Privacy Policy
Last updated: 28 May 2026
This Privacy Policy explains how MyRota.ie ("MyRota", "we", "us") collects, uses and protects personal data when you use our staff-scheduling service at myrota.ie.
We comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and the Irish Data Protection Act 2018.
1. Who we are (the Data Controller)
MyRota is operated as MyRota.ie, based in Dublin, Ireland.
For privacy questions you can contact us at hello@myrota.ie.
2. The data we collect
Account data — your name, email address, hashed password and any organisation details you provide during sign-up.
Billing data — billing email, country and payment card last 4 digits (full card data is handled by Stripe, see Subprocessors below).
Employee data you enter — when you use MyRota to manage staff, you (the employer) enter personal data about your employees: names, contact details, contracted hours, pay rates, leave balances, documents you upload (contracts, certifications, photos) and HR notes. In respect of this data, MyRota is the Processor and your business is the Controller. See our Data Processing Agreement.
Usage data — basic logs of when you sign in, which pages you access and basic device information (browser, OS, IP address). We use this for security, debugging and product improvement.
Analytics + marketing data (opt-in) — when you accept analytics cookies on our cookie banner, Google Analytics 4 collects anonymised pageview and click data. When you accept marketing cookies, Meta Pixel collects similar data to measure our advertising on Facebook and Instagram. Both are off by default and you can change your mind any time on the cookie policy page.
Cookies — full list and controls in the Cookie Policy.
3. Why we use your data (lawful basis)
To provide the service (contract) — account creation, authentication, storing rotas, generating exports, sending notifications.
To take payment (contract) — Stripe processes payments on our behalf under their own terms.
To keep the service secure (legitimate interest) — fraud prevention, abuse detection, audit logging.
To comply with the law (legal obligation) — tax records, responding to lawful requests from Irish authorities.
We do not sell your data, and we do not use it for advertising or train any third-party AI models on it.
4. Subprocessors we use
We use a small number of carefully chosen subprocessors. All store data in the European Union:
- Supabase (Frankfurt, Germany / eu-west-1) — Postgres database and file storage for documents and photos.
- Vercel (EU-Frankfurt region) — application hosting and serverless functions.
- Stripe Payments Europe Ltd (Dublin, Ireland) — payment processing for subscriptions.
- Resend (Dublin, Ireland) — transactional emails (invites, password resets, rota notifications).
- Google Analytics 4 (Google Ireland Ltd, Dublin) — anonymised website analytics. Only loaded after you accept analytics cookies. IP anonymisation is enabled.
- Meta Pixel (Meta Platforms Ireland Ltd, Dublin) — measures the effectiveness of any Facebook / Instagram ads we run. Only loaded after you accept marketing cookies.
A signed Data Processing Agreement is in place with each subprocessor. The full, up-to-date list is also published on our Data Processing page.
5. International transfers
Your account and employee data (everything you enter in MyRota) is stored and processed entirely within the European Union. We do not transfer this data outside the EU/EEA.
Optional analytics and marketing cookies — only if you accept them on the cookie banner — involve a small amount of non-EU processing by Google and Meta under their EU-US Data Privacy Framework certifications. You can opt out at any time on the cookie policy page; declining these keeps every byte of data inside the EU.
6. How long we keep your data
Active accounts — for as long as your account is active.
Cancelled accounts — your data is retained in read-only mode for 30 days after cancellation so you can export it. After 30 days it is permanently deleted.
Billing records — kept for 6 years to satisfy Irish Revenue requirements.
You can request earlier deletion at any time via Settings → Danger Zone or by emailing hello@myrota.ie.
7. Your rights under GDPR
You have the right to: access your data, correct it, erase it, port it elsewhere, restrict how we use it, object to certain uses, and withdraw any consent you previously gave.
To exercise any of these rights, email hello@myrota.ie. We will respond within one month.
If you are unhappy with how we handle your data, you can complain to the Irish Data Protection Commission (dataprotection.ie).
8. Security
Passwords are hashed using industry-standard algorithms and never stored in plain text. All data is encrypted in transit (TLS 1.2+) and at rest. Document and certificate files are served via short-lived signed URLs only — they are not publicly accessible.
9. Children
MyRota is a B2B service for businesses. We do not knowingly collect data from anyone under 16. If you are an employer entering data about an employee under 18, the lawful basis for that processing rests with you as the controller.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email and the "Last updated" date above will change.
11. Contact
For any privacy-related question, email hello@myrota.ie or visit our contact page.