Privacy policy
How we collect, use, and protect your information.
Who this applies to
This policy covers shop owners and staff who create accounts on WiQ, and customers who check in via a WiQ kiosk or interact with the queue at app.walkinque.com and walkinque.com.
Information we collect
From shop owners and staff: name, email address, password (via Supabase Auth), shop name and business address, payment information (processed by Stripe — WiQ never stores card numbers), and usage activity like login times.
From customers checking in at the kiosk: first name (to identify position in queue), phone number (optional, used only for notifications if enabled by your shop), service selected, check-in timestamp, and loyalty visit history if your shop has that feature enabled.
Automatically collected: browser type, device type, IP address, pages visited, and error logs for platform reliability.
How we use your information
- ✓ Operate and maintain the WiQ platform
- ✓ Send transactional emails (account confirmations, password resets) via AWS SES
- ✓ Provide queue, loyalty, and analytics features to shop owners
- ✓ Respond to support requests
- ✓ Improve the platform based on usage patterns
- ✓ Comply with legal obligations
We do not sell your data. We do not use customer check-in data for advertising.
Data isolation
Each shop on WiQ operates in an isolated data environment enforced at the database level using row-level security policies. Shop A cannot access the data of Shop B. Staff accounts are scoped to the shop they belong to.
Data sharing
We share data with third parties only as necessary to operate the platform:
| Third party | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| AWS (SES, EC2) | Email delivery and application hosting |
| Stripe | Payment processing and identity verification |
| Google Places API | Business verification during shop registration |
Data retention
| Data type | Retained for |
|---|---|
| Shop owner and staff accounts | While active; deleted 90 days after cancellation or on request |
| Customer queue entries | 12 months from check-in date |
| Loyalty records | While the shop is active on WiQ |
