Privacy Policy
Written so a shop owner can read it. If you joined a queue, the short version is: we hold as little as possible, and not for long.
Version 2026-10-02 · Last updated 2 October 2026
This policy is published in English. If it is translated into any other language, the English version governs.
governs.
The short version
turnda helps businesses run a queue. If you joined a queue, the business you visited decides what to ask you for and how long to keep it; we hold it for them and delete it on their schedule — 48 hours after your visit unless they chose otherwise. We ask for as little as possible: usually a name and one way to reach you. We do not sell anything about you, we do not advertise to you, and we do not use your data to train artificial intelligence.
1. Who we are and how to reach us
turnda is provided by SKANDAN PTE. LTD. (UEN 202621966R), a private limited company incorporated in Singapore, registered at 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051.
- Privacy questions and requests (to see, correct or delete your data): legal@turnda.com
- Our data protection officer is the company's founder and director. Write to them at legal@turnda.com, marked "For the data protection officer".
2. Two roles, because they have different rules
If you joined a queue or made a booking at a shop, clinic, salon or other business ("a business"), that business is in charge of your details (in legal terms, the controller). We store and handle them only on its instructions (in legal terms, its processor or data intermediary). The business's own privacy notice applies to what it does with your details; a business can show its own short notice on its join, booking and kiosk pages, and where it has, you will see it there. If you want to see, correct or delete them, the business is the quickest route — it has the tools in turnda to do it — but you can also write to us and we will pass your request on and help.
For everything else in this policy — the accounts of people who run a business on turnda, billing, security records, our website and emails sent to us — turnda is in charge (the controller).
3. What we handle, and where it comes from
3.1 If you joined a queue or made a booking
The business chooses which questions its join page, entrance tablet and booking page ask. Each question is a switch it controls, and most are off unless it turns them on. Depending on those choices we hold:
- Your name, if asked. If you joined by sending a WhatsApp message, the name on your WhatsApp profile is used as your name.
- One way to reach you — either a WhatsApp number or an email address, never both for the same visit. A visit has a single contact field, so a second contact has nowhere to go. A visitor who joins at an entrance tablet gives no contact at all.
- Anything else the business asks: party size, what you came for (as a label such as "haircut"), a vehicle registration, or a note you write.
- Your place in the queue and its times: when you joined, were called and were served, and which counter served you.
- Things the business's staff add: a note, or a flag such as "needs step-free access". These are only ever shown to staff, never on a public screen. A business may record something sensitive here; it must have a legal basis to do so.
- Things you write: a rating or comment, and WhatsApp messages you send to the turnda number.
- A one-time code, if the business asks you to confirm your email before joining. We store only a one-way fingerprint of your address and of the code, for a few minutes.
- Your device's network address (IP address), used only to stop abuse. See section 3.5.
Your name can appear on the business's lobby screen only if the business chose to show names or initials; a screen set to numbers only is never sent names at all.
You never pay us, so we never receive your payment details.
3.2 If you run a business on turnda, or work for one
- Owner and manager accounts: name, sign-in email address, an optional recovery email, role and the locations you work at. If you sign in with Google, Google tells us your email address, name and profile picture.
- Staff accounts: a username, a PIN (stored only as a one-way fingerprint), an optional sign-in email, role and locations.
- Your devices: a short device name worked out from your browser (such as "Chrome on Android"), so you can see and sign out your devices; your sign-in sessions; and for a lobby screen, its pairing code.
- The business's account: business name, logo, locations, lines, settings and message wording.
- What you do in turnda: a security log of changes made in the account (who changed what and when), messages your team sends each other in the app, and notifications.
- Billing: your subscription, invoices and payments (amounts, dates, Stripe reference numbers). Card details go straight to Stripe — we never see or store a card number. When a trial starts we keep a one-way fingerprint of the card (section 8.3).
- Support: reports you send from inside the app, including a screenshot of your screen if you attach one and technical details of the page you were on, and our replies. The words of your report (not the screenshot) are also emailed to our support mailbox so we see it at once — so please do not type a visitor's details into a report.
