The short version. Your group's data belongs to your group. Every group's data sits in its own walled-off database that no other group can reach. It is stored in Sydney, Australia. We do not sell it, we do not advertise against it, and there are no third-party trackers in RollCall. You can export it or delete it at any time.
Who we are
RollCall is operated by Ephraim Stocks, based in Christchurch, New Zealand. Contact: hello@rollcallcheckin.com.
Under the New Zealand Privacy Act 2020, your organisation is the agency responsible for the personal information it collects about its members. RollCall provides the software that stores it on your behalf, and handles it only as described here or as you instruct.
What is collected
About the people in your group
Your organisation decides what to collect when someone registers. Typically that is: name, phone number, email, school and year level, date of birth, and an emergency contact's name and phone number. Most of these fields are optional and configurable — turn off what you do not need. RollCall also records attendance: the dates and times a person checked in.
About you, the account holder
Your email address, a password (stored only as a hash by Google Firebase Authentication — never in readable form), your group's name, and your plan and billing status.
What is never collected
- Card numbers. Payments go through Stripe's own hosted pages. Card details never touch RollCall's servers and we never see them.
- Location data, advertising identifiers, or behavioural tracking.
- Third-party analytics. RollCall carries no advertising or analytics trackers.
Who can see it
- Your administrators — full access to your group's member list and attendance.
- Your leaders — sign in with a PIN and see only the members of the group they lead.
- Anyone at your check-in screen can search names to sign in. That is how self-service check-in works, so put the screen where you would be comfortable having a member list visible. Profiles, contact details and reports are never reachable without an admin or leader sign-in.
- No other organisation. Every group's data is isolated by database security rules keyed to that group's identity. There is no query another group can run that reaches your data.
- RollCall (the operator) can access a group's data only where needed to run and support the service — investigating a fault you have reported, or where the law requires it. It is never used for anything else.
Where it lives
Data is stored in Google Firebase (Firestore and Firebase Authentication) in the australia-southeast1 (Sydney) region, on Google Cloud infrastructure. Every device must be authenticated before it can read anything.
Who else processes it
| Provider | What for | What they hold |
|---|---|---|
| Google Firebase | Database, sign-in, hosting | All group data, at rest in Sydney |
| Stripe | Subscription payments | Your billing email, card details and payment history. Members' details are never sent to Stripe — only a count of members, for metered billing. |
Children's information
Most people in a RollCall database are under 18. Because of that:
- Tell parents and caregivers what you collect and why. A line in your regular parent communication is usually enough, and you may link to this page.
- Collect only what you actually need — fields are configurable.
- Remove people who have left. Archiving and deletion are both built in.
- RollCall never markets to members, and never contacts them. Only your own leaders do, using the contact details you hold.
Access, correction and complaints
Under the Privacy Act 2020, a person (or their parent or caregiver) can ask to see the information held about them and ask for it to be corrected. Because your organisation is the agency, those requests go to your administrator, who can view, edit, export or delete a profile in seconds. If you need help fulfilling a request, contact us and we will assist.
If you are not satisfied with how a privacy issue has been handled, you can complain to the Office of the Privacy Commissioner: privacy.org.nz.
Keeping it and deleting it
- Attendance history is kept for as long as your group keeps using RollCall — the history is the point of the product.
- You can delete any individual at any time, and export your full database to CSV on the Pro plan.
- If you stop using RollCall, ask us and your group's data will be deleted. Backups holding it are cycled out within 30 days.
- Billing records are kept as long as New Zealand tax law requires (currently seven years).
Security
Access is controlled by per-group security rules enforced by the database itself, not just by the app. Data is encrypted in transit (HTTPS) and at rest by Google Cloud. Admin accounts use email and password sign-in — use a strong, unique password, since anyone with it can see your whole member list.
If a breach occurs that is likely to cause serious harm, we will notify affected organisations and the Privacy Commissioner as required by the Privacy Act 2020.
Changes to this policy
If this policy changes in a way that materially affects you, we will email the address on your account before it takes effect. The date at the top always shows the current version.
Contact
Questions about this policy or your data: hello@rollcallcheckin.com.