Privacy Policy
Last updated: 14 August 2026
This Privacy Policy applies to all personal information collected by OneOtium Pty Ltd (we, us or our) via the website located at https://rosteraapp.com (Website) and our related mobile application, Rostera (the App).
What information do we collect?
The kind of Personal Information that we collect from you will depend on how you use the Website and App. The Personal Information which we collect and hold about you may include:
- Name and email address — when you create an account or join the waitlist.
- Age confirmation — when you create an account, we ask you to confirm that you are at least 16 years old. We store only this confirmation; we do not collect your full date of birth for this purpose.
- Roster and shift data — the shifts, hours, and shift types you log.
- Pay information — the base rates, penalties, loadings, and allowances you enter so the App can calculate your estimated pay. This is information you enter yourself; we do not connect to any employer or payroll system.
- Professional development records — training and CPD hours you log, and any certificates or supporting documents you choose to upload.
- Credential information — details of tickets, registrations, and certifications you add (such as expiry dates), and any documents you upload to support them. Some of these documents (such as professional registration certificates) may be considered Sensitive Information and are only collected when you actively choose to provide them.
- Payment information — subscriptions are purchased through the Apple App Store, with Apple as the merchant of record. Apple, not us, processes your payment, and we do not receive or store your card details. We use RevenueCat, a subscription-management provider, to receive and manage your subscription status (such as whether your trial or subscription is active). RevenueCat does not receive your card details.
- Usage and device data — how you interact with the App, plus device type, operating system, and app version, used for support, troubleshooting, and improving the product.
Children and young people
Rostera is intended for users aged 16 years and over. When you create an account, we ask you to confirm that you are at least 16 years old. We collect and store only this confirmation — we do not collect your full date of birth for this purpose. We do not knowingly collect personal information from anyone under 16. If we become aware that we have collected personal information from a person under 16 without appropriate consent, we will take reasonable steps to delete it. Because some users may be aged 16 or 17, we handle their personal information with particular care and in accordance with the Australian Privacy Principles.
Types of information
The Privacy Act 1988 (Cth) (Privacy Act) defines types of information, including Personal Information and Sensitive Information.
Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable:
- whether the information or opinion is true or not; and
- whether the information or opinion is recorded in a material form or not.
If the information does not disclose your identity or enable your identity to be ascertained, it will in most cases not be classified as "Personal Information" and will not be subject to this privacy policy.
Sensitive Information is defined in the Privacy Act as including information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
Sensitive Information will be used by us only:
- for the primary purpose for which it was obtained;
- for a secondary purpose that is directly related to the primary purpose; and
- with your consent or where required or authorised by law.
How we collect your Personal Information
We may collect Personal Information from you whenever you input such information into the Website, related App or provide it to us in any other way.
We may also collect cookies from your computer which enable us to tell when you use the Website and also to help customise your Website experience. As a general rule, however, it is not possible to identify you personally from our use of cookies.
We distinguish between essential cookies, which are necessary for the Website to function, and non-essential cookies used for analytics, tracking, and personalisation. We will obtain your explicit consent before deploying any non-essential cookies, and you may withdraw or manage your cookie preferences at any time through our cookie preference centre. Non-essential cookies will not be activated until consent is given, and each cookie category will be retained only for the period necessary to fulfil its stated purpose.
We generally don't collect Sensitive Information, but when we do, we will comply with the preceding paragraph. Where we do collect Sensitive Information, including professional registration certificates and credential documents, we will only do so with your explicit consent, for the purpose of maintaining your personal professional-development and credential records within the App. We do not verify these documents against any external register. We retain such information for as long as you keep the record in the App, and we delete it when you remove the record or close your account, unless we are otherwise required to retain it by law.
Where reasonable and practicable we collect your Personal Information from you only. However, sometimes we may be given information from a third party; in cases like this we will take steps to make you aware of the information that was provided by a third party.
Purpose of collection
We collect Personal Information to provide you with the Services and to operate, support and improve the Website and App. Where you have consented, or where it is material of a type you would reasonably expect to receive from us, we may also use your contact details to keep in touch with you about developments in our business (see "Direct marketing" below).
We customarily only disclose Personal Information to our service providers who assist us in operating the Website and App. Your Personal Information may also be exposed from time to time to maintenance and support personnel acting in the normal course of their duties.
Prior to disclosing your Personal Information to any third-party service provider, we require that provider to execute a Data Processing Agreement incorporating the Australian Privacy Principles, mandating appropriate security standards including encryption and access controls, obligating notification of any data breach within 30 days of discovery, and confirming their geographic jurisdiction complies with the Privacy Act 1988 (Cth). We remain liable to you for any breach of your Personal Information caused by our service providers.
Direct marketing
We may use your Personal Information to send you direct marketing material where you have consented to receive it, or where it is material of a type which you would reasonably expect to receive from us. We do not use Sensitive Information in direct marketing activity. Our direct marketing material will include a simple means by which you can request not to receive further communications of this nature, such as an unsubscribe link. You may opt out of direct marketing at any time.
Security, access and correction
We store your Personal Information in a way that reasonably protects it from unauthorised access, misuse, modification or disclosure. When we no longer require your Personal Information for the purpose for which we obtained it, we will take reasonable steps to destroy, anonymise or de-identify it.
Content you control — including your logged shifts, pay inputs, CPD records, credentials, and any documents you upload — is deleted when you remove the relevant record or close your account, unless we are required to retain it by law. Certain records that we are legally required to keep, such as billing and transaction records, may be retained for up to 7 years to meet our record-keeping, tax and legal obligations, after which they are securely destroyed or de-identified.
The Australian Privacy Principles:
- permit you to obtain access to the Personal Information we hold about you in certain circumstances (Australian Privacy Principle 12); and
- allow you to correct inaccurate Personal Information subject to certain exceptions (Australian Privacy Principle 13).
Where you would like to obtain such access, please contact us in writing on the contact details set out at the bottom of this privacy policy.
If you wish to request the deletion of your Personal Information held by us, you may submit a written request to the contact details set out at the bottom of this privacy policy. We will respond to your request within 30 days and, subject to any legal obligations requiring us to retain data, will take reasonable steps to securely destroy or permanently de-identify your Personal Information and provide written confirmation upon completion.
Overseas transfer
Your Personal Information is stored on infrastructure operated by our platform provider, Base44, whose servers are located in the United States. Subscription purchases are processed by Apple through the App Store, and your subscription status is managed using RevenueCat. This means your Personal Information, including any certificates or documents you upload, is stored and processed in the United States.
The United States has data protection laws that differ from, and may be less comprehensive than, the Australian Privacy Principles. Where your information is transferred overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, including requiring our service providers to be bound by appropriate data processing agreements and, where applicable, approved transfer mechanisms. By providing your Personal Information to us, you consent to it being stored and processed in the United States as described above.
Complaint procedure
If you have a complaint concerning the manner in which we maintain the privacy of your Personal Information, please contact us on the contact details set out at the bottom of this policy. All complaints will be considered by our Privacy Officer, and we may seek further information from you to clarify your concerns. If we agree that your complaint is well founded, we will, in consultation with you, take appropriate steps to rectify the problem.
We will acknowledge receipt of your complaint within 5 business days and endeavour to resolve the matter within 30 business days of receipt. If we are unable to resolve your complaint within that period, we will notify you in writing with reasons for the delay and an estimated resolution timeframe. Should you remain dissatisfied following our final response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
How to contact us about privacy
If you have any queries, if you seek access to your Personal Information, or if you have a complaint about our privacy practices, you can contact our Privacy Officer at: info@rostera.com.au
Last updated: 14 August 2026