Updated 4 October 2026. RotaPilot is provided by Studio8022. Contact support@studio8022.com about privacy, access, corrections or deletion.
Your agreement and our responsibilities
RotaPilot is operated by David Duff, trading as Studio8022, Asprou Potamou 1, Oikia 2, Agios Georgios Peyias, 8570, Cyprus. The merchant, normally the employer, controls workplace records and employment decisions; we process those records on its lawful instructions. We are controller for our own account, security and support records. For those records we use contract performance where the individual is a party, legitimate interests in providing and securing the business service where appropriate, and legal obligations where applicable. The employer is responsible for its own lawful basis, staff notices and employment-record requirements. App access is not blanket consent to employment monitoring.
RotaPilot service terms · Data-processing agreement · All app agreements. Publication does not record merchant acceptance; contact support to arrange written acceptance where no in-app control is available.
Providers, transfers and rights
We operate from Cyprus; providers and merchant-selected recipients may process information elsewhere. We do not claim all processing stays in the EEA. See our providers and integrations page and contact us for applicable location and transfer information. We do not sell personal information, use staff records for advertising profiles or train AI models on merchant data.
Depending on applicable law, individuals may request access, correction, deletion, restriction or a portable copy, or object to processing. Historical audit trails do not remove those rights. You may complain to the competent authority, including the Commissioner for Personal Data Protection in Cyprus. We communicate material changes where required. RotaPilot supports human review; it does not make employment decisions.
Support correspondence and security records are retained while needed for their purpose or legal obligations, separately from workplace records. Contact us for applicable retention information or deletion. Restricted recovery copies may retain deleted records until their rotation/deletion cycle; applicable deletions must be reapplied before recovery returns data to normal use. A failed callback is not proof of completed deletion.
Information used
We store the shop’s identity and name, verified Shopify administrator identity, location names and timezones, staff names and email addresses, password hashes, sign-in security records, schedules, availability and leave requests, shift swaps, attendance, corrections, approved timesheets and action history. Notes are supplied by the merchant or staff; do not include medical diagnoses or unnecessary sensitive information.
Shopify supplies installation and subscription status. RotaPilot does not collect payment-card details or connect to your payment provider. It does not read Shopify customer records, orders or storefront browsing activity.
Why and who can access it
Information is used to provide scheduling, staff access, notifications, attendance review, billing eligibility, support and security. Shop owners control their workspace and approve manager access. Managers have workspace-wide scheduling and review access; owners retain team/access administration and final timesheet/correction approval. Employees see their own records and limited colleague shift information needed to request swaps. Workplaces remain separate even when someone works for more than one merchant.
Hosting, email and cookies
The service and database run on our OVH-hosted server. OVH also provides the mailbox used to deliver invitations, password recovery and schedule notices. Shopify handles app installation and subscription billing. We use necessary sign-in and security cookies, not advertising pixels in the app. Passwords are hashed; invitation and reset credentials expire and are single-use. Operational logs are bounded and are not intended to contain passwords, invitation links or email message bodies.
Retention and leaving the service
Archiving staff or locations preserves historical schedules and attendance. Uninstalling disables workspace access, revokes sessions and invitations, pauses notifications and leaves retained records available for deliberate owner recovery until Shopify’s shop-redaction process removes the workspace. Recovery does not restore old sessions or revoked staff access. Encrypted backups are held separately for recovery and require restricted administrative access; contact us for a deletion request covering retained recovery copies as well as active records.
Your requests
Employees should first contact their employer about workplace records and corrections. Merchants can contact Studio8022 for workspace access, export or deletion assistance. We verify the requester’s authority before disclosing or deleting information. Approved timesheets preserve their historical evidence; later requests do not silently rewrite the original record.
RotaPilot is an online scheduling and attendance tool, not payroll, legal-compliance advice or proof of physical attendance.