Privacy Policy
Written so a shop owner can read it. If you joined a queue, the short version is: we hold as little as possible, and not for long.
Version 2026-07-01 Β· Last updated 18 August 2026
This policy is published in English. If it is translated into any other language, the English version governs.
We help businesses run a queue. If you joined one, the business you visited decides what to ask you for β we just hold it for them and delete it on their schedule. We ask for as little as possible: usually a name and one way to reach you. We do not sell anything about you, we do not advertise to you, and we do not use your data to train artificial intelligence.
1. Who we are
turnda is provided by SKANDAN PTE. LTD. (UEN 202621966R), a private limited company incorporated in Singapore, registered at 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051. You can reach us about anything on this page β including a request to access, correct or delete your personal data β at legal@turnda.com.
2. Two different relationships
If you are a visitor β you scanned a code or opened a link to join a queue at a shop, clinic or salon β then that business decides what it collects about you and how long it keeps it. In law it is the data controller and we are its processor: we hold the information on its instructions. If you want your data corrected or deleted, the business is the right first stop, and we give it the tools to do it. You can also come to us and we will help.
If you run a business on turnda, then for your own account, billing and our security records, we are the controller.
3. What we handle
If you joined a queue:
Your name, if the business asks for it β many do not. One way to contact you: either a WhatsApp number or an email address, never both. That is not a policy we could quietly reverse β our database has a single contact field and a single channel setting per visit, so a second contact detail has nowhere to go.
Also: your place in the queue and the times around it; what you came for, if the business asks, as a label such as "haircut" rather than a description; anything the business's staff type about you, such as a note or a flag like "needs step-free access"; anything you write, such as a rating comment or a WhatsApp message to the business; and your device's network address, used only to stop abuse. We store it hashed rather than in the clear wherever we keep it in our database, and the abuse limiter β which has to compare one request against the last minute's β holds it in the clear for the length of that minute and no longer.
We never receive your payment details, because visitors do not pay us.
If you run a business: your name and email, your team's names and roles, your locations, your company name and logo, your billing records, a security log of changes made in your account, and messages your team sends each other inside the app. Card details go straight to Stripe β we never see or store a card number.
4. Why we handle it
To run the queue and tell you when it is your turn. To keep the service secure and stop abuse. To bill businesses. And, if the business switches it on, to send you one "how did we do?" email after your visit, inviting a review of that business. Nothing else. We send no marketing of our own to visitors, and we sell your details to nobody.
5. How we contact you, and how you stop it
Almost everything we send you is a service message β where you are in the line, and when you are called. There is one exception, and we would rather name it than let you find it: if the business turns it on and adds a review link, you get a single "how did we do?" email after your visit, asking you to review that business. It is email only β never WhatsApp β at most once per visit, and not more than once in the period the business sets (30 days unless they change it). It carries the same one-click unsubscribe as every other email, and unsubscribing does not affect the queue messages that tell you it is your turn.
The tracking link and the lobby screen are free, and they are what you always have for the day of your visit β they are the backbone. A message on whichever single channel you gave the business is a best-effort extra on top of them, never a replacement for them. Your link stays live through your visit and for the rest of that day; after that the visit is closed and the link retires with it.
WhatsApp only ever replies to you. We can send you a WhatsApp message only inside a 24-hour window that opens when you message the business first. If you have not messaged them there is no window and no message is sent β you simply keep the tracking link and the lobby screen. We do not send WhatsApp marketing, and the product has no ability to.
There is no SMS. We do not send text messages at all. Every email carries one-click unsubscribe β both the button your mail app shows and a visible link in the message.
Replying STOP on WhatsApp always works. Because businesses share one WhatsApp sender, a STOP stops queue messages from every business using turnda on that number. Reply join to turn them back on.
6. Who else handles your data
A short list of companies help us run the service β our database and sign-in, our servers, our email and WhatsApp delivery, our payment provider and our error monitoring. The current list, with what each one handles and where it runs, is on our security page, and we update it before adding anyone. That list covers everyone who handles the businesses' and their visitors' data. The one company that receives data about you reading this page is Google, through the analytics on this website β described at the foot of this policy, and kept separate because it receives none of the queue data above.
We do not sell your data. We do not share it for advertising. Nobody gets it for their own purposes.
One thing that is not on that list, and should be: if a business gives us its logo as a link to an image on another website rather than uploading the file, your browser loads that image directly from that other website β so that website can see your network address. We do not choose it and have no agreement with it, which is why it cannot appear on our sub-processor list. Businesses that upload their logo instead avoid this.
