Security
How we protect your data and your customers' data, in plain words.
Where your data is kept
Your records live in one database. Logos and photos are kept in it too, and exports are built when you ask for them and never saved as files.
When you sign in, your session is held on our server. Your browser only keeps a signed reference to it.
When you look up an address, only the postcode is sent to the address service. Nothing else is.
The companies that help us run RotaRound, and what each one does, are listed in our Privacy policy.
How it is protected in transit and at rest
Every page is sent over HTTPS. A plain http address is sent to the secure one, and browsers are told to use HTTPS every time.
The link between our server and the database is encrypted. The server will not start without it.
The most private things you write are encrypted inside the database as well: a property's access instructions and every change to them, the reason and notes for time off, and the private notes on a customer, a property or a team member. The key is kept apart from the database.
Passwords are stored as strong one-way hashes. Nobody can read them, including us.
Every page carries security headers that stop other sites framing it or running scripts in it.
Signing in and passwords
A password needs at least 10 characters, and common passwords are refused.
Two-factor sign in is on for every account from the day it is made. We email a six digit code that lasts ten minutes, works once, and stops after three wrong tries.
You can have a device remembered for seven days. You can see your remembered devices and remove any of them.
Turning two-factor off needs a fresh emailed code, and we email you to say it was turned off.
After ten wrong passwords in fifteen minutes, sign in is locked for fifteen minutes.
If nothing happens for four hours, you are signed out.
Resetting your password signs you out everywhere. You can also sign out of all devices at any time.
Your customers' and team members' page links, and revoking them
Each customer and each team member has their own page link. The link carries a long random code that cannot be guessed.
A link keeps working, so old emails still open the page, until you revoke it. You can revoke one link, revoke it and send a new one, or revoke everyone's at once. A revoked link opens nothing.
A team member's link stops when they leave or are archived.
A property's access instructions are hidden behind a code we email to the customer. The code lasts 15 minutes, and a correct code shows the instructions for 30 minutes on that device.
A team member's page shows only their own diary for the next seven days, and they cannot change it. A device that has not been checked for 30 days needs a code we email to them.
Who can see what
Once signed in, you see your own business and nobody else's. Every request is checked against your business, and a record from another business answers as if it does not exist.
Your customers and team members see only their own page.
If we ever need to look at your account to help you, every look and every action is recorded in our own log.
Even then, our screens never show access instructions or the reasons for time off.
Backups
The private notes and access instructions encrypted in the database stay encrypted in any backup, because the key is never kept in the database.
How long backups are kept is set out in our Privacy policy.
Monitoring and how problems are handled
Errors are recorded so we can see them and fix them. Personal details, such as email addresses, phone numbers, postcodes and passwords, are removed before any error report leaves our server.
Our logs never hold passwords, cookies, email addresses or message subjects.
An alert is raised when emails start failing to send.
The server will not start if a security setting is missing, and it names what is wrong.
We are warned when a part of the software we rely on needs a security update.
Your data rights: export, correction and deletion
You can download your records at any time as spreadsheet files, up to three times a day. This works even while your account is paused.
You can correct any record yourself. Customers can change their own access instructions and email choices from their page.
You can archive a customer or team member, delete their personal details for good, or remove their record entirely. A record is only archived or deleted when you choose to.
Old records we no longer need, such as spent sign in codes and old contact messages, are deleted on a schedule set out in our Privacy policy.
Card details are typed on our payment provider's own pages and never reach our servers.
Closing your account
Closing your account needs a code we email to you.
For the next 30 days you can still sign in, download your records, or change your mind.
Your data is not deleted before the 30 days are up. After that, the account and everything in it is deleted.
We keep only a payment record and a note that the account existed, with no name or email address.
How to report a security concern
If you think you have found a security problem in RotaRound, please email us. We read every message and reply as soon as we can.
Please tell us what you found and how to see it. Do not include anyone's personal details.
The full detail of what we hold and why is in our Privacy policy.