Rota by SproulTech
Privacy policy
Last updated 25 September 2026
Rota is call-schedule software for hospital departments and physician groups, operated by CRBN MOTORSPORTS LLC, trading as SproulTech, of 10845 Derringer Drive, Orlando, Florida 32829, United States. In this policy, "we" and "us" mean that company, and "Rota" means the software at callrota.com.
The short version. Rota holds the working lives of the staff in a department: who they are, when they are on call, and what they asked for. It holds nothing about patients. We do not sell it, we do not advertise, there is no analytics of any kind, and no third-party script runs on any page. It sits on one server in Virginia, it is backed up every night, and you can have a copy or have it deleted by asking.
1. Who this covers
Two different people read this page and they are not in the same position.
- A customer is the department, practice or hospital that holds the subscription. The customer decides what goes into Rota and who may see it. In data-protection language, the customer is the controller of the staff data in their own installation and we are their processor, handling it on their instructions.
- A member of staff whose name is in a call list did not sign anything with us. If you are asking why your name is in here, or you want it changed or removed, your department is the right first stop — they put it there and they can change it. We will help them do it, and we will act on a request sent to us directly by passing it to them and following what they instruct.
2. What Rota stores
| What | Why it is there |
|---|---|
| Name, email address and role of each person who signs in | To let them in, and to decide what they may change |
| A password, held only as a scrypt hash with a random salt | To check a sign-in. The password itself is never stored and never logged, so we cannot tell you what it is |
| The roster of providers a schedule is built for: names, roles, working patterns, the days they cannot work | It is the thing being scheduled |
| The schedule itself, and wall-board and calendar views of it | It is the product |
| Time-off requests, swap requests and profile changes, each with a free-text note the person writes | So the office can decide them, and so the schedule can honour them |
| An audit trail of who changed what, and when | So a disputed schedule change has an answer |
| Quotes and invoicing details for the customer | To get paid |
| Beta sign-up requests: name, email address, organisation and a free-text note on how scheduling is done today | To follow up about early access. Nobody is emailed automatically because of a sign-up; a person reads and replies |
| Feedback submitted from the app or the marketing site: the message, the page it came from, and the organisation or person it came from when that is known | To find and fix what is wrong |
No patient data
Nothing in Rota's design names, identifies or describes a patient, and no part of the software asks for it. It schedules staff, not care.
One thing worth saying out loud
Those free-text notes are typed by staff, and somebody asking for leave sometimes explains why. So a note can contain a member of staff's own health information. That is staff data rather than patient data, and it does not make Rota a clinical record — but it is real, and we would rather you read it here than discover it. Departments that would prefer those notes stayed bland should say so to their own people; the field is free text and Rota does not read it.
3. What Rota does not do
- No advertising, and nothing is sold or shared for marketing. Not to anyone, at any price.
- No analytics. No Google Analytics, no product analytics, no session recording, no heatmaps, no tracking pixels.
- No third-party scripts. Rota's pages load no content delivery network, no font service and no embedded widget. Everything the browser fetches comes from Rota's own server, which is enforced by a content-security policy on every response.
- No tracking cookies. In fact no cookies at all: your session token is kept in your browser's local storage and sent in a request header, which is also what makes the app immune to cross-site request forgery by construction.
- No training of AI models on your data. Your schedules and your staff's requests are not used to build anything.
4. What is kept in your browser
When you sign in, Rota stores a session token in your browser's local storage for that site. It lasts thirty days or until you sign out, and only your browser has it — the server keeps a digest of it, not the token, so a copy of our database does not yield a working session. Rota also remembers in the same place whether you have already been shown the guided tour. Clearing your browser's site data for callrota.com removes both and signs you out.
5. Where it is kept, and who can reach it
- Location. One virtual server rented from Hetzner Online GmbH, in their Ashburn, Virginia data centre, in the United States. Your data does not leave that server except in the backups described below.
- In transit. HTTPS only, with a Let's Encrypt certificate. Plain HTTP is redirected and the app publishes no other port.
