The short version. Your group's data belongs to your group. Every group's data sits in its own walled-off database that no other group can reach. It is stored in Sydney, Australia. We do not sell it, we do not advertise against it, and there are no third-party trackers inside the RollCall app — the app your group signs into, and your check-in screens, carry no advertising or analytics code at all. Our public marketing website uses one advertising-measurement tool, the Meta Pixel; it never sees your group's data. You can export or delete your data at any time.
Who we are
RollCall is operated by Ephraim Stocks, based in Christchurch, New Zealand. Contact: hello@rollcallcheckin.com.
Under the New Zealand Privacy Act 2020, your organisation is the agency responsible for the personal information it collects about its members. RollCall provides the software that stores it on your behalf, and handles it only as described here or as you instruct.
What is collected
About the people in your group
Your organisation decides what to collect when someone registers. Typically that is: name, phone number, email, school and year level, date of birth, and an emergency contact's name and phone number. Most of these fields are optional and configurable — turn off what you do not need. RollCall also records attendance: the dates and times a person checked in.
About you, the account holder
Your email address, a password (stored only as a hash by Google Firebase Authentication — never in readable form), your group's name, and your plan and billing status.
What is never collected
- Card numbers. Payments go through Stripe's own hosted pages. Card details never touch RollCall's servers and we never see them.
- Location data, advertising identifiers, or behavioural tracking.
- Third-party analytics in the app. The RollCall app — where your member and attendance data lives — carries no advertising or analytics trackers, and neither do your check-in screens. Our public marketing website uses the Meta Pixel for advertising measurement; see "Who else processes it" below.
Who can see it
- Your administrators — full access to your group's member list and attendance.
- Your leaders — sign in with a PIN and see only the members of the group they lead.
- Anyone at your check-in screen can search names to sign in. That is how self-service check-in works, so put the screen where you would be comfortable having a member list visible. Profiles, contact details and reports are never reachable without an admin or leader sign-in.
- No other organisation. Every group's data is isolated by database security rules keyed to that group's identity. There is no query another group can run that reaches your data.
- RollCall (the operator) can access a group's data only where needed to run and support the service — investigating a fault you have reported, or where the law requires it. It is never used for anything else.
Where it lives
Data is stored in Google Firebase (Firestore and Firebase Authentication) in the australia-southeast1 (Sydney) region, on Google Cloud infrastructure. Every device must be authenticated before it can read anything.
Who else processes it
| Provider | What for | What they hold |
|---|---|---|
| Google Firebase | Database, sign-in, hosting | All group data, at rest in Sydney |
| Stripe | Subscription payments | Your billing email, card details and payment history. Members' details are never sent to Stripe — only a count of members, for metered billing. |
| Meta (Facebook) | Advertising measurement, on our public marketing website only | Standard web-visit data from marketing pages (pages viewed, browser information, and Meta's cookies), and signup events that say which plan was chosen. When you create an account, we also send Meta a hashed (irreversible, one-way-scrambled) version of the account holder's own email address and name, so a signup that started from one of our ads can be credited to it; if that account later becomes a paid subscription we report the conversion and amount the same way. All of this is always and only the adult who sets up the account — never members, never children, never any attendance data, and the hashing means Meta receives a scrambled fingerprint, not readable details. |
The Meta Pixel runs only on the public marketing pages of rollcallcheckin.com — the home page, the pricing page, the contact page and our resource and solutions pages (not this policy page). It is deliberately absent from the app your group signs into and from every check-in screen, so members and their attendance are never tracked. It exists so we can tell whether our advertising works. You can limit how Meta uses this data in your Meta ad preferences, and browser tracking protection or ad blockers stop it entirely without affecting RollCall.
Children's information
Most people in a RollCall database are under 18. Because of that:
- Tell parents and caregivers what you collect and why. A line in your regular parent communication is usually enough, and you may link to this page.
- Collect only what you actually need — fields are configurable.
- Remove people who have left. Archiving and deletion are both built in.
- RollCall never markets to members, and never contacts them. Only your own leaders do, using the contact details you hold.
- The advertising pixel on our marketing website is never present in the app or on check-in screens — members are never tracked or added to any advertising audience.
Access, correction and complaints
Under the Privacy Act 2020, a person (or their parent or caregiver) can ask to see the information held about them and ask for it to be corrected. Because your organisation is the agency, those requests go to your administrator, who can view, edit, export or delete a profile in seconds. If you need help fulfilling a request, contact us and we will assist.
If you are not satisfied with how a privacy issue has been handled, you can complain to the Office of the Privacy Commissioner: privacy.org.nz.
Keeping it and deleting it
- Attendance history is kept for as long as your group keeps using RollCall — the history is the point of the product.
- You can delete any individual at any time, and export your full database to CSV on any plan.
- If you stop using RollCall, ask us and your group's data will be deleted. Backups holding it are cycled out within 30 days.
- Billing records are kept as long as New Zealand tax law requires (currently seven years).
Security
Access is controlled by per-group security rules enforced by the database itself, not just by the app. Data is encrypted in transit (HTTPS) and at rest by Google Cloud. Admin accounts use email and password sign-in — use a strong, unique password, since anyone with it can see your whole member list.
If a breach occurs that is likely to cause serious harm, we will notify affected organisations and the Privacy Commissioner as required by the Privacy Act 2020.
Changes to this policy
If this policy changes in a way that materially affects you, we will email the address on your account before it takes effect. The date at the top always shows the current version.
Contact
Questions about this policy or your data: hello@rollcallcheckin.com.