Privacy Policy
Last updated: 8 August 2026
This policy explains how Who's On What ("we", "us") handles personal data in the rota planning application at whosonwhat.com and its organisation subdomains. We process personal data in accordance with UK data protection law, including the UK GDPR and the Data Protection Act 2018.
1. The two roles we play
- Controller. For account sign-up details, billing records, and enquiries you send us, we decide how and why the data is used, so we act as the controller.
- Processor. For the data an organisation enters about its people — names, work email addresses, teams, roles, working patterns, rotas, leave and skills — the organisation is the controller and we process that data only on its behalf, to provide the Service. If you have a question about how your employer uses your data in the Service, ask your organisation's admin first.
2. What we collect
- Account data: your name, email address and password hash (or your Google account identifier if you sign in with Google).
- Organisation data: the rota content your organisation creates — people, teams, tasks, schedules, staffing rules and settings.
- Billing data: plan, seat counts and subscription status. Card details are collected and stored by Stripe, not by us.
- Integration data: if you connect a calendar feed we store its URL and the events it produces as rota entries; if your organisation connects Slack we store the workspace bot token and a log of reminders sent. Both are optional.
- Signup enquiries: details you give us before creating an account (for example business name and team size).
We do not sell personal data, and we do not use Customer Data for advertising.
3. Why we process it
- To provide the Service — our contract with you or your organisation.
- To take payment and keep required accounting records — contract and legal obligation.
- To secure the Service, prevent abuse and fix faults — legitimate interests.
- To respond to your messages — legitimate interests or steps prior to a contract.
4. Where your data lives
Application data is stored in a Supabase-managed PostgreSQL database hosted in London (AWS eu-west-2). The web application is served by Netlify. Payments are handled by Stripe. Optional integrations send data to Slack and read data from Google Calendar only when your organisation or you enable them. Where any provider processes data outside the UK, transfers are protected by recognised safeguards such as adequacy decisions or standard contractual clauses.
5. How long we keep it
- Account and organisation data: for as long as the account or organisation exists, then deleted within a reasonable period after closure (see the Terms for the 30-day export window).
- Billing records: as long as tax and accounting law requires.
- Notification and audit logs: kept only as long as needed for reliability and security.
6. Security
All traffic is encrypted in transit (TLS/HSTS). Access to data is enforced server-side with row-level security, so members of one organisation cannot read another's data, and role checks are applied in the database rather than the browser. Secrets such as integration tokens are write-only from the app and never exposed to the browser. If you believe you've found a vulnerability, please email hello@whosonwhat.com rather than opening a public report.
7. Cookies and local storage
We use only what the Service needs to work: an authentication session, and local settings such as your theme and in-progress signup details. We do not use third-party advertising or analytics cookies.
8. Your rights
You have the right to ask for access to, correction of, or deletion of your personal data, to object to or restrict processing, and to data portability. Where we act as processor we will refer your request to your organisation and help it respond. To exercise a right, email hello@whosonwhat.com. You can also complain to the UK Information Commissioner's Office (ico.org.uk), though we'd appreciate the chance to help first.
9. Changes to this policy
We may update this policy from time to time; material changes will be notified to organisation admins by email or in the app, and the date at the top always shows the current version.
10. Contact
Who's On What — hello@whosonwhat.com.