1. Who we are
Weekwright is operated by Rodez Digital LLC, a limited liability company organized under the laws of Wyoming, with its registered office at 30 N Gould St, Ste R, Sheridan, WY 82801, USA. For anything in this policy, write to privacy@weekwright.com.
We sell Weekwright to businesses established in the United States and Canada, and we do not offer it elsewhere — see Terms §1. US federal and state privacy law is therefore what governs this notice, principally the CCPA/CPRA and the comparable state laws that follow it. For customers established in Canada, the federal PIPEDA applies as well, and CASL governs the commercial email we send them; where the two regimes differ, we apply whichever gives you the stronger protection.
We publish part of this site in Spanish. That is for Spanish-speaking businesses in the United States, which is a large share of the hospitality and retail workforce we build for — not an offering to Spain. Where the GDPR nonetheless applies to you, because you employ someone in the EU or the UK and their data ends up here, sections 4, 7 and 10 set out how we handle it, and the Data Processing Agreement carries the transfer terms.
2. The two roles, and why you should care
Scheduling software has an unusual property: most of the people whose data it holds never opened it. Your employees did not sign up, did not read this page, and may not know the product exists. That shapes who is responsible for what.
- Your account data — we are the controller. Your email, your name, your billing details, how you use the product. We decide the purposes, and this policy is the notice for it.
- Your employees' data — you are the controller and we are the processor. The names, availability, shifts, notes, and time-off reasons you enter about your team. You decided to collect it; we only act on your documented instructions. Our obligations to you are in the Data Processing Agreement, which forms part of the Terms and applies automatically — you do not need to request it.
The practical consequence: if one of your employees asks to see or delete their data, that request goes to you, not to us — you are their controller. We will help you answer it, and the dashboard gives you the export and deletion tools to do so. What we will not do is act on it behind your back, because we have no lawful basis to unilaterally alter your records.
It also means you need your own lawful basis for putting your team into Weekwright, and you must tell them you have done it. That is your obligation as controller, not a formality we can discharge for you. See Terms §7.
3. What we collect
The data you submit while using Weekwright, and the metadata our infrastructure produces while operating it:
- Account data — email address, display name, and the password hash held by Supabase Auth. We never see your password.
- Organization data — organizations you create or join, your role within them, and your access timestamps.
- Scheduling data — employees, positions, locations, schedules, shifts, time-off requests, swaps, compliance rules, and any notes you write. This is the category that is mostly about other people.
- Operational data — audit log entries (who did what, when), notification records, AI conversation history if you use the chat, and aggregated usage metrics.
- Billing data — the Stripe customer id, plan, status, location count, and renewal date. Card numbers go directly from your browser to Stripe and never touch our servers.
- Technical data — IP address, browser and device type, and request logs, retained for security and abuse prevention.
- Mobile app data — if you install the app and allow notifications, a push token identifying that device, held until you sign out or uninstall. The notification text we send through it can name a team member and their hours, because that is what the notification says.
We do not ask for special-category data under Article 9 — health, religion, union membership, and the like. A free-text note or a time-off reason is a field where such data could be typed, so treat those fields as unstructured and avoid recording sensitive detail you do not need. If you must, that processing is yours to justify.
4. Why we are allowed to process it
Where GDPR or UK GDPR applies, we rely on these legal bases for the data we control:
- Performance of a contract (Art. 6(1)(b)) — creating and running your account, delivering the service, billing you, and sending transactional email about it. Without this we cannot provide the product.
- Legitimate interests (Art. 6(1)(f)) — securing the service, preventing abuse, product analytics, and error monitoring. We have weighed these against your rights; you can object at any time (§10) and we will stop unless we have compelling grounds.
- Legal obligation (Art. 6(1)(c)) — retaining financial records, and responding to lawful requests from authorities.
- Consent (Art. 6(1)(a)) — marketing email, which you may withdraw at any time without affecting the service. We do not bundle it into signup.
5. How we use it
To operate the service, secure your account, bill you, deliver the AI features you invoke, support you when you ask, and understand which parts of the product work, and know which of our ads are worth paying for. We do not sell your data, and we do not build advertising profiles. The only thing an ad platform ever receives from us is that a click on one of our ads ended in a signup — never a name, an email address, or anything from inside an account. We do not use your scheduling data to train AI models, ours or anyone else's.
