Privacy Notice
1. Who We Are
TeamGT Aviation Ltd ("we", "us") operates RosterShare and is the data controller for it. We are responsible for deciding how and why your personal data is processed through this Service.
Registered in England and Wales, Company No. 14421662. Registered office: SIU Offices, 4-6 Greatorex Street, London, E1 5NF, United Kingdom.
This is an independent crew tool and is not operated by, or an official system of, any airline. Data protection queries: see Section 13.
2. What Personal Data We Collect
Identity & contact data you give us: first name, surname, rank (Captain/First Officer/Senior Cabin Crew Member/Cabin Crew), employee number, home base, and email address, collected when you complete your profile or when an administrator sets up your account directly on your behalf.
Your roster calendar link: the crew scheduling app's ".ics" calendar subscription URL you provide. We use this link to fetch your schedule (see Section 4).
Roster & duty data derived from that calendar feed: flight numbers, routes, scheduled times, aircraft registration, block hours, and a day-by-day classification of your duty (working, standby/reserve, or off). See Section 3 for how sickness and fatigue entries specifically are handled.
Account security data: your password (stored by our authentication provider, Google Firebase, in hashed/encrypted form. We never see or store your actual password), and a sign-in log recording the time, success or failure, sign-in method, IP address, and browser/device information (User-Agent string) for each sign-in attempt, and for each time you open the Service while you are still signed in from an earlier visit (recorded at most once every 30 minutes). This log is visible only to administrators and is kept for 90 days.
Content you create: custom "friend list" groups you set up to view rosters across bases, and any invitations you send (which record the recipient's name).
Swap flags and swap messages (optional): if you flag one of your own flights as one you'd like to swap, or a day off you'd be happy to work, we store that flag (the flight or date, your name, rank, employee number and home base, and any note you add). If a colleague messages you about it, we store those messages (the text, who sent it, and when) in a conversation between the two of you.
Roster history: each time your calendar is synced, we remember what is on each upcoming day of your roster - which flights (number and route) and which other duties (such as standby, reserve, days off, leave or training) - the first time we see that day, and again whenever it changes. We do not store times for this, so a delay is not recorded as a change. Sickness and fatigue are never stored. This lets you see how your roster has changed and look at earlier versions of it. It is kept in a private record that only you can read.
Your permanent logbook record: so that your logbook can last for years, once a flight you worked is a couple of days old we keep a private copy of it just for you: the date, flight number, route, times, aircraft, and the names and ranks of the crew who were on it (as shown in the roster at the time). Colleagues' employee numbers are not kept in it. Only you can see it; it is not shown to other crew or to administrators.
Invitations: if you join by following an invite link another member shared, we store that member's user ID on your profile. It is visible to you and to administrators (who see it when deciding whether to approve you), and may be used later to thank members who bring colleagues in. Sending an invite stores nothing about the person you send it to - the link is just a web address.
Commission entries (optional, cabin crew only): if you log the commission you earned on a flight, we store the amount together with the flight, route, date, and your name and employee number. We also keep a running total and count per route, used to show an average to other cabin crew.
Flight times from the ACARS page (optional, pilots only, in the app or on the website): if you photograph the aircraft's ACARS flight log page to add your actual flight times, the photo is read on your own phone or computer (in the app by the phone's own text recognition, on the website by a reader that runs in your browser and is served from our own site) and is not uploaded or saved. We store the four times (out, off, on and in), the flight and date. Because the aircraft itself is the best source of these times, when the photo matches the flight (the same airports and day) the times are also added to the private logbook of every crew member on that flight, and a later photo of the same flight replaces them for everyone. Besides your own copy, we keep a shared record of the times for that flight, which nobody can read directly, and a record of who submitted them that only administrators can read, so a mistake can be traced and put right. Times you type in by hand, without a photo, are saved to your own logbook only. A time you adjust by hand on a Logbook row is kept only on your device.
