Snapshot 25409
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy Policy
Last updated: September 18, 2026
Round Robin is provided by Irrelevant Labs OÜ ("we", "us", "our"), a company registered in Estonia (Sepapaja tn 6, 15551 Tallinn, Estonia). This policy explains what personal data we collect, why, and what your rights are when you use Round Robin — our Slack app, the dashboard at dash.roundrobinbot.eu, our websites (roundrobinbot.eu and its subdomains), and our API.
Questions about this policy or your data: support@irrelevantlabs.com.
Our Roles: Controller and Processor
For most of the data described below — your account, billing, our websites, and product analytics — we act as a data controller.
For the Slack workspace data that your organization makes available to Round Robin (member names, channels, rotation assignments), we act as a data processor on behalf of your organization, which decides who is placed in rotations and how the app is used. If you have questions about how your employer uses Round Robin, contact your workspace administrators first.
Data We Collect
When your workspace installs Round Robin
Slack workspace details: workspace ID and name, and the OAuth tokens needed to operate the app (stored encrypted — see our Security page).
Slack member details for people involved in rotations: Slack user ID, display name, avatar, time zone, and — where your workspace's plan and settings allow it — email address.
Channels, user groups, and messages the bot posts or is directed to interact with. The bot does not read your channels' conversation history.
When you use the dashboard
Sign-in via Slack (through Auth0): your Slack identity (user ID, name, email, workspace).
The rotations, schedules, notes, and settings you create.
Support conversations when you contact us.
When your workspace subscribes to a paid plan
Billing details (name, email, payment method, invoices) — collected and stored by our payment processor, Stripe. We never see or store full card numbers.
When you connect optional integrations
Google Calendar: calendar events used to detect out-of-office periods (see the Google user data section below).
PagerDuty / Jira Service Management: schedule and on-call data from those services, to link external schedules to rotations.
GitHub: repository and event configuration needed to route notifications.
Each integration only runs if your workspace connects it, and can be disconnected at any time from the dashboard.
Automatically, when you use our websites
Standard technical logs: IP address, browser type, pages visited, timestamps.
Error reports (via Sentry) when something breaks, including technical details of the failure.
Product analytics (PostHog, hosted in the EU): pages visited and feature usage in the dashboard, pages read on our documentation site, and events from our bot and API (for example, that a rotation was created). This activity is linked to your Round Robin account, and your name and email address are stored alongside it so we can tell who a workspace's users are without a separate lookup. Documentation-site analytics are always cookieless and are never linked to an account. If you accept analytics cookies, this also includes session replay of dashboard usage (with all text you type masked), kept for 30 days. Without your consent, analytics runs in a cookieless mode that cannot recognize you across visits.
Why We Process Data (Legal Bases)
Performance of a contract: operating rotations, posting notifications, providing the dashboard, billing.
Legitimate interests: securing our services, preventing abuse, improving Round Robin, and the product analytics that runs without cookies, including the activity our bot and API record against your account.
Consent: analytics cookies and session replay. You can withdraw consent at any time via the cookie banner or by contacting us.
We currently send only service and billing email. If we ever introduce marketing email, it will be opt-in, with a one-click unsubscribe.
Legal obligations: accounting and tax records we are required to keep.
How Data Flows To and From Other Companies
We do not sell personal data. To be precise about direction: some companies process data for us, one platform hosts the content we post for you, and the optional integrations mostly send data to us.
Service providers that process data for us
These providers store or process data on our behalf, under data processing agreements, solely to run Round Robin. We will update this list before engaging a new provider:
Provider Purpose Location
Google Cloud Hosting (Belgium, europe-west1) and encryption key management EU
MongoDB Atlas Database EU
Cloudflare Network security, content delivery, website hosting EU/US
Auth0 (Okta) Dashboard sign-in EU tenant
Stripe Payments and invoicing (Stripe also acts as an independent controller for fraud prevention and regulatory compliance) EU/US
PostHog Product analytics and session replay EU (Frankfurt)
Sentry Error monitoring US
Twilio SendGrid Transactional email US
Help Scout Customer support conversations US
CookieYes Cookie consent management and consent records EU/US
Slack
Slack is the platform Round Robin runs on. We receive workspace data from Slack (members, channels, user groups), and the messages, home pages, and user-group updates the app produces are delivered into your Slack workspace, where Slack's own terms and privacy policy govern them.
