← Back to RosterMate

Privacy Policy

RosterMate · Effective 27 July 2026

This policy explains what personal data RosterMate collects, why, and your choices. It applies to the Service at https://roster-m8.com.

1. What we collect

  • Account details: your payroll number, your @saudia.com email address, and a securely hashed password (we never store your password in readable form).
  • Crew profile: your crew type (cockpit or cabin), rank or role, base, your fleet (cockpit) or bidding group (cabin), and an optional first/last name — used to match you to the correct bid-pack data.
  • Optional salary figure: a basic monthly salary you may enter yourself to make pay estimates more accurate. You can leave it blank or remove it at any time.
  • Roster data: the bid-pack PDFs you upload for parsing. The bid lists and planner preferences you build in the app are stored on your own device, not on our servers.
  • Basic usage records: sign-in events (time and browser type), a session cookie needed to keep you logged in, and technical logs of requests and email deliveries (delivery logs include the recipient address, never the message content).

2. Why we use it

We use this data only to provide and operate the Service — to authenticate you, show you the correct bid-pack data for your rank, base, and equipment, produce your rankings and pay estimates, and keep the Service secure and working. We do not sell your personal data or use it for advertising.

3. Service providers we rely on

We use a small number of trusted providers to run the Service. They process data only to provide their service to us:

  • Railway (cloud hosting and database) — stores your account and roster data and runs the application.
  • Cloudflare (content-delivery and security network) — serves the site and protects it from abuse.
  • Resend (transactional email) — delivers verification codes, password-reset links, and service notices to your email address.
  • Sentry (error alerting) — receives technical error information so we learn about faults; our alerts are designed not to include your roster content or personal identifiers.

Lemon Squeezy (payment processing) — when paid subscriptions are live, Lemon Squeezy processes your payment as our merchant of record. Your card details go directly to Lemon Squeezy; RosterMate never sees or stores them. We keep a limited, normalized purchase record for each order — order reference, plan, amount, purchase email, payment/refund state, and dates — to provide and audit your access.

Some of these providers operate outside the Kingdom of Saudi Arabia, so your data may be processed abroad. We choose reputable providers and share only what each one needs to do its job.

4. How long we keep it

We keep your data for as long as your account exists. If your subscription lapses or your account is disabled, your data is retained — access pauses, nothing is deleted — so you can pick up where you left off. Routine backups made for service recovery also retain copies of data for a period after it changes or is deleted.

5. Your choices and rights

You can view and update your profile and salary in Settings. You may request access to, correction of, or deletion of your personal data by emailing [email protected] from your account email address. Deletion requests are handled by us (there is no in-app delete button yet).

What account deletion removes: your account record (payroll number, email, password hash, names, and any salary figure), your crew profile, your sign-in history, and your awarded-line records.

What it does not remove: records of administrative and security actions are retained for the integrity of the Service — these records can include your payroll number and email address; bid-pack documents you submitted for publication may remain part of the shared dataset library that serves other crew, together with a note of who submitted them; and backup copies persist until they are replaced. If you want a submitted bid-pack removed as well, say so in your request and we will remove it where the Service allows.

6. Security

Passwords are stored using strong one-way hashing, all traffic is encrypted over HTTPS, and access to accounts is protected by session cookies and rate limiting. No system is perfectly secure, but we take reasonable measures to protect your data.

7. Cookies

We use a single essential session cookie to keep you signed in. We do not use advertising or third-party tracking cookies.

8. Contact

For any privacy question or request: [email protected].