6. Subprocessors
We use a small set of vendors to run Weekwright. Each is bound by a written agreement no weaker than this policy, and each receives only what its function requires. The current list is maintained on the subprocessors page, which is the authoritative version and where changes are announced.
| Subprocessor | Purpose | Data shared | Processing location |
|---|---|---|---|
| Supabase | Primary infrastructure: the Postgres database, authentication, realtime, and file storage. | All customer data at rest, including employee records, schedules, notes, and account credentials. | United States (AWS us-east-2) |
| Vercel | Application hosting and content delivery for the web app. | Data in transit as requests are served, plus request logs. No customer data is stored at rest. | United States |
| Stripe | Subscription billing and payment processing. | Billing contact email, company name, plan, and location count. Card details go directly to Stripe and never reach our servers. | United States |
| Anthropic | The Claude API, which powers the AI scheduling features. | Only when an AI feature is invoked: the org context that request needs — employee names, availability, shifts, notes — and the prompt. Anthropic does not train its models on this data. | United States |
| Resend | Transactional email: invitations, notifications, and password resets. | Recipient name and email address, and the content of that message — which may name a shift or a schedule. | United States |
| PostHog | Product analytics: which features are used and where people get stuck. On the public marketing pages only, session replay as well. | User id, email, organization id, and which actions were taken, plus the pages visited with identifiers and access tokens stripped out of the address. On the public pages, a recording of the session — clicks, scrolling and mouse movement, with the contents of every form field masked. Recording stops the moment you enter the app, so it never sees any schedule, employee record, or note. Never the content of schedules, notes, or anything typed to the AI. | United States |
| Sentry | Error monitoring and performance diagnostics, including a replay of the seconds before an error inside the app. | Technical diagnostics when something breaks: stack traces, browser, and the URL with tokens and access codes stripped out. When an error happens inside the app, also a replay of the seconds leading up to it — the layout of the screen and which controls were used, with every piece of text and every form field masked out, so names, hours and notes are never transmitted. Nothing is recorded on a visit that produces no error. | United States |
| Expo | Push notification delivery for the mobile app, forwarding to Apple and Google. | A device push token, and the notification text itself — which can include a team member's name and their scheduled or worked hours. No email, no pay rate, and nothing beyond the one line shown on the lock screen. | United States |
| Microsoft Clarity | Heatmaps and session replay for the public marketing pages, to see which parts of a page get read and where people give up. | Page interactions on the public site only — clicks, scrolling, and mouse movement, with the browser and approximate location. It is not loaded once you sign in, so it never sees any schedule, employee record, or note. | United States |
| Google Ads | Advertising measurement: whether a paid ad click ended in a signup, so we know which ads are worth running. | Two events on the public site and at checkout, each carrying the id of the ad click and an opaque reference we generate. No name, no email, no account content — and personalised advertising is switched off, so it cannot be used to build a profile or follow you elsewhere. | United States |
| Microsoft Advertising | Advertising measurement for the Bing campaign: whether a paid ad click ended in a signup, so we know which ads are worth running. | Two events on the public site and at checkout, each carrying the id of the ad click and, for a purchase, the amount. No name, no email, no account content. | United States |
7. Where your data goes
All of it is processed in the United States. Our database is provisioned in AWS us-east-2 (Ohio); our hosting, analytics, and error-monitoring vendors are US-hosted. Backups are encrypted and rotated.
That is where our customers are, so for most of them nothing leaves the country. It becomes an international transfer only in one case: you are a US business with staff in the EU, the UK, or Switzerland, and their records are in here. For that case our mechanism is the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Two and Module Three as applicable), incorporated into the Data Processing Agreement along with the UK International Data Transfer Addendum, plus supplementary technical measures — encryption in transit and at rest, and access limited to the personnel who need it.
The honest version: SCCs are a legal instrument, not a force field. US law can reach US-hosted data in ways EU law does not contemplate, which is exactly what the Schrems II ruling was about. We have no EU region today. If data residency in the EU is a hard requirement for you, raise it before you import your roster rather than after — it is a question we would rather answer honestly up front.
