Privacy Policy
How Chronomancer collects, uses, stores and shares personal information.
Who we are
Chronomancer is a rostering platform operated as a sole trader based in Auckland, New Zealand ("we", "us").
Contact for privacy matters: go@chronomancer.live.
Our role
Businesses use Chronomancer to roster their own staff and contractors. For that information, the business decides what is collected and why; we hold and process it on their instructions. For our own customer accounts and website visitors, we make those decisions ourselves.
In practice this means that if you are rostered by a business using Chronomancer, that business holds your information and is the first place to ask about it. We will help them respond, and you can contact us directly if you would rather.
What we collect
About rostered people (entered by the business that rosters them, not by us):
- Name, and preferred name if given
- Email address and/or mobile number
- The work they were offered, asked for, were allocated to, and attended, with hours
- A reliability score computed from their own attendance history
- Messages we sent them and their replies
- The recorded basis on which they agreed to be contacted, and when
- Technical details when they open a roster link: IP address, browser and device type, and an approximate location derived from the IP
About account holders (managers and administrators): name, email address, role, and authentication details.
Why we collect it
To operate the rostering service: to publish work, take shift requests, allocate people, send them the messages that service requires, record attendance and hours, and compute reliability. Link-open details are recorded to detect a roster link being used by someone it wasn't issued to.
We do not sell personal information, and we do not use it for advertising.
Messaging and consent
We send SMS and email only where a basis for contacting that person has been recorded by the business that rosters them. Our SMS programme — what it sends, how often, and how to stop — is described on our SMS programme page.
Reply STOP to any SMS to stop all messages to that number, permanently and across every business on the platform. Opt-out is held against the number and cannot be undone by a business editing or re-uploading its records.
Who we share it with
We use these providers to deliver the service. Each receives only what their function requires:
- Supabase — database, authentication and file storage (hosted in Sydney, Australia)
- Vercel — application hosting
- Modica Group — SMS delivery
- Kudosity — SMS delivery
- Resend — email delivery
- Cloudflare — DNS
We do not otherwise share personal information, except where the law requires it.
Where it is stored
Your information is stored in Australia (Sydney). Some of the providers listed above may process it in other countries in the course of delivering their service. Before disclosing personal information outside New Zealand we satisfy ourselves that the recipient is subject to safeguards comparable to those in the Privacy Act 2020, as information privacy principle 12 requires.
How long we keep it
We keep roster history, message history, change logs and opt-in records for as long as the business that rosters you holds an account with us. We do not delete them on a fixed schedule, and we would rather say so than state a period we do not enforce.
Two deliberate exceptions:
- Raw inbound message data — the unprocessed payload our SMS providers send us when someone replies — is erased automatically after 90 days. The message itself stays on the conversation.
- Opt-in and opt-out records are kept permanently and cannot be edited or deleted by anyone, including us. Mobile carriers can require us to produce evidence that someone agreed to be contacted, and a record that could be altered would be worthless for that purpose.
If you want your information removed, contact the business that rosters you, or us at the address above. Note that removing a record does not undo an opt-out: a STOP is held against the number precisely so that it survives a record being deleted and re-added.
Your rights
Under the Privacy Act 2020 you have the right to ask for a copy of the personal information we hold about you, and to ask us to correct it if it is wrong.
If you are rostered by a business using Chronomancer, ask that business first — they hold your information and can see and correct all of it. If they cannot help, or you would rather come to us, email go@chronomancer.live and we will respond as soon as we can, and within 20 working days.
If you are not satisfied with how we or a business have handled your request, you can complain to the Office of the Privacy Commissioner at privacy.org.nz, by emailing enquiries@privacy.org.nz, or by calling 0800 803 909.
Security
Access to a business's data is restricted to that business's own authorised users, enforced at the database level. Administrator accounts require two-factor authentication. Rostered staff have no login: they access their own roster through a signed, expiring link issued only to them.
Changes
We will update this page when our practices change and revise the date below.
Last updated: 29 July 2026