Privacy Policy
Last updated: July 2026
Rota Rooster ("we", "us", "our") provides a rota-scheduling web application. This policy explains what personal data we collect, why, and how you can exercise your rights over it. Rota Rooster is currently in beta and access is limited to invited users.
1. What we collect
When you or your employer creates an account, we collect:
- Name and email address (all account holders)
- Phone number and address, where your employer adds them to your employee record
- Company and rota data: shift times, locations, and role assignments
- Billing information for paid plans, handled entirely by Stripe (see below) — we never see or store card numbers
- Basic technical data (error reports and, for session replay, interaction data) — only if you accept optional cookies; if you reject or haven't decided, none of this is collected
2. Why we collect it
We use this data to provide and operate the scheduling service: authenticating you, storing and displaying your company's rota, managing subscriptions and billing, and diagnosing and fixing bugs. We do not sell personal data, and we do not use it for advertising.
3. Who we share it with
We use the following processors to run the service. Each only receives the data it needs to perform its function:
- Firebase (Google Cloud) — authentication and storage of account, company, and rota data
- Stripe — payment processing and subscription billing
- Sentry — error monitoring and session replay, both only with your consent (see Cookies below)
These providers may process data on servers outside the UK/EEA (including the US), under their own data protection and standard contractual safeguards.
4. Cookies
The only storage we use without your consent is strictly necessary: keeping you signed in (Firebase Authentication) and remembering your cookie preference. If you accept optional cookies, we additionally run Sentry to monitor errors and record session replays, helping us find and fix issues faster. If you reject or haven't responded, none of this runs — no Sentry of any kind. You can change your choice at any time using "Cookie Settings" in the footer.
5. How long we keep it
We retain account and company data for as long as your account is active. If your company's account is closed, we delete or anonymise personal data within a reasonable period, except where we're required to retain it (e.g. billing records for tax purposes).
6. Your rights
Under UK GDPR you have the right to access, correct, or request deletion of your personal data, and to object to or restrict how we process it. During beta, these requests are handled manually — email us at support@marlowsoftware.com and we'll action it as soon as possible.
7. Contact
Questions about this policy or how your data is handled? Email support@marlowsoftware.com.