Legal

Privacy policy

This policy explains what we do with personal data. Which parts apply to you depends on who you are — read section 2 first, because the answer differs for a business using Queue Join and for someone who joined a queue.

Last updated 28 August 2026

1. Who we are

Queue Join is provided by TRUSTED MEDIA LIMITED, a company registered in England and Wales (number 08153782) at 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom.

For anything in this policy, contact hello@queuejoin.com.

2. Which parts apply to you

If you joined a queue or made a booking at a business, that business decides what to collect and why. It is the data controller; we only handle your details on its instructions, as its processor. Sections 3 to 9 describe what we do with that data on its behalf, but to exercise your rights you should contact the business — or us, and we will pass it on promptly.

If you run a business that uses Queue Join,we are the controller for your own account details, and a processor for your customers’ details. Our obligations to you as a processor are in section 13 of our Terms and conditions.

If you are just visiting this website, section 10 on cookies is the relevant part.

3. What we collect

From people joining a queue or booking

  • Name and mobile number — needed to hold your place and tell you when it is your turn.
  • Email address, if the business asks for it.
  • Party size, the service you selected and any notes you or staff add.
  • Your visit history with that business: when you joined, when you were called, whether you were served, cancelled or did not arrive.
  • Whether you agreed to marketing messages, the exact wording you were shown, and when — kept as the record of what you consented to.
  • A record of each message sent to you: the channel, the address it went to, and whether it was delivered, opened or failed.
  • If you enable browser notifications, the technical subscription your browser provides.
  • Approximate location, only where a business requires on-site check-in and only at the moment you join. It is used to check you are nearby and is not stored.

From businesses using the service

  • Your name and email address, from sign-up or from Google or Apple if you use single sign-on.
  • Your business details: name, address, industry, website, locations and opening hours.
  • Your role, permissions and which locations you can access.
  • A log of administrative changes you make — who changed what, and when.
  • Billing details are handled by Paddle. We receive a subscription status and a customer reference. We never see your card number.

Automatically

  • Standard server logs from our hosting provider, including IP address and browser type, used for security and diagnosing faults.
  • We do not use advertising or analytics trackers. See section 10.

4. Why we use it, and our lawful basis

What forLawful basis
Holding your place in a queue and telling you when it is your turnPerformance of a contract with the business you are visiting, or its legitimate interest in running its queue
Sending booking confirmations, reminders and updatesSame as above
Sending marketing messagesYour consent, which you give explicitly and can withdraw at any time
Running accounts, support and securityOur legitimate interest in operating the service, and performance of our contract with the business
Billing and taxPerformance of a contract, and our legal obligations
Keeping records of consent and of messages sentOur and the business's legal obligation to demonstrate compliance
Preventing abuse and meeting mobile carrier rulesOur legitimate interest, and legal obligations to carriers and regulators

5. Messages, and how to stop them

There are two kinds of message, and they work differently.

Messages about your visit — that it is your turn, that your booking is confirmed — are the service you asked for by joining. They are not marketing.

You give your number either by typing it into the business's join or booking form yourself, or by handing it to a member of their staff in person, having been told you will get a message or a call when it is your turn. Nobody adds your number without you knowing, and we do not accept purchased, rented or scraped lists. There is more detail, including the exact wording used, on our SMS opt-in policy.

Marketing messages are only ever sent if you ticked a box saying so. The box is never pre-ticked, and joining a queue or making a booking never requires it.

You can stop everything at any time by replying STOP to any text message. That takes effect immediately and across every channel, not just the one you replied on. Reply HELP for help. Every marketing email and message also contains a link to a page where you can change your preferences without contacting anyone.

Message and data rates may apply depending on your mobile plan. Message frequency depends on your own visits and bookings.

6. Who we share data with

We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes.

We do not sell personal data, and we do not share it for advertising. We use the following processors to run the service. Each is bound by contract to protect the data and to use it only for the purpose shown — including delivering the messages you asked for, which is not sharing your number for marketing.

