Privacy

Privacy at Rostaff

Rostaff looks after the most sensitive thing a business has β€” its people. Here's what we collect, how we use it, and the control you keep, in plain language.

Last updated July 2026 Β· Applies to Rostaff Β· Questions? [email protected]

Never trained on

Your team's data is never used to train AI models β€” ours or anyone else's.

Yours alone

Each workspace is kept separate, and people only see what their role allows.

Safe to change

Edits go through approval and are logged, so anything can be reviewed or undone.

Our promise

The assistant works for you, not on you.

Rostaff's assistant reads a request, then drafts the change for a person to approve. It sees only the context it needs, never trains on your data, and we never sell or share it for advertising.

What we collect

Only what's needed to run your workspace: the people records you enter (names, roles, contact details, pay, shifts, time-off, onboarding, and any documents you upload); attendance β€” check-in and check-out times, and, if your organization turns on geofenced check-in, the location a check-in was made; the requests you send the assistant, so it can respond and the change can be audited; and account activity β€” who signed in, their role, and what they changed. We don't run advertising trackers, and we don't buy data about your team.

How we use it

To run rosters, attendance, time-off, onboarding, profiles, and pay and rewards; to let the assistant understand a request and propose the change for approval; to keep an audit trail of who changed what; and to keep the service secure and send the account emails you'd expect β€” invitations, email verification, approvals.

AI and your data

Three rules. We never use your data to train AI models. The assistant is given only the context it needs for your request. And it only proposes changes β€” a permitted person approves before anything is written, so nothing happens silently. No advertising, no resale.

Where it's kept, and security

Your data lives on Google Cloud in managed, backed-up databases. It's encrypted in transit and at rest, access follows role-based permissions, and each workspace is isolated. Access to live data is limited to running and supporting the service, and it's logged. If a security incident affects your data, we'll let you know.

Your controls

You stay in charge. Set permissions so only the right roles can see or change each record. Correct or update any profile you manage. And ask us for a copy of your data, or its deletion β€” email us and we'll take care of it. A terminated teammate loses access immediately but stays in your records for history.

Who we work with

We keep your data in-house and rely on a small set of trusted providers to run the service: cloud hosting (Google Cloud) to store your workspace, an AI model provider to answer assistant requests (it doesn't train on your data), and an email provider to send transactional messages like invitations and approvals. We'll share the current list on request and update it before adding anyone new. We never sell your data.

How long we keep it

We keep your data while your workspace is active. Delete a record and it's removed from live systems right away, then drops out of backups on our regular cycle. Close your account and we delete or anonymize your data, keeping only what the law requires.

Questions

Privacy is a conversation, not a policy you sign and forget. Email [email protected] and a real person will reply.

Your team's data, treated the way you'd want yours treated.