Landings, instrument time and simulator time (optional, pilots only, in the app or on the website): if you type these into your logbook yourself, we store the numbers (landings, instrument time, or a simulator session's date, duration and short note), the flight they belong to, and your user ID, in your own private logbook. The same applies to the other optional details a pilot can add to a flight - whether you were pilot flying, night landings, holds, up to three approaches (type, runway and airport) - and to the short note any crew member can add to a flight (up to 80 characters). None of this comes from the roster feed.
Importing your own logbook (optional, in the app or on the website): if you import a logbook file from another app or a spreadsheet, the file is read on your phone and only the flight entries in it (date, airports, times, flight time, aircraft type and registration, your capacity, commander's name, landings, instrument and simulator time, and a short remark) are stored, in your own private logbook, with your user ID. The file itself is not uploaded or kept. You can delete an import at any time from the import screen.
Crew conversations (optional): if you tap the message button on a flight, the Service starts one group conversation between you and the other crew on that flight (or in your shared list) whom you are allowed to contact. We store who is in the conversation (their user IDs and names, fixed when it starts), each message (the text, who sent it, and when), who has read it, and when the last message was sent. Everyone in the conversation sees every message. Nobody's email address is ever shown to anyone else, only names. You can leave a conversation at any time, and you can block a colleague: we then store your list of blocked people (private to you), they can no longer add you to a new conversation, and their messages in conversations you share are hidden from you. They are not told you blocked them.
Message notification emails: if you have a message you have not opened for about ten minutes, we send you one short email (at most one an hour) saying who messaged which crew, for example "Alex messaged the LS3245 crew". The email never contains the message itself, and replying to it does nothing.
Reporting a conversation: administrators cannot read crew conversations. The only way an administrator sees one is if a person in it chooses to report it. We then copy the last 30 messages, the names of the people in it, the flight and the note the reporter wrote to a report that only administrators can read. The app tells the reporter this before they confirm. A report is deleted 90 days after it was made, or sooner if its reporter deletes their account.
Technical data: your browser temporarily stores a cached copy of your roster (for up to 15 minutes, to avoid repeated loading) in your browser's session storage. This is cleared automatically when you sign out or close the tab, and never leaves your device. Both the website and the mobile app also keep a longer-lived copy of the last roster and profile you loaded on your own device, so they can still be viewed without a signal (see Section 11).
If you delete your account, the reason you give is kept in two places. A copy with no name, employee number, or any other identifying detail attached is stored so we can see patterns in why people leave. Separately, just before your data is erased, we send an email to the administrators' mailbox (crewrosters@teamgt.aero) saying that you have left, with your name, email address, base, rank and the reason you gave, so an administrator knows about it. That email is an ordinary email record, not part of the app's database, and is permanently removed from the mailbox and the mail server within 30 days.
3. Sickness & Fatigue: Not Stored At All
Your roster feed can include days marked as sick leave or fatigue. Information about your health is "special category data" under UK GDPR, requiring a higher level of protection than ordinary personal data, so we've designed the Service to avoid holding any record of it: when a sickness or fatigue entry appears in your feed, the Service recognises it only long enough to discard it, and stores nothing for that day at all: no entry, no status, no label of any kind, the same as any day the Service simply has no data for.
This means we do not hold a record you could later ask us to produce showing which days you were marked sick or fatigued. That information isn't kept in any form. If you ever need a record of your own sickness/fatigue history, your official airline roster remains the authoritative source for that, not this Service.
4. How We Get Your Data
Most data comes directly from you (profile details, your calendar link). Your roster and duty data comes from your airline's own systems, via the personal calendar link you provide. We fetch it automatically on a schedule (roughly every 30 minutes) and whenever a crew member triggers a manual refresh, and we do not modify or verify it against any other source.
