Privacy policy
Version 2026-09-17.1, effective 17/09/2026.
Template draft: review before launch.
[COMPANY LEGAL NAME] Ltd, trading as RotaRound, registered in England & Wales, operates rotaround.com and the RotaRound application. For anything about personal data, including requests to exercise your rights, email [email protected].
Related documents: Terms of service · Privacy policy · Cookie policy.
1. The two scopes of this policy
This policy covers two different situations, and it is worth being clear about the difference:
- Scope 1: website visitors. People who browse rotaround.com, use the contact form, or accept analytics cookies. For this data, [COMPANY LEGAL NAME] Ltd, trading as RotaRound is the data controller.
- Scope 2: app accounts. Businesses that subscribe and the data they enter. For the subscriber's own account details, [COMPANY LEGAL NAME] Ltd, trading as RotaRound is the controller. For the personal data a subscribing business enters about its customers and workers, the subscribing business is the controller and [COMPANY LEGAL NAME] Ltd, trading as RotaRound is its processor, handling that data only on the business's instructions to provide the service.
If you are a customer or worker of a business that uses RotaRound and you want your data corrected or removed, ask that business first: it controls that data. We assist it in meeting your request.
2. What we collect, why, and on what legal basis
| Data | Scope | Purpose | Lawful basis |
|---|---|---|---|
| Contact-form name, email, optional business type, message | 1 | Replying to your enquiry | Legitimate interests |
| Analytics events (pages viewed, device type, approximate location) | 1 | Understanding how the site is used | Consent (only after you accept the cookie banner) |
| Account email, password hash, two-factor sign in codes (stored hashed), business profile and logo | 2 (we are controller) | Operating your account and securing it | Contract with you |
| Customer, property, agreement and worker records you enter | 2 (you are controller, we process) | Providing the service to you | Your instructions under our agreement with you |
| Emails sent on your behalf (visit notifications, updates): recipient addresses and delivery records | 2 (you are controller, we process) | Delivering the communications you trigger | Your instructions under our agreement with you |
| Verification and password-reset tokens (stored hashed) | 2 (we are controller) | Proving mailbox control, account recovery | Contract with you; legitimate interests (security) |
| Record of your acceptance of the terms and this policy at signup (document, version and time) | 2 (we are controller) | Evidencing the agreement between us | Contract with you; legitimate interests (record keeping) |
| Payment records: the amount, the date and our payment provider's references. No card number ever reaches us | 2 (we are controller) | Taking your subscription payment and keeping the records the law requires | Contract with you; legal obligation |
| The link you used to reach the sign up page: the source, the medium, the campaign and the landing page | 1 and 2 (we are controller) | Understanding which pages and links bring people to RotaRound | Legitimate interests. No cookies are used for this |
| Your marketing email choice, and every time it changed | 2 (we are controller) | Only sending product news to people who asked for it, and proving we did | Consent, which you can withdraw at any time |
| Sign in records: the time and the address you signed in from | 2 (we are controller) | Spotting and investigating unauthorised access | Legitimate interests (security) |
| Messages we send you about your account or about the product, and who received them | 2 (we are controller) | Knowing what we told you and when | Contract with you; legitimate interests (record keeping) |
2a. How we know where a sign up came from
When you arrive at rotaround.com we read the address of the page that linked to you, and any campaign values already on the address, and we carry them along in the address as you move about the site. If you sign up, we record them with the account. No cookie is used for this, and nothing is stored on your device. You are never asked to choose anything and you never see it.
2b. Support access to your account
We may look at your account data to answer a support question, to investigate a problem you have reported, and to keep the service running. Every such access is recorded in our own log. We do not look at the contents of your account for any other reason.
3. What we do not do
We do not sell personal data. We do not use the data your business enters to advertise to your customers or to anyone else. We do not collect more than the service needs, and we do not use your content to train anything.
