Privacy Policy
Last updated: 18 August 2026
1. Who this policy applies to
QRQ is a customer-flow and virtual queue-management platform. Different people interact with the Service in different ways:
- a Customer is the business, organization, or individual using QRQ to manage customer flow;
- a Workspace Owner or Workspace Member manages a Customer's workspace and queues;
- a Queue Operator manages Queue Visits and serves Visitors; and
- a Visitor joins or interacts with a Customer's queue. A Queue Visit is the record of that interaction.
This Policy applies to all of these interactions, but QRQ's legal role depends on the context.
2. Who controls your personal data
QRQ is generally the controller of personal data used to manage QRQ accounts, subscriptions, security, support, our website, and our direct communications.
For personal data that a Customer collects from Visitors or enters into its queues, the Customer normally decides what data to collect, why it is needed, how long it should be kept, and who may access it. The Customer is therefore normally the controller of that data, and QRQ processes it on the Customer's behalf to provide the Service.
Customers are responsible for their collection and use of Visitor data, including providing appropriate privacy notices, establishing a lawful basis, obtaining any required consent, configuring the Visitor Form appropriately, and complying with applicable privacy laws. QRQ may provide tools for collecting consent and attaching a policy, agreement, or other PDF document, but the Customer remains responsible for the content and legal validity of those materials and consents.
3. Personal data we handle
The data we handle depends on how you use QRQ and how a Customer configures its queues.
Account and workspace data. This may include names, email addresses, profile images, preferred language, country, workspace details, industry, team membership and invitations, account roles, product-update preferences, and authentication information.
Customer content and configuration. Customers may provide queue names and settings, operator profiles, branding, uploaded images, custom content, consent documents, and other materials used to configure and operate their Workspaces.
Visitor and Queue Visit data. Depending on the Customer's configuration, this may include a ticket or visit identifier, selected services, queue status and timestamps, form responses, consent responses, feedback, and records of actions taken during the Queue Visit. A Customer may configure fields requesting information such as a name, telephone number, email address, vehicle registration number, group size, or other custom information.
Device, usage, and security data. We may process IP addresses, browser and device details, operating system, language, timezone, session identifiers, device identifiers, authentication cookies, access times, requested pages, actions, error information, and security or diagnostic logs.
Notification data. If a Visitor enables notifications, we may process a push-notification token or subscription, platform information, and notification-delivery information. Notifications may be delivered through Apple or Google/Firebase services, depending on the device and method used.
Billing data. For paid plans, we and our payment provider may process billing contact details, plan and subscription information, transaction status, invoices, and related records. Payment-card details are collected and processed by Stripe; QRQ does not store full payment-card numbers.
Communications. If you contact us, we process the information in your message and any related contact, support, or troubleshooting records.
We receive data directly from you, from the Customer and its authorized users, automatically from devices interacting with the Service, and from service providers involved in authentication, billing, notifications, infrastructure, and support.
4. How and why we use personal data
We use personal data as reasonably necessary to:
- provide, operate, maintain, and support the Service;
- create accounts, authenticate users, manage Workspaces, and administer subscriptions;
- register and manage Queue Visits, display queue status and estimated waiting times, route Visitors, and deliver notifications;
- process uploads and make Customer-configured materials available through the Service;
- communicate about accounts, security, support, transactions, and important Service changes;
- send product news or other optional communications where permitted, subject to your communication preferences;
- monitor reliability, diagnose problems, prevent fraud and misuse, protect the Service and its users, and enforce our agreements;
- understand and improve the Service, including through aggregated or de-identified information; and
- comply with law, respond to lawful requests, resolve disputes, and protect our rights and those of others.
Where European data-protection law applies and QRQ acts as controller, we rely on one or more of the following legal bases: performance of a contract or steps requested before entering a contract; our legitimate interests in operating, securing, supporting, and improving the Service; compliance with legal obligations; and consent where required. You may withdraw consent at any time, without affecting processing already carried out lawfully.
Where QRQ acts as a processor for Visitor data, the Customer determines the applicable legal basis and instructs QRQ how to process that data, subject to our agreement and applicable law.
5. How we disclose personal data
We do not sell personal data or share it for cross-context behavioral advertising.
