Last updated 15 August 2026

Privacy

RotaBuilder is run by Sports Stats Limited. This explains what we hold about you, why, and what you can make us do about it.

Who we are

Sports Stats Limited (“we”), company number [company number — to be completed], registered at [registered office address — to be completed].

For anything in this notice, write to [privacy contact email — to be completed].

Which of us is responsible for what

Two different relationships run through this app, and they have different answers.

  • Your employer's data about you. Your shifts, whether you said yes or no, the groups you're in — the business you work for decides all of that. They are the data controller; we only hold it for them. Questions about what's on your rota go to your manager first.
  • Your account with us. The email and password you log in with, and what the business pays us — we decide how those are handled, so for those we are the controller.

What we hold

  • Account: name, email address, role (manager or staff), and the business you belong to. Passwords are stored only as a hash by our login provider — we never see them.
  • Rota: shifts and their times, which sites and rotas you're on, any groups a manager tags you with, your yes / maybe / no answers, offers to cover a shift, and notes a manager adds to a shift.
  • Invites: the email address an invite was sent to and a single-use link, which expires after seven days.
  • Billing: subscription status, how many sites are covered, and a customer reference from Stripe. Card numbers go from your browser to Stripe directly — they never touch our servers and we can't see them.
  • Technical: ordinary server and security logs, which include IP addresses, and — only if you accept cookies — measurement data from our Google tags.

We don't ask for and don't want anything sensitive: no health data, no bank details, nothing about your background. Please don't put any of it in a shift note.

Why we're allowed to hold it

  • To run the service — our contract with the business, and its legitimate interest in telling its staff when they're working.
  • To take payment — our contract with the paying business, and the law that says we must keep the records.
  • To keep the service secure and working — our legitimate interest in stopping abuse and fixing faults.
  • To measure how the website is used — your consent, which you gave or refused on the cookie banner and can change at any time.

Cookies and analytics

Essential only, by default. A session cookie keeps you logged in and a small amount of local storage remembers your cookie choice. Neither is optional — without them you can't stay signed in — so neither needs your permission.

Analytics without cookies. We count page views with Plausible, which is hosted in the EU, sets no cookies, and builds no profile of you across websites. It runs for everyone because it identifies nobody.

Google tags, only if you say yes. We use Google Tag Manager to load measurement tags. Every storage permission is set to denied before it loads, so nothing is written to your device unless you accept — and if you refuse, it stays that way.

Changed your mind? Use Cookie settings at the bottom of any page.

Who else sees it

We don't sell personal data and we don't share it for anyone's advertising. These are the companies that handle it on our behalf:

Supabase

Database, login and file storage — where your rotas live.

EU / UK region, depending on your project

Netlify

Hosting and content delivery for the website itself.

Global CDN, US company

Stripe

Subscription payments. Card details go straight to Stripe and never reach our servers.

EU / US

Resend

Sends invite and account emails.

EU / US

Plausible Analytics

Counts page views without cookies and without tracking anyone across sites.

EU (Germany)

Google Tag Manager

Loads our measurement tags. Nothing that stores data runs until you accept cookies.

US, under UK/EU transfer safeguards

Where a provider is outside the UK, the transfer is covered by the UK's international data transfer agreement or the equivalent standard clauses. We'll also hand data over if the law genuinely requires it.

How long we keep it

  • Rota and account data: for as long as the business uses RotaBuilder. If they close their account we delete it within 90 days.
  • Invites: deleted once used, and expired ones are cleared out after seven days.
  • Billing records: six years, because tax law says so.
  • Server logs: a rolling short window, typically 30 days.

What you can make us do

Under UK GDPR you can ask for a copy of your data, ask us to correct or delete it, object to how we use it, or ask us to send it somewhere else. Where consent is the reason we hold something, you can withdraw it without giving a reason.

If the data is your employer's — your shifts, your answers — ask them; we'll pass any request straight to them. For anything else, email [privacy contact email — to be completed] and we'll answer within one month.

If we get it wrong you can complain to the Information Commissioner's Office at ico.org.uk — though we'd rather you gave us the chance to fix it first.

Changes

If we change this notice we'll update the date at the top, and for anything significant we'll tell account holders by email. Carrying on using RotaBuilder after that means the new version applies.

See also our terms of service.