Security & privacy

Rosters hold real people's lives. We treat them that way.

Plain answers, not a trust badge wall. If something here isn't true yet, it says so.

Sydney
Where data lives

Australian region, with backups in the same region.

90 days
Location retention

Default, and shortenable by you in Setup.

Per venue
Access

Managers see only the venues they run.

7 days
Deletion on request

Account and backups purged within a week.

How the data is held

One business can never read another

Every row in the database carries the business it belongs to, and the database itself refuses reads from anywhere else — not the app, the database. It is the first thing we test on every release.

Encrypted in transit and at rest

TLS everywhere, disk encryption on the database and backups. Nobody at Rostru can read a password: we don’t store them — sign-in is a magic link or a one-time code.

Permissions that match the venue

Owners see everything. Managers see the venues they run. Staff see their own shifts, hours and requests — never anyone else’s pay rate.

Every change is logged

Who moved that shift, who approved those hours, and when. Attendance approvals record the approver, so a pay dispute has an answer.

Backups you can actually restore

Point-in-time recovery for 7 days and daily snapshots for 30. We restore into a scratch project monthly to prove it works.

Your data leaves whenever you want

Export roster, people and approved timesheets as CSV any time, including during the trial. No export fee, no wind-down period.

Location data

What we collect, in one table.

DataWhenWho sees itKept
GPS point at clock-on / offOnly when clocking, around a rostered shiftManagers of that venue90 days
Inside-the-fence flagWith each clock eventManagers of that venue7 years
Approved hoursAfter approvalManagers, the employee, payroll export7 years
Availability and leaveWhen the employee sets itManagers of their venuesWhile employed
Device push tokenOn sign-inNobody — used to send notificationsUntil sign-out

We collect no continuous location trail, sell nothing to anyone, and run no advertising trackers on the staff app. Retention is yours to shorten in Setup → Rules.

Australian obligations we design around

Privacy Act 1988

Collect the minimum, say why, let people see it. Staff can request everything we hold about them and get it as a file, and the consent screen is written in the same plain words as this page.

Surveillance laws

Location is tied to shifts, and staff are told before it starts. State workplace-surveillance rules expect notice and a purpose; we give both, and the manual clock-on exists so nobody is forced into background tracking.

Fair Work records

Hours, breaks and approvals kept for seven years. Attendance records are immutable once approved — corrections are new entries with an author, not silent edits.

Notifiable breaches

If something goes wrong you hear it from us. We notify affected businesses and the OAIC within the required window, with what happened and what we did about it.

Rostru is scheduling and attendance software, not legal or payroll advice. Award interpretation and penalty rates stay with your payroll provider — our warnings are prompts for a human, not a ruling.

Not true yet

Things people ask for that we haven't done. We'd rather you read it here than find out later.

No SOC 2 or ISO 27001

We’re too small to have paid for an audit. The practices above are real; the certificate isn’t there yet.

No award interpretation

No penalty rates, allowances or award rules. Warnings only. Payroll still does the maths.

No single sign-on

Magic link and one-time code today. SAML/SSO is on the list for venue groups.

No on-premise option

Cloud only, Australian region. If you need self-hosting, we’re not the right fit yet.

Ask us anything before you put your team in.

A real person answers, usually the same day, and we'll happily talk to whoever handles privacy for you.