Privacy notice

What QueueFlow stores, why, and who can see it. Written to be read rather than to be lawyer-proof.

This notice describes the product as it is built today.

Who the data belongs to

Every business using QueueFlow is a separate tenant, and every row in the system belongs to exactly one of them. A business is the controller of the customer data it collects; we hold it on their behalf. One business can never read another one's data — that is enforced at the data layer, on every query, and it is covered by tests rather than by a policy.

What a business collects about a customer

Whatever it asks for at check-in, which is usually a first name and a mobile number, and optionally an email address and answers to questions the business wrote itself. Times are recorded: when somebody arrived, was called, was served and left. Nothing about a customer's device, location or browsing is collected.

What is shown in public

A waiting-room screen shows a ticket number, a first name and a service, and never a surname, a telephone number or an answer given at check-in. Showing the first name can be switched off. A customer's own status page is reached by a random token, shows only their own visit, and stops working shortly after that visit ends.

Messages

A business chooses which of four events send an email, and every message carries a one-click unsubscribe link that applies to that business alone. A customer who unsubscribes from one business is unaffected at another. There are no marketing emails and no tracking pixels.

Third parties, and the fact that there are none on this website

These public pages load no third-party script: no analytics, no tag manager, no chat widget and no font from somebody else's server. That is why there is no cookie banner — there is nothing to consent to. Inside the product, an email is delivered by the mail server the operator configures and a payment, where billing has been switched on, is taken by Paddle as described below. Nothing else leaves the installation.

Keeping and deleting

A business decides how long it keeps its own records; finished visits can be archived automatically. Records with history behind them are deactivated rather than deleted, so past visits still make sense. To ask about the data one business holds about you, contact that business — they are the ones who collected it.

Payments

Where billing has been switched on, the checkout is Paddle's and card details never reach us: what we store is a Paddle customer id, a subscription id, the plan and its dates. Paddle is the merchant of record and handles the payment, the receipt and the tax under its own privacy notice. It is never sent a customer record, a visit, or anything a business collected at check-in.