Privacy Policy
Last updated: August 22, 2026
Privacy at a Glance
This summary highlights the points most people want to know. The full policy below contains the complete details.
- What we handle: account and organisation details, workforce records, rosters, time and leave information, messages and documents, billing records, technical data, and a precise point when a user submits a GPS-enabled clock-in.
- Who controls workforce records: the Customer usually decides why workforce information is collected, who can see it, and how it is used. TaskForceOne may supply documented feature defaults, and the Customer controls the available settings. ROVYN processes the information to provide the Customer's enabled and configured service.
- Why we use it: to operate TaskForceOne, secure accounts, provide support, manage billing and integrations, send service messages, and improve reliability. Optional marketing is sent only where the recipient has made that choice.
- Automation: Enabled features and Customer-configured rules can apply a clock-in radius, round completed times, approve some workflow records, assign eligible open-shift claims, and calculate warnings or pay interpretations. Some pay and labour-cost functions may be enabled by default. Customers remain responsible for settings, review, corrections, and final employment and payroll decisions.
- Sharing and locations: we use service providers and Customer-selected integrations. Personal information may be processed outside Australia, including in the United States and, for some integrations or provider routes, New Zealand. Other likely countries are described below and in our provider register.
- Your choices: ask the Customer first about Customer-controlled workforce records. Contact ROVYN for information it controls directly, privacy complaints, or help with access and correction. Optional marketing can be stopped at any time.
We do not sell personal information or use Customer workforce information to train unrelated third-party machine-learning models.
1. About This Policy
Khanh Vy Nguyen (ABN 85 581 687 451), carrying on business under the registered business name ROVYN (ROVYN, we, us), operates the TaskForceOne service. This policy explains how ROVYN handles personal information through the public website, mobile applications, and workforce platform. We handle personal information under this policy and, where applicable, the Privacy Act 1988 (Cth), the Australian Privacy Principles, contractual privacy obligations, and other applicable law.
Privacy enquiries can be sent to [email protected].
2. Our Role and the Customer's Role
ROVYN determines how it handles website enquiries, account administration, subscriptions, security records, and its direct customer relationship.
For workforce information, the Customer usually decides why information is collected, who can access it, which available feature settings to retain or change, and how the information is used for work. TaskForceOne may supply documented feature defaults. ROVYN handles the information to provide the enabled and configured service and follow the Customer's instructions. Employees and contractors should usually direct workforce-record questions to their organisation administrator first.
A Customer's employee-record exemption, if any, does not automatically apply to ROVYN. Our Data Processing Addendum describes the parties' responsibilities in more detail.
3. Information We Collect
Account, organisation, and subscription information
- name, email address, phone number, profile image, password hash, authentication identifiers, and security settings;
- organisation name, business details, address, industry, locations, timezone, and roles or permissions;
- billing contact, plan, invoices, subscription events, tax information, and payment tokens handled by Stripe;
- support messages, survey or partnership responses, and related correspondence; and
- records of legal acceptance, including document version, time, IP address, user agent, acceptance source, and account or organisation snapshot.
Workforce information supplied by Customers and users
- worker identity, contact details, position, workplace, employment type, pay method, rates, contracted hours, status, and access credentials or identifiers;
- rosters, shifts, availability, open-shift claims, swaps, leave requests, approvals, and comments;
- clock-in and clock-out events, breaks, timesheets, original and adjusted times, adjustment reasons, rounding, approvals, and audit history;
- messages, chats, attachments, reactions, read receipts, presence, and notification preferences;
- staff requirement records, licences, certificates, expiry dates, documents, signatures, reviewer notes, reminders, and approval or rejection history;
- payroll-provider identifiers, settings, earnings rates, pay calendars, leave types and balances, export payloads, responses, status, and errors; and
- other files, images, notes, comments, or records a Customer or user submits.
Sensitive and higher-risk information
The service can hold sensitive or higher-risk information where a Customer configures an authorised workflow or a user chooses to submit it. This may include health information in a leave reason or workplace record; professional, security, driver, Responsible Service of Alcohol (RSA), first-aid, or other licence and certificate details; signatures; and precise clock-in location.
Customers must decide whether collecting that information is necessary and configure access appropriately. Users should not place diagnoses, complete identity documents, or other unnecessary sensitive details in general messages or unapproved uploads.
