Skip to main content

Legal

Privacy Policy

This page mirrors the current privacy policy source used across Darouta so public links from emails and the site resolve to one canonical document.

Last Updated: 2026-08-24

1. Introduction

Darouta ("we", "our", or "us") provides a staff rota and shift-scheduling application (the "Service"). Darouta serves customers around the world and is operated from the United Kingdom. We are committed to protecting your privacy and handling personal information responsibly, wherever you are located.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have. It covers the Darouta app, our public website, and the public Live Schedule pages you can choose to share. As a UK-based provider we are governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and we apply those standards to the personal data we handle for all of our users.

This policy works alongside our Terms of Service. It is written to be read in plain language — if anything is unclear, please contact us using the details in Section 26.

2. Our Role: Controller And Processor

Data protection law distinguishes between a "controller" (who decides why and how data is processed) and a "processor" (who processes data on a controller's instructions). Darouta acts in both roles, depending on the data:

  • We are the controller of your account, billing, and usage data — the information we need to run Darouta, bill you, secure the Service, and support you.
  • You are the controller, and we are your processor, for Employee Data. When you add information about your staff to manage rotas, you decide why and how that data is used. We process it on your behalf, on your instructions, to provide the Service. You are responsible for having a lawful basis and for giving any notices your staff are entitled to.

Where we act as your processor, this policy describes how we handle the data, but your own privacy notice governs your relationship with your staff. If a member of your staff asks us about their data, we will generally direct them to you as the controller and support you in responding.

3. Information We Collect

We collect the following types of information.

A. Account Information

  • Email address (required for authentication)
  • Full name
  • Company or organization details
  • Subscription plan details

B. Employee Data (Input By You)

You may input data about your employees ("Employee Data") to manage rotas. You are the controller of this data (see Section 2). We collect it from you, the employer or workspace owner — not directly from the individual employees.

  • Full name (required)
  • Contact details: email, phone
  • Department
  • Shift preferences and availability
  • Shift assignments and rota history
  • Leave and absence records (category — for example holiday or sickness —, dates, and any notes your workspace chooses to add)

C. Usage Data

  • Rota schedules and shift patterns
  • Metadata (creation and update timestamps)
  • Operational records of AI feature usage (for example, usage counts used to apply plan limits)

D. Sign-In Information

If you choose to sign in with Google, we receive basic profile information from your Google account. Section 6 explains this in detail.

E. Live Schedule Sharing Data

When you publish a rota, Darouta serves a read-only staff-facing schedule view of it. Publishing is what shares it — there is no separate Live Schedule setting to switch on — and the audience is the staff rostered on that rota, plus the workspace owner and any collaborators with access to it.

  • Visible to viewers: employee display names (or full-name fallback), section labels, shift dates and times, break durations, and shift tags from the published rota snapshot.
  • Not exposed on public Live Schedule pages: employee email addresses, phone numbers, availability/preferences, private notes, and draft-only rota data.
  • Staff sign-in: staff can sign in to a shared schedule with their own work email, which creates a Darouta account linked to their entry on the venue's staff list. That link only identifies them — what they can see is re-checked against the current rota on every visit, so removing someone from a rota removes their access to it.
  • Access-protection data: a venue may optionally set a shared access code as an additional way in. Access codes are stored only as hashes, and verification attempts are logged using hashed IP data rather than raw IP addresses.
  • Schedule view records: when staff view a live schedule while signed in, we record which employee viewed which published rota version and when (first view of each version only). Viewing with only the venue access code, or without signing in on that device, records nothing. These records are visible to the venue's managers so they can confirm the schedule was seen; they contain no location, device, or browsing information.

F. Collaboration And Invite Data

When you invite collaborators into a workspace, Darouta stores the minimum data needed to deliver and enforce that access flow.

  • Invited collaborator email address.
  • Inviter name and email address.
  • Permission level and scoped collaboration rules for the invite.
  • Invite timestamps, acceptance status, and any removal state needed to stop showing revoked invitations.

We use this information to send collaboration emails, show pending invite state in the app, and verify that only the invited address can accept workspace access.

G. Billing, Tax, And Checkout Data

When you start a paid Pro checkout, Darouta and our payment processor Stripe process billing-specific data needed to calculate tax, present the correct legal disclosures, and reconcile the resulting subscription.

