Privacy policy

Version 2026-09-17.1, effective 17/09/2026.

Template draft: review before launch.

[COMPANY LEGAL NAME] Ltd, trading as RotaRound, registered in England & Wales, operates rotaround.com and the RotaRound application. For anything about personal data, including requests to exercise your rights, email [email protected].

Related documents: Terms of service · Privacy policy · Cookie policy.

1. The two scopes of this policy

This policy covers two different situations, and it is worth being clear about the difference:

  • Scope 1: website visitors. People who browse rotaround.com, use the contact form, or accept analytics cookies. For this data, [COMPANY LEGAL NAME] Ltd, trading as RotaRound is the data controller.
  • Scope 2: app accounts. Businesses that subscribe and the data they enter. For the subscriber's own account details, [COMPANY LEGAL NAME] Ltd, trading as RotaRound is the controller. For the personal data a subscribing business enters about its customers and workers, the subscribing business is the controller and [COMPANY LEGAL NAME] Ltd, trading as RotaRound is its processor, handling that data only on the business's instructions to provide the service.

If you are a customer or worker of a business that uses RotaRound and you want your data corrected or removed, ask that business first: it controls that data. We assist it in meeting your request.

2. What we collect, why, and on what legal basis

DataScopePurposeLawful basis
Contact-form name, email, optional business type, message1Replying to your enquiryLegitimate interests
Analytics events (pages viewed, device type, approximate location)1Understanding how the site is usedConsent (only after you accept the cookie banner)
Account email, password hash, two-factor sign in codes (stored hashed), business profile and logo2 (we are controller)Operating your account and securing itContract with you
Customer, property, agreement and worker records you enter2 (you are controller, we process)Providing the service to youYour instructions under our agreement with you
Emails sent on your behalf (visit notifications, updates): recipient addresses and delivery records2 (you are controller, we process)Delivering the communications you triggerYour instructions under our agreement with you
Verification and password-reset tokens (stored hashed)2 (we are controller)Proving mailbox control, account recoveryContract with you; legitimate interests (security)
Record of your acceptance of the terms and this policy at signup (document, version and time)2 (we are controller)Evidencing the agreement between usContract with you; legitimate interests (record keeping)
Payment records: the amount, the date and our payment provider's references. No card number ever reaches us2 (we are controller)Taking your subscription payment and keeping the records the law requiresContract with you; legal obligation
The link you used to reach the sign up page: the source, the medium, the campaign and the landing page1 and 2 (we are controller)Understanding which pages and links bring people to RotaRoundLegitimate interests. No cookies are used for this
Your marketing email choice, and every time it changed2 (we are controller)Only sending product news to people who asked for it, and proving we didConsent, which you can withdraw at any time
Sign in records: the time and the address you signed in from2 (we are controller)Spotting and investigating unauthorised accessLegitimate interests (security)
Messages we send you about your account or about the product, and who received them2 (we are controller)Knowing what we told you and whenContract with you; legitimate interests (record keeping)

2a. How we know where a sign up came from

When you arrive at rotaround.com we read the address of the page that linked to you, and any campaign values already on the address, and we carry them along in the address as you move about the site. If you sign up, we record them with the account. No cookie is used for this, and nothing is stored on your device. You are never asked to choose anything and you never see it.

2b. Support access to your account

We may look at your account data to answer a support question, to investigate a problem you have reported, and to keep the service running. Every such access is recorded in our own log. We do not look at the contents of your account for any other reason.

3. What we do not do

We do not sell personal data. We do not use the data your business enters to advertise to your customers or to anyone else. We do not collect more than the service needs, and we do not use your content to train anything.

4. Processors and sub-processors

We use a small set of service providers. Each processes data only to provide its function to us:

ProviderFunctionLocation / notes
RailwayApplication and database hostingEU region. Backups are kept for 7 days
StripePayments. Card details are entered on Stripe's own pages and never reach our serversTransfer safeguards in place
SentryError trackingEU region. Personal details are removed before an error report leaves our servers
TrustpilotReview invitationsOnly for owners who agreed to marketing emails, and only the owner's own address
ResendEmail delivery (verification, resets, notifications, contact acknowledgements)See provider terms; transfer safeguards in place
Ideal PostcodesPostcode and address lookupUK. A postcode is sent; nothing else is
postcodes.ioTurning a postcode into a map point, so the diary can estimate travelUK. A postcode is sent; nothing else is
CloudflareDNS and network proxyGlobal network; transfer safeguards in place
Google, Apple and Mozilla push servicesDelivering a notification to a phone or computer that asked for themOnly for people who turned notifications on. The service receives the address the browser gave us for that device, and a message it cannot read
Google MapsOpening a route or an address in a map, from the Open route and address linksWe send nothing to Google. The link is opened by your own browser, which passes the address to Google when you press it
Google AnalyticsWebsite analyticsLoads only after cookie consent; IP anonymisation enabled

