Security measures used in the service
Payments
Paid subscriptions use Stripe-hosted Checkout and Stripe's Customer Portal. Rota Generator stores the identifiers and billing status needed to connect an organisation to its subscription, but does not store full card numbers or card security codes.
Stripe webhooks are signature-verified before billing events are accepted by the application, and processed events are recorded to reduce duplicate billing-state updates.
Workforce privacy controls
Employee accounts are separate from employee records. Published rota visibility is separated from draft scheduling work, and public share links can limit names, roles, locations and notes. Managers control whether employees can see same-shift colleagues, their wider team or no colleague directory.
Free-text fields should still be used carefully. In particular, Rota Generator is not designed as a medical-record repository and organisations should minimise sensitive details in sickness or leave notes.
Infrastructure and service providers
Rota Generator currently relies on Hostinger for production hosting infrastructure, Stripe for payments and Cloudflare Turnstile for bot protection. Email is sent using configured mail infrastructure. These providers have access only to the information needed for their role, subject to their applicable contracts and privacy responsibilities.
Our Privacy Notice provides more detail about service providers and international processing.
What we do not promise
No internet service is completely immune from vulnerabilities, outages or human error. We therefore do not claim “100% secure” or guarantee uninterrupted availability. Our approach is to reduce risk, limit access, respond to issues and improve controls as the service grows.
RESPONSIBLE DISCLOSURE
Found a security problem?
Please report suspected vulnerabilities privately to [email protected] with the subject “Security report”. Include enough detail for us to reproduce the issue, but do not access, alter or download other people's data to prove a point.
Security contact
Email [email protected]. We also publish a machine-readable security contact at /.well-known/security.txt.