Privacy Policy
Last Updated: September 2026
This Privacy Policy explains what information Roster collects, how we use it, and the choices you have. It applies to Roster's web application, mobile app, and public pages (collectively, the "Service").
1. Information We Collect
Account information. When you or your organization creates a Roster account, we collect your email address and password (stored securely and never in plain text), your role within the organization, and, if you enable it, two-factor authentication settings.
Organization data. Organizations use Roster to manage their own contacts, members, donors, and volunteers. This may include names, email addresses, phone numbers, mailing addresses, membership and donation history, and event attendance. This data is uploaded, created, and controlled by the organization using Roster — see "Organization Responsibilities" below.
Waitlist and application information. If you request early access to Roster, we collect your name, email, phone number (if provided), and information about your organization so we can evaluate your request.
Usage information. We collect basic product usage data (such as which features are used and when) to understand how Roster is used and to improve it. This analytics is handled entirely by our own systems — we do not use third-party advertising or cross-site tracking services.
Device and technical information. We collect IP addresses for security purposes (such as detecting abuse and enforcing rate limits) and, on mobile, a device push token if you enable notifications.
Images. If you upload an image (for example, an event flyer), it is stored so it can be displayed within the Service.
2. How We Use Information
- To provide, operate, and maintain the Service
- To authenticate accounts and keep them secure
- To send transactional emails, such as sign-in links, invitations, approval notices, and password resets
- To generate AI-assisted insights and answer questions you ask within the Service (see "AI Features" below)
- To sync data with third-party services an organization chooses to connect, such as a payment processor or mailing list provider
- To understand product usage and improve Roster over time
- To respond to support requests
3. AI Features
Roster uses Anthropic's Claude API to power AI-assisted features, such as generating insights from an organization's data or answering natural-language questions about it. When you use these features, relevant data from your organization's Roster account may be sent to Anthropic to generate a response. This data is used to produce your result and is not used by Roster or Anthropic to train models on your organization's data.
4. Third-Party Service Providers
We use a limited number of third-party providers to operate the Service. We share only the information each provider needs to perform its function, and we do not sell personal information to anyone.
- Supabase — hosts our database and handles account authentication
- Stripe and PayPal — process payments on behalf of organizations that choose to connect them; Roster never receives or stores full payment card numbers
- Mailchimp — syncs mailing list subscribers for organizations that choose to connect it
- Resend — delivers transactional emails on our behalf
- Anthropic — powers AI-assisted features, as described above
- Vercel — hosts the Roster application
5. Data Storage and Security
Data is stored in Supabase (PostgreSQL) and encrypted in transit. Access to organization data is scoped so that each organization can only see its own data, and internal access is limited to what is needed to operate and support the Service. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
6. Data Retention
We retain account and organization data for as long as the account is active or as needed to provide the Service. If you close your organization's account or request deletion, we will delete or anonymize your data within a reasonable time, except where we are required to retain it for legal or accounting purposes.
7. Your Choices and Rights
You can delete your own account at any time directly from Settings in the Roster web app or mobile app. You can also request access to, correction of, or deletion of your personal information by contacting us at info@rosterhq.ai.
8. Children's Privacy
Roster is a business tool intended for use by organization administrators and staff. It is not directed to children, and we do not knowingly collect personal information from anyone under the age of 13.
9. Cookies
Roster's web app uses essential cookies to keep you signed in and to remember your session. We do not use advertising cookies or cross-site tracking.
10. Organization Responsibilities
Organizations using Roster act as the data controller for the contact, member, and donor information they upload or create within the Service — Roster acts as a data processor on their behalf. Organizations are responsible for having the appropriate rights and legal basis to collect, upload, and manage this data, and for responding to requests from their own contacts regarding their information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Continued use of the Service after changes are published constitutes acceptance of the updated policy.
12. Contact
Questions about this Privacy Policy may be directed to info@rosterhq.ai.
