy or to exercise your rights:
Email: [email protected] Contact form: rokohome.com/contact Mailing address: ModaTrends, LLC (DBA ROKO) Attn: Privacy 2800 E Enterprise Ave., Ste. 333 Appleton, WI 54913 USA
We aim to respond within 7 business days for general inquiries and within the legally required timeframe for privacy rights requests.
This Privacy Policy is available in English and Spanish. The English version is the controlling version in case of discrepancy.