5. Why We Use Your Data, and Our Legal Basis
| Purpose | Legal basis (UK GDPR Art. 6) |
|---|---|
| Creating and administering your account, approving access | Contractual necessity: required to provide the Service you've asked to use |
| Displaying roster/schedule data to you and relevant colleagues | Contractual necessity: the core purpose you signed up for |
| Keeping a private, permanent copy of the flights you have flown, with the crew's names, as your logbook | Contractual necessity: it is the logbook feature you use |
| Recording who invited you (invite links) | Legitimate interests: helping administrators check a new sign-up, and growing the Service among crew |
| Remembering your roster as it was and when it changed (roster history) | Contractual necessity: it is a feature of the Service you use |
| Swap flags and swap messages, crew conversations and the notification emails about them, and commission entries (optional features you choose to use) | Contractual necessity: they only happen when you use these features of the Service |
| Sign-in and access logging (security, detecting misuse) | Legitimate interests: account and data security |
| Bot/abuse protection for the Service generally, and specifically for SMS codes during optional two-factor authentication (reCAPTCHA) | Legitimate interests: keeping the Service and your account secure |
Where we rely on legitimate interests (sign-in logging and bot/abuse protection above), we've considered that this is balanced against your rights: both exist purely to keep the Service and your account secure, access to the sign-in log itself is restricted to administrators, and neither is used for any other purpose. Separately, the more sensitive categories of data (your full profile including email and calendar link) are visibility-restricted rather than shared with every user, and sickness/fatigue data specifically is designed not to be stored at all (Section 3).
6. What Other Crew Members Can See About You
- Visible to any approved crew member: your name, rank, employee number, home base, and your flight assignments (route, flight number, time, aircraft registration). Access to flight data is controlled at the account-approval level, not scoped to your own base or to people you're connected with: any approved crew member's account can technically access any base's flight data, the same access boundary that lets the app show you your own base's full roster and lets a custom cross-base list work at all. In practice, the app's own screens only ever surface another base's flights to you if you view it directly (e.g. as an administrator) or you're in a shared list with someone based there, but this is a design choice about what the interface displays by default, not a technical restriction on what your account can access. Separately: if you choose to flag one of your own flights as one you'd like to swap, or one of your own days off as one you'd be happy to work, that flag and any note you add is shown to your own base. Nothing is shown for a flight or day you haven't actively flagged. The name and membership of any shared "friend list" group you're part of is visible to its other members. Your name, rank, and home base can also be found by any approved crew member using the name-search tool used to invite people to a shared list, regardless of whether you're already connected to them or share a base.
- Your day-by-day work/standby/off classification: used to show your own "current month / next month" block hours and flight counts, visible only to you by default. If you're a member of a custom list whose creator has enabled showing days off, standby days, or work days for that list, your status for those categories becomes visible to the other members of that specific list, the same account-level access boundary described above applies here too, so this is a statement of what the app's screens show by default, not an absolute technical restriction.
- Visible only to you and administrators: your email address and your calendar (.ics) link. Your email address is never shown to the people you message, and theirs is never shown to you (Section 2).
- Swap messages: visible only to the two people in the conversation, not to administrators.
- Crew conversations: visible only to the people in the conversation (everyone who was in it when it started sees every message), not to administrators. The one exception is a conversation a participant reports (Section 2): then an administrator can read the copy in the report. Your list of blocked people is visible only to you.
- Roster history: visible only to you - not to other crew and not to administrators.
- Your permanent logbook record: visible only to you - not to other crew and not to administrators.
- Commission entries: each individual entry is visible only to you and administrators. Cabin crew and administrators see an average per route (with the number of entries behind it) on the roster, where only a few entries exist, an average can be close to, or the same as, one person's figure.
- Typed-in logbook entries and imported logbook: visible only to you - not to other crew and not to administrators.
- ACARS flight times: each person's copy is in their own private logbook, visible only to them. Times added from a photo are copied into the logbook of every crew member on that flight (they show up as flight times, not as something you submitted). Administrators can see who submitted the times for a flight.
- Visible only to administrators: the sign-in log (Section 2).
