QRQ

Privacy Policy

Last updated: 18 August 2026

1. Who this policy applies to

QRQ is a customer-flow and virtual queue-management platform. Different people interact with the Service in different ways:

This Policy applies to all of these interactions, but QRQ's legal role depends on the context.

2. Who controls your personal data

QRQ is generally the controller of personal data used to manage QRQ accounts, subscriptions, security, support, our website, and our direct communications.

For personal data that a Customer collects from Visitors or enters into its queues, the Customer normally decides what data to collect, why it is needed, how long it should be kept, and who may access it. The Customer is therefore normally the controller of that data, and QRQ processes it on the Customer's behalf to provide the Service.

Customers are responsible for their collection and use of Visitor data, including providing appropriate privacy notices, establishing a lawful basis, obtaining any required consent, configuring the Visitor Form appropriately, and complying with applicable privacy laws. QRQ may provide tools for collecting consent and attaching a policy, agreement, or other PDF document, but the Customer remains responsible for the content and legal validity of those materials and consents.

3. Personal data we handle

The data we handle depends on how you use QRQ and how a Customer configures its queues.

Account and workspace data. This may include names, email addresses, profile images, preferred language, country, workspace details, industry, team membership and invitations, account roles, product-update preferences, and authentication information.

Customer content and configuration. Customers may provide queue names and settings, operator profiles, branding, uploaded images, custom content, consent documents, and other materials used to configure and operate their Workspaces.

Visitor and Queue Visit data. Depending on the Customer's configuration, this may include a ticket or visit identifier, selected services, queue status and timestamps, form responses, consent responses, feedback, and records of actions taken during the Queue Visit. A Customer may configure fields requesting information such as a name, telephone number, email address, vehicle registration number, group size, or other custom information.

Device, usage, and security data. We may process IP addresses, browser and device details, operating system, language, timezone, session identifiers, device identifiers, authentication cookies, access times, requested pages, actions, error information, and security or diagnostic logs.

Notification data. If a Visitor enables notifications, we may process a push-notification token or subscription, platform information, and notification-delivery information. Notifications may be delivered through Apple or Google/Firebase services, depending on the device and method used.

Billing data. For paid plans, we and our payment provider may process billing contact details, plan and subscription information, transaction status, invoices, and related records. Payment-card details are collected and processed by Stripe; QRQ does not store full payment-card numbers.

Communications. If you contact us, we process the information in your message and any related contact, support, or troubleshooting records.

We receive data directly from you, from the Customer and its authorized users, automatically from devices interacting with the Service, and from service providers involved in authentication, billing, notifications, infrastructure, and support.

4. How and why we use personal data

We use personal data as reasonably necessary to:

Where European data-protection law applies and QRQ acts as controller, we rely on one or more of the following legal bases: performance of a contract or steps requested before entering a contract; our legitimate interests in operating, securing, supporting, and improving the Service; compliance with legal obligations; and consent where required. You may withdraw consent at any time, without affecting processing already carried out lawfully.

Where QRQ acts as a processor for Visitor data, the Customer determines the applicable legal basis and instructs QRQ how to process that data, subject to our agreement and applicable law.

5. How we disclose personal data

We do not sell personal data or share it for cross-context behavioral advertising.

We may disclose personal data in the following circumstances:

Third-party websites, documents, integrations, and services are governed by their own privacy practices.

6. International data transfers

QRQ is based in Portugal, but we and our service providers may process data in other countries. Those countries may have different data-protection laws from the country where you live.

Where required, we use appropriate safeguards for international transfers, such as adequacy decisions, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism. You may contact us for more information about safeguards relevant to your data.

7. Data retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, follow Customer instructions and configuration, maintain security and business records, comply with legal obligations, resolve disputes, and enforce agreements.

Retention periods vary by data type and context. Account and subscription records may be kept while an account is active and for an appropriate period afterward. Queue Visit data and operational records are retained according to the Customer's configuration and instructions, the operation of the relevant queue, and applicable legal requirements. Uploaded materials may remain until the Customer removes or replaces them or the relevant Workspace is deleted. Security logs, backups, and legal or financial records may be retained for limited additional periods.

When data is no longer required, we delete or anonymize it, subject to technical limitations and applicable law.

8. Security

We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures include access controls, authentication, encryption in transit, service monitoring, and safeguards provided by our infrastructure partners.

No internet service or storage system can be guaranteed completely secure. Customers and authorized users are also responsible for protecting their access links, devices, accounts, and credentials and for granting access only to appropriate people.

9. Cookies and local device storage

QRQ uses cookies and similar local storage where necessary to operate the Service—for example, to maintain authenticated sessions, remember language preferences, preserve queue or device state, support security, and enable requested functionality.

We do not use these technologies for cross-site advertising. Blocking essential cookies or storage may prevent parts of the Service from working correctly. Notification permissions are controlled through your browser or device settings.

10. Your privacy rights

Depending on where you live and the circumstances, you may have rights to request access to, correction of, deletion of, or restriction of personal data; receive portable data; object to certain processing; withdraw consent; and complain to a data-protection authority. You may also opt out of direct marketing at any time.

If your request concerns information submitted to a Customer's queue, please contact the Customer operating that queue first. Because that Customer normally controls the information, it is usually best placed to identify the relevant Queue Visit and respond. If you cannot identify or reach the Customer, contact us at inbox@qrq.app, and we will assist where reasonably possible.

For data QRQ controls directly, send your request to inbox@qrq.app. We may need to verify your identity and may retain limited information about the request where required by law. Rights are not absolute and may be subject to lawful exceptions.

You may lodge a complaint with Portugal's data-protection authority, the Comissão Nacional de Proteção de Dados (CNPD), or another competent supervisory authority.

QRQ does not use personal data for solely automated decisions that produce legal or similarly significant effects for QRQ's own purposes. Customers may configure queue ordering, service selection, routing, and waiting-time features and are responsible for their use of those configurations.

11. Children

QRQ is designed for Customers managing real-world customer flow and is not directed to children for their own independent use. Customers are responsible for deciding whether their queues may be used by minors and for providing any notices, obtaining parental authorization, or establishing another lawful basis required by applicable law.

If you believe a child has provided personal data improperly, contact the Customer operating the queue or email us at inbox@qrq.app.

12. Changes to this Policy

We may update this Policy to reflect changes in the Service, our practices, or applicable law. We will post the updated version with a revised date and, where appropriate, provide additional notice of material changes.

13. Contact

QRQ, LDA
NIPC 518816516
Rua das Amendoeiras 56
Apartado 444-Z
8200-593 Albufeira
Portugal
Email: inbox@qrq.app