Privacy Policy
RosterUp — Privacy Policy
Effective date: September 4, 2026
RosterUp is a booking and scheduling platform for venues, agencies and talent, operated by VDA Solutions LLC, 18 Frederick Ave, Lake Grove, NY 11755 (contact: [email protected]) ("RosterUp", "we", "us"). This policy explains what personal information we collect, why, who sees it, how long we keep it and what you can do about it.
Two things shape everything below:
- RosterUp is a business tool. Most of the information in it is business information you publish
deliberately so other businesses can book you: an act's stage name and rates, a venue's load-in instructions, a contact for the night of the show.
- We do not sell personal information, and we do not advertise. There are no advertising SDKs,
no third-party trackers and no data brokers in this product. Our revenue is subscriptions.
1. Who controls your data
For the account information of a User — your name, email, login and sessions — RosterUp is the controller.
For the content inside an Organization — Bookings, notes, documents, media, contact records, the personal information of people you enter — the Organization is the controller and RosterUp is its processor. If you are a venue contact whose details a venue put into RosterUp, ask that venue first; we will help route the request (§7.4).
2. What we collect
2.1 Account information
Name, email address, optional display name, optional phone number, optional avatar, timezone, password (stored only as an Argon2id hash — never in readable form), email-verification state, and your onboarding choices.
2.2 Sign-in and session information
Refresh sessions with their device name, browser user agent and IP address, so you can see where you are signed in and end sessions you do not recognize; and the time of your last sign-in.
2.3 Organization and business information
Everything your Organization publishes about itself: name, type, description, logo and cover image, website, business phone and email, social links, and the type-specific profile — a venue's capacity, load-in, parking, sound, house rules, insurance requirements and payment terms; an agency's legal business name, markets, categories and default terms; talent's stage name, act name, legal name, genres, home city and region, approximate home coordinates and travel radius, rates, equipment requirements, availability preferences and bio.
Locations and stages, including street address, coordinates, capacity and phone.
2.4 People you enter
Contact records for your Organization and for a specific show: name, title, email, phone, role and notes. Act members: name, role label, email, phone. Some of these people are not RosterUp users; you entered them, and you are responsible for having the right to (Terms §9).
2.5 Relationship and invitation information
Who is connected to whom, the terms of the relationship, and each side's private view of it — directory status, internal rating, internal notes, preferred contact. A side's private data is only ever returned to the Organization that wrote it.
Invitations record the email address invited, who sent it, what it was for, and its state. The invitation token itself is stored only as a hash; the token leaves our systems exactly once, in the email.
2.6 Booking information
The event's name, type, date, times, timezone, place and stage; participants and their approval decisions; every offer and counter-offer with its money terms; every revision; public, private, technical, hospitality and equipment notes; the day-of contacts copied onto the booking; and money recorded for record-keeping — rate, deposit, commission, payout, balance. Booking history is append-only: offers, approvals and revisions are never overwritten, because the negotiation record is the evidence of what was agreed.
2.7 Availability and calendar
Availability rules and their status, recurring patterns, and calendar events including external gigs and personal blocks. Who can see the detail versus only "unavailable" is set by you (§5.1).
2.8 Documents and media
Files you upload: agreements, riders, stage plots, input lists, W9s, insurance certificates, press kits, invoices, receipts, photos, headshots, logos, cover images, video and audio, plus their titles, captions, alt text, tags, credit lines, visibility and usage rights. A W9 or an insurance certificate contains identifying information about you or your business; treat its visibility setting accordingly.
We record who downloaded which media asset, in which format, and when, and show that to the owner — that is the point of the usage-rights feature.
2.9 Messages (planned; not in the launch build)
When in-app messaging ships, we will store message text, attachments (by reference to a document), read state and per-thread mute settings. Message content is never written into logs, notifications or audit records.
2.10 Device and diagnostic information from error reporting
The app reports its own crashes and failures so we can fix them. A report contains:
- the error type, its message and its stack trace;
- the app version and build number, the platform (iOS, Android, web, desktop), the OS version, a
coarse device model such as iPhone15,2 or Pixel 7, and your locale;
- the route template you were on —
/bookings/:id, never the filled-in URL; - up to 50 breadcrumbs: recent screens as route templates, recent API calls as method plus route
template plus HTTP status, and a handful of named actions such as sent_offer;
- a per-launch random session id, your user id and organization id when you were signed in, and a
hashed installation id.
What it never contains: request or response bodies, message text, booking notes, document contents, authorization headers, cookies, access or refresh tokens, API keys, or raw email addresses. Email addresses and phone numbers that appear inside an error message are masked before the report is stored — v···[email protected]. Values are scrubbed on the device before the report is queued and again on our servers before it is written. Anything a report carries beyond the fields above is restricted to a fixed list of allowed keys; anything else is dropped rather than stored.
