Security and data
Where it lives, who can see it, how money and identity documents are handled, and what we are not yet certified for. Written for the owner who has to sign off, not for an auditor.
roster runs on Supabase, a managed Postgres platform hosted in the European Union. Your venue's schedule, staff records, timecards and documents are stored there, encrypted at rest, and every connection to roster is encrypted in transit.
Backups are taken automatically by the platform. We are adding our own independent nightly backups outside the platform; until that is live, we say so here rather than imply it.
Access is enforced in the database, not only in the app. The owner sees everything. A manager sees what you give them. A supervisor login sees their people and the schedule and never pay. A payroll login sees pay and nothing else. Employees see their own schedule, their own record and their own documents, and nobody else's.
PPS numbers, dates of birth and bank details are held in a separate private table that supervisors cannot query even by mistake, and they never appear in lists or exports.
Card and bank details never touch roster. Stripe collects and stores them, and roster only ever holds a reference. Shift payments are authorised when you book a worker and captured only after the shift completes. Subscriptions are billed by Stripe on the schedule shown at checkout.
Marketplace workers are verified by a person on our team from a photo of their ID. Documents are stored in a private bucket, visible only to the worker and to the verification team, and deleted on request.
Documents an employee uploads to their own venue record are visible to the venue's managers only, stored in the venue's private document store, and go with the record if the venue removes the employee.
Punch photos are optional per venue. When on, they are stored for the venue, visible to its managers, and employees are told on their first punch. Venues can turn them off at any time.
roster is the data processor for your staff data and you are the controller. Employees can ask for their data and for deletion; the routes are documented on our GDPR page and the account deletion page, and both work without contacting support.
roster does not hold ISO 27001 or SOC 2. We are a small Irish company and those audits are planned, not done. What we can say today is what is written on this page: EU hosting, encryption in transit and at rest, database-level access control, Stripe for every card, and human verification of identity documents. If your venue needs a signed data processing agreement, ask and you will have one.
Email hello@roster.ie with "security" in the subject and you will hear from a person, not a ticket. We do not run a bounty programme and we will not pursue anyone who reports a problem in good faith.
See also GDPR, Privacy and Deleting your account. Last reviewed September 2026.