Privacy Policy
What we collect, why we have it, who we share it with, and what you can ask us to do about it. Written to be read, not to be skimmed past.
Who we are
Roster is a shift-fill and roster management tool for event staffing agencies. It is owned and operated by Ryan Blair, a sole proprietor doing business as Roster, located at 12111 Averhoff Cove, San Antonio, TX 78253, United States. In this policy, “we” and “Roster” mean that business, and “you” means whoever is reading it.
We are not a staffing agency, an employer, or an employment agency. We make software that staffing agencies use to run their own operations.
Two kinds of people, two different roles
This distinction decides most of what follows, so it comes first.
Agency users
These are the coordinators, owners and schedulers who log into Roster. We collect their information directly and we decide how it is used. For them, we are the controller (or, under US state law, the “business”).
Workers
These are the people an agency staffs onto shifts. We do not recruit them, contact them on our own behalf, or decide anything about their data. The agency uploads their records and directs every message sent to them. For worker data we act only as a service provider and processor on the agency’s instructions.
If you are a worker and you want your information corrected or removed, the agency that staffs you is the right place to start. They control the record. We will help them action your request, and if you contact us directly we will pass your request to them and tell you we have done so. You can stop text messages yourself at any time by replying STOP.
What we collect
| Category | What it is | Where it comes from |
|---|---|---|
| Account data | Name, work email, organization name, role, and a one-way hashed password. We never store your password itself. | You, at signup |
| Worker records | Name, mobile number, skills or role tags, notes, active and opt-out status, shift history, and reliability signals derived from that history. | Uploaded or entered by the agency |
| Event and shift data | Client name, venue, dates, times, roles needed, pay rate, headcount, claims and cancellations. | Entered by the agency |
| Message metadata | Which number a message went to, when, its template, delivery status, carrier error codes, and inbound replies. | Generated when messages are sent |
| Technical logs | IP address, browser and device type, pages requested, timestamps, and error traces. | Automatically, when you use the app |
What we do not collect. Roster does not collect or store payment card numbers, government identifiers, Social Security numbers, photographs, facial images, fingerprints, or any other biometric identifier. It does not track worker location. We do not buy personal information from data brokers, and we do not run advertising or third-party tracking on the application.
How we use it
- To operate the product: authenticate logins, build fill boards, send shift offers, record claims, and keep the roster accurate.
- To compute the reliability and fill statistics the agency sees in its own account.
- To keep the service secure and diagnose faults.
- To bill agency customers and support them when they ask for help.
- To meet legal obligations, including message consent and opt-out records.
We do not use worker data to train machine learning models, and we do not use it for any purpose the agency has not asked for.
Text messages
The messaging rules are set out in full in our Messaging Terms. The privacy points that matter most:
- We do not sell personal information, and we never share mobile numbers or text-message consent data with third parties for their own marketing.
- Messages Roster sends on an agency’s behalf are operational: shift offers, confirmations, reminders and cancellations. They are not marketing.
- An opt-out applies immediately and permanently within that agency’s account until the worker asks to be added back.
- We keep a record of opt-outs specifically so they can be honored. That record is a compliance obligation, not a mailing list.
Who we share it with
We share personal information only with the vendors that make the product run. Each is bound by contract to use it only to provide their service to us.
| Vendor | What they do | What they receive |
|---|---|---|
| Render Services, Inc. | Application hosting and managed database, United States | All application data, stored at rest on their infrastructure |
| Telnyx LLC | Text message delivery | Recipient mobile number and message body, at send time |
We may also disclose information if we are legally required to, or to protect someone’s safety or our legal rights. If the business is ever sold or transferred, customer data may transfer with it, and we will say so before that happens.
All of our infrastructure is located in the United States. If you use Roster from outside the US, your information will be processed here.
How long we keep it
- Account data: while the account is active, then up to 90 days after closure.
- Worker and event data: for as long as the agency keeps it. Agencies can delete individual records at any time, and can export everything before closing an account. On closure we delete the organization’s data within 30 days of a written request, or within 90 days automatically.
- Opt-out records: retained indefinitely. This is deliberate. Deleting an opt-out would risk texting someone who told us to stop.
- Technical logs: up to 30 days.
Security
- All traffic is encrypted in transit with TLS. Data is encrypted at rest by our hosting provider.
- Passwords are stored only as one-way salted hashes and cannot be recovered by us.
- Access is scoped by organization and by role, so one agency cannot see another’s data.
- The production database accepts no connections from the public internet; the application reaches it over a private network.
No system is perfectly secure. If we become aware of a breach affecting your information, we will notify affected customers without undue delay and comply with applicable breach-notification law.
Your rights
Depending on where you live, you may have the right to know what personal information we hold about you, to get a copy of it, to correct it, to delete it, and to not be discriminated against for asking. Residents of Texas, California, and other states with comprehensive privacy laws have these rights by statute; if the GDPR applies to you, you also have the rights to restrict and object to processing and to data portability.
We do not sell personal information and we do not share it for cross-context behavioral advertising. There is no “Do Not Sell” action to take, because there is nothing being sold.
To exercise a right, email ryan@rhinorosters.com. We will verify your request and respond within 45 days, and we will tell you if we need longer. If your information was uploaded by a staffing agency, we will route the request to that agency, because they control the record.
Children
Roster is a business tool and is not directed to children. We do not knowingly collect information from anyone under 16. Agencies must not upload records for workers under 16.
Changes to this policy
We will update this page when our practices change and revise the date at the top. If a change materially reduces your privacy protections, we will notify account holders by email before it takes effect.
Contact
Ryan Blair, d/b/a Roster
12111 Averhoff Cove
San Antonio, TX 78253
ryan@rhinorosters.com