Rosters hold real people's lives. We treat them that way.
Plain answers, not a trust badge wall. If something here isn't true yet, it says so.
Australian region, with backups in the same region.
Default, and shortenable by you in Setup.
Managers see only the venues they run.
Account and backups purged within a week.
How the data is held
One business can never read another
Every row in the database carries the business it belongs to, and the database itself refuses reads from anywhere else — not the app, the database. It is the first thing we test on every release.
Encrypted in transit and at rest
TLS everywhere, disk encryption on the database and backups. Nobody at Rostru can read a password: we don’t store them — sign-in is a magic link or a one-time code.
Permissions that match the venue
Owners see everything. Managers see the venues they run. Staff see their own shifts, hours and requests — never anyone else’s pay rate.
Every change is logged
Who moved that shift, who approved those hours, and when. Attendance approvals record the approver, so a pay dispute has an answer.
Backups you can actually restore
Point-in-time recovery for 7 days and daily snapshots for 30. We restore into a scratch project monthly to prove it works.
Your data leaves whenever you want
Export roster, people and approved timesheets as CSV any time, including during the trial. No export fee, no wind-down period.
What we collect, in one table.
| Data | When | Who sees it | Kept |
|---|---|---|---|
| GPS point at clock-on / off | Only when clocking, around a rostered shift | Managers of that venue | 90 days |
| Inside-the-fence flag | With each clock event | Managers of that venue | 7 years |
| Approved hours | After approval | Managers, the employee, payroll export | 7 years |
| Availability and leave | When the employee sets it | Managers of their venues | While employed |
| Device push token | On sign-in | Nobody — used to send notifications | Until sign-out |
We collect no continuous location trail, sell nothing to anyone, and run no advertising trackers on the staff app. Retention is yours to shorten in Setup → Rules.
Australian obligations we design around
Collect the minimum, say why, let people see it. Staff can request everything we hold about them and get it as a file, and the consent screen is written in the same plain words as this page.
Location is tied to shifts, and staff are told before it starts. State workplace-surveillance rules expect notice and a purpose; we give both, and the manual clock-on exists so nobody is forced into background tracking.
Hours, breaks and approvals kept for seven years. Attendance records are immutable once approved — corrections are new entries with an author, not silent edits.
If something goes wrong you hear it from us. We notify affected businesses and the OAIC within the required window, with what happened and what we did about it.
Rostru is scheduling and attendance software, not legal or payroll advice. Award interpretation and penalty rates stay with your payroll provider — our warnings are prompts for a human, not a ruling.
Not true yet
Things people ask for that we haven't done. We'd rather you read it here than find out later.
No SOC 2 or ISO 27001
We’re too small to have paid for an audit. The practices above are real; the certificate isn’t there yet.
No award interpretation
No penalty rates, allowances or award rules. Warnings only. Payroll still does the maths.
No single sign-on
Magic link and one-time code today. SAML/SSO is on the list for venue groups.
No on-premise option
Cloud only, Australian region. If you need self-hosting, we’re not the right fit yet.
Ask us anything before you put your team in.
A real person answers, usually the same day, and we'll happily talk to whoever handles privacy for you.