7. Third Parties We Use
We use the following service providers to run the Service. They process data on our instructions and are contractually/by their own terms restricted from using it for their own purposes:
- Google Firebase (Authentication, Cloud Firestore database, and Cloud Functions), which hosts your account credentials and all data described in Section 2. Our background processing (roster sync, sign-in logging) runs in Google's London (europe-west2) data center; the database itself is stored in Google's "eur3" multi-region location, which replicates data across data centers in Belgium, the Netherlands, and Finland for availability and durability.
- Google reCAPTCHA: runs invisibly in the background on every page load (including before you sign in) to verify requests to the Service are coming from a genuine user, not a bot or script, protecting the Service from automated abuse. A separate, equally invisible instance is also used specifically during optional two-factor authentication (Options) to prevent automated abuse of SMS verification codes. Neither ever shows you a visible challenge (no "click the traffic lights" puzzle) under normal use.
- Our email service: the mailbox crewrosters@teamgt.aero, hosted by BB Online UK Limited, a UK provider. It is used to send the message notification emails (Section 2, with no message text), password reset and email confirmation emails, and to notify us of new registrations (which include the applicant's name, email address, base, rank and calendar link).
- Our web hosting and delivery provider, which serves the website itself: Cloudflare, Inc. (cloudflare.com), through its worldwide network. Like any web host it sees the technical details of each page request (your IP address, your browser type and which file was asked for). Cloudflare also forwards email sent to contact@rostershare.app on to our mailbox, so the content of those emails passes through it. Your roster and the rest of your account data do not pass through Cloudflare: the app talks to Google Firebase directly. The old address teamgt.aero/v2, which now only redirects to the new one, is still hosted by BB Online UK Limited (Company No. 3458098, PO Box 2162, Luton, Bedfordshire, LU3 2YT, United Kingdom).
We do not sell your data, and we do not share it with anyone for marketing purposes.
8. International Transfers
Your data is processed in two locations, both recognised as adequate under UK GDPR. Our Cloud Functions processing (roster sync, sign-in logging) runs in Google's London data centre (europe-west2), inside the UK itself, not a transfer at all. The Firestore database is stored in Google's "eur3" multi-region location (Belgium, the Netherlands, and Finland), within the European Economic Area, which the UK government has formally recognised as providing an adequate level of data protection under UK GDPR and the Data Protection Act 2018. Under Google's own Cloud Data Processing Addendum, a transfer to a recognised adequate country doesn't require Standard Contractual Clauses or any other additional transfer safeguard. The adequacy recognition itself is sufficient. We don't use any Google configuration that would move your data outside these two locations.
The one exception is the technical details of a page request (your IP address, browser type and the file asked for), which Cloudflare handles on servers around the world to deliver the website, including in the United States. For transfers to the United States Cloudflare relies on its certification under the UK Extension to the EU-U.S. Data Privacy Framework and, if that were ever invalidated, on standard contractual clauses with the UK addendum. No roster or account data is sent through Cloudflare.
9. How Long We Keep Your Data
- Sign-in log: 90 days, then automatically deleted.
- Profile data: for as long as your account exists, plus a short period after removal to handle any queries, unless you ask us to delete it sooner (Section 12).
- Roster/duty history: flight and duty records are kept for 12 months after the date they occurred, then automatically deleted. You can ask for this to be deleted sooner on request.
- Your permanent logbook record: kept for as long as your account exists, so your logbook lasts for years (the shared roster data it is copied from is still deleted after 12 months). It is erased when you delete your account.
- Who invited you: kept on your profile for as long as your account exists.
- Roster history: 12 months after the end of the month it covers, then automatically deleted, or sooner if you delete your account.
- Swap flags: until you remove the flag, or 7 days after the flagged date, whichever is sooner.
- Swap messages: 90 days after the last message in the conversation, then automatically deleted.
- Crew conversations: 90 days after the last message in the conversation, then automatically deleted (the messages and the conversation). Your list of blocked people is kept until you remove someone from it or delete your account.