Marketing emails from RotaRound go only to owners who asked for them, and every one carries a link that turns them off in one click, with no sign in. Emails about your own account are not marketing and always come.

5. International transfers

Application and database hosting is in the UK/EU. Where a provider (such as an email or network service) processes data outside the UK or EEA, we rely on that provider's UK-recognised transfer safeguards, such as the UK Addendum to the EU's standard data-transfer clauses or an adequacy decision.

6. How long we keep data

DataRetention
Contact messages24 months from the day we receive the message, then deleted automatically
Sign in records (the time and the address)90 days, then counted into a daily total and the detail removed
Messages we send you about your account or the product, and who received them6 years
Payment records6 years
Account, customer, property, agreement and worker data (including your acceptance records)While the account is open. If you close the account, it closes immediately and all account data is deleted 30 days later (section 7)
Records required for tax and accounting purposes (such as payment records)Up to 6 years after the end of the relevant tax year, even if the account is deleted, as required by UK law
Verification, reset and sign in code recordsExpire within minutes to hours; a spent one is inert immediately, and the record itself is deleted 30 days after it expired or was used
Server logsKept for 7 days, then deleted. They contain no email addresses, no message subjects and no sign in details
Copies of the emails we send, held by our email providerDeleted after 30 days
Analytics dataPer Google Analytics retention settings, kept to the shortest practical period
BackupsKept for 7 days, then they age out automatically; erased data may persist in a backup until it does

7. Closing your account

You can close your account at any time from Settings, or by emailing [email protected]. Here is exactly what happens:

  • Immediately: the account closes and is deleted 30 days later. We email you the date.
  • During the 30 days: you can sign in, download everything we hold, and cancel the closure, which fully restores the account. If you do nothing, the deletion goes ahead.
  • After the 30 days: all account data is permanently and irreversibly deleted, including the customer, property, agreement and worker records the account holds. We keep no copy of your email address, so the address can be used to sign up again.

What is left afterwards, and why:

  • Backups: deleted data may persist in a database backup for up to 7 days before ageing out. Backups exist only to restore service after a failure; we do not use them to resurrect deleted accounts.
  • Payment records: the amount, the date and our payment provider's references are kept for up to 6 years after the end of the relevant tax year, as UK law requires. They carry no name and no email address.
  • A record that the account existed and was deleted: an account reference and some dates, with no name, no email address and no personal details, kept for 6 years.

8. Security

Data is encrypted in transit (HTTPS everywhere). Passwords are stored as strong one-way hashes, and every sign in code and email token is stored hashed as well. Two-factor authentication by emailed code is on for every account from the day it is created: a six digit code goes to the account's own sign in address, lasts ten minutes, works once, and dies after three wrong tries. You can choose to be remembered on one device for seven days, and turning two-factor off at all requires a current emailed code. Access to production systems is restricted and credentialed. No system is perfectly secure, but we treat your data the way we would want ours treated, and we will tell you without undue delay if a breach affects you. If you believe you have found a security problem, please tell us at [email protected].

9. Your rights

Under UK GDPR you have the right to access your data, correct it, delete it, restrict processing, object to processing based on legitimate interests, and receive a portable copy. Where processing is based on consent (analytics cookies) you can withdraw consent at any time with the Change your cookie choices button on the cookie policy page.

To exercise any right, email [email protected]. That is the only way to ask us: there is no form to fill in. We respond within one calendar month, and we will tell you if we need longer and why. Remember the scope split in section 1: if your data was entered by a business you deal with, that business is the controller and we will loop them in.

If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to sort it out first.

10. Children

The Service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18 as an account holder. Data a business enters about households it serves is that business's responsibility as controller.

11. Changes to this policy

If we change this policy materially we will email account holders and update the version and date at the top. Minor clarifications may be made without notice.