Privacy Policy
Last updated: 2026-07-23 · Version 1.2 (beta)
1. Who we are
RosterPilot is a software product operated by MRS KIM'S BBQ PTY LTD (ABN 90 613 150 708), an Australian private company. Our service and contact address is 136 Koornang Road, Carnegie VIC 3163, Australia. Contact: rosterpilotsupport@gmail.com. Each workspace operator controls the staff records they enter; RosterPilot processes those records to provide the service.
2. What we collect
| From whom | What | Why |
|---|---|---|
| Workspace owner | Email, name, authentication identifier, business name and optional business details; Stripe customer and subscription identifiers after checkout | Account, billing, support |
| Staff (added by operator) | Name, email, phone, hourly rate, role, optional TFN, visa, bank and emergency-contact details, shift records, timesheets and availability | Rostering, time records and operator-configured pay estimates |
| Automatic | IP, device, log events, error reports | Security, debugging, abuse prevention |
3. How we use it
- Operate the service (authentication, billing, rostering, time records and operator-configured pay estimates).
- Send account and workflow emails where an email feature is enabled.
- Provide optional AI features when an operator chooses to use them.
- Comply with legal obligations.
We do not sell your data or use it for advertising. RosterPilot does not train its own AI model on staff personal data. When an operator uses an AI feature, relevant prompts and workspace data are sent to OpenAI for processing. Do not place TFNs, bank details or other unnecessary sensitive information in an AI prompt.
4. Sensitive data (TFN, bank, visa)
- TFN, bank details and visa information are highly sensitive. Private staff profiles are limited by Firestore rules to the workspace owner and the staff member's authenticated account. Manager-level accounts cannot read these private profiles.
- These fields are not masked in every owner or staff view. Only collect fields you genuinely need, and do not place them in support messages or AI prompts.
- If you suspect compromise, contact us immediately.
5. Where it lives
- Primary database: Google Firebase Firestore in nam5, a United States multi-region.
- Authentication: Google Firebase Authentication. Google may process authentication and service data outside Australia under its service configuration.
- Hosted backend: some Google Cloud Functions run in australia-southeast1 (Sydney).
- Payments: Stripe. Stripe handles card and payment details; RosterPilot stores billing identifiers and subscription status, not full card numbers.
- Email delivery: SendGrid.
- Optional AI tools: prompts and relevant workspace data are transferred to and processed by OpenAI when an operator invokes an AI feature.
- Operational logging: Google Cloud Logging.
6. Sharing
We share your data only with:
- Service providers above (Google Firebase and Google Cloud, Stripe, SendGrid and OpenAI) to the extent needed to provide the selected feature.
- Government authorities or other parties where disclosure is legally required or permitted.
- A party involved in a proposed business transfer, subject to applicable obligations.
7. Your rights (Australian Privacy Principles)
- Access: ask for a copy of your data.
- Correction: ask us to fix incorrect data.
- Deletion: ask us to delete data, subject to legal or operational retention requirements.
- Complaint: email us first; if unresolved, contact OAIC (oaic.gov.au).
Email rosterpilotsupport@gmail.com to request access, correction or deletion. We will respond as soon as reasonably practicable.
8. Staff data (the people working at the workspace)
You — the workspace owner — are the data controller for your staff data. You decide retention, you respond to their requests. RosterPilot is your data processor.
You must inform staff that their data is processed by RosterPilot and provide them this Privacy Policy URL.
9. Security
- HTTPS everywhere.
- Workspace access is controlled by Firebase Authentication and Firestore security rules.
- Passwords hashed by Firebase Authentication.
- Card details handled by Stripe only.
- Private staff profiles are restricted to the workspace owner and the staff member's authenticated account; sensitive fields are not masked in every permitted view.
10. Retention
- Workspace data is kept while the service is in use and may remain stored after cancellation.
- Cancellation does not automatically delete workspace data. Contact support to request deletion.
- Some records may be retained when reasonably required for billing, security, dispute handling or legal obligations.
- Operational logs are retained according to current provider settings and operational needs; no fixed beta retention period is promised.
11. Children
The service is for businesses, not children. We do not knowingly collect data from anyone under 16 (except in the staff context where parents/guardians have consented).
12. Changes
We will post an updated date here and, where reasonably practicable, notify affected operators of material changes.