- Reports of a conversation: 90 days after the report was made, then automatically deleted, or sooner if the person who made it deletes their account. The copied messages in a report belong to the people who wrote them, so they stay until then even if one of them later deletes their account.
- Commission entries: until you delete them yourself or delete your account. Deleting an entry also removes it from the route average.
- ACARS flight times, typed-in logbook entries and imported logbook: until you delete them or delete your account. The shared record of a flight's ACARS times is deleted 12 months after the flight, and the record of who submitted it is cleared if that person deletes their account.
- Notification emails: we don't keep a copy of the text; the recipients' own mailboxes hold them.
- Copies on your device: the 15-minute session cache is cleared on sign-out; the longer-lived offline copy is cleared on sign-out and when you delete your account.
- If you delete your account (Options): we erase your profile, roster and duty records, roster history, swap flags, commission entries, list memberships and invitations, your permanent logbook record, and every swap conversation you took part in, including the other person's copy of it, since the conversation can't be split. For a crew conversation (which has other people in it) we remove you from it, delete the messages you wrote and your name from it, and delete the whole conversation if nobody else is left in it. Your blocked list, and reports you made, are deleted too.
10. How We Protect Your Data
Access to your data is controlled by security rules enforced on every request (not just hidden in the interface), for example, your email and calendar link are only ever readable by you and administrators, never by other crew. All connections use HTTPS. Passwords are never stored by us directly. They're handled entirely by Google Firebase's authentication system in hashed form.
11. Cookies & Similar Technology
We don't use advertising or tracking cookies. The Service uses your browser's temporary session storage to cache your own roster view for performance (Section 2). Since October 2026, it also uses your browser's IndexedDB storage to keep a longer-lived local copy of your roster data, so it remains viewable if you lose signal. Unlike session storage, this can persist after you close the browser tab, and is cleared automatically when you sign out. It also remembers a few small preferences on your device - such as whether times are shown in UTC or local time, how airports are written, when your roster last updated, whether you have signed in on this device before (so the website's front page can take you straight to the app), and (in the app) whether the app lock is on. These stay on your device and contain no personal information. If you use the website's photo reader for flight times, your browser also keeps a copy of the reader's own program files (about 7 MB, containing no personal information) so it does not download them each time. The mobile app does the same job using its own storage on your device (not a cookie): it keeps a copy of the last roster and profile you loaded so they can still be shown without a signal, and clears it when you sign out or delete your account. Google reCAPTCHA (Section 7) runs invisibly in the background to protect the Service from automated abuse. It doesn't track you for advertising or profiling purposes, and shows no visible challenge under normal use. All of this falls within UK PECR's "strictly necessary" exemption and doesn't require separate cookie consent, which is the same basis most websites rely on for essential security measures like bot/abuse protection, distinct from tracking cookies that do require consent.
12. Your Rights
Under UK GDPR, you have the right to: access the data we hold about you; have inaccurate data corrected; ask us to delete your data; restrict or object to certain processing; receive your data in a portable format; and withdraw consent at any time where we rely on it (this doesn't affect processing already carried out). To exercise any of these, contact us using the details in Section 13 and we'll respond within one month as required by law.
For deletion specifically, you don't need to wait on us at all. Options in the Service has a "Delete Account" tool that erases your account and data immediately and permanently, yourself, at any time.
13. Contact Us & Complaints
For any question about this notice or your data, or to exercise your rights, contact contact@rostershare.app. If you're unhappy with how we've handled your data, you also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk or by phone on 0303 123 1113.
14. Automated Decision-Making
We don't use your data to make any automated decision about you that has a legal or similarly significant effect. Duty classification (working/standby/off) is a simple, transparent categorisation of your own roster data for display purposes, not a decision made about you.
15. Changes to This Notice
We may update this notice from time to time. Material changes require you to accept the new version before continuing to use the Service (see the Terms of Service Section 10).