Privacy Policy
This policy explains what personal information Rotation Scheduler collects, why, who we share it with, and how you can get it back or have it deleted. It's written to be read by a coach, not a lawyer.
Last updated: 28 July 2026
1. Who we are
Rotation Scheduler is operated by Vaughn Edmonds trading as Invert Systems (ABN 44 869 392 328), of Goulburn, New South Wales, Australia. We are the entity responsible for the personal information described here.
We aim to handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth), whether or not we’re legally required to. Privacy questions go to vaughn@invertsystems.com.au.
2. The short version: we don't collect data about children
This is the most important thing in this policy, so it goes first. Rotation Scheduler holds no information about athletes, gymnasts, students or any other child.
The service schedules groups, not people. A class in the system is a label, a time and a duration: “Bronze Competitive, Tuesday, 4:00–5:30”. There is nowhere to put a participant list, a date of birth, a parent or guardian, a phone number, a medical note or an attendance record, because the service doesn’t need any of it to build a rotation.
If you import your timetable from iClassPro, we read only the class schedule, level, class name and program columns. Everything else in that export, including enrolment numbers, is discarded and never reaches our database.
Class names are free text, so nothing physically stops a coach typing a child’s name into one. Please don’t. Name your classes as groups.
3. What we do collect
Your account
- Email address: how you sign in, and how we contact you.
- Password: stored only as a scrypt hash. We can’t read your password, and neither can anyone who obtained the database.
- Signup code cohort: for example whether you joined with a Congress code, which is what determines your rate.
- When you signed up, and when you were last active.
Your gym’s data
- Gym name, apparatus, class names and times, programs, lesson plans, and committed schedule history.
This is club operational data, not personal information, but it’s yours, so it’s covered here too.
How you use the service
- We record two events against your account: signing in, and committing a schedule(with the day and week it was for). That’s the entire usage log.
- We use it to see whether the product is actually being used and where it’s getting stuck. There is no Google Analytics, no tag manager, no advertising pixel and no third-party tracker of any kind.
Billing
- A Stripe customer ID, your subscription status, renewal date, and which price you’re on.
- We never see your card.Card details are entered on Stripe’s own hosted checkout page and never touch our servers.
IP addresses
- We record IP addresses for one purpose only: rate limiting, so sign-in and password reset can’t be brute-forced or spammed. They are stored as part of a counter, are not linked to your usage history, and are cleared about a day after the limit window expires.
- We do not log your browser user-agent.
The interest list
- If you fill in the “register your interest” form on the landing page, we keep the email address and club name you gave us so we can get back to you.
4. Why we collect it
- To give you an account, and keep it secure.
- To run the service: generate, store, print and display your schedules.
- To take payment and manage your subscription.
- To email you about things that matter: password resets, trial reminders, billing problems, and material changes to the service or these policies.
- To understand whether the product is working, and to improve it.
- To protect the service from abuse.
We do not sell your personal information, and we don’t use it for advertising or share it with data brokers.
5. Who we share it with
We use a small number of service providers to run the product. Each one gets only what it needs to do its job:
- Stripe: payments. Receives your email address and your gym’s name, and handles your card directly.
- Resend: transactional email. Receives your email address and the contents of the message (a password reset link, or a trial reminder naming your gym). No schedule data.
- Neon: the database. Stores everything in section 3.
- Vercel: hosting. Serves the application, and therefore sees the network traffic, including IP addresses.
- Sentry: error monitoring. When something breaks, it receives the technical details of the error (the error message, the page it happened on, and the browser type) so we can find and fix the bug. It is not sent your personal information, your schedule data, or anything about athletes.
These providers operate globally, so your information may be stored or processed outside Australia, including in the United States. We only use providers we consider reputable and that offer appropriate protections, but by using the service you agree to this overseas handling.
We’ll also disclose information where the law requires it, or where it’s reasonably necessary to protect our rights, your safety or someone else’s. If we ever sell the business, your data may transfer with it, and you’d be told first.
6. Cookies
We use strictly necessary cookies only: the ones that keep you signed in and protect the sign-in form. That’s it.
There are no analytics cookies, no advertising cookies and no third-party trackers, which is why you have never seen a cookie banner here and won’t. Web fonts are served from our own domain, so your browser doesn’t call out to a font provider either.
The app also stores a couple of things in your browser’s local storage: a cached copy of the schedule you’re working on, and a note of which one-time tips you’ve dismissed. These stay on your device and are never sent to us.
7. The public live view
Your gym can publish a read-only live view at a secret link (/live/<token>) to put the day’s rotation on a screen. Anyone with that link can see it without signing in.
It shows your gym name, apparatus, class labels and times, and the day’s rotation, which is exactly what’s already on the printed wall sheet. It shows no person’s name and no contact details.
Treat the link as a secret. If it gets out, regenerate the token in Setup and every previously shared link stops working immediately. Live view responses are briefly cached (about 5 minutes) on Vercel’s edge network so an always-on screen doesn’t hammer the database.
8. How we protect it
- Everything is served over HTTPS.
- Passwords are stored as scrypt hashes, never in plain text.
- Card data never reaches us. Stripe’s hosted checkout handles it.
- Sign-in and password reset are rate limited.
- Access to the admin view is restricted to a fixed allowlist of addresses.
No system is perfectly secure, and we can’t promise otherwise. If a data breach occurs that is likely to cause you serious harm, we’ll tell you and the OAIC as required by the Notifiable Data Breaches scheme.
9. How long we keep it
- While you’re a customer: for as long as your account is open.
- After you cancel or close your account: we keep your data for 90 days, so a club that lapses over a term break can pick up where it left off, and then we delete it. Ask us and we’ll delete it sooner.
- Rate-limiting IP records: about a day.
- Interest-list entries: until you ask us to remove them.
- Billing records: Stripe keeps transaction records for as long as tax and financial record-keeping law requires, independently of us.
10. Your rights
You can ask us to:
- Tell you what we hold about you, and give you a copy.
- Correctanything that’s wrong.
- Deleteyour account and your club’s data.
- Stop emailing you anything other than essential service messages.
Email vaughn@invertsystems.com.auand we’ll action it within 30 days. There’s no charge. We may need to confirm it’s really you first.
We’re a small operation and these requests are currently handled by hand rather than by a button in the app. That doesn’t change what you’re entitled to or how quickly we’ll do it.
11. Complaints
If you think we’ve mishandled your personal information, tell us first at vaughn@invertsystems.com.au. We’d rather hear it and fix it. We’ll respond within 30 days.
If you’re not satisfied with how we handle it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
12. Changes to this policy
We may update this policy. If a change materially affects how we handle your information, we’ll tell you by email or in the app before it takes effect. The date at the top always shows the current version.