Privacy Policy

Last updated: 2026-05-06 · Version 1.0 (beta)

Beta release. We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Final policy will be reviewed by a privacy lawyer before public launch.

1. Who we are

RosterPilot, based in Melbourne, Victoria, Australia. Contact: melbourneairostering@gmail.com. We are the data controller for workspace owner data and the data processor for staff records on behalf of each operator.

2. What we collect

From whomWhatWhy
Workspace ownerEmail, name, password (hashed), business name, address, ABN, bank details (via Stripe)Account, billing, support
Staff (added by owner)Name, email, phone, hourly rate, role, TFN, visa expiry, bank, emergency contact, shift records, timesheets, leaveRoster, payroll, payroll compliance
AutomaticIP, device, log events, error reportsSecurity, debugging, abuse prevention

3. How we use it

We do not sell your data. We do not use it for advertising. We do not train AI models on staff personal data.

4. Sensitive data (TFN, bank, visa)

5. Where it lives

6. Sharing

We share your data only with:

7. Your rights (Australian Privacy Principles)

Email melbourneairostering@gmail.com to exercise any right. We respond within 30 days.

8. Staff data (the people working at the workspace)

You — the workspace owner — are the data controller for your staff data. You decide retention, you respond to their requests. RosterPilot is your data processor.

You must inform staff that their data is processed by RosterPilot and provide them this Privacy Policy URL.

9. Security

10. Retention

11. Children

The service is for businesses, not children. We do not knowingly collect data from anyone under 16 (except in the staff context where parents/guardians have consented).

12. Changes

We notify operators by email 30 days before any material change.