The same is true of video on a lobby screen. A business can show a YouTube or Vimeo video on its waiting-room display, and that screen then loads the video from Google or Vimeo directly. Unlike the logo case this is the business's own screen on its own premises, so the network address it reveals is the business's rather than yours, and we use YouTube's no-cookie player. We mention it because it is the same mechanism.
7. Artificial intelligence
turnda predicts wait times, busy periods and no-shows. Those predictions are ordinary statistics calculated from a single business's own past visits, used only for that business.
We do not send any business or visitor data to an external AI service, and we do not use any business or visitor data to train a shared or general-purpose model. There is no such service connected to turnda.
8. How long we keep things
Visitor data: the business chooses, and we enforce the limits. A business sets its own window between 24 hours and 1 year, and the default is 48 hours. When it expires, the name and contact are erased, and notes, flags and comments are deleted outright. We deliberately do not print a single number here β it would be wrong for every business that has changed the setting.
Beyond that: WhatsApp message contents, 30 days, then deleted; our security log of account changes, 1 year. An account is deleted on one of two clocks: an account you close yourself is reversible for 7 days and then permanently deleted, while an account that simply lapses β the trial ends, or you stop paying β is kept 90 days before it is deleted.
Three shorter clocks inside the app. Messages your team sends each other are kept 7 days. Notices about a support reply are kept at least 30 days, and notices about a payment or refund at least 90 days β "at least", because a business that sets a retention window longer than that keeps these for its own window instead, so that a payment alert never disappears before the ordinary notification sitting next to it. Anything carrying a visitor's details is on the business's own window above, whatever it is set to.
People who leave a business. When a business removes a team member we clear their login email and their PIN immediately. Their username stays for as long as the business's account exists, because past reports are attributed to it and reissuing it to someone else would silently relabel their work. If you have left a business that uses us and want that username removed, write to us and we will work it out with the business.
What is left after an account is deleted. The queue data goes. What we keep is a stub of the account itself β the business name, its account code and the recovery email β so that we can recognise it if it ever comes back, and so a deleted account cannot be silently recreated. The security log of who changed what goes on its own 1-year clock, and backups age out as described below. You can ask us to clear the stub too.
Two honest exceptions. Opt-out records outlive erasure, because they are the only way we can keep honouring a request to stop messaging you β they are kept minimally. And backups: we take one nightly and keep 14 daily and 8 weekly copies, so a copy of data can persist for roughly eight weeks after it was erased from the live system. Backups are stored privately and used only to recover from a disaster.
A gap we found ourselves, and are fixing. When a business reports a problem from inside the app, it can attach a screenshot of its own screen β which on a queue page may show guests' names. Those support reports do not currently expire on any schedule and are not reached by an erasure request. We are fixing it, and we will update this page when it is done. We would rather tell you than wait.
9. Where your data is, and where it travels
Your data is stored in Frankfurt, in the European Union β the database, sign-in, files and backups. Our application runs there too.
Requests travel, and we would rather tell you than let you assume. When you open a queue page, your connection is accepted at the server location nearest you and then passed to Frankfurt. So your data is stored in the EU; it is not true that it never leaves it.
10. Your rights
You can ask what we hold about you, ask for it to be corrected, and ask for it to be deleted.
If you joined a queue, ask the business first β it holds the controls, and we have built them: an owner can look up everything held about one visitor and erase it in a single action. Erasure removes the name and contact and blanks message contents, leaving behind only counts that carry nothing about you, so the business's own statistics stay correct. If the business does not respond, contact us and we will help.
11. Security
Each business's data is isolated at the database level, not merely by application code, and an automated test fails our build if a new table is ever added without that protection. We keep an audit-logged record of every change made in an account. When something breaks, our error reports are configured to carry the fault and not the person β personal details and the contents of program variables are never sent to our error-monitoring provider.
We are not SOC 2 or ISO 27001 certified, and we have not commissioned an external penetration test. We would rather say so than imply otherwise. There is more detail on our security page.
12. Children
turnda is a tool for businesses and is not directed at children. We do not knowingly collect data about children beyond what a parent might give when joining a queue on their behalf.
13. Changes
If we change this policy we will update the version and date above and, for anything significant, tell the businesses that use turnda before it takes effect.
About this website: we use Google Analytics to see how many people visit turnda.com and which pages they read. It runs without cookies β nothing is stored on your device and you are not followed around the internet β so there is no banner here asking you to agree to one. It tells us how many visits a page had, not who you are. This is separate from the businesses' data described above; Google receives none of that.
This policy is with our lawyer for review. We have published it rather than holding it back because everything in it is true today and you are entitled to read it now. If anything changes after that review, we will update the version above.