Privacy Policy
This policy explains what personal information MyRostra holds, why, who it is shared with, and how to ask about it. It covers the rostering service at myrostra.com and the records we hold about the people our customers roster.
Whose information this is
Our customers are organisations that roster staff. They decide what information goes in and why; we hold and process it for them. If you are an employee of one of those organisations and want something corrected or removed, ask your employer first — we act on their instructions — and you can also contact us using the details below.
What we hold
- Account details for people who sign in: name, email address, role, and sign-in security information such as passkeys, one-time codes and session records.
- Workforce records our customers keep: names, contact details, employee numbers, branch and region, employment type, start and end dates, and the custom fields an organisation chooses to configure.
- Roster and attendance data: shifts, start and finish times, standby, overtime, training completions, and leave entries recorded by category — annual, personal or sick, and other leave. Leave categories are recorded so the roster and reports are accurate; the detail behind a sick-leave entry is health information, and we treat it as sensitive.
- Records of activity: who changed what and when, and what notifications were sent.
Why we hold it
To run the rostering service: to show rosters and reports, to send the notifications an organisation has switched on, to bill for the service, to keep it secure, and to meet our legal obligations. We do not sell personal information, and we do not use it for advertising.
Who it is shared with
Only the service providers needed to operate, each bound to use the information solely for that purpose:
- Supabase — the production database, hosted in Sydney, Australia.
- Linode (Akamai) — the application server, hosted in Sydney, Australia.
- Resend — delivery of email (invitations, roster notifications, reminders).
- Stripe — payment processing. Card details are handled by Stripe; they never reach our systems.
- Clerk — where an organisation still signs in through Clerk, it processes sign-in information. We are retiring it (B-283) and this list will shrink when we do.
- Pushover — alerts to the operator's own phone, containing no customer personal information.
Some of these providers store data outside Australia, principally in the United States. Where that happens we disclose only what the provider needs to perform its function.
How long we keep it
Customer data is kept while the account is active and for a short period after it closes, so records can be exported or restored if needed. After that, or sooner on a valid request, it is deleted. Database backups are rotated continuously and hold roughly two days of history.
Security
Data is encrypted in transit, access is limited by role, and administrative actions are logged. We monitor availability and back up the database. If a breach occurs that is likely to cause serious harm, we will notify affected organisations and the Office of the Australian Information Commissioner as the law requires.
Access, correction and complaints
Ask your organisation, or contact us directly, to access or correct personal information, or to raise a concern. We will respond within a reasonable period. If you are not satisfied, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).
Contact
Hayden Bednarz, sole trader (ABN 89355086016) — support@myrostra.com.