Precise location at GPS clock-in
If a Customer enables GPS clock-in and a user submits a location-enabled clock-in, the record may contain precise latitude and longitude, device-reported accuracy, and distance from the configured workplace.
If a location-radius rule applies, the service may reject the clock-in when the reported point is outside the configured radius or required location is unavailable. The current feature records one point associated with that clock-in; it is not continuous background tracking. Device and mapping conditions can make the record inaccurate.
Technical, device, and usage information
- IP address, browser, device, operating system, app version, locale, timezone, session, and request information;
- push-notification and device tokens;
- security, access, event, performance, error, and crash diagnostics; and
- feature interactions and workflow metadata needed to operate, secure, support, and improve the service.
Email communications and preferences
For service and optional marketing email, we may keep the recipient address and account association; the message type and provider identifier; delivery, bounce, complaint, and suppression status; and records needed to manage email preferences. Where a person opts into product news and offers, we also keep the consent wording and version, time, source, and later withdrawal or unsubscribe history.
4. How We Collect Information
We collect information directly from a person, from the Customer and its administrators, and automatically from devices, browsers, and service use. We also receive information from connected providers such as Stripe, Xero, MYOB, or another supported payroll service.
Website support and industry design-partner submissions are routed to our team through Discord. A Customer may provide workforce information before the worker creates an account.
5. Why We Use Information
We use personal information to:
- create and administer accounts, organisations, permissions, subscriptions, and billing;
- deliver rostering, time, leave, messaging, document, award, costing, and payroll-integration workflows;
- send service, security, invitation, workflow, and support communications;
- send optional TaskForceOne product news and offers where the recipient has recorded that choice;
- manage email preferences, honour unsubscribe requests, prevent unwanted recontact, investigate complaints, and reconcile provider delivery events;
- authenticate users, prevent misuse and fraud, diagnose errors, and protect the service;
- provide support, investigate disputes, reconcile exports, and maintain audit evidence;
- improve usability and reliability using operational and aggregated insights;
- enforce agreements and exercise or defend legal rights; and
- comply with lawful requests and legal obligations.
Optional marketing email can be stopped using the unsubscribe link in the message, account preferences, a valid request sent to support, or mailbox-provider one-click unsubscribe where supported. Factual account, security, billing, invitation, payroll, and workflow messages may still be sent where needed to provide or secure the service and where they contain no promotional content.
We do not sell personal information. We do not use Customer workforce information to train unrelated third-party machine-learning models.
6. Automated Processing and Significant Decisions
TaskForceOne uses rule-based computer programs, enabled features, and Customer settings to perform calculations, warnings, suggestions, and some workflow decisions. Depending on the features enabled for the Customer, including documented defaults, and the settings the Customer chooses, the service may:
- allow or reject a GPS-enabled mobile clock-in under the Customer's configured location rule and radius;
- round completed clock-in and clock-out times using the Customer's configured increment;
- approve a timesheet when recorded times and breaks match its scheduled shift within configured tolerances, or send it for manager review when they do not;
- approve a leave request when the selected leave type does not require approval and applicable time-off limits do not require review;
- approve an availability request when the Customer has disabled approval or the requester has a management role, provided applicable time-off limits do not require review;
- assign an eligible open-shift claim when claim approval is disabled or the claimant can manage that shift, provided position checks do not require review; and
- calculate labour-cost estimates and pay interpretations, detect roster or time conflicts, create warnings, or suggest workflow actions.
Inputs may include a person's organisation role, position, classification, rate, rostered shift, clock and break records, availability, leave type and dates, open-shift eligibility, precise location point, and the Customer's configured rules, radius, and tolerances. The resulting action may affect whether a clock-in is accepted, workflow status, shift assignment, recorded payable time, or information presented for payroll.
TaskForceOne may supply initial feature defaults. The Customer controls the available settings and can review and correct records through available workflows. ROVYN does not independently decide whether to hire, discipline, terminate, classify, roster, or pay a worker. Customers remain responsible for meaningful human review of significant employment and pay decisions and should give affected people a way to raise incorrect data or results.
