Privacy Policy
Effective Date: 2026-08-15
If there is a conflict between Rosterli's Privacy Policy and any privacy policy provided by this group or organization, Rosterli's Privacy Policy controls.
This Privacy Policy describes how Rosterli ("we," "us," or "our") collects, uses, discloses, and safeguards information when you use the Rosterli platform, including associated websites, applications, and services (collectively, the "Service").
1. Information We Collect
Account InformationWhen an organization or user registers, we may collect:
- Name
- Email address
- Organization name
- Role or permissions within an organization
- Authentication credentials or identifiers (including passkey-based credentials)
We automatically collect limited technical information necessary to operate the Service:
- IP address
- Browser type and version
- Device and operating system information
- Timestamps and activity logs related to use of the Service
Rosterli websites use cookies and similar technologies in two distinct groups:
- Strictly necessary cookies operate security, authentication and sign-in, form submission, checkout and payment flows, saved preferences, and core website functionality. Required cookies are always allowed: they cannot be switched off, because the Service cannot run without them.
- Optional analytics and advertising technologies, for example measurement, tracking, remarketing, and targeting platforms, are controlled separately. They are never loaded until a visitor gives consent for the relevant category, and a group or organization administrator may switch them off entirely for its website. When they are switched off, no cookie consent notice is shown because there are no optional cookies to choose between; strictly necessary cookies continue to operate.
If you process payments through the Service, payment details are handled by third-party payment processors. We do not store full credit card numbers or banking details on our servers. We do store payment records associated with a transaction, which may include the payer's name and email address, amounts, currency, status, payment method type and card brand, and the processor's transaction identifiers.
Registration and Membership InformationA group or organization decides what its registration forms ask for. Information submitted through a registration, and information associated with a membership, is collected and stored on that group's behalf. This may include participant and guardian details, answers to group-defined questions, acknowledgements, and records of review and approval.
Profile and Contact InformationWhere the member portal is used, this may include one or more email addresses and their verification status, phone numbers and their verification status, mailing addresses, a profile photo, and communication preferences.
Communications, Mailing Lists, and Text MessagesMessages a group sends through the Service, along with recipient selection, attachments, and delivery information such as delivery, bounce, and complaint events. If you join a mailing list, we record your subscription, the wording you agreed to, the time of your consent, and the page you subscribed from, and we keep a record of an unsubscribe. If you enrol a mobile number for text messages, we record the number, the categories and groups you chose, evidence of your consent, and any opt-out.
Merchandise InformationIf merchandise is offered and you place an order, this may include your name, email address, phone number, shipping address, and order details.
Communications With UsInformation you provide when contacting support, submitting feedback, or communicating with us through the Service.
2. How We Use Information
We use collected information solely to:
- Provide, operate, and maintain the Service
- Authenticate users and manage access control
- Process transactions and subscriptions
- Communicate service-related notices and updates
- Improve performance, security, and usability
- Comply with legal and regulatory obligations
We do not sell personal information. Rosterli does not use personal information for its own advertising or profiling, and does not build advertising profiles from the information a group or organization stores in the Service.
3. Data Sharing and Disclosure
We may share information only in the following circumstances:
- Service Providers: With vendors who perform services on our behalf, under confidentiality obligations. These currently include cloud hosting and storage, email delivery, image moderation, text message delivery, payment processing, support messaging, merchandise production and fulfillment, address lookup, and bot protection.
- Group-Configured Analytics and Advertising: A group or organization may choose to enable third-party measurement or advertising technologies on its own public website. Where it does, and only after a visitor gives consent for the relevant category, those third parties receive information about that visit and may use it for the group's measurement or advertising purposes and in accordance with their own privacy policies. Rosterli does not enable these technologies on a group's behalf, and a visitor who does not consent is not tracked by them.
- At Your Group's Direction: With the group or organization whose registration, membership, mailing list, communication, or event you interact with.
- Legal Requirements: If required to comply with applicable laws, regulations, or lawful requests.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, subject to this Privacy Policy.
Rosterli does not share personal information with third parties for Rosterli's own marketing purposes, and does not sell it.
Calendar subscriptions work differently, and the difference matters. If you subscribe to a Rosterli calendar in Apple Calendar, Google Calendar, Outlook, or any other calendar application, you give that application the subscription address. From then on it contacts Rosterli directly, on its own schedule, and keeps its own copy of the events under its own retention rules. Rosterli has no account with those providers and cannot see, change, or delete what they keep. If your subscription address is a personal one, treat it like a password: anyone who has it can read that calendar. You can revoke it at any time, which stops any further updates - but it does not remove events already downloaded to a device.
When we send you a calendar reminder, or tell you that an event has changed, we keep a small record that the message was sent. These records hold no message content and no event details - no subject, no text, no title, no times. They hold only enough to recognise that a particular message has already gone out, so that you are never told the same thing twice. Where a message was sent to you individually, the record includes an internal reference to your account; where an administrator approved a change, it includes a value derived from that administrator's account. These references carry no name, address, or contact details, but they can be linked back to a person using information we already hold, so we treat them as personal information rather than anonymous information. We keep these records for as long as the organization exists, because deleting one would allow the same message to be sent again. They are removed when the organization's data is removed. While the organization is retained, we do not currently have a way to remove these particular records for one person.
4. Data Retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this policy, and longer where a longer period is required by law or is needed to keep records that protect you. Some records are deliberately kept after you ask us to stop contacting you, because they are the evidence of that request: for example, a mailing list unsubscribe and a text message opt-out are retained so that you are not contacted again.
Organizations may request deletion of their data, subject to legal and contractual constraints. Certain financial, transaction, and audit records are retained after an organization's data is otherwise removed. Deletion does not remove information from backups taken before the deletion; those copies expire on their own schedule.
5. Security
We implement administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction. This includes modern authentication mechanisms, encrypted connections, and restricted access controls.
No system can be guaranteed 100% secure. Use of the Service is at your own risk.
6. User Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate information
- Request deletion of your data
- Object to or restrict certain processing activities
Requests can be made by contacting us using the information below. We do not currently offer a self-service data export or account deletion tool; requests are handled by our team. Where the information is held on behalf of a group or organization, we will direct your request to that group or organization, because it decides what is collected and how it is used.
You can manage some choices yourself: communication preferences and, where available, your profile details in the member portal; the unsubscribe link in any mailing list email; replying STOP to any text message; and the cookie preferences on a public website.
7. Children's Privacy
The Service is intended for organizational use and is not directed to children. Accounts may only be created by adults, and children do not hold their own accounts.
The Service is used by teams, clubs, and associations whose participants may be minors. Information about a minor reaches the Service only when an adult submits it: a parent or legal guardian, or an administrator who has represented that they hold the required parental or guardian consent and authority. Where that happens, we store and process that information on behalf of the group or organization, and that group or organization is responsible for obtaining the necessary consents and for deciding what is published. Requests concerning a minor's information should be directed to the group or organization, or to us using the information below.
8. International Data Transfers
Data may be processed or stored in jurisdictions outside your own, including Canada and the United States. Our primary infrastructure is hosted in Canada; certain functions, and certain of the service providers listed above, operate in the United States or elsewhere. We take reasonable steps to ensure appropriate protections are in place for such transfers.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by other reasonable means. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
10. Contact Information
For questions, requests, or concerns regarding this Privacy Policy or data practices:
Rosterli
Email: privacy@rosterli.com
117 McKenzie LnMount Uniacke, NS B0N 1Z0