RollCall ← Back to RollCall
Privacy

Privacy Policy

Last updated: 13 August 2026

RollCall holds the names of people in your group — most of them children. This page says plainly what is collected, who can see it, where it lives, and how to get it back or delete it.

The short version. Your group's data belongs to your group. Every group's data sits in its own walled-off database that no other group can reach. It is stored in Sydney, Australia. We do not sell it, we do not advertise against it, and there are no third-party trackers in RollCall. You can export it or delete it at any time.

Who we are

RollCall is operated by Ephraim Stocks, based in Christchurch, New Zealand. Contact: hello@rollcallcheckin.com.

Under the New Zealand Privacy Act 2020, your organisation is the agency responsible for the personal information it collects about its members. RollCall provides the software that stores it on your behalf, and handles it only as described here or as you instruct.

What is collected

About the people in your group

Your organisation decides what to collect when someone registers. Typically that is: name, phone number, email, school and year level, date of birth, and an emergency contact's name and phone number. Most of these fields are optional and configurable — turn off what you do not need. RollCall also records attendance: the dates and times a person checked in.

About you, the account holder

Your email address, a password (stored only as a hash by Google Firebase Authentication — never in readable form), your group's name, and your plan and billing status.

What is never collected

Who can see it

Where it lives

Data is stored in Google Firebase (Firestore and Firebase Authentication) in the australia-southeast1 (Sydney) region, on Google Cloud infrastructure. Every device must be authenticated before it can read anything.

Who else processes it

ProviderWhat forWhat they hold
Google FirebaseDatabase, sign-in, hostingAll group data, at rest in Sydney
StripeSubscription paymentsYour billing email, card details and payment history. Members' details are never sent to Stripe — only a count of members, for metered billing.

Children's information

Most people in a RollCall database are under 18. Because of that:

Access, correction and complaints

Under the Privacy Act 2020, a person (or their parent or caregiver) can ask to see the information held about them and ask for it to be corrected. Because your organisation is the agency, those requests go to your administrator, who can view, edit, export or delete a profile in seconds. If you need help fulfilling a request, contact us and we will assist.

If you are not satisfied with how a privacy issue has been handled, you can complain to the Office of the Privacy Commissioner: privacy.org.nz.

Keeping it and deleting it

Security

Access is controlled by per-group security rules enforced by the database itself, not just by the app. Data is encrypted in transit (HTTPS) and at rest by Google Cloud. Admin accounts use email and password sign-in — use a strong, unique password, since anyone with it can see your whole member list.

If a breach occurs that is likely to cause serious harm, we will notify affected organisations and the Privacy Commissioner as required by the Privacy Act 2020.

Changes to this policy

If this policy changes in a way that materially affects you, we will email the address on your account before it takes effect. The date at the top always shows the current version.

Contact

Questions about this policy or your data: hello@rollcallcheckin.com.