  • Billing email address.
  • Billing country and, where required, state or province.
  • Payer name and business or trading name.
  • Selected plan, checkout timestamps, legal acknowledgement records, and billing-policy version references.
  • Pro trial eligibility and lifecycle records when Pro is selected, including trial policy version, trial reservation/consumption status, trial period dates, and related Stripe customer, checkout session, and subscription identifiers.
  • Limited tax information such as tax ID type, validation outcome, and hashed or reference-based identifiers used for reconciliation. Darouta prefers not to store raw tax ID numbers locally whenever Stripe can hold them instead.
  • Stripe tax-ID verification responses and related verification metadata when Stripe returns them, including disclosed business-name or address fragments used to compare Stripe-returned verification details against the billing details you submitted.
  • Stripe customer, checkout session, subscription, and invoice identifiers needed to support billing, recovery, and customer support.
  • If a paid workspace is created or later claimed from a successful guest checkout, the declared billing country and subdivision may also be used once to seed the workspace working-time warning jurisdiction while that workspace default is still unset. After that initial seed, working-time location is stored as ordinary owner-managed workspace or venue settings inside the app.

H. AI Feature Inputs

When you use our AI features, we process the content you submit to them — the text you type into the AI command bar and the files you upload for parsing. Section 5 explains how this works.

I. Communications And Support

  • Emails you send to our support, billing, or privacy inboxes.
  • Feedback you submit in the app, which may include contextual information about what you were doing, to help us diagnose and resolve issues.
  • Records needed to send and manage transactional and rota emails, including unsubscribe state.

J. Cookies And Technical Data

We use a small number of essential and functional cookies, and we process basic technical data (such as IP address) to keep the Service secure and working. Section 22 explains our use of cookies.

We use your data only for the purposes below, each supported by a legal basis under the UK GDPR.

  • To provide the Service — creating and running your account, building and sharing rotas, and delivering the features you use. _Legal basis: performance of our contract with you._
  • To process Employee Data on your behalf — as your processor, on your instructions, to deliver the Service. _Legal basis: your instructions as controller; your own lawful basis governs the underlying processing._
  • To process payments, trials, tax, and billing records — taking payment via Stripe, managing the Pro trial, calculating tax, and keeping billing and checkout records. _Legal basis: performance of our contract, and compliance with legal obligations (such as tax and accounting law)._
  • To secure the Service and prevent abuse — authenticating access, protecting Live Schedule pages (including hashed access-code verification and hashed-IP attempt logging), and preventing fraud and misuse. _Legal basis: our legitimate interests in keeping the Service and your data secure._
  • To confirm schedules were seen — recording which employee first viewed which published rota version, when they view it signed in to their own staff account. _Legal basis: the legitimate interests of our customers in confirming staff have seen published schedules; viewing with only the venue access code, or without signing in, is not recorded._
  • To provide AI-assisted features — processing the content you submit to the AI command bar, file parsing, and working-time guardrails. _Legal basis: performance of our contract, and our legitimate interests in providing reliable features._
  • To communicate with you — sending transactional and service emails (such as invites, confirmations, and rota notifications) and responding to support requests. _Legal basis: performance of our contract and our legitimate interests; where any message is optional, you can unsubscribe._
  • To comply with the law — meeting our legal and regulatory obligations and responding to lawful requests. _Legal basis: compliance with legal obligations._

Providing your account and billing information is necessary to use the Service: it forms part of our contract with you, and without it we cannot create your account or process payments. Adding Employee Data is at your discretion, but the rota features need the relevant scheduling information to work.

We do NOT sell your data to third parties.

5. AI Features And Your Data

Darouta offers AI-assisted features: a natural-language command bar, AI parsing of files you upload to extract rota information, and automated working-time guardrails that flag potential compliance risks.

  • How it is processed. When you use these features, the relevant content (your text input or uploaded file) and the AI's output are processed by Cloudflare Workers AI, our AI inference provider, to generate the result.
  • We do not train AI models on your data. Cloudflare does not use the content you send to Workers AI to train its own or any third party's AI models, does not retain it after processing, and does not share it with other customers. Content is only stored where you save it in the product as part of normal use.
  • Human oversight. Our AI features are assistive. They help you work faster, but they do not make final decisions about people on their own — you stay in control of every scheduling and employment decision. The working-time guardrails provide information only and are not legal advice (see our Terms of Service).

If you access the Service from the European Union, AI-driven surfaces are identified as such so you know when you are interacting with, or viewing output from, an AI system.

6. Sign In With Google

If you choose "Sign in with Google", Google shares a limited set of profile information with us so we can create and authenticate your account: your name, email address, basic profile details, and your Google account identifier.

