Privacy Policy

Version 2026-05-16 · Last updated: 16 May 2026

This Privacy Policy explains how VQS Capital Pty Ltd (ABN 69 682 623 990), trading as SecureRoster ("we", "us"), collects, uses, holds and discloses personal information through the SecureRoster mobile app and admin web app (together, the "Service"). It reflects our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Information we collect (APP 3 + APP 5)

What we collect depends on your role (security guard, manager, admin, super admin) and which features your employer has enabled.

Account & identity

Employment & HR (guards only)

Banking & tax (guards only, opt-in)

These categories are stored in a separate profile_payroll table with stricter access controls — only the guard themselves and the org owner/admin can read them. Managers cannot.

Licensing & compliance

Operational activity

Communications

Third-party information you enter

When you use the Service to record information about people who are not SecureRoster users, that information is also stored. Categories include:

Your employer is the data controller for this third-party information. Their incident-management and watchlist practices must comply with the Privacy Act and any state laws on photographing / recording the public.

Technical & device

Sensitive information

Incident reports may include sensitive information under APP 3 (for example: details of a medical incident, intoxication state of a patron, or a recorded BAC reading). Banking and tax data is also sensitive personal information. We treat both categories with the heightened protections APP 3.3 and APP 11 require.

2. Why we collect each item

3. Who can see your information

4. In-app AI help chat

The admin web app includes a help chat powered by Google Gemini. When you send a message:

5. Where your information is stored (APP 8)

Primary storage is in Australia in the Supabase Sydney region (ap-southeast-2). All data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Push notifications are delivered via Apple Push Notification Service and Firebase Cloud Messaging. The push token and the notification payload (a short message and a deep link) pass through those services' global infrastructure. No incident body content, banking details, or sensitive information is included in notifications.

The AI help chat sends your typed messages to Google's Gemini API, which routes globally.

If your employer connects an accounting integration (Xero), banking, tax, timesheet and venue contact data is transmitted to that integration to create payroll records and invoices. Xero stores that data per Xero's own privacy policy.

A full list of third-party services we use is at /subprocessors.html.

6. How long we keep your information

These retention windows are enforced by an automated daily purge that writes proof of each run to our audit log.

7. Security (APP 11)

We protect your information with:

8. Your rights (APP 12 + APP 13)

9. Children

The Service is intended for adults employed in the security industry. We do not knowingly collect information from anyone under 18.

10. Changes to this policy

We may update this policy. Material changes will be communicated through the Service and by email to admin contacts. The "Version" string at the top of this page increments on each material change. You will be asked to re-accept the policy at the next sign-in following a material change.

11. Contact

Privacy questions and requests: privacy@secureroster.com.au

Security-vulnerability disclosure: security@secureroster.com.au (see also /.well-known/security.txt).

General support: support@secureroster.com.au