Privacy policy
The short version
1.Who is responsible
For this website and the waitlist, RCKTS is the data controller. We decide what is collected and why.
For the products, the position splits. Information about our customer, meaning the account holder, their billing details and who signed in when, we control. Information a customer puts into the software about their own people and contacts, such as an employee’s hours or a prospect’s phone number, belongs to that customer: they are the controller and we are their processor, acting on their instructions under a written agreement. If you are an employee of a firm that uses RCKTS Time, your employer is who to ask about your data first; we will help them answer, and we will help you reach them.
2.Part 1: this website
What we collect. Only what the waitlist form sends:
- your email address, which is the only required field;
- your name and company, if you choose to give them;
- which products you ticked as interesting;
- whether you asked for the newsletter as well;
- the page you were on when you submitted, and the time you did. Not your browsing history, just one path on our own site, so we know which page persuaded people;
- the IP address the submission came from, stored beside the time you gave consent and used for nothing else. The law requires us to be able to demonstrate that consent was given, and a tick box on its own cannot: it records what is true now, not that somebody chose it. It is never used to identify you, locate you or join your entry to anything.
What we do not collect. No analytics or measurement product runs on this site. No advertising or social pixels. No fingerprinting. No cookies at all. See the cookie policy, which is short for that reason. Our server records the usual web server log entries needed to keep the site up and to stop abuse, including the IP address a request came from; those are kept briefly and are not used to build a picture of you.
Why we are allowed to. Your consent, given by submitting the form, for writing to you about the thing you asked about and, separately and only if you ticked it, for the newsletter. Our legal obligation under Article 7(1) to be able to demonstrate that consent, for the record of when and from where it was given. Our legitimate interests in keeping the site available and secure, for the server logs. You can withdraw consent at any time and it costs nothing.
How long. Until you unsubscribe or ask us to delete it, or until two years after the last time we wrote to you and heard nothing back, whichever comes first. A waitlist that keeps addresses forever is a mailing list nobody agreed to.
Unsubscribing and deleting are different, deliberately. Unsubscribing keeps a record that you asked to be left alone, so that somebody typing your address into the form later cannot quietly put you back on. A month after you leave, that record is stripped back to your address and the date: the name, the company, what you were interested in, where you signed up and the consent record are all deleted, because they were held to write to somebody we are no longer writing to. Asking us to delete instead removes the row outright, and then there is nothing left to stop a future signup. That is the trade, and it is yours to make.
3.Part 2: the products
Nothing below applies to you yet unless you are one of the small number of people testing this. It is here so you can read it before deciding to be a customer, rather than after.
Everywhere. An account holds a name, an email address, a hashed password and the organisations you belong to. Billing is handled by Stripe; card details go to them and never reach us. We keep the subscription, the seats and the invoice history. Signing in, changing a permission and other consequential acts are written to an append-only audit log, which is a safeguard rather than a marketing tool.
Pipelines is a sales CRM, so it holds what you put in it about companies and contacts. It also records, transcribes and scores calls where a customer has switched that on. Two things about that are worth reading twice:
- Recording calls is the customer’s responsibility, not ours. Whoever records has to have a lawful basis and, in practice, has to tell the people on the call. We give them the controls; we cannot give them the consent.
- Card numbers and similar are masked before storage. A prospect reading a card number aloud would otherwise put it in a transcript, a search index and every backup. Masking runs before the transcript is written, not after.
Time is time and attendance, so it holds the most sensitive material of the three:
- Location, only with consent. A punch carries coordinates only if the worker has agreed, in the app, on a screen that says what it means. Consent can be withdrawn and takes effect immediately: new punches carry no coordinates. Locations already recorded stay on the punches they belong to, because those are part of a pay record.
- Payroll identifiers, held encrypted. National Insurance number, date of birth, CIS details. They are stored encrypted and are never shown back. The screen tells a manager whether something is on file, not what it says.
- Health information, where a fit note is uploaded. That is special category data. Where it is processed, it is under Article 9(2)(b), obligations in employment law, and it is deleted on a much shorter clock than everything else.
- Compliance records. Working Time flags, 48-hour opt-outs and the evidence behind them, because the regulations require the employer to keep them.
4.How long things are kept
Retention pulls in two directions: employment and tax law require some records to survive for years, and data protection law says personal data must not outlive its purpose. Those are answered per kind of record rather than by one window applied to everything. A fit note kept for six years because a pay record needs six years would be a breach.
Deletion is real deletion, not a hidden flag. The one thing we cannot remove on request is a record we are legally required to keep, and where that applies we will tell you which one and why.
5.Who else sees it
We do not sell personal data, we do not share it with anybody for their own marketing, and we do not use it to advertise to you elsewhere. We use a small number of suppliers who process data on our instructions:
Where it is. Google is a United States company and we use its London region, so the data itself sits in the UK. Where a transfer outside the UK does happen, whether for support or because a Google service runs elsewhere, it is covered by the standard contractual clauses and the UK addendum in Google’s data processing terms, which is the arrangement the law provides for exactly this.
We will also disclose information where the law requires it, and to professional advisers or a buyer if the business is ever sold, in which case you would be told before anything moved.
6.How it is kept
Two things are worth naming specifically because they are structural rather than promises:
- Customers are separated by the database itself. Every row carries the organisation it belongs to and the database enforces it, so a query that forgot to filter returns nothing rather than somebody else’s data. A missing filter is an error, not a leak.
- The sensitive fields are encrypted and never shown back. A payroll identifier can be written and used; it cannot be read out of the interface, by anybody.
Alongside those: encryption in transit, hashed passwords, least-privilege database roles, and an audit log that records consequential actions. Nothing is perfect. If you find a problem, please tell us at hello@rckts.io and put “security” in the subject. We will not take legal action against somebody who reports a vulnerability in good faith and gives us a reasonable chance to fix it.
7.Your rights
Under UK data protection law you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it if it is wrong;
- delete it, where we are not required to keep it;
- stop or restrict a particular use;
- send it to you, or to somebody else, in a portable format;
- stop using it for direct marketing, which is absolute and takes one click.
Write to hello@rckts.io. We will answer within one month, and it is free. If the data is your employer’s rather than ours to decide about, we will say so and point you at them rather than leaving you without an answer.
You can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you raised it with us first, but you do not have to.
8.Children
These are products for businesses. The website and the waitlist are not directed at children and we do not knowingly collect anything from one. A customer’s own use of RCKTS Time may involve workers under 18, which is a matter for that employer and the law that applies to them.
9.Changes
The date at the top says when this last changed. If we change something that affects how we use information we already hold about you, we will email you rather than only editing this page.