This Privacy Policy explains how Rostia (“Rostia”, “we”, “us”), a product of Tirzah Motel Management, collects, uses, and protects personal information when you use the Rostia staff-scheduling platform at rostia.app (the “Service”). We are committed to handling your information in accordance with the New Zealand Privacy Act 2020.
Information we collect
- Account information: your name, email address, and password (stored securely by our authentication provider), and the business details you provide when creating an account.
- Business and staff data: information that account owners and managers enter to run their business — staff profiles, rosters, shift records, hours, tasks, notes, and contacts. Where pay rates or payroll details are entered, they are restricted to authorised roles.
- Usage and device data: basic technical information such as browser type, device, and log data generated when you use the Service.
How we use your information
- To provide, operate, and maintain the Service and its features (rostering, shift tracking, team chat, reporting, and payroll).
- To authenticate you and keep your account secure.
- To send service-related communications, such as email verification and password-reset messages.
- To improve and support the Service and respond to your requests.
Service providers
We use trusted third parties to operate the Service. These providers process data on our behalf under their own privacy and security commitments:
- Google Firebase — authentication, database, and storage.
- Vercel — application hosting.
- Resend — delivery of transactional emails (verification and password reset).
- Google Sign-In — optional sign-in using your Google account; we receive your name and email address from Google when you choose this method.
Cookies and local storage
We use cookies and similar browser storage that are necessary to keep you signed in and to remember your preferences. We do not use them for advertising.
Data retention
We retain your information for as long as your account is active or as needed to provide the Service. Account owners control their business data and may request its deletion. Some records may be retained where required for legal, tax, or accounting purposes.
Security
We take reasonable technical and organisational measures to protect your information, including encryption in transit, role-based access controls, and tenant isolation so each business’s data is kept separate. No method of transmission or storage is completely secure, but we work to protect your information.
Your rights
Under the New Zealand Privacy Act 2020 you have the right to access and request correction of your personal information. To exercise these rights, contact us at the address below.
Children
The Service is intended for businesses and their staff and is not directed at children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, where appropriate, notify you of material changes.
Contact us
If you have questions about this Privacy Policy or your information, contact us at hello@rostia.app or support@rostia.app.