We may disclose personal data in the following circumstances:
- Customers and their authorized users. Visitor and Queue Visit data is available to the Customer operating the queue and to authorized Workspace Owners, Workspace Members, and Queue Operators according to their roles and queue configuration.
- Service providers. We use providers that help us host, store, secure, support, and deliver the Service. These currently include Cloudflare for infrastructure, storage, files, images, networking, and related platform services; Stripe for billing and payment processing; and Apple and Google/Firebase for certain push notifications and device services.
- Professional advisers and authorities. We may disclose data to advisers, regulators, courts, law-enforcement bodies, or other parties where reasonably necessary to comply with law, establish or defend legal claims, or protect people, QRQ, the Service, and our rights.
- Business transactions. Data may be disclosed or transferred as part of a merger, financing, reorganization, sale of assets, acquisition, or similar transaction, subject to appropriate safeguards.
- With your direction or consent. We may disclose data when you direct us to do so or give valid consent.
Third-party websites, documents, integrations, and services are governed by their own privacy practices.
6. International data transfers
QRQ is based in Portugal, but we and our service providers may process data in other countries. Those countries may have different data-protection laws from the country where you live.
Where required, we use appropriate safeguards for international transfers, such as adequacy decisions, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism. You may contact us for more information about safeguards relevant to your data.
7. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, follow Customer instructions and configuration, maintain security and business records, comply with legal obligations, resolve disputes, and enforce agreements.
Retention periods vary by data type and context. Account and subscription records may be kept while an account is active and for an appropriate period afterward. Queue Visit data and operational records are retained according to the Customer's configuration and instructions, the operation of the relevant queue, and applicable legal requirements. Uploaded materials may remain until the Customer removes or replaces them or the relevant Workspace is deleted. Security logs, backups, and legal or financial records may be retained for limited additional periods.
When data is no longer required, we delete or anonymize it, subject to technical limitations and applicable law.
8. Security
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures include access controls, authentication, encryption in transit, service monitoring, and safeguards provided by our infrastructure partners.
No internet service or storage system can be guaranteed completely secure. Customers and authorized users are also responsible for protecting their access links, devices, accounts, and credentials and for granting access only to appropriate people.
9. Cookies and local device storage
QRQ uses cookies and similar local storage where necessary to operate the Service—for example, to maintain authenticated sessions, remember language preferences, preserve queue or device state, support security, and enable requested functionality.
We do not use these technologies for cross-site advertising. Blocking essential cookies or storage may prevent parts of the Service from working correctly. Notification permissions are controlled through your browser or device settings.
10. Your privacy rights
Depending on where you live and the circumstances, you may have rights to request access to, correction of, deletion of, or restriction of personal data; receive portable data; object to certain processing; withdraw consent; and complain to a data-protection authority. You may also opt out of direct marketing at any time.
If your request concerns information submitted to a Customer's queue, please contact the Customer operating that queue first. Because that Customer normally controls the information, it is usually best placed to identify the relevant Queue Visit and respond. If you cannot identify or reach the Customer, contact us at inbox@qrq.app, and we will assist where reasonably possible.
For data QRQ controls directly, send your request to inbox@qrq.app. We may need to verify your identity and may retain limited information about the request where required by law. Rights are not absolute and may be subject to lawful exceptions.
You may lodge a complaint with Portugal's data-protection authority, the Comissão Nacional de Proteção de Dados (CNPD), or another competent supervisory authority.
QRQ does not use personal data for solely automated decisions that produce legal or similarly significant effects for QRQ's own purposes. Customers may configure queue ordering, service selection, routing, and waiting-time features and are responsible for their use of those configurations.
11. Children
QRQ is designed for Customers managing real-world customer flow and is not directed to children for their own independent use. Customers are responsible for deciding whether their queues may be used by minors and for providing any notices, obtaining parental authorization, or establishing another lawful basis required by applicable law.
If you believe a child has provided personal data improperly, contact the Customer operating the queue or email us at inbox@qrq.app.
12. Changes to this Policy
We may update this Policy to reflect changes in the Service, our practices, or applicable law. We will post the updated version with a revised date and, where appropriate, provide additional notice of material changes.
13. Contact
QRQ, LDA
NIPC 518816516
Rua das Amendoeiras 56
Apartado 444-Z
8200-593 Albufeira
Portugal
Email: inbox@qrq.app
