Protected access
Supabase authentication, organisation-level membership and role-based permissions keep access scoped.
We use clear access controls and proven infrastructure to keep your organisation's scheduling data private and available.
Supabase authentication, organisation-level membership and role-based permissions keep access scoped.
Encrypted HTTPS connections and database row-level security protect data in transit and between organisations.
We collect only the information needed to run the service and document how it is used in our privacy policy.
An agent can be limited to viewing assigned work, while a team leader edits their team and an organisation admin manages membership. Database row-level policies provide a separate boundary between organisations.
No service can promise absolute security. Customers remain responsible for authorised membership, strong account practices and not placing unnecessary sensitive customer data in rota labels. Contact us for current hosting, retention or procurement evidence.
The application uses Supabase-hosted services. Contact us for current region and data-processing details relevant to your organisation.
Organisation roles control access. Admins and authorised managers can edit; team members can be limited to viewing their schedules.
Email hello@whosonwhat.com with “Security” in the subject. Please do not include sensitive data in the first message.
Start free with up to five people. Add your team when you're ready.