Information handling

Privacy

How RosterBeam handles public-site information and school roster data.

Last reviewed 3 August 2026

Who this information is for

This page describes RosterBeam’s current information-handling practices. For a school deployment, the school determines why its roster information is used and who may access it; RosterBeam provides the service and handles that information to operate and support the application. An executed customer agreement may add more specific privacy, retention or data-processing requirements.

Information RosterBeam handles

A school application can hold account identity and role information, staff rules, master and student timetables, supported-student names, class and duty configuration, roster exceptions, generated assignments, review changes, validation issues, audit events and exported workbooks. Support email contains whatever the sender chooses to provide.

Why information is used

School data is used to import and validate scheduling inputs, generate and review support-officer rosters, control authorised access, produce approved exports, diagnose service problems and protect the service. RosterBeam does not use school roster data for advertising.

School-specific storage and access

Each school deployment uses school-specific application credentials, database storage and document storage. The school database is kept on a private network, uploaded documents are held in non-public encrypted object storage, and application secrets are supplied through AWS Secrets Manager. Access is limited through school organization membership and assigned Viewer, Planner or Admin roles.

Service providers

RosterBeam uses Amazon Web Services for application hosting, storage, databases, logs and secrets, and Auth0 for school identity and access.

Retention and deletion

School data is retained while needed to provide the service and meet agreed operational or legal requirements. Authorised Admins can delete roster data or reset setup data. Database recovery backups are configured for 14 days. Because document storage is versioned and currently has no automatic lifecycle expiry, an earlier object version can remain after an in-app deletion. Customer-specific retention, return and final deletion arrangements are governed by the executed agreement where applicable.

Public website

The public website does not use analytics, advertising trackers, account registration or a contact-form database. Email links open the visitor’s own mail application, so the sender’s email provider handles the message.

Security and assurance

Current technical safeguards and their evidence boundary are described on the Security and Assurance pages. No online service can promise absolute security; suspected privacy or security issues should be reported promptly.

Enquiries and requests

Privacy enquiries and requests concerning information held by RosterBeam can be sent to support@rosterbeam.com. Please avoid including student or staff information in the initial email. A school user may also need to contact their school for requests concerning school-controlled records.