- Sign-up and leaving: how you heard of us, and the reason you pick if you cancel or close (with any words you add).
3.3 If you visit turnda.com or the Help Centre
We use Google Analytics on turnda.com, set to run without cookies: nothing is stored on your device for analytics and you are not tracked across other websites. Google still receives the request from your browser, including your network address, the page and where you came from, and gives us counts of visits by page, country and source. If our website has an error, a report goes through our own server to our error monitor without your network address.
3.4 If you email us
Mail sent to any turnda.com address passes through Cloudflare, which routes it, and is delivered to our support mailbox at Google (Gmail). We keep it there to answer you and to keep a record of what was agreed.
3.5 Network addresses and abuse protection
To stop abuse (for example someone guessing codes or flooding a join page), we count requests from each network address. The address is held in plain form as part of the counter for at most 15 minutes, then the counter expires. Where we write a network address into our database or logs, we store only a one-way fingerprint of it.
4. Why we use it, and on what basis
For visitors: to run the queue or booking and tell you when it is your turn — on the business's instructions and for the purpose the business set. The business is responsible for its own legal basis.
Where turnda is in charge:
| What | Why | Basis (where the law asks for one) |
|---|---|---|
| Owner, manager and staff accounts; sign-in | To give you the service you signed up for | Performing our contract with the business |
| Billing records | To charge and keep financial records | Contract; legal duty to keep records |
| Security log, abuse protection, error reports | To keep turnda secure and working | Our legitimate interest in a secure service |
| Trial card fingerprint | To notice one card starting trial after trial | Our legitimate interest in preventing misuse |
| Support reports and emails to us | To answer you and fix problems | Contract; our legitimate interest |
| Opt-out (STOP and unsubscribe) records | To keep honouring a request to stop messages | Legal duty; legitimate interest |
| Website analytics | To see how many people read which pages | Our legitimate interest; no cookies are set |
| Emails to owners about the account | Billing, trial ending, closing, weekly summary | Contract; you can turn the weekly summary off |
We do not use any of it for advertising, we do not sell it, and we do not make decisions about anyone by automated means that have legal or similarly significant effects.
5. Messages, and how to stop them
- The tracking link and the business's lobby screen are free and always there for the day of your visit. A message is a best-effort extra on top of them. Your tracking link stays live through your visit and the rest of that day.
- WhatsApp. turnda sends WhatsApp messages from one turnda number shared by many businesses. We can only message you on WhatsApp after you have messaged that number (for example by scanning a WhatsApp join code or tapping the button on your tracking page), and only inside WhatsApp's 24-hour reply window. We send no WhatsApp advertising and the product cannot. If you message the number without joining a queue, an automatic reply tells you nobody reads it and to contact the business directly.
- Reply STOP on WhatsApp and we stop sending you WhatsApp messages from every business using turnda, because the number is shared. Reply JOIN to turn them back on.
- Email. Every email has a one-click unsubscribe, in your mail app and as a link in the message. Unsubscribing stops email about your visits from every business on turnda.
- The review request. If the business switches it on, you may get one email after your visit asking you to review that business — email only, at most once per visit, and not again within the period the business sets (30 days unless it changes it). This is the business's marketing, sent for it. Unsubscribing from it does not affect the messages telling you it is your turn.
- There is no SMS. We do not send text messages.
6. Who else handles it
- Our suppliers. A short list of companies help us run turnda: our database and sign-in, our servers, our job queue, email and WhatsApp delivery, payments, error monitoring, our domain and incoming mail, Google sign-in and our support mailbox. The full list, with what each one handles and where, is on our sub-processor page. We update it before adding anyone, and businesses get notice.
- The business you visited sees what it collected about you.
- When the law requires it, we may disclose data to a court, regulator or police force. Where we are allowed to, we tell the business concerned first.
- If turnda is sold or merged, the data would pass to the new owner, who would be bound by this policy and the commitments in our Terms.
We do not sell your data. We do not share it for advertising. Nobody gets it for their own purposes.