We do not read an advertising identifier, device serial, IMEI or Android ID. IP addresses are not stored on error records at all — our rate limiter sees the address and keeps only a counter.
Automatic error reporting has no user-facing opt-out, because it collects diagnostics rather than content and a half-populated crash stream cannot be acted on. We can switch it off fleet-wide.
2.11 Feedback you send us
If you use "Report a problem" or "Send feedback": what you wrote, the report type, and the same automatic context listed in §2.10. The form shows you exactly what will be attached before you send it.
Screenshots. A screenshot is attached only if you leave the toggle on, and you see a thumbnail of exactly what will be sent, with a Remove button, before you send. A screenshot is a picture of your screen — it may contain a booking, a rate or a contact's details. Only RosterUp platform administrators can open it, through a short-lived signed link, and each opening is logged.
2.12 Push notification tokens (planned; not in the launch build)
When push notifications ship, we will store the push token your device's platform issues, its platform, a device identifier and the app version, so we can deliver a notification to the right device. Tokens are never returned by any API and are deleted when you sign out of that device or turn push off.
2.13 Usage and operational data
Server-side request logs with a request id, route, method, status and timing; rate-limit counters; webhook records from the payment processor; and an append-only audit log of significant actions — who did what, to which record, when, from which IP address and user agent, with sensitive values redacted. Audit entries record identifiers and statuses, never notes, message bodies, stack traces or file contents.
2.14 Billing information
Your plan, subscription status, trial and period dates, and the payment processor's customer and subscription references. Card numbers never reach our servers — checkout and card storage happen on the processor's own hosted pages. We do not process payments between Organizations at all (Terms §6.3).
3. Where the information comes from
- You — what you type, upload and configure.
- Your Organization's other Members — colleagues acting for the same business.
- Connected Organizations — an agency that adds you to its roster, a venue that books you.
- An Agency that created a Managed Talent Record about your act before you joined (Terms §10).
- Your device, automatically, for error and diagnostic reports (§2.10).
- Our payment processor, for subscription status via webhooks.
- Someone who invited you, who gave us your email address to send the invitation.
We do not buy personal information, and we do not enrich profiles from third-party data sources.
4. Why we use it, and on what legal basis
The legal-basis column applies where the GDPR or a similar law governs the processing.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and secure accounts, authenticate, keep sessions | §2.1, §2.2 | Contract; legitimate interests (security) |
| Run Organizations, memberships, roles and permissions | §2.1, §2.3 | Contract |
| Connect Organizations and deliver invitations | §2.5 | Contract; legitimate interests (the sender's business relationship) |
| Create, negotiate, confirm and record Bookings | §2.4, §2.6 | Contract |
| Show calendars and detect conflicts | §2.7 | Contract |
| Store and deliver documents and media per your visibility settings | §2.8 | Contract |
| Deliver notifications and, later, messages | §2.9, §2.12 | Contract |
| Bill subscriptions and manage plans | §2.14 | Contract; legal obligation (tax records) |
| Fix crashes and defects; keep the service reliable | §2.10, §2.13 | Legitimate interests (a working product) |
| Answer and act on feedback and support requests | §2.11 | Contract; legitimate interests |
| Detect abuse and fraud, enforce the Terms, respond to legal process | §2.2, §2.13 | Legitimate interests; legal obligation |
| Send transactional email — verification, password reset, invitations, booking notifications | §2.1, §2.6 | Contract |
| Product announcements and service messages | §2.1 | Legitimate interests; consent where required |
We do not use your data for profiling, automated decision-making with legal effects, advertising, or training machine-learning models.
5. Who sees it
5.1 Other Organizations, according to your settings
This is the main way information moves in RosterUp, and it is under your control:
- Your Organization's Members see its content, limited by their role's permissions. Money on a
booking is separately gated.
- Booking participants — the venue, the agency and the act on a booking — see that booking, its
offers, its day-of contacts and anything attached with booking-participant visibility. What a participant may see of the money is determined by its role.
- Connected Organizations see what you have marked connected: media, documents linked to your
relationship, profile information, and availability if you share it with them. Pausing or ending a relationship stops that access immediately.
- Anyone, including people who are not signed in, sees only what you have marked public —
public media and, later, a marketplace listing.
- Private and internal-only items never leave your Organization. Internal notes, internal
ratings and directory status are returned only to the Organization that wrote them.
An Agency operating an unclaimed Managed Talent Record sees that record as its operator until the act claims it, after which the Agency drops to ordinary connected-agency access (Terms §10.3).