7. When We Disclose Information
We may disclose information:
- within the Customer account according to configured roles and permissions;
- to providers in our Service Provider and Subprocessor Register for hosting, storage, email, billing, notifications, diagnostics, mapping, support, authentication, and integrations;
- to a provider the Customer chooses to connect or an adviser acting for the Customer;
- to professional advisers, insurers, financiers, or a buyer in a genuine corporate transaction under confidentiality protections;
- where reasonably necessary to address fraud, abuse, security, safety, or a legal claim; and
- where required or authorised by law.
8. Overseas Processing
We do not represent that all information remains exclusively in Australia. Personal information is likely to be processed in the United States and may be processed in New Zealand through some integrations or provider routes. Depending on the provider and support path, processing may also occur in countries including Canada, the United Kingdom, European Union countries, India, Malaysia, the Philippines, Singapore, Japan, and South Africa.
The exact locations depend on the enabled service, the Customer-selected integration, and a provider's current infrastructure and support arrangements. Our Service Provider and Subprocessor Register identifies each provider's role, likely processing locations, and current provider information.
9. Security
Technical safeguards used by the service include transport encryption, role-based access, credential and integration-token protections, security logging, and error monitoring. Security is shared with Customers and users, who must secure accounts, devices, roles, integrations, and downloaded data. No online service can guarantee absolute security.
10. Retention
We retain information for as long as reasonably needed for the Customer's active service, the purposes in this policy, Customer instructions, security, billing and tax records, backup cycles, dispute resolution, and applicable legal obligations. Retention differs by record and account state.
- Active organisation and workforce records generally remain available while the Customer maintains them in the service.
- Deleting an app account removes or replaces its direct identifiers and revokes access, but Customer-controlled workplace records may remain with limited membership identity where needed for their stated purpose.
- Some short-lived import files, deleted attachments, and orphaned requirement files are eligible for operational cleanup after their configured windows.
- Backups may contain deleted or de-identified records until the relevant backup ages out.
- We may retain limited records to meet law, prevent fraud, establish acceptance or marketing consent, continue honouring an unsubscribe or suppression, investigate security or complaints, or resolve a dispute.
Employers may have obligations to retain time and wage records for seven years. The Customer—not ROVYN—decides which employment laws apply and must export and retain its required records. ROVYN does not promise that every workforce record will remain accessible for seven years after subscription termination.
11. Access, Correction, Export, and Deletion
You may ask to access or correct personal information ROVYN controls directly. For workforce records controlled by a Customer, first contact an organisation administrator; we will assist the Customer where reasonably needed.
To make a request to ROVYN, email [email protected] with “Privacy Access or Correction Request” in the subject and identify the relevant account or organisation. Do not send identity documents unless we ask for them through an appropriate channel.
Account deletion revokes access and removes or replaces login and direct contact identifiers. A Customer organisation may retain an accepted membership name and internal staff identifier with restricted workforce records, messages, and audit history. See Account Deletion for current behavior. We may need to verify identity and authority before acting and may refuse or limit a request where law permits, explaining why where required.
12. Privacy Complaints
Email [email protected] with “Privacy Complaint” in the subject. Describe what happened, the relevant Customer organisation, dates, and the outcome you seek. We will acknowledge the complaint, investigate it with the relevant Customer or provider where necessary, and communicate an outcome within a reasonable period.
If you are not satisfied, you may be able to complain to the Office of the Australian Information Commissioner or another regulator with jurisdiction.
13. Data Breaches
We assess suspected breaches and notify affected Customers promptly where their information is materially affected. Where the Notifiable Data Breaches scheme applies and an eligible data breach is established, the responsible entity will make notifications required by law. Our DPA explains Customer cooperation.
14. Young Workers
TaskForceOne is a business workforce service, not a consumer service directed to children. A Customer may invite a young worker where lawful. The Customer is responsible for age-appropriate notices, permissions, parental involvement, supervision, and workplace-law requirements. A parent, guardian, or young worker with a concern should contact the Customer and may also contact us.
15. Cookies and Changes
Our Cookie Policy describes cookies and browser storage. We may update this Privacy Policy to reflect legal, provider, or service changes. We will update the date above and give Customers reasonable notice of material changes where required or practicable.
16. Contact
Privacy questions, requests, and complaints can be sent to [email protected]. You may also use that address to ask for this policy in another accessible form. Please do not email identity documents or sensitive workforce records unless we ask for them through an appropriate channel.