  • We use this information only to sign you in and to operate your account. We do not use it for advertising, and we do not sell it.
  • We request only basic sign-in scopes (your identity, email, and profile). We do not request access to your Gmail, Google Drive, contacts, or other Google services.
  • Our use of information received from Google complies with the Google API Services User Data Policy, including its Limited Use requirements.
  • You can review or revoke Darouta's access at any time in your Google Account permissions. Google's own handling of your data is governed by the Google Privacy Policy.

7. Who We Share Data With

We share personal data only with the service providers ("sub-processors") we rely on to run Darouta, each bound by contract to protect it and to use it only for the purposes we set. We do not sell your data. Our current sub-processors are:

  • Supabase — database, authentication, file storage, and realtime updates. Processes account and app data at rest.
  • Cloudflare — hosting, edge delivery, and AI inference (Workers AI). Processes app data in transit and the content you send to AI features.
  • Stripe — payment and tax processing. Processes billing and payment data (US / EU / UK).
  • Google — "Sign in with Google" authentication. Processes the sign-in profile data described in Section 6.
  • Resend — transactional and rota email delivery. Processes recipient email addresses and message content.

We may also disclose data where required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (in which case we will tell you).

We keep our list of sub-processors up to date. If we add or change a sub-processor in a way that affects how your data is handled, we will update this policy.

8. International Data Transfers

Because we serve customers worldwide and rely on global infrastructure, your personal data may be processed in countries other than your own, including outside the United Kingdom and the European Economic Area. The sub-processors listed in Section 7 store and process personal data principally in the United Kingdom, the European Economic Area and the United States. Cloudflare and Google additionally operate global networks — edge delivery and AI inference in Cloudflare's case, sign-in infrastructure in Google's — so data they handle may be processed in or near the country you connect from. Where a section below tells you which countries your data is held and processed in, this is the list it means.

Wherever personal data is transferred across borders, we rely on an appropriate safeguard recognised under UK data protection law — such as an adequacy decision, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum — so that your data continues to receive an equivalent level of protection.

9. Data Retention

  • Active data: retained as long as your account is active.
  • Deleted data: when you delete a record (for example, an employee or a rota), it is "soft deleted" initially.
  • Anonymization: soft-deleted records are anonymized after 30 days in line with the GDPR data-minimization principle. We scrub personally identifiable information such as names and emails, but may keep non-identifiable statistics.
  • Live Schedule access attempts: hashed-IP verification-attempt records are retained only for short-lived abuse prevention and operational monitoring.
  • Schedule view records: kept as long as the rota version and employee they reference; deleting the employee or the rota removes them automatically.
  • Billing, tax, trial, and checkout evidence: some billing, Pro trial, and checkout records may be retained longer than ordinary app content where needed for accounting, tax, fraud prevention, dispute handling, repeat-trial prevention, retroactive invoice records, or legal compliance. Stripe retains payment details and raw tax IDs under Stripe's own compliance and retention controls.

10. Your Rights

Under the UK GDPR you have the following rights over your personal data:

  1. Right of access: request a copy of the data we hold about you (you can also use our "Export Data" feature).
  2. Right to rectification: correct inaccurate data, for example via your profile.
  3. Right to erasure ("right to be forgotten"): delete your account or specific records; data is anonymized to protect your privacy after the verification period.
  4. Right to restriction of processing: ask us to limit how we process your data in certain circumstances.
  5. Right to data portability: receive certain data in a portable format.
  6. Right to object: object to processing based on our legitimate interests.
  7. Right to withdraw consent: where we rely on consent, withdraw it at any time.

To exercise any of these rights, contact us using the details in Section 26. If a venue uses Live Schedule sharing, these rights still apply to the employee and rota data included in published schedule snapshots.

If your data was added to Darouta by an employer (Employee Data), the employer is the controller — we will direct your request to them and support them in responding.

Complaints. If you are unhappy with how we handle your data, please contact us first so we can put it right; we will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

11. Your Rights In The European Economic Area

If you are located in the European Economic Area (EEA), the EU General Data Protection Regulation (EU GDPR) applies to our processing of your personal data, in addition to the rights set out in Section 10 — those rights apply equally under the EU and UK GDPR.

  • Supervisory authority. You have the right to lodge a complaint with the data protection supervisory authority in your EEA country of residence, place of work, or where the issue arose, in addition to contacting us directly.
  • International transfers. Where your personal data is transferred outside the EEA, we rely on the safeguards described in Section 8.
  • Contacting us. For any data protection matter, you can reach us at privacy@darouta.com.

12. Your Rights In The United States

If you are a resident of a US state with a comprehensive consumer privacy law — such as California (the CCPA, as amended by the CPRA), and similar laws in other states — you have certain rights over your personal information, to the extent those laws apply to us.