8. How long we keep it
- Account and scheduling data — for as long as your organization is active.
- After deletion — 30 days, so a mistaken deletion is recoverable, then permanent erasure from live systems. Encrypted backups age out within a further 30 days.
- Audit log — the period your plan specifies: 90 days on Starter, Core, and Pro; seven years on Business.
- Financial records — as long as tax and accounting law requires, typically seven years. This survives account deletion, and we cannot shorten it.
- Technical and security logs — up to 90 days.
9. AI features and automated decisions
The AI drafts schedules, fills gaps, and answers questions about your week. When you invoke it, the context that request needs — employee names, availability, shifts, notes — is sent to Anthropic's Claude API to fulfil that request and is not used to train their models.
Article 22 GDPR gives people the right not to be subject to decisions based solely on automated processing that significantly affect them. Who works which shift is exactly that kind of decision. Our answer is structural rather than contractual: the AI cannot publish a schedule. It produces a proposal, a human reviews it, and a human applies it. There is always a person in the loop, so no shift assignment is made solely by automated means. Keeping it that way is a design constraint, not a preference.
Every assignment the AI proposes can be traced: the app explains why a person was suggested for a shift, and the audit log records who accepted it.
10. Your rights
Under the CCPA/CPRA and the comparable state laws, you may know what we hold, delete it, correct it, and opt out of sale or sharing — we do neither, so there is nothing to opt out of. We do not discriminate against anyone who exercises a right, and we do not charge for it.
Where the GDPR or UK GDPR applies (§1), the same requests are available as access, rectification, erasure, restriction, and portability, along with the right to object to processing based on legitimate interests.
Much of this needs no request: you can export or delete your organization's data from the dashboard at any time, and deleting your account is self-service. For anything else, write to privacy@weekwright.com and we will respond within 30 days. We do not charge for this.
If you are an employee of a Weekwright customer, send your request to your employer — they control your record (§2). Tell us anyway if they do not respond and we will pass it on.
You also have the right to complain to a supervisory authority. In the EU that is the authority where you live or work (in Spain, the AEPD); in the UK, the ICO. We would prefer you came to us first, but it is your right and we will not obstruct it.
11. Security
HTTPS everywhere, encryption at rest, scoped server-side credentials that never reach the browser, a permission check on every operation, and deny-by-default row-level security in the database underneath them — so a mistake in the application layer is contained by the data layer rather than exposed by it. Details are on the security page.
No system is unbreakable and we will not claim otherwise. If a breach affects your data we will notify you without undue delay and within 72 hours of becoming aware where the law requires it. Report a vulnerability to security@weekwright.com; we will not pursue researchers who act in good faith.
12. Cookies
Our cookies fall into three groups. Two are strictly necessary and do not require consent, because the service cannot function without them: one keeps you signed in, one remembers whether you chose English or Spanish. Three are product analytics. Two measure our advertising. The cookie policy lists every one of them by name, with what each does and when it expires, and is the authoritative list.
Analytics and advertising measurement both run on consent, and nothing is loaded or stored until you give it: refuse the banner, or ignore it, and neither script runs at all. They never receive the content of your schedules, your notes, or anything you type to the AI. The advertising pair is first-party and answers one question — whether a click on one of our ads ended in a signup; personalised advertising is switched off, so nothing follows you to another site and no profile is built. Refusing takes the same single click as accepting, and you can withdraw at any time from the cookie policy, which also clears the cookies already set. We honour Global Privacy Control and Do Not Track: when your browser sends either, we treat it as a refusal, never ask, and nothing is initialised at all.
13. Children
Weekwright is a business tool and is not directed to children. We do not knowingly collect data from anyone under 16 through signup. Note that in many jurisdictions minors may lawfully be scheduled to work — if you schedule under-18 staff, you are the controller of their data and their protections, including working-time limits, are yours to enforce.
14. Changes
We may update this policy. Material changes are announced by email to organization owners or in-app at least 30 days before they take effect, and the date at the top always reflects the current version. Continued use after the effective date constitutes acceptance.
15. Contact
Questions about this policy, or about a request you have made: privacy@weekwright.com, or the contact page.