Legal

Privacy Policy

Last updated: July 2026

This Privacy Policy explains how InQueue Limited ("InQueue", "we") collects, uses and shares information when you use our queue-management platform and websites (the "Service"). Our processing of personal data is governed by the Data Protection Act, 2025 of The Bahamas (the "Act"), and this policy is written to be consistent with it.

1. Controller and processor, who is responsible for your data

InQueue is a platform used by businesses ("tenant businesses") to manage their queues, bookings and visits. If you took a ticket, booked a visit, or gave feedback at a business that uses InQueue, that business decides what data is collected and why, it is the "controller" of your data. InQueue processes that ticket-holder data on the business's behalf as its "processor", under its instructions.

For the data of our direct customers themselves, account holders, staff users and billing contacts, InQueue is the controller.

2. Information we collect

Ticket-holder data (processed for tenant businesses)

Depending on what the business you visited chooses to collect: your name, phone number, email address, your visit and queue history (tickets taken, services requested, waiting and serving times), and any feedback or survey responses you submit.

Account & billing data

Name, email, phone, company details, staff user records, and billing information (payments are processed by Stripe; we do not store full card numbers).

Usage & device data

Log data, device and browser information, IP address, and analytics about how the Service is used, to operate and improve it.

3. Why we use it

  • To run the queue: issue tickets, show your place in line, and call you when it is your turn;
  • To send transactional messages you asked for (e.g. SMS queue alerts, booking confirmations and reminders);
  • To invite and record feedback about your visit, for the business you visited;
  • To provide, secure, maintain and improve the Service, and process subscriptions and payments;
  • To provide support, prevent fraud and abuse, and comply with legal obligations.

We do not sell personal data, and we do not use ticket-holder data for advertising.

4. How long we keep it

Ticket-holder data is kept only as long as the business you visited configures, then automatically deleted, at most 2 years. Account and billing records are kept for as long as the account is active and as required for legal, accounting and tax purposes.

5. Subprocessors

We use a small number of service providers ("subprocessors") to run the Service, under contractual protections consistent with the Act:

  • Stripe, subscription billing and payment processing;
  • Amazon Web Services SES, transactional email delivery (USA);
  • SMS Gate, the SMS delivery gateway used for queue and booking text alerts;
  • Backblaze B2, encrypted backups (USA);
  • DigitalOcean, cloud hosting of the Service;
  • Cloudflare Turnstile, anti-bot verification on our public booking forms, to prevent automated abuse (USA). Turnstile runs without tracking cookies and does not use your data for advertising. See Cloudflare's Turnstile Privacy Addendum.

We may also disclose information where the law requires it, to enforce our terms, or to protect rights and safety.

6. Cross-border transfers

Some of the providers above store or process data outside The Bahamas (including in the United States). Where personal data leaves The Bahamas, we take the steps required by the Act to make sure it stays protected, including contractual safeguards with each provider and encryption of backups.

7. Security and breach notification

We use technical and organisational measures appropriate to the risk, including encryption in transit, encrypted backups, access controls and audit logging. If a personal data breach occurs, we will notify the affected tenant business without undue delay so it can meet its obligations, and we will notify the Data Protection Commissioner and affected individuals where and as the Act requires.

8. Your rights

Under the Act you have the right to access the personal data held about you, to have it corrected, to have it deleted, and to object to certain processing. If your data was collected by a business you visited, the quickest route is to contact that business, it is the controller, but you can also contact us at support@inqueue.com.co and we will assist or pass your request to the right business without undue delay.

9. Cookies

Essential cookies are required for the Service to function. Where required by law, we obtain consent for non-essential cookies and provide controls to manage them. You can also control cookies through your browser settings.

10. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children.

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified by updating the date above and, where appropriate, by additional notice.

12. Contact

For privacy questions or to exercise your rights, contact support@inqueue.com.co, or write to [DPO name], Data Protection Officer.