  • We do not sell or share your personal information. Darouta does not sell your personal information, and does not "share" it for cross-context behavioral advertising, as those terms are defined under California law — and we have not done so in the preceding 12 months. We also do not use advertising or tracking cookies (see Section 22), so there is no sale or sharing for you to opt out of.
  • Your rights. Depending on your state, these may include the right to know about and access the personal information we collect, to delete it, to correct it, to opt out of sale/sharing and certain profiling, and not to be discriminated against for exercising your rights. California's law also covers personal information about employees, job applicants, and business contacts, not only consumers.
  • What we collect and why. The categories of personal information we collect, the purposes we use it for, and the providers we disclose it to are described in Sections 3, 4, and 7.
  • How to exercise your rights. Contact us at privacy@darouta.com. We will verify your request and respond within the timeframes the applicable law requires. Where the law allows, you may use an authorized agent to make a request on your behalf.

13. Your Rights In Canada

If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to how we handle your personal information, and if you are in Quebec, so does Quebec's Law 25. The rights in Section 10 apply equally, and in particular:

  • the right to access the personal information we hold about you and to have it corrected;
  • the right to withdraw your consent, where we rely on it;
  • if you are in Quebec, the right to have your information sent to you or to another organisation in a structured, commonly used technological format, and the right to ask us to stop disseminating your information or to de-index a link to it.

We process your personal information outside Canada, in the countries listed in Section 8. That means your information may be accessible to courts and public authorities in those countries under their laws. We hold our service providers to contractual protections comparable to those we apply ourselves.

Our person in charge of the protection of personal information is the sole director of Darouta Ltd, reachable at privacy@darouta.com. You can complain to us first; you can also complain to the Office of the Privacy Commissioner of Canada, or, in Quebec, to the Commission d'accès à l'information du Québec.

14. Your Rights In Switzerland

If you are in Switzerland, the revised Federal Act on Data Protection (revFADP) applies. The rights in Section 10 apply equally, including the right to data portability.

The controller is Darouta Ltd, contactable at privacy@darouta.com and at the address in Section 26. We transfer personal data to the countries listed in Section 8. Of those, the United Kingdom and the European Economic Area are on Switzerland's list of countries with adequate data protection, so no additional safeguard is needed for those transfers; transfers to the United States, and to anywhere else not on that list, are made under contractual safeguards with each provider.

You can complain to the Federal Data Protection and Information Commissioner (FDPIC).

15. Your Rights In Australia

If you are in Australia, we handle your personal information in line with the Privacy Act 1988 and the Australian Privacy Principles. The rights in Section 10 apply equally, and in particular you may ask us for access to the personal information we hold about you and ask us to correct it.

We collect the kinds of personal information described in Section 3, for the purposes described in Section 4, and we hold and process it in the countries listed in Section 8, under contractual protections comparable to the Australian Privacy Principles. To complain about how we have handled your personal information, email privacy@darouta.com — we will acknowledge your complaint and respond with the outcome. If you are not satisfied, you can also contact the Office of the Australian Information Commissioner (OAIC). Where a data breach is likely to cause you serious harm, we will tell you and the OAIC.

16. Your Rights In New Zealand

If you are in New Zealand, the Privacy Act 2020 applies. The rights in Section 10 apply equally, including the right to access and correct your information.

Much of the information we hold about employees reaches us indirectly: your employer uploads it so that we can produce their rota. Where we collect your information from someone other than you, your employer is the agency that collected it and is responsible for telling you about that collection; we act on their instructions and support them in doing so. Section 2 explains this split in full.

We hold and disclose personal information in the countries listed in Section 8, under contractual protections comparable to the Privacy Act's. Our privacy officer is reachable at privacy@darouta.com. You can complain to us, and then to the Office of the Privacy Commissioner. Where a privacy breach is likely to cause serious harm, we will notify you and the Commissioner.

17. Your Rights In Japan

If you are in Japan, the Act on the Protection of Personal Information (APPI) applies to us. The rights in Section 10 apply equally, including access, correction and the right to ask us to stop using your personal data; you may also ask us to stop providing it to third parties.

For the retained personal data we hold:

  • Business name and address: Darouta Ltd, at the address in Section 26. Our representative is our sole director, named without delay on request — email privacy@darouta.com.
  • Purposes of use: as set out in Section 4.
  • Security measures: as described in Section 23.
  • Where to complain: privacy@darouta.com. You may also contact the Personal Information Protection Commission.