ProviderWhat it doesWhereTransfer safeguard
PlanetScaleDatabase hosting — all application dataUnited StatesEU SCCs / UK IDTA
VercelApplication hosting and deliveryUnited States / global edgeEU SCCs / UK IDTA
TwilioSMS, WhatsApp, RCS and voice callsUnited States, with EU processingEU SCCs / UK IDTA
Mailgun (Sinch)Transactional and marketing emailEuropean UnionWithin EEA
AblyRealtime queue position updatesUnited Kingdom / EUWithin UK/EEA
Cloudflare R2Uploaded logos and imagesGlobalEU SCCs / UK IDTA
PaddlePayments, invoicing and tax — merchant of recordUnited Kingdom / EUWithin UK/EEA
GoogleSign-in, address lookup and map tilesUnited StatesEU SCCs / UK IDTA
AppleSign-in, where you choose itUnited StatesEU SCCs / UK IDTA

We may also disclose data where required by law, to enforce our terms, or in connection with a merger or acquisition — in which case we will tell affected businesses beforehand.

7. International transfers

Some providers above process data outside the UK and EEA, chiefly in the United States. Where that happens, transfers rely on the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision, together with additional safeguards where appropriate.

Email is deliberately processed in the European Union, and realtime updates in the UK or EU.

8. How long we keep it

Because businesses control their customers’ data, they largely decide how long it is kept. In practice:

  • Visit and booking records are kept while the business's account is open, because they are its operating history and its analytics.
  • Consent records are kept for as long as the consent is relied on, and afterwards for as long as the business may need to evidence it.
  • Message delivery records are kept as the record of what was sent and whether it arrived.
  • When a business erases a customer at that customer's request, the name, mobile number, email address, notes, consent records and message addresses are removed immediately. The anonymous fact that a visit happened remains, so the business's counts and accounts stay correct — it no longer identifies anyone.
  • When a business closes its account, we delete its data within 90 days.

We do not currently apply automatic time-based deletion to operational logs beyond the above. If that changes, we will update this policy before it takes effect.

9. Your rights

Under UK and EU data protection law you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw consent at any time.

If you joined a queue, ask the business you visited — it holds the relationship and can export or erase your record itself, using tools we provide for exactly this. If you cannot reach it, contact us and we will help.

If you run a business using the service, contact us directly.

We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

You can complain to the Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority in the EEA. We would rather you came to us first.

10. Cookies

We use only what is necessary to make the service work. We do not use advertising cookies, and we do not track you across other websites.

CookiePurposeLasts
Session cookieKeeps you signed in to the dashboard. Set only after you sign in.Until you sign out or it expires
current_location_idRemembers which of your locations you are viewing.Until changed or cleared
recent_location_idsLists the locations you switched to recently, so they are quick to reach.Until changed or cleared

Because these are strictly necessary for a service you have asked for, they do not require consent. Public queue and booking pages set no cookies at all unless you sign in.

11. How we protect it

  • Data is encrypted in transit. Sign-in is by emailed magic link or single sign-on — we never store a password.
  • Each business's data is separated, and every request is checked against the account making it.
  • Staff access is limited by role, and can be restricted to particular locations.
  • Administrative changes are recorded in an audit log showing who did what and when.
  • Unsubscribe and consent links are signed, so they cannot be guessed or altered.
  • We keep the number of providers with access to a minimum, and each is listed in section 6.

No system is perfectly secure. If a breach affects personal data we hold, we will notify the affected business without undue delay, and the ICO where the law requires it.

12. Children

The service is not directed at children and we do not knowingly collect data from anyone under 13. A child may join a queue with a parent, in which case the parent’s details are normally the ones given. If you believe we hold a child’s data without appropriate consent, tell us and we will remove it.

13. Changes to this policy

We will update this policy when what we do changes. Material changes affecting businesses using the service are notified by email at least 30 days beforehand. The date at the top always shows the current version.