Security & privacy

Your customers' data, handled properly

Everything on this page is something turnda does today. Where we have not earned a claim yet, we say so further down rather than putting a badge on it.

Every business is isolated at the database level

turnda uses Postgres row-level security, forced on tenant data. That means the isolation is enforced by the database itself rather than by application code remembering to add a filter — the usual way this kind of thing goes wrong. An automated check runs in the release gate every change has to pass, and it refuses to pass if a tenant table is ever added without that protection — so it cannot quietly regress.

We collect only what a queue needs

Every visitor field — name, phone, party size, a note — is a switch the merchant controls, and each is off unless it is turned on. If your front desk does not need a phone number, do not ask for one. turnda is not a records system and holds no clinical, financial or identity data about your visitors.

Privacy on the lobby screen is enforced, not hidden

A display set to numbers-only is never sent the names in the first place — the restriction is applied where the data is read, not by hiding text in the page. That matters in a waiting room, where a screen is visible to everyone in it.

Secrets and personal data stay out of the logs

Our own logs are scrubbed before they are written: values that look like an email address, a phone number or a key are redacted, and sensitively-named fields are removed at any depth. Crash reports sent to our error monitor are separately restricted — its personal-data collection is switched off and the variables inside a stack frame are never transmitted. So the operational trail your data passes through does not accumulate copies of it.

One channel failing does not take the product down

The free tracking link is the primary way a customer sees their turn; WhatsApp and email are best-effort extras on top. If a messaging channel has an outage — or a location reaches its monthly allowance — the tracking link keeps working, so nobody is left without a way to know it is their turn.

PDPA and GDPR-shaped, with real deletion

We support data-subject requests, and the things you put in — your business details, your branding — can be cleared by you rather than only by us. If you stop paying, your data is kept for 90 days so you can return, and can be removed on request.

A pasted logo link is loaded from someone else's server

If you upload your logo, it is stored by us and served by us, and nobody else is involved. If instead you paste a link to your logo on another website, your customers' browsers fetch that image directly from that website — which means that website can see your customers' IP addresses. We do not choose it and have no agreement with it, so it is not on our sub-processor list and cannot be. Uploading avoids this entirely, and it is the option we recommend.

Sub-processors

The short, honest list

These are the companies that process data on turnda's behalf. It is a deliberately small list, and we will update this page before adding to it.

Who What they do Notes
Supabase Database, sign-in and image storage Where your account, team and queue data lives — EU, Frankfurt (eu-central-1)
Fly.io Application hosting Runs the app itself. Primary region Frankfurt (eu-central)
Upstash Cache, live updates and background jobs Short-lived queue state and job data; also visitor IP addresses, used to rate-limit abuse
Stripe Payments and subscription billing Card details go directly to Stripe — turnda never sees or stores them
Meta (WhatsApp Cloud API) WhatsApp message delivery The route in use today, and only when a merchant switches WhatsApp on for a line
Twilio · Gupshup · 360dialog Alternative WhatsApp delivery routes Configured alternatives to Meta. Named here because switching route is a config change, not a rebuild — so any of them may carry a WhatsApp message
Resend Transactional email delivery Join confirmations, updates and account email
Cloudflare Domain names (DNS) and inbound email routing Resolves turnda.com. It does not proxy your web traffic, so it does not see request content. It does receive and forward mail sent to turnda.com addresses — so anything you email us passes through Cloudflare on its way to us
Sentry Error monitoring Diagnostics only. Sentry's personal-data collection is switched off and stack-frame variables are never sent, so a crash report carries the fault, not the person
Being straight with you

What we do not claim

Trust pages usually list only the wins. Here is the other half — the things a careful buyer should know we have not done yet. If any of them is a blocker for you, tell us and we will give you a straight answer rather than a roadmap promise.

Ask us a security question
  • We are not SOC 2 or ISO 27001 certified. We will say so when we are, and not before.
  • We have not commissioned an external penetration test. Our security work so far is internal adversarial auditing.
  • We do not offer a signed enterprise DPA or a security questionnaire process yet. If you need one, get in touch and we will tell you honestly where we are.
  • We have no uptime SLA. The product is designed to degrade gracefully rather than to promise a number we cannot yet stand behind.

Security questions we get asked

Can one business ever see another's data?

No. Isolation is enforced by the database through row-level security, and an automated test fails the build if a tenant table is ever introduced without it. It is not left to application code to remember.

Where is our data stored?

In Frankfurt, in the EU. Your data is held in a managed Postgres database run by Supabase; the application itself runs on Fly.io in the same region. If your regulator requires a specific region, tell us before you sign up rather than after — we would rather say no than mislead you.

Do you store card details?

No. Payment details go directly to Stripe. turnda never receives or stores a card number.

What happens to our data if we leave?

That depends on how you leave. If you close the account yourself, you can reverse it for 7 days — after that it is permanently deleted. Before you close, take what you need: your setup exports as a file at any time, and every report downloads as CSV, Excel or PDF. Individual visit records are not in the export, because we delete visitors' details on the retention window you set rather than storing them long-term. If you simply stop paying, we keep the account for 90 days so you can come back without redoing your setup. Either way you can ask us to delete it sooner. Nothing is sold, and nothing is used to train anything.

How long is visitor data kept, and do backups follow the same clock?

You choose the window — anything from 24 hours to a year, and it is 48 hours unless you change it. When it expires the name and contact are erased and any notes or flags are deleted outright. Backups are the honest exception: we take one nightly and keep 14 daily and 8 weekly copies, so a copy can survive for around eight weeks after it is gone from the live system. Backups are private, used only to recover from a disaster, and never for anything else.

If we send you a screenshot with a support report, what happens to it?

It is stored privately, and only we can see it — it is not public and not shared. We said here that support reports never expired and promised to tell you when that changed. It changed on 19 August 2026: the screenshot and the technical details attached to a report are now erased 30 days after it is made, and a closed report is deleted in full after a year. Both happen automatically. One part is still true and we would rather say it: erasing a visitor's data does not reach a support report you sent us weeks earlier — the 30-day window is what limits how long such a screenshot exists at all. So it is still worth avoiding a screenshot that shows a guest's details.

Can we get our data out?

Yes — ask and we will provide it. We also support data-subject requests for individual visitors.

Do you have a security contact?

Yes — email security@turnda.com and it reaches a person, not a queue. It is the address published in our security.txt (at /.well-known/security.txt), and it is for vulnerability reports and nothing else. If you believe you have found a vulnerability, please tell us before disclosing it publicly and we will work with you.

Also see our privacy policy and terms.

Try it with your own data.

A 30-day free trial, and everything on this page applies from the first minute.

Start 30-day free trial

Or sign in · works worldwide · cancel anytime