- At rest. The database is a file on that server and it is not encrypted at rest. Access to it is controlled by key-only SSH to the host — passwords are disabled — with repeat-failure banning in place. We state this plainly because a policy that implies otherwise is worse than one that does not.
- Between customers. One customer cannot reach another's data. Every route that takes an identifier resolves it against the signed-in account's own organisation, and an identifier belonging to somebody else answers "no such thing" rather than confirming that it exists. This is covered by an automated test that sweeps every such route.
- Us. Nobody at SproulTech has an account inside your installation, and your data is not visible from ours. Running the server does mean administrative access to the machine it sits on, which is how it gets deployed, backed up and repaired. We look at customer content only when it is necessary to operate or fix the service, or when you ask us to — for example to investigate something you have reported.
6. Logs
The server records, for each request, the method, the path, the status code, how long it took and a random request identifier. It does not record request bodies, form contents or headers, so passwords and session tokens do not reach the log. Links that carry a secret in the address itself — password reset links, provider links, wall-board links — have that part replaced before the line is written, because a reset link in a log file is a working reset link.
7. Other companies involved
We keep this list as short as we can, and it is the whole of it.
| Who | What they do | What they can see |
|---|---|---|
| Hetzner Online GmbH | Hosts the server (Ashburn, Virginia) | They hold the disk the database sits on |
| An email provider | Delivers password-reset and notification mail | The address mailed and the contents of that mail. Note: this is not yet configured, so at the date above Rota sends no mail at all |
| Stripe, Inc. | Takes payment, if you choose to pay a quote by card | Your card details, which you give to Stripe on their own page. Rota has no card field, holds no Stripe key and stores no payment details; the quote carries a link and nothing more |
8. How long it is kept
- Your data stays until you or we delete it. Rota does not expire schedules or staff records on a timer, because a department that loses last year's call schedule loses the answer to who covered what.
- Backups. The database is snapshotted nightly and kept for thirty days, and a second copy is pulled to a machine outside the host. Backups are restored into a scratch container every night to prove they still work. Deleted data therefore persists in backups for up to thirty days after deletion, and then goes.
- After a subscription ends. See section 9 of the terms: you can export, then we delete on request.
9. Getting your data, correcting it, or having it deleted
Rota exports the schedule as CSV and as a calendar (.ics) file from inside the app, at any time, without asking us. Beyond that, write to nate@sproultech.com and we will:
- tell you what is held about you or your organisation;
- give you a copy of your organisation's data in a machine-readable form;
- correct anything wrong;
- delete it.
We aim to answer within thirty days. If you are a member of staff rather than the customer, see section 1 — we will route the request to your department, because they are the ones who decide what their schedule says.
10. HIPAA
We do not currently offer a business associate agreement, and Rota is not designed to hold protected health information. Do not enter patient information into it. If your own analysis concludes that the free-text notes described in section 2 make this a HIPAA matter for you, tell us before you sign rather than afterwards, and we will have that conversation honestly.
11. Security, stated without varnish
A fuller account is available to any customer or prospective customer on request, including the parts that are not finished. The headlines: passwords are hashed with scrypt; sessions are stored as digests and last thirty days; sign-in attempts are rate limited per address and per account; every response carries a strict content-security policy with no inline script permitted; and the software has no file-upload route.
Not true yet, and we will not imply otherwise: there is no encryption at rest, no multi-factor authentication, no single sign-on, one server with no failover, and no third-party penetration test.
12. Children
Rota is workplace software for clinical staff. It is not directed at children and we do not knowingly collect anything from them.
13. Changes to this policy
If this policy changes, the new version appears on this page with a new date at the top. For a change that materially affects what we do with customer data, we will email the customer's account owner rather than relying on you noticing.
14. Contact
CRBN MOTORSPORTS LLC, trading as SproulTech
10845 Derringer Drive, Orlando, Florida 32829, United States
nate@sproultech.com