Skip to main content

QueueDrop

Privacy Policy

What QueueDrop collects, why, who it reaches, and how long it is kept. QueueDrop is in a pilot phase in Australia.

Last updated 2026-09-04

This Privacy Policy explains how QueueDrop (“we”, “our”, or “us”) collects, uses, and handles your information when you use our queue-management software and services. QueueDrop is operated by Sk Digital (ABN 62 698 348 872), Queensland, Australia, and is currently in a pilot phase in Australia.

QueueDrop provides software that allows businesses to manage their queues and allows customers to join those queues remotely or on-site.

1. Information we collect

What we collect depends on whether you are a business using our software or a customer joining a queue.

Business owners and staff

  • Account information: your name, email address, and password, which is stored only as a secure hash.
  • Business details: organisation details, locations, timezones, coordinates, contact phone numbers, and regular opening hours.
  • Service information: the services you offer, their expected durations, and informational pricing.
  • Operational activity: queue opening and closing times, staff assignments, and queue progression history.
  • Product research: if you register interest in Market Insights, we store the feature, the business user who responded, and any optional monthly value band until you withdraw that interest or the business is offboarded.

Customers

  • Joining as a guest: the display name you type, the queue and service you joined, and your queue activity — join times, completion times, cancellations, and no-shows. No account and no phone number are required to join a queue.
  • Verifying your phone number, which is always optional: your phone number and a preferred display name. Your phone number is encrypted at rest and looked up through a blind index rather than stored in a searchable form. QueueDrop does not store customer passwords.
  • An anonymous device identifier: to stop a single device joining a queue many times, we set a random, opaque cookie. It is generated by our server and is not derived from your device characteristics, IP address, browsing history, or any advertising identifier.

Technical and security data

  • Rate limiting and abuse signals: we count request volumes by source to prevent brute-force attacks and automated abuse. Sources are converted into a keyed digest before being stored, so we do not keep plain-text IP addresses in our database or a permanent history of them.
  • Sessions and idempotency records: active sessions are stored only as hashes, and short-lived records that prevent duplicate requests are swept automatically.

2. Why we collect it

  • To operate the queue: letting customers join and businesses serve them.
  • To estimate wait times and queue progression.
  • To prevent abuse, including automated bots, duplicate joins, and malicious sign-in attempts.
  • To support optional verified-customer features, including your visit history and loyalty progress at a specific business.
  • To understand business demand for optional paid analysis features and inform product pricing.
  • To send queue updates and verification codes by SMS or email, where those are configured.

3. How we process and share data

Cross-business isolation

If you are a verified customer, your relationship and visit history with a business is visible only to that business. QueueDrop does not combine your visits across different businesses into a central profile for businesses to view.

Infrastructure and subprocessors

We use third-party providers to run the platform, and share only what each needs to do its job:

  • Hosting: DigitalOcean (Sydney, Australia) for the application, and Neon on AWS (Sydney, Australia) for the database.
  • Maps and geocoding: MapLibre and OpenFreeMap for map rendering; Geoapify and Photon (OpenStreetMap) to turn addresses into coordinates.
  • Communications: Resend for transactional email, and Mobile Message for SMS verification codes.

QueueDrop does not claim compliance with any specific data-privacy certification for this pilot phase.

4. How long we keep it

QueueDrop is built on the principle of deleting the person and keeping the event. We keep operational facts, such as how long a service took, because they are the business’s own record and they are what makes wait estimates work. We delete the identifiers attached to them once they have served their purpose.

  • Guest credentials: the access token and check-in codes issued when you join are erased four hours after the visit is completed, cancelled, or marked a no-show. A loyalty visit is claimable within that same window, for the same reason — the claim voucher reaches you through the ticket and nowhere else.
  • Customer display names: a guest customer’s typed display name is retained on historical queue entries for 90 days following completion, cancellation, or no-show. After 90 days, the display name is automatically pseudonymised and replaced with a neutral placeholder ([removed]). Operational facts, such as queue timings and service durations, are retained.
  • Security data: rate-limiting windows, expired and revoked sessions, and used or expired verification codes are swept automatically once they can no longer authorise anything.
  • Market Insights research: a current expression of interest and its optional monthly value band are kept until the business withdraws it or is offboarded, then deleted.

5. How we protect it

  • Passwords and floor PINs are hashed with Argon2id.
  • Verified phone numbers are encrypted at rest with AES-256-GCM.
  • Session tokens and ticket credentials are stored only as digests, so a database leak alone does not yield anything usable.
  • All traffic is carried over HTTPS.

6. Access, correction, and deletion

You can ask us for access to your personal information, for it to be corrected, or for it to be deleted.

  • Customers: you can delete your verified identity, which removes the identity record entirely. The anonymous operational history of your past visits remains as the business’s own record.
  • Businesses: you can suspend or close your account.

To submit a privacy or personal information request, email [email protected] with the subject “Privacy Data Request”. We aim to respond within 2 to 3 business days. QueueDrop may require reasonable identity verification before fulfilling the request.

7. Changes to this policy

As QueueDrop changes during its pilot, we may update this policy to match what the software actually does. The current version is always the one published here.

8. Contact us

QueueDrop is operated by Sk Digital (ABN 62 698 348 872), Queensland, Australia.