Privacy Policy
Last updated: 10 August 2026
RosterSphere ("we", "us", "our") operates the RosterSphere web application at rostersphere.com and the RosterSphere mobile application (together, the "Service"). This policy describes how we collect, use and protect your personal information.
1. Information We Collect
- Account information: name, email address, phone number and role — provided by your employer or entered during sign-up.
- Location data: precise GPS coordinates are collected only when you explicitly tap "Check in" or "Check out" during a shift, or when trip tracking is active. Location is never collected in the background outside of an active trip.
- Photos: images you capture for expense receipts or incident reports. Photos are uploaded to secure cloud storage and linked to your account.
- Device tokens: Firebase Cloud Messaging tokens are stored to deliver push notifications about published rosters. We store the platform type (iOS/Android) alongside the token.
- Usage data: we collect basic server logs (IP address, request timestamps) for security and debugging.
2. How We Use Your Information
- To provide the rostering, scheduling and time-tracking service to your employer.
- To send push notifications about published shifts and roster changes.
- To verify check-in/check-out locations for compliance and payroll.
- To generate timesheets, mileage reports and expense records.
3. Data Sharing
Your data is shared only with:
- Your employer's coordinators and administrators within RosterSphere.
- Infrastructure providers: Railway (hosting), Cloudflare (CDN/DNS), Firebase (push notifications), Cloudflare R2 (file storage). These providers process data on our behalf under their own privacy policies.
We do not sell your personal information. We do not use your data for advertising or tracking.
4. Data Isolation
Each organisation's data is logically isolated using PostgreSQL Row Level Security. Employees and coordinators can only access data belonging to their own company.
5. Data Retention
Your data is retained for as long as your employer maintains an active account. Archived employee records are kept for compliance purposes. You may request deletion of your personal data by contacting your employer or us directly.
6. Security
We use HTTPS for all data in transit, JWT-based authentication, bcrypt password hashing, and encrypted storage for sensitive tokens. Access to production systems is restricted to authorised personnel.
7. Your Rights
Under the Australian Privacy Act 1988, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your personal data.
- Complain to the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached.
8. Children's Privacy
The Service is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision.
10. Contact
For privacy inquiries, contact us at:
[email protected]