Optional integrations: data flows to us, not from us
If your workspace connects Google Calendar, PagerDuty, Jira Service Management, or GitHub, data flows from those services to Round Robin: we read calendar events, on-call schedules, or repository events to operate your rotations. In the other direction we send only the authentication tokens and API queries needed to read that data — we do not push your workspace's personal data to these services.
We may also disclose data where required by law, or as part of a merger, acquisition, or sale of assets — in which case this policy continues to apply to the transferred data.
For organizations that need one, our Data Processing Agreement covers the workspace data we process on your behalf.
International Transfers
Our primary infrastructure is in the European Union, and encrypted backup copies are additionally stored in Switzerland, which holds a European Commission adequacy decision. Where a provider processes data outside the EU/EEA (for example Sentry or SendGrid in the US), the transfer is protected by the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
How Long We Keep Data
Workspace and rotation data: for as long as your workspace uses Round Robin. When your workspace deletes its account or uninstalls the app, its data is permanently removed from our systems within 7 days. Two cases wait: a workspace with a live paid subscription, and one with an unpaid invoice. We keep those until the subscription is cancelled or the invoice is settled, and remove them within 7 days of that. Otherwise uninstalling would be a way to cancel a subscription without telling us, and a plan limit could be reset by uninstalling and reinstalling a week later. You can ask us to delete such a workspace sooner by writing to support@irrelevantlabs.com.
Session replay recordings: 30 days.
Backups: encrypted backups expire on a rolling schedule; the last backup containing deleted data expires no later than 5 weeks after deletion from our live systems.
Billing records: 7 years, as required by accounting law.
Data Breaches
If a personal data breach affects your data, we will notify affected workspaces without undue delay and the competent supervisory authority as required by law.
Your Rights
Under the GDPR you can ask us at any time to:
access the personal data we hold about you and receive a copy in a portable, machine-readable format;
correct inaccurate or incomplete data;
delete your data ("right to be forgotten");
restrict or object to processing based on our legitimate interests;
withdraw consent for consent-based processing, without affecting past processing.
Write to support@irrelevantlabs.com and we will respond within one month; for particularly complex requests the law allows us to extend by up to two further months, and we will tell you if we need to. We will never discriminate against you for exercising these rights. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.
Google User Data
If your workspace connects the Google Calendar integration, Round Robin accesses calendar events solely to detect out-of-office periods so rotations can skip unavailable members.
Round Robin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell it, and humans do not read it except with your explicit permission, for security purposes, or where required by law. You can disconnect the integration at any time from the dashboard, which removes the stored Google tokens and synced event data.
Cookies
See our Cookie Policy for the full list of cookies we use and how to manage them. Analytics cookies are only set with your consent.
Children
Round Robin is a workplace tool intended for users aged 18 or over. We do not knowingly collect data from children.
Notices for Specific Regions
United Kingdom
For UK users, we are a data controller (and, for workspace data, a processor) under the UK GDPR, and the rights described above apply equally. Transfers from the UK are protected by the UK Addendum to the Standard Contractual Clauses or the UK Extension to the EU–US Data Privacy Framework. You may lodge a complaint with the Information Commissioner's Office (ico.org.uk), though we would appreciate the chance to address your concern first.
Australia
We handle personal information consistently with the Australian Privacy Principles. Note that our services are hosted in the European Union, so your information is processed overseas. Complaints may be directed to the Office of the Australian Information Commissioner (oaic.gov.au).
Canada
We handle personal information consistently with PIPEDA. Our services are hosted in the European Union, so your information is processed outside Canada. You may access or correct your personal information by contacting us, and complaints may be directed to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
United States
Depending on your state of residence, you may have rights to know, access, correct, and delete personal information, and to opt out of its sale or sharing. We do not sell personal information. To exercise any right, contact us at the address below. We do not currently respond to browser "Do Not Track" signals.
Changes to This Policy
We may update this policy as our services or the law change. The current version always lives at this address; significant changes will be announced to registered users.
Contact
Irrelevant Labs OÜ Sepapaja tn 6, 15551 Tallinn, Estonia support@irrelevantlabs.com
Download this document (Markdown)