Security & privacy

Your customers' data, handled properly

Everything on this page is something turnda does today. Where we have not earned a claim yet, we say so further down rather than putting a badge on it.

Every business is isolated at the database level

turnda uses Postgres row-level security, forced on tenant data. That means the isolation is enforced by the database itself rather than by application code remembering to add a filter — the usual way this kind of thing goes wrong. An automated check runs in the release gate every change has to pass, and it refuses to pass if a tenant table is ever added without that protection — so it cannot quietly regress.

We collect only what a queue needs

Every visitor field — name, phone, party size, a note — is a switch the merchant controls, and each is off unless it is turned on. If your front desk does not need a phone number, do not ask for one. turnda is not a records system and holds no clinical, financial or identity data about your visitors.

Privacy on the lobby screen is enforced, not hidden

A display set to numbers-only is never sent the names in the first place — the restriction is applied where the data is read, not by hiding text in the page. That matters in a waiting room, where a screen is visible to everyone in it.

Secrets and personal data stay out of the logs

Our own logs are scrubbed before they are written: values that look like an email address, a phone number or a key are redacted, and sensitively-named fields are removed at any depth. Crash reports sent to our error monitor are separately restricted — its personal-data collection is switched off and the variables inside a stack frame are never transmitted. So the operational trail your data passes through does not accumulate copies of it.

One channel failing does not take the product down

The free tracking link is the primary way a customer sees their turn; WhatsApp and email are best-effort extras on top. If a messaging channel has an outage — or a location reaches its monthly allowance — the tracking link keeps working, so nobody is left without a way to know it is their turn.

PDPA and GDPR-shaped, with real deletion

We support data-subject requests, and the things you put in — your business details, your branding — can be cleared by you rather than only by us. If you stop paying, your data is kept for 90 days so you can return, and can be removed on request.

A pasted logo link is loaded from someone else's server

If you upload your logo, it is stored by us and served by us, and nobody else is involved. If instead you paste a link to your logo on another website, your customers' browsers fetch that image directly from that website — which means that website can see your customers' IP addresses. We do not choose it and have no agreement with it, so it is not on our sub-processor list and cannot be. Uploading avoids this entirely, and it is the option we recommend.

Sub-processors

One list, kept in one place

The complete list of companies that process data on turnda's behalf — what each one does, what it can see and where it is — lives on its own page. We update it before adding anyone, and email every business at least 14 days ahead.

See the sub-processor list
Being straight with you

What we do not claim

Trust pages usually list only the wins. Here is the other half — the things a careful buyer should know we have not done yet. If any of them is a blocker for you, tell us and we will give you a straight answer rather than a roadmap promise.

Ask us a security question
  • We are not SOC 2 or ISO 27001 certified. We will say so when we are, and not before.
  • We have not commissioned an external penetration test. Our security work so far is internal adversarial auditing.
  • Our Data Processing Agreement is part of what every business accepts at sign-up, and we will sign a copy on request. We do not offer a negotiated enterprise agreement or a security-questionnaire process.
  • We have no uptime SLA. The product is designed to degrade gracefully rather than to promise a number we cannot yet stand behind.

Security questions we get asked

Can one business ever see another's data?

No. Isolation is enforced by the database through row-level security, and an automated test fails the build if a tenant table is ever introduced without it. It is not left to application code to remember.

Where is our data stored?

In Frankfurt, in the EU. Your data is held in a managed Postgres database run by Supabase; the application itself runs on Fly.io in the same region. If your regulator requires a specific region, tell us before you sign up rather than after — we would rather say no than mislead you.

Do you store card details?

No. Payment details go directly to Stripe. turnda never receives or stores a card number.

What happens to our data if we leave?

That depends on how you leave. If you close the account yourself, you can reverse it for 7 days — after that it is permanently deleted. Before you close, take what you need: your setup exports as a file at any time, and every report downloads as CSV, Excel or PDF. Individual visit records are not in the export, because we delete visitors' details on the retention window you set rather than storing them long-term. If you simply stop paying, we keep the account for 90 days so you can come back without redoing your setup. Either way you can ask us to delete it sooner. Nothing is sold, and nothing is used to train anything.

How long is visitor data kept, and do backups follow the same clock?

You choose the window — anything from 24 hours to a year, and it is 48 hours unless you change it. When it expires the name and contact are erased and any notes or flags are deleted outright. Backups are the honest exception: we take one nightly and keep 14 daily and 8 weekly copies, so a copy can survive for around eight weeks after it is gone from the live system. Backups are private, used only to recover from a disaster, and never for anything else.

If we send you a screenshot with a support report, what happens to it?

It is stored privately, and only we can see it — it is not public and not shared. We said here that support reports never expired and promised to tell you when that changed. It changed on 19 August 2026: the screenshot and the technical details attached to a report are now erased 30 days after it is made, and a closed report is deleted in full after a year. Both happen automatically. One part is still true and we would rather say it: erasing a visitor's data does not reach a support report you sent us weeks earlier — the 30-day window is what limits how long such a screenshot exists at all. So it is still worth avoiding a screenshot that shows a guest's details.

Can we get our data out?

Yes, from inside turnda: your setup exports as a file at any time and every report downloads as CSV, Excel or PDF. Visitor details are deleted on the window you set, so individual visits are not kept to export. For one visitor, an owner can find and erase everything we hold in one step.

Do you have a security contact?

Yes — email security@turnda.com and it reaches a person, not a queue. It is the address published in our security.txt (at /.well-known/security.txt), and it is for vulnerability reports and nothing else. If you believe you have found a vulnerability, please tell us before disclosing it publicly and we will work with you.

Also see our privacy policy and terms.

Try it with your own data.

A 30-day free trial, and everything on this page applies from the first minute.

Start 30-day free trial

Or sign in · works worldwide · cancel anytime