Last updated: 1 September 2026 · Effective: 1 September 2026
This policy explains what personal data the Nearby Staff Rota app (the “App”) collects, why, and how it is protected. The App is a staff-scheduling tool provided by Nearby Group Ltd (“we”, “us”). It is available to organisations and their workers and managers, who use it to manage staff rotas, holidays and shifts. You use it because your employer or organisation has given you an account.
1. Who we are
The data controller is Nearby Group Ltd, 140 Victory Rd, South Shields, NE33 4NQ. For any privacy question, or to exercise your rights, contact us at it@nearbygroup.co.uk.
2. How the App works
The App is a secure “wrapper” around our web service at staff.nearbyne.co.uk. When you open the App it loads that service over an encrypted (HTTPS) connection. Your data is stored on our own server database, not on your device. The App does not read your photos, contacts, location, calendar, microphone or camera.
3. What we collect
Account & sign-in
- Username and, where provided, email address
- Password — stored only as a salted one-way hash (bcrypt); we never store or see your plain password
- Your role (manager or staff), account status and last sign-in time
Staff / HR profile
Where you or your manager complete your profile, we hold: title and name, date of birth, gender, home address, personal email and mobile number, and emergency-contact name, number and relationship. These sensitive fields are encrypted at rest (AES-256-GCM) and are visible only to administrators and to you.
Work & scheduling data
- Shifts and rota assignments, and the companies/teams you are assigned to
- Holiday requests, approvals and remaining balances
- Clock-in / clock-out times and any shift feedback rating or comment you leave
- Offers to cover shifts
- Optionally, your birthday (day and month only) shown on the shared rota — only if you tick the box to opt in; off by default
Notifications
If you enable push notifications, the App registers a device push token with Apple’s Push Notification service (APNs) on iOS, or Google’s Firebase Cloud Messaging (FCM) on Android, and we store that token so we can send you rota, holiday and shift-reminder alerts. You can turn notifications off at any time in your device settings.
Operational records
- A session cookie to keep you signed in
- An administrative activity/audit log of significant management actions
- Standard server logs (e.g. request and error logs) needed to run and secure the service
4. What we do NOT collect
- No location data, contacts, photos, health or financial information
- No advertising identifiers and no advertising
- No third-party analytics, profiling or cross-app/cross-site tracking
5. Why we use your data (legal bases)
| Purpose | Basis (UK GDPR) |
|---|---|
| Running the rota, holidays, clock-ins and your account | Performance of your employment/engagement and our legitimate interest in managing the workforce |
| Holding emergency-contact details | Protecting your and others’ vital interests; legitimate interest in workplace safety |
| Sending you notifications | Your consent (device permission), which you can withdraw at any time |
| Showing your birthday on the rota | Your explicit opt-in consent |
| Keeping audit logs and securing the service | Legitimate interest and legal obligation |
6. Who we share it with
We do not sell your data. We share it only with the service providers needed to run the App, acting as our processors:
- Our hosting provider — runs the server and PostgreSQL database that store your data.
- Apple (APNs) / Google (FCM) — deliver push notifications to your device.
We may also disclose data where required by law.
7. Where your data is held & how long
Your data is stored on our server infrastructure and retained while your account is active and for as long as needed for employment, legal and audit purposes. When your account is closed we delete or anonymise your personal data within a reasonable period, unless we must keep certain records to meet a legal obligation. Backups are rotated and expire on their own schedule.
8. How we protect it
- Encrypted (HTTPS/TLS) connections between the App and our server
- Field-level AES-256-GCM encryption of sensitive profile details at rest
- Passwords stored only as bcrypt hashes
- Access controls — HR profile details are limited to administrators and to you
9. Your rights
Subject to applicable law (including the UK GDPR), you may ask us to access, correct, delete or restrict your personal data, or to object to certain processing. Contact it@nearbygroup.co.uk. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
10. Children
The App is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Account deletion
To request deletion of your account and associated personal data, contact your manager or email it@nearbygroup.co.uk.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date above shows the latest version, and material changes will be communicated through the App or by your organisation.
13. Contact
Nearby Group Ltd
140 Victory Rd, South Shields, NE33 4NQ
it@nearbygroup.co.uk