We handle your personal data in the countries listed in Section 8. The Personal Information Protection Commission has designated the United Kingdom and the European Economic Area as having a personal data protection system of a standard equivalent to Japan's, so we do not need your separate consent to handle your data there. Where we use service providers outside those countries — including in the United States — we do so under contractual safeguards.

18. Your Rights In Singapore

If you are in Singapore, the Personal Data Protection Act 2012 (PDPA) applies. The rights in Section 10 apply equally, including the right to ask for access to and correction of your personal data, and the right to withdraw consent where we rely on it.

We handle your personal data with your consent, or where the PDPA allows us to without it — including where it is necessary to provide the service your organisation has contracted us for. Our Data Protection Officer for the purposes of the PDPA is reachable at privacy@darouta.com. We transfer personal data out of Singapore, to the countries listed in Section 8, under contracts that require a standard of protection comparable to the PDPA's. Where a data breach is likely to result in significant harm or is of significant scale, we will notify the Personal Data Protection Commission and affected individuals.

19. Hong Kong

Darouta is operated from the United Kingdom, and we hold and process personal data in the countries listed in Section 8. We do hold personal data about customers and staff in Hong Kong. As Section 2 explains, we control the collection and use of account, billing and usage data — but we do so from the United Kingdom, not in or from Hong Kong, whichever server in the global networks described in Section 8 happens to answer a request, so the Personal Data (Privacy) Ordinance does not apply to us as a data user.

It does apply to you as a data user when you upload your staff's information to Darouta. We process that data only on your instructions and for the purposes you set, we secure it as described in Section 23, and we give you the tools to let your staff see and correct their own data. If you need anything further to satisfy your own obligations, email privacy@darouta.com.

20. Your Rights In South Africa

If you are in South Africa, we handle your personal information in line with the Protection of Personal Information Act (POPIA). The rights in Section 10 apply equally, including access, correction, deletion and the right to object.

  • Who we are: Darouta Ltd, at the address in Section 26.
  • What we collect and why: as set out in Sections 3 and 4. Where we collect information from someone other than you, it is normally your employer, who uploads it to produce their rota.
  • Whether you have to give it: giving us your information is voluntary, but we cannot provide the service without the information described in Section 3.
  • Where it goes: we hold and process personal information in the countries listed in Section 8. We transfer it only under contracts requiring protection substantially similar to POPIA's, including limits on onward transfer.
  • Complaints: email privacy@darouta.com. You may also complain to the Information Regulator (South Africa).

21. Other Regions

Darouta is available in many countries, and the data protection laws of your country may give you additional rights. Wherever you are located, we apply the standards described in this policy as a baseline, and we will honor the data protection rights that the laws applicable to you provide.

To exercise any right, or to ask how your local law applies to your data, contact us at privacy@darouta.com. If the law of your country requires us to take additional steps — such as acting through a local representative or providing further information — we will do so as required by that law.

22. Cookies

Darouta uses only essential and functional cookies — we do not use advertising or third-party tracking cookies, and we do not run analytics that profile you.

  • Essential cookies keep you signed in, maintain your session, protect access to shared schedules, and support secure account-recovery flows. The Service cannot work without these.
  • Functional cookies remember your preferences, such as your light/dark theme, command-bar state, and local Playground data, to improve your experience.

Because we only use strictly necessary and functional cookies, we do not show a tracking-consent banner. You can clear or block cookies in your browser, but essential cookies are required for the Service to function.

23. How We Keep Data Secure

We take technical and organizational measures to protect your data, including:

  • encryption of data in transit and at rest;
  • row-level security on our database so each workspace can only access its own data;
  • storing venue access codes only as hashes, and logging verification attempts with hashed IP data;
  • role-based access controls and authenticated access to all workspace data.

No system is perfectly secure, but we work to protect your data and to limit what is exposed when you share schedules externally.

24. Children's Data

The Service is intended for use by businesses, and account holders must be at least 18 years old. Darouta is not directed at children and we do not knowingly collect personal data directly from children.

Some Employee Data may relate to workers under 18 (for example, younger staff in hospitality or retail). Where that is the case, the employer is the controller of that data and is responsible for the lawful basis and any additional protections required for younger workers.

25. Changes To This Policy

We may update this Privacy Policy from time to time. If we make a material change, we will give reasonable notice, for example by email or within the Service, and we will update the "Last Updated" date above. Your continued use of the Service after a change takes effect means you accept the updated policy.

26. How to Contact Us

For any privacy-related questions, to exercise your rights, or to make a data request, please contact us at privacy@darouta.com.

Darouta is operated by Darouta Ltd, registered in England and Wales with company number 16935611, whose registered office is at 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF. You can also write to us at that address.