4. Processors and sub-processors
We use a small set of service providers. Each processes data only to provide its function to us:
| Provider | Function | Location / notes |
|---|---|---|
| Railway | Application and database hosting | EU region. Backups are kept for 7 days |
| Stripe | Payments. Card details are entered on Stripe's own pages and never reach our servers | Transfer safeguards in place |
| Sentry | Error tracking | EU region. Personal details are removed before an error report leaves our servers |
| Trustpilot | Review invitations | Only for owners who agreed to marketing emails, and only the owner's own address |
| Resend | Email delivery (verification, resets, notifications, contact acknowledgements) | See provider terms; transfer safeguards in place |
| Ideal Postcodes | Postcode and address lookup | UK. A postcode is sent; nothing else is |
| postcodes.io | Turning a postcode into a map point, so the diary can estimate travel | UK. A postcode is sent; nothing else is |
| Cloudflare | DNS and network proxy | Global network; transfer safeguards in place |
| Google, Apple and Mozilla push services | Delivering a notification to a phone or computer that asked for them | Only for people who turned notifications on. The service receives the address the browser gave us for that device, and a message it cannot read |
| Google Maps | Opening a route or an address in a map, from the Open route and address links | We send nothing to Google. The link is opened by your own browser, which passes the address to Google when you press it |
| Google Analytics | Website analytics | Loads only after cookie consent; IP anonymisation enabled |
Marketing emails from RotaRound go only to owners who asked for them, and every one carries a link that turns them off in one click, with no sign in. Emails about your own account are not marketing and always come.
5. International transfers
Application and database hosting is in the UK/EU. Where a provider (such as an email or network service) processes data outside the UK or EEA, we rely on that provider's UK-recognised transfer safeguards, such as the UK Addendum to the EU's standard data-transfer clauses or an adequacy decision.
6. How long we keep data
| Data | Retention |
|---|---|
| Contact messages | 24 months from the day we receive the message, then deleted automatically |
| Sign in records (the time and the address) | 90 days, then counted into a daily total and the detail removed |
| Messages we send you about your account or the product, and who received them | 6 years |
| Payment records | 6 years |
| Account, customer, property, agreement and worker data (including your acceptance records) | While the account is open. If you close the account, it closes immediately and all account data is deleted 30 days later (section 7) |
| Records required for tax and accounting purposes (such as payment records) | Up to 6 years after the end of the relevant tax year, even if the account is deleted, as required by UK law |
| Verification, reset and sign in code records | Expire within minutes to hours; a spent one is inert immediately, and the record itself is deleted 30 days after it expired or was used |
| Server logs | Kept for 7 days, then deleted. They contain no email addresses, no message subjects and no sign in details |
| Copies of the emails we send, held by our email provider | Deleted after 30 days |
| Analytics data | Per Google Analytics retention settings, kept to the shortest practical period |
| Backups | Kept for 7 days, then they age out automatically; erased data may persist in a backup until it does |
7. Closing your account
You can close your account at any time from Settings, or by emailing [email protected]. Here is exactly what happens:
- Immediately: the account closes and is deleted 30 days later. We email you the date.
- During the 30 days: you can sign in, download everything we hold, and cancel the closure, which fully restores the account. If you do nothing, the deletion goes ahead.
- After the 30 days: all account data is permanently and irreversibly deleted, including the customer, property, agreement and worker records the account holds. We keep no copy of your email address, so the address can be used to sign up again.
What is left afterwards, and why:
- Backups: deleted data may persist in a database backup for up to 7 days before ageing out. Backups exist only to restore service after a failure; we do not use them to resurrect deleted accounts.
- Payment records: the amount, the date and our payment provider's references are kept for up to 6 years after the end of the relevant tax year, as UK law requires. They carry no name and no email address.
- A record that the account existed and was deleted: an account reference and some dates, with no name, no email address and no personal details, kept for 6 years.
8. Security
Data is encrypted in transit (HTTPS everywhere). Passwords are stored as strong one-way hashes, and every sign in code and email token is stored hashed as well. Two-factor authentication by emailed code is on for every account from the day it is created: a six digit code goes to the account's own sign in address, lasts ten minutes, works once, and dies after three wrong tries. You can choose to be remembered on one device for seven days, and turning two-factor off at all requires a current emailed code. Access to production systems is restricted and credentialed. No system is perfectly secure, but we treat your data the way we would want ours treated, and we will tell you without undue delay if a breach affects you. If you believe you have found a security problem, please tell us at [email protected].
9. Your rights
Under UK GDPR you have the right to access your data, correct it, delete it, restrict processing, object to processing based on legitimate interests, and receive a portable copy. Where processing is based on consent (analytics cookies) you can withdraw consent at any time with the Change your cookie choices button on the cookie policy page.
To exercise any right, email [email protected]. That is the only way to ask us: there is no form to fill in. We respond within one calendar month, and we will tell you if we need longer and why. Remember the scope split in section 1: if your data was entered by a business you deal with, that business is the controller and we will loop them in.
If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to sort it out first.
10. Children
The Service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18 as an account holder. Data a business enters about households it serves is that business's responsibility as controller.
11. Changes to this policy
If we change this policy materially we will email account holders and update the version and date at the top. Minor clarifications may be made without notice.