Two things not on the sub-processor list, because we do not choose them:
- If a business gives us its logo as a link to a picture on another website instead of uploading it, your browser loads that picture from that website, which can see your network address. Uploaded logos are served by us.
- If a business shows a YouTube or Vimeo video on its lobby screen, the screen loads it from Google or Vimeo. That screen is the business's own device, so the address seen is the business's, not yours. We use YouTube's privacy-enhanced player.
7. Artificial intelligence
turnda predicts wait times, busy periods and no-shows using ordinary statistics worked out from one business's own past visits, used only for that business. We do not send any data to an outside artificial-intelligence service, and we do not use any data to train a shared or general-purpose model. No such service is connected to turnda.
8. How long we keep things
8.1 Visitor data
The business chooses, between 24 hours and 1 year, and the default is 48 hours. The clock starts when your visit ends (for a booking, at the booked time). When it runs out, your name and contact are erased, and notes, flags, comments and your WhatsApp reply-window record are deleted. What remains is an anonymous record (times, line, outcome) the business uses for its statistics. A visit nobody touches for 24 hours is closed automatically and the same clock then applies.
8.2 Everything else
| What | How long |
|---|---|
| WhatsApp message contents | 30 days |
| One-time join codes | A few minutes |
| Network address in an abuse counter | At most 15 minutes |
| Review-request marker (a one-way fingerprint, so a regular is not asked twice) | Up to 365 days |
| Messages your team sends each other | 7 days |
| Notifications about a support reply | At least 30 days (longer if the business keeps visitor data longer) |
| Notifications about a payment or refund | At least 90 days (same rule) |
| Other notifications | The business's visitor-data window |
| Support report screenshot and technical details | 30 days |
| Support report and its conversation | 1 year after the last message |
| Security log of account changes | 1 year |
| Owner, manager and staff accounts | While the business's account exists |
| A team member removed from a business | Their sign-in email and PIN are cleared at once; their username stays while the account exists, because past reports name it |
| Emails sent to us | Kept in our support mailbox; there is no automatic deletion, and we delete them on request |
| Website analytics | Kept by Google under our Analytics retention setting (at most 14 months) |
| Backups | About 8 weeks (section 8.4) |
8.3 When an account is deleted
- Closed by the owner: reversible for 7 days, then deleted.
- Lapsed (the trial ended without a card, or the subscription ended): deleted 90 days after it lapsed. An account that never added a card is deleted 90 days after it was created.
- Sign-in records. When an account is deleted, the sign-in record of everyone on it — their email address and, if they used Google, their name and picture — is deleted at our sign-in provider too. If the same email address also belongs to another business on turnda, it stays until that business is deleted as well.
What we still keep after deletion, and why — stated plainly:
- A stub of the account: the business name, its account code (so the code is never given to another business) and the leaving reason picked from our list. The recovery email and any words typed when leaving are erased.
- Payment records: amounts, dates, currency and Stripe reference numbers — no names or contacts — for our accounts and tax.
- Our own records about the account: the security log (until its 1-year clock), the support conversation (until 1 year after its last message), and records of data requests we handled (which identify the person only by a one-way fingerprint).
- Opt-out records: a one-way fingerprint of a phone number or email address that asked us to stop messaging, kept so we keep honouring it. They are not deleted.
- The trial card fingerprint: a one-way fingerprint of the card that started a trial (never the card number, never a name), kept so the same card cannot quietly start trial after trial. It is not deleted.
- Backups: see 8.4.
8.4 Backups, and what could be lost
We back up the whole database once a night and keep 14 daily and 8 weekly copies, so a copy of erased data can survive for about 8 weeks. Our database provider also keeps its own daily backups for 7 days. A backup also holds the sign-in records that existed on the night it was taken. Backups are private and used only to recover from a disaster. If we ever restore one, we re-apply every erasure made since that backup before turnda is used again. Because backups are nightly, up to 24 hours of data could be lost if our systems failed badly.
8.5 Support screenshots
A screenshot attached to a support report can show visitors' names if it was taken on a queue page. An erasure request cannot reach a name inside a picture, so the 30-day limit is what protects you: the screenshot is deleted 30 days after the report was made, whatever else happens.
