Your rota is your business.

We use clear access controls and proven infrastructure to keep your organisation's scheduling data private and available.

Protected access

Supabase authentication, organisation-level membership and role-based permissions keep access scoped.

Secure by design

Encrypted HTTPS connections and database row-level security protect data in transit and between organisations.

Responsible operations

We collect only the information needed to run the service and document how it is used in our privacy policy.

Access example

An agent can be limited to viewing assigned work, while a team leader edits their team and an organisation admin manages membership. Database row-level policies provide a separate boundary between organisations.

Security boundaries

No service can promise absolute security. Customers remain responsible for authorised membership, strong account practices and not placing unnecessary sensitive customer data in rota labels. Contact us for current hosting, retention or procurement evidence.

Security questions

Where is data hosted?

The application uses Supabase-hosted services. Contact us for current region and data-processing details relevant to your organisation.

Who can edit a rota?

Organisation roles control access. Admins and authorised managers can edit; team members can be limited to viewing their schedules.

How do I report a concern?

Email hello@whosonwhat.com with “Security” in the subject. Please do not include sensitive data in the first message.

Make next week's rota the easy one.

Start free with up to five people. Add your team when you're ready.

Create your rota