Privacy Policy

Last updated: June 4, 2026

This Privacy Policy describes how QlessQ ("we," "us") collects, uses, and discloses information when you use our website, applications, and queue management services (the "Service"). It applies to organization administrators and staff who register for an account. Customer-facing collection and messaging decisions are controlled by each organization that uses the Service. We do not sell personal information.

1. Information We Collect

Account information: name, email address, organization name, phone number (if provided), and credentials. Organization and operational data: branches, services, queues, tickets, appointments, staff assignments, and configuration you enter. Customer data you submit: names, contact details, queue positions, and interaction history for your patrons. Technical data: IP address, browser type, device identifiers, and usage logs. Communications and support: support tickets, email, and troubleshooting materials you send us (which may include sample records, screenshots, or logs needed to resolve an issue). Payment data: processed by our payment provider; we do not store full card numbers.

2. How We Use Information

We use information to provide and operate the Service, authenticate users, enforce security, send transactional service messages (for example verification, password reset, queue updates, and appointment reminders when configured), respond to support requests, develop and maintain the platform (including through internal engineering and AI-assisted tooling under confidentiality and data-protection terms), analyze aggregated operational trends to improve reliability, and comply with legal obligations. We may use CRM or business analytics tools for internal relationship management and service analysis only—not to sell data or build third-party advertising audiences.

3. No Sale of Personal Information

We do not sell, rent, or trade personal information. We do not share personal information with third parties for their independent marketing, advertising, or data-broker purposes. Service providers listed in our subprocessor register process information only to help us operate and support the Service under contractual confidentiality and data-protection terms.

5. How We Share Information

We may share information with service providers who support hosting, messaging delivery, payment processing, internal engineering, security monitoring, customer support, and internal business analytics or CRM tools (including AI-assisted development and support platforms and the model providers they use), under contractual confidentiality and data-protection obligations and only for our operational purposes—not for sale. When you request assistance that requires accessing, correcting, or customizing data or behavior in your account, we process applicable Customer Data as your service provider on your instructions. We may also share information with professional advisers or authorities when required by law, and with successors in a merger or acquisition. Organizations control what customer data is used in patron notifications and public tracking links. A current subprocessor register and DPA overview are published at /subprocessors and /dpa.

6. Data Retention

We retain account and organization data while your account is active and for a reasonable period afterward for backup, audit, security, and legal compliance. Support correspondence and related troubleshooting records are retained for a reasonable period to handle disputes, security reviews, and legal obligations. Customer-level retention controls include platform defaults and administrative support workflows; organizations remain responsible for selecting retention practices that meet applicable legal requirements.

7. Security

We implement administrative, technical, and organizational measures designed to protect information, including encryption in transit, access controls, least-privilege access to production systems, and monitoring. Production access for support is limited to documented tenant requests and operational need. No method of transmission or storage is completely secure; you are responsible for safeguarding your credentials.

8. Your Rights and Requests

Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing. We respond to verified requests within applicable timelines. For customer-level queue or appointment data, the organization you interacted with is typically the primary decision-maker for your request, and we assist that organization as its service provider.

9. International Transfers

We may process data in countries other than your own, including through service providers in multiple jurisdictions. Where required, we use contractual and technical safeguards for cross-border processing and disclose these transfer realities so organizations can meet their own notice obligations.

10. Children

The Service is not directed to children under 16. We do not knowingly collect personal information from children. Contact us if you believe we have collected such information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy with an updated "Last updated" date. Material changes may be communicated via email or in-app notice where appropriate. When we add or replace a material subprocessor that processes Customer Data, we update /subprocessors and notify organization account owners by email or in-app notice before the new subprocessor begins processing, except where a shorter timeline is required for security or legal compliance.

12. Contact

Privacy questions and requests may be sent to [email protected]. Canadian organizations can use this contact for PIPEDA-related processing questions, incident coordination, and records support.

Contact

For questions about this document, email [email protected].