RotaKeep

Privacy Policy

Last updated: January 2026

1. Introduction

OnShift Ltd ("we", "us", or "our") operates RotaKeep, a staff scheduling application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email address, password
  • Business information: venue name, address, contact details
  • Staff information: names, email addresses, phone numbers, roles, hourly rates
  • Scheduling data: shift times, availability, holiday requests
  • Time & attendance data: clock-in/out times, GPS location (when enabled)
  • Payment information: processed securely via Stripe (we do not store card details)

2.2 Information Collected Automatically

  • Device information: browser type, operating system, device identifiers
  • Usage data: pages visited, features used, time spent
  • Log data: IP address, access times, referring URLs

3. How We Use Your Information

We use your information to:

  • Provide and maintain our scheduling service
  • Process payments and manage subscriptions
  • Send transactional emails (shift notifications, password resets)
  • Provide customer support
  • Improve our service and develop new features
  • Comply with legal obligations

4. Data Sharing

We do not sell your personal data. We may share information with:

  • Service providers: Firebase (hosting/database), Stripe (payments), Resend (email)
  • Legal authorities: when required by law or to protect our rights
  • Business transfers: in connection with a merger or acquisition

5. Data Retention

We retain your data for as long as your account is active. Upon account deletion, we will delete your data within 30 days, except where required for legal compliance or legitimate business purposes.

6. Your Rights (UK GDPR)

You have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request deletion of your data
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time

To exercise these rights, contact us at [email protected]

7. Data Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews.

8. International Transfers

Your data is primarily stored in the UK/EU. Where data is transferred outside these regions (e.g., to US-based service providers), we ensure appropriate safeguards are in place.

9. Children's Privacy

Our service is not intended for individuals under 16. We do not knowingly collect data from children.

10. Changes to This Policy

We may update this policy periodically. We will notify you of significant changes via email or in-app notification.

11. Contact Us

OnShift Ltd
Email: [email protected]
ICO Registration: ZB591532