Privacy Policy
Last updated 3 July 2026
1. Who we are
Rovva ("we", "us", "our") operates the Rovva platform at rovva.co.uk. We are committed to protecting your personal data and processing it in accordance with applicable data protection law, including the UK GDPR and the Data Protection Act 2018.
2. Data we collect
We collect the following types of personal data:
- Account data: name, email address, and hashed password when you register. If you sign in with Google, we receive your name, email address, and profile picture from Google.
- Profile data: optional first name, last name, and phone number you add to your membership profile.
- Organisation data: name, slug, contact details, organisation type, and an optional logo image uploaded by an admin.
- Usage data: rota events, duty assignments, availability, waitlist entries, and cover requests you create within your organisation.
- Calendar data: if you connect an external calendar, the dates of events in that calendar (to mark you unavailable).
- Device data: if you use the mobile app and enable notifications, a push notification token for your device.
- Log and diagnostic data: IP address, browser type, and error reports collected automatically for security and to fix faults.
- Communications: email notifications sent by the platform on your behalf, and messages you send us via the contact form.
- Update signups: if you ask to be notified about product news (e.g. the mobile app launch), your email address and when you consented.
3. How we use your data
We use your data to:
- Provide, maintain, and improve the Rovva platform.
- Send transactional emails (invitations, password resets, duty reminders).
- Respond to support requests and resolve disputes.
- Detect and prevent fraud, abuse, or security incidents.
- Comply with legal obligations.
We do not sell your personal data to third parties, and we do not use it for advertising.
4. Legal basis for processing
We process personal data on the following bases:
- Contract: to provide the Service you have signed up for.
- Legitimate interests: to improve the platform, maintain security, and communicate service updates.
- Consent: for optional things you opt into, such as analytics cookies and product-update emails. You can withdraw consent at any time — every update email includes an unsubscribe link.
- Legal obligation: where required by law.
5. Data retention
We retain your personal data for as long as your account is active. If you delete your account, your account and personal data are permanently deleted immediately — this cannot be undone. Organisation activity records (audit logs) may be retained for up to 12 months for security purposes, but are anonymised when the account they relate to is deleted. If an organisation is deleted, its data is retained in a deactivated state for a short period in case the deletion needs to be reversed, then removed.
6. Third-party services
We use the following sub-processors:
- Vercel — hosting, infrastructure, and file storage (organisation logos)
- Neon — PostgreSQL database hosting
- Resend — transactional email delivery
- Stripe — payment processing (for paid plans; we never see your card details)
- Sentry — error monitoring and diagnostics
- Google — optional sign-in with Google, and analytics (only with your consent)
- Expo — push notification delivery for the mobile app
Each sub-processor is bound by data processing agreements consistent with UK GDPR requirements.
If you choose to connect an external calendar via iCal sync, Rovva will periodically fetch the calendar URL you provide in order to import your availability. This URL and its contents are processed solely to populate your availability within your organisation and are not shared with third parties.
7. International transfers
Some of our sub-processors are based in, or store data in, the United States. Where personal data is transferred outside the UK, we rely on safeguards recognised under UK GDPR, such as the UK International Data Transfer Agreement/Addendum or the UK Extension to the EU–US Data Privacy Framework, as applicable to each provider.
8. Security
We take reasonable technical and organisational measures to protect your data, including encryption in transit (HTTPS), hashed passwords, tenant isolation between organisations, and role-based access controls. No system is completely secure, but if we become aware of a personal data breach that is likely to result in a risk to you, we will notify you and the ICO as required by law.
9. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Object to or restrict certain processing.
- Data portability (receive your data in a machine-readable format).
To exercise any of these rights, contact us at privacy@rovva.co.uk.
10. Cookies
Rovva uses strictly necessary session cookies to authenticate users. With your consent, we also use Google Analytics cookies (_ga, _gid, _ga_WFFENVK6YG) to understand how visitors use the platform. IP addresses are anonymised. Analytics cookies are only set after you accept via the consent banner.
For a full list of cookies and how to manage your preferences, see our Cookie Policy.
11. Changes to this policy
We may update this Privacy Policy periodically. We will notify you of material changes by email. Continued use of the Service after changes constitutes acceptance.
12. Contact
For privacy enquiries, contact our data controller at privacy@rovva.co.uk.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.