5.2 Service providers
They process data on our instructions, under contract, for the purpose we engaged them for:
| Provider role | What it handles | Vendor |
|---|---|---|
| Application hosting | Runs the API and the web app | Fly.io (API), Cloudflare Pages (web app) |
| Managed PostgreSQL | The primary database — everything in §2 except files | Neon |
| Object storage | Uploaded documents, media, derived image sizes, media-kit zips, feedback screenshots | Cloudflare R2 |
| Transactional email | Verification, password reset, invitations, notification emails | Resend |
| Push notification delivery (planned) | Apple and Google push services | APNs, FCM |
| Payment processing | Subscription checkout, card storage, billing portal, webhooks | A third-party payment processor |
| Error monitoring (optional) | A mirror of error events for on-call visibility. Off unless configured; when on, it receives the error, its stack, the tags in §2.10 and a user id — never an email, username or IP address | Sentry-compatible error monitoring (disabled unless configured) |
5.3 Legal and safety
We may disclose information when we reasonably believe it is required by law or valid legal process, or necessary to investigate fraud or abuse, enforce the Terms, or protect the rights, property or safety of RosterUp, our users or the public. Where we are permitted to tell you, we will.
5.4 Business transfer
If RosterUp is acquired or merged, information may transfer as part of that transaction, subject to this policy. We will tell you before your information becomes subject to a materially different policy.
5.5 What we never do
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not rent or trade it. We run no advertising and embed no advertising or analytics SDK in the app.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and Organization data | Until you delete the account or Organization, then removed or de-identified within 30 days |
| Bookings, offers, approvals, revisions | For the life of the participating Organizations — the negotiation record is shared, so deleting one side does not erase the other side's copy |
| Documents and media | Until you delete them; the stored object is removed on deletion |
| Media-kit zip files | 24 hours |
| Invitations | Until accepted, declined, cancelled or expired, then kept as a record of the invitation; the token hash is invalidated on use |
| Sessions | Refresh sessions expire after 30 days of inactivity and at most 90 days; revoked sessions are retained briefly for reuse detection |
| Verification and reset tokens | 24 hours and 1 hour respectively, single-use, stored hashed |
| Individual error and crash reports | 30 days, then deleted |
| Error groups (the de-duplicated summary: title, counts, first and last seen, status) | Retained indefinitely — they contain no personal information beyond counts, and they are the history of what broke and when. A group whose samples have expired shows no sample. An ignored group with no occurrence for 180 days is deleted |
| Feedback you sent us | Retained — it is your words and its status is our support history |
| Feedback screenshots | Deleted 180 days after the report is resolved or dismissed |
| Push tokens (planned) | Until sign-out, token invalidation, or disabling push |
| Audit log | Retained as an append-only security and dispute record for 24 months, after which identifiers are reduced to what dispute history requires |
| Billing records | As long as tax and accounting law requires |
| Backups | Age out within 35 days |
7. Your rights and how to use them
7.1 In the app
- See and edit your profile and your Organization's information at any time.
- See your active sessions and end them, individually or all at once.
- Change what each document and media asset is visible to, and its usage rights.
- Change who sees your availability.
- See the reports you have sent us and their status.
- Export your Organization's data.
- Close your account, or close an Organization you own.
7.2 On request
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, obtain a portable copy, object to or restrict processing based on legitimate interests, withdraw consent where we relied on it, and not be discriminated against for exercising any of these rights.
Write to [email protected]. We verify the request against your account — we may ask you to act from your registered email or to confirm details we already hold. We respond within 45 days (extendable once, with notice, to 90) or within the shorter period your local law requires. There is no charge unless a request is manifestly unfounded or excessive.
7.3 Authorized agents
An authorized agent may make a request for you with written permission we can verify; we may also ask you to confirm it directly.
7.4 Data an Organization holds about you
If your information is in RosterUp because an Organization put it there — you are a venue's day-of contact, or a member of an act — that Organization is the controller. Ask them first. If you cannot reach them or they do not act, write to [email protected] and we will route the request and, where appropriate, act ourselves.
7.5 Complaints
If you are in the EEA, the UK or Switzerland you may complain to your local supervisory authority. We would rather you told us first.
8. International transfers
RosterUp is operated from the United States and our providers process data in the United States. If you use RosterUp from outside the United States, your information is transferred to and processed there, under laws that may differ from your own.
Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) with our providers and apply the security measures in §11. RosterUp is not currently marketed or offered as a targeted service in the EEA, the UK or Switzerland, and we have not appointed an Article 27 representative; we will do so if that changes.
9. Children
RosterUp is a business tool for adults. You must be 18 or older to use it. We do not knowingly collect personal information from anyone under 18, and we have no service directed at children.
