N° Q The Queue
Find my booking How it works Pricing
EN DE
Log in Open your queue
Legal

Privacy Policy

Last updated [Platzhalter: Effective date] · v1.0 · Questions? [email protected]

This page is under legal review — details to follow.
On this page

We built The Queue so guests can book without an account and organisers don't have to babysit a spreadsheet. That means collecting as little personal data as the job allows — and being clear about the rest. This policy explains what we collect, why, and the rights you have under the GDPR.

Two kinds of people use The Queue. Organisers create events and have accounts with us. Guests book a place with just a name and email. For most guest data, the organiser decides what's collected and why — they are the controller, and we act as their processor. For accounts, billing, and the platform itself, we are the controller. This policy covers both and says which is which.

Who we are

The controller for platform and account data is [Platzhalter: Legal form & name], [Platzhalter: Address], Germany. You can reach us about privacy at [email protected]. [Platzhalter: If a Data Protection Officer is appointed, give their contact here.]

What we collect

When you create an organiser account

  • Your name, email, and password (stored only as a secure hash).
  • Your organisation, the places and events you set up, and your team members.
  • Billing details, handled by our payment provider Polar (merchant of record) — we don't store full card numbers.
  • Support messages you send us.

When a guest books

  • Name and email, so we can send the ticket and keep the waitlist in order.
  • [Platzhalter: Any extra fields the organiser adds, e.g. phone, dietary notes] — set by the organiser.
  • Booking status and check-in time at the door.

Automatically, when anyone uses the site

  • Basic log data — IP address, browser type, pages viewed — kept short-term for security and reliability.
  • The essential and (where consented) analytics cookies described in our Cookie Policy.

Why we use it, and our legal basis

  • To provide the service — creating events, sending tickets, running the waitlist and check-in. Legal basis: performance of a contract (Art. 6(1)(b) GDPR), or our processing on the organiser's instructions.
  • To keep accounts secure and prevent abuse — logs, rate limits, fraud checks. Legal basis: legitimate interests (Art. 6(1)(f)).
  • To bill and meet tax duties — invoices and records. Legal basis: contract and legal obligation (Art. 6(1)(b),(c)).
  • To improve the product — privacy-friendly analytics. Legal basis: consent where required, otherwise legitimate interests.
  • To send service emails — booking confirmations, changes, and essential notices. Legal basis: contract. Marketing emails, if any, only with your consent.

Who we share it with

We don't sell your data. We share it only with:

  • The organiser of your event (for guest bookings) — they see the bookings for their own events.
  • Service providers (processors) who run things like hosting, email delivery, and payments — under contracts that bind them to our instructions. Current providers: [Platzhalter: hosting, e.g. Hetzner], [Platzhalter: email, e.g. Postmark], Polar (payments), [Platzhalter: analytics].
  • Authorities, where the law requires it.

Where your data is stored

We host data in the EU/EEA wherever we can [Platzhalter: name region]. If a provider processes data outside the EEA, we rely on appropriate safeguards — an adequacy decision or the EU Standard Contractual Clauses — and can tell you which on request.

How long we keep it

  • Booking data — kept for the event and a reasonable window after, then deleted or anonymised per the organiser's settings [Platzhalter: default retention period].
  • Account data — kept while your account is active, then deleted after closure, save for what we must keep.
  • Invoices and tax records — kept for the statutory period (generally up to 10 years under German law).
  • Logs — kept short-term [Platzhalter: e.g. 30–90 days].

Your rights

Under the GDPR you can ask us to:

  • Access the personal data we hold about you, and get a copy;
  • Correct data that's wrong or incomplete;
  • Delete your data ("right to be forgotten"), where no legal duty makes us keep it;
  • Restrict or object to certain processing, including processing based on legitimate interests;
  • Port your data to another service in a common format;
  • Withdraw consent at any time, without affecting what we did before.

For guest bookings, the quickest route is often the organiser — but you can always contact us and we'll help or pass it on. To exercise any right, email [email protected]. You also have the right to complain to a supervisory authority, e.g. your local German state data-protection authority [Platzhalter: name authority].

How we protect it

We use encryption in transit, hashed passwords, access controls, and regular backups, and we keep staff access to personal data on a need-to-know basis. No system is perfectly secure, but we work to keep the risk low and will notify you and the authorities of a breach where the law requires.

Children

The Queue isn't aimed at children, and accounts are for adults. Organisers running events for minors are responsible for any consents the law requires.

Changes to this policy

We'll post any update here with a new date, and flag material changes in the product or by email. Continuing to use The Queue after a change means the updated policy applies.

N° Q The Queue
How it works Pricing Privacy Cookies Terms Acceptable use Imprint Cookie settings [email protected]
© 2026 · thequeue.me
Privacy

Cookies

We use a handful of essential cookies to keep the service running and analytics cookies — with your consent — to understand how The Queue is used. No advertising, ever. Cookie Policy