9. Where your data is stored, and where it travels
- Stored in Frankfurt, in the European Union: the database, sign-in, files and backups (Supabase), and the application itself (Fly.io).
- Requests travel. When you open a turnda page, your connection is accepted at the server location nearest you and passed on to Frankfurt. So your data is stored in the EU; it is not true that it never leaves it.
- Some suppliers are elsewhere. Our job queue and abuse counters run at Upstash in Frankfurt, Germany (EU). Payments (Stripe), WhatsApp (Meta), email delivery (Resend, which sends from Ireland), our domain and incoming mail (Cloudflare), error monitoring (Sentry, Germany) and Google (sign-in, support mailbox, website analytics) may handle data in other countries, including the United States.
- How it is protected when it crosses borders. We use suppliers whose own data-processing terms commit them to protect it to a standard comparable to Singapore's law and, for data from Europe and the UK, include the standard contractual clauses approved for that purpose. turnda is a Singapore company, so data a European business gives us is itself transferred to Singapore under our Data Processing Agreement, which includes those clauses.
10. Your rights
You can ask us to:
- tell you what we hold about you and how we use it, and give you a copy;
- correct it;
- delete it;
- stop or limit a use of it, or move it to someone else, where the law gives you that right; and
- withdraw consent where something relies on it.
How to ask. Write to legal@turnda.com. If you joined a queue, tell us which business and the phone number or email you used. We may ask you to confirm the request comes from you (for example by replying from that email address). We reply within 30 days, and sooner where your law requires it. There is no charge.
If you joined a queue, we pass your request to the business, because it is in charge of your details — and we help it answer. An owner can find everything held about one visitor and erase it in one step. Erasure removes the name and contact, deletes notes, flags and comments, and blanks message contents, leaving only counts that carry nothing about you.
If you are unhappy with our answer, you can complain to your data protection regulator — in Singapore, the Personal Data Protection Commission; in Europe, your country's supervisory authority; in the UK, the Information Commissioner's Office.
11. Storage on your device
turnda.com and the Help Centre set no cookies, so there is no cookie banner.
The turnda app (the pages businesses and visitors use) sets no cookies either. It uses your browser's own storage only for things the page needs to work:
- for a business: keeping you signed in, the location and line you last chose, your language and display choices, and which tips you have already seen;
- for a visitor: your place in the line, so that reopening the join page takes you back to it instead of joining twice, and your language; and
- for a lobby screen: its pairing, so it reconnects after a restart.
The app also keeps a copy of its own files on your device so it loads quickly. None of this is used for advertising or to follow you elsewhere. Clearing your browser's storage removes it.
12. Security
- Each business's data is kept apart by the database itself, and an automated check refuses any new table without that protection.
- Every change made in an account is recorded in a security log that records what happened, not the personal details involved.
- Our logs and error reports are scrubbed: email addresses, phone numbers and keys are removed before anything is written, and our error monitor never receives personal details.
- There are no passwords. PINs and recovery codes are stored only as one-way fingerprints.
- Everything travels encrypted. Our database provider encrypts stored data.
- We are not SOC 2 or ISO 27001 certified, and no outside company has tested our security. Our testing so far is our own.
13. If something goes wrong
If personal data is lost, stolen or exposed, we act at once to contain it. We tell each business affected without undue delay and within 48 hours of becoming aware, with what we know, so it can meet its own deadlines. Where turnda is in charge of the data, we tell the regulator within the time the law sets (in Singapore, within 3 days of deciding it must be reported) and tell the people affected when the law requires it or the risk to them is serious.
14. Children
turnda is a tool for businesses and is not aimed at children. We do not knowingly collect children's details except where a parent or guardian joins a queue for them, or a business records a child's visit.
15. Changes to this policy
If we change this policy we will update the version and date above. For any change that affects businesses, we tell them at least 30 days beforehand by email and in the app, unless the law or a security problem requires it sooner.
Also see our Terms of Service, Data Processing Agreement and sub-processor list.