We chose 18 rather than 16 deliberately. RosterUp exists to form business relationships, agree commercial terms and hold business records — activities that presume the capacity to contract. The threshold is contractual, not a judgment about who can perform.
If a performer under 18 works with a venue or agency, their information reaches RosterUp only through an adult-run Organization — as a talent member record or a contact — and that Organization is responsible for having the guardian's authority to provide it. If you believe we hold information about someone under 18 that should not be there, write to [email protected] and we will delete it.
10. California
This section is for California residents and uses CCPA/CPRA terms.
10.1 What we collect. In the last 12 months we collected the categories in the table below. Sources, purposes and recipients are in §3, §4 and §5.
| CCPA category | Do we collect it? | Where |
|---|---|---|
| Identifiers (name, email, phone, account id, device id) | Yes | §2.1, §2.4, §2.10 |
| Customer records (Cal. Civ. Code §1798.80: name, address, phone, business contact details) | Yes | §2.3, §2.4 |
| Commercial information (subscription, plan, transaction records, booking terms) | Yes | §2.6, §2.14 |
| Internet or network activity (route templates, API breadcrumbs, request logs) | Yes | §2.10, §2.13 |
| Geolocation | Coarse only — a venue's address, an act's home city and approximate coordinates and travel radius, which you enter. No device GPS is collected | §2.3 |
| Audio, visual, electronic information (photos, video, audio, feedback screenshots) | Yes | §2.8, §2.11 |
| Professional or employment information (role, title, act membership, business affiliation) | Yes | §2.1, §2.3, §2.4 |
| Sensitive personal information | We do not seek it. A W9 or insurance certificate you upload may contain a taxpayer identification number; we hold it as an opaque file for the visibility you set and do not read, index or infer from it | §2.8 |
| Education information | No | — |
| Inferences / profiles | No | — |
| Biometric information | No | — |
10.2 We do not sell or share. We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the last 12 months. We do not do either now.
10.3 Sensitive personal information. We do not use or disclose sensitive personal information for any purpose beyond providing the service, so no right to limit its use applies. Do not upload tax or identity documents to a visibility setting wider than you intend.
10.4 Your rights. To know, access, correct, delete, obtain a portable copy, and not be discriminated against for exercising them. We offer no financial incentive programs. Use §7.2.
10.5 Opt-out preference signals. We honour the Global Privacy Control where we can detect it, though we neither sell nor share personal information, so there is nothing for it to opt out of.
10.6 Shine the Light. We do not disclose personal information to third parties for their own direct marketing.
11. Security
The measures below are the ones actually implemented; the full specification is our internal security model.
- Authorization is server-side. Every request is checked against your membership and permissions
in the Organization you are acting as. The client hides controls you cannot use, but the server is the only enforcer.
- Organization boundary. Every query is scoped to your Organization. A record belonging to
another Organization returns "not found" — never "forbidden" — so nothing leaks by existence.
- Passwords are hashed with Argon2id and re-hashed as parameters strengthen. Minimum 10
characters, checked against a deny-list, no arbitrary composition rules.
- Sessions. Short-lived access tokens; opaque refresh tokens stored hashed, rotated on every
use, with reuse detection that revokes the whole token family. You can sign out everywhere.
- Files are uploaded and downloaded through short-lived signed URLs with content-type and size
limits. Storage keys are random and never derived from file names. Private files are never reachable without a fresh signed link.
- Transport is HTTPS only, with HSTS and a strict origin allowlist.
- Logging. Request and response bodies are never logged. Email addresses are masked. Secrets
live only in environment configuration and the process refuses to boot without them.
- Rate limiting on every endpoint, tightest on authentication and token endpoints.
- Audit logging is append-only, with sensitive values redacted, and covers administrative
actions including every time an administrator opens a record containing personal information.
- Card data never touches our servers.
No system is perfectly secure. If you find a vulnerability, write to [email protected] — we will work with you and will not pursue good-faith research.
12. Changes to this policy
We may update this policy. The current version is always at https://rosterup.vip/legal/privacy, with its effective date at the top. If a change materially affects how we use your information, we will give notice by email and in the app before it takes effect.
Text Messaging (SMS) Data
If you opt in to RosterUp Reminders, we collect your mobile number, your verification and consent records (timestamp, method), and delivery status of messages we send. We use this information only to send the booking notifications you enrolled in and to honor STOP and HELP requests. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties except our SMS delivery provider acting on our behalf, and only as necessary to deliver the messages. You can opt out at any time by replying STOP or turning text notifications off in the app.
13. Contact
VDA Solutions LLC 18 Frederick Ave, Lake Grove, NY 11755 Email: [email protected]
For questions about the service itself, see the Terms of Service.