← Back to site

Privacy Policy

Last updated: 14 June 2026

1. Who we are

ClearRota is rota, booking and invoicing software for service businesses, operated by Harry Osborne, trading as ClearRota, as a sole trader based in Portsmouth, UK. For any privacy question, contact us at [email protected].

2. The two ways we handle data

(a) Data about our own customers (the businesses who buy ClearRota). When a business signs up, we hold the account-holder's name, email, and billing details so we can provide and bill for the service. For this data, we are the data controller.

(b) Data our customers put into the app (their clients, staff and bookings). When a business uses ClearRota, they enter information about their own clients (names, addresses, contact details, access notes) and staff. For this data, the business is the data controller and ClearRota is the data processor — we only store and process it on their instructions. We do not decide how it is used and we never use it for our own purposes.

3. What we collect and why

4. Lawful basis

We process account and billing data on the basis of contract (to provide the service you signed up for) and legitimate interests (to run and secure ClearRota). App data is processed on our customers' instructions under our agreement with them.

5. Where data is stored

App data is stored in dedicated databases hosted by Supabase, in the EU, and the application is served via Cloudflare. Both encrypt data in transit and at rest. Each customer's app data is held in a separate database. If data is ever processed outside the UK/EU, we rely on appropriate safeguards.

6. How long we keep it

We keep account data for as long as you are a customer and for a reasonable period afterwards for legal and accounting purposes. App data is kept while your account is active; when you leave, we delete or return it on request within 30 days.

7. Who we share it with

We do not sell data. We share it only with the service providers needed to run ClearRota (our hosting and payment providers, listed above), and where required by law.

8. Your rights

Under UK GDPR you have the right to access, correct, delete, or restrict use of your personal data, and to complain to the Information Commissioner's Office (ICO) at ico.org.uk. To exercise any right, email us at [email protected].

9. Security

We use encrypted connections, access controls, and per-customer database separation. No system is perfectly secure, but we take reasonable steps to protect your data and will notify you and the ICO of any breach as required by law.

10. Changes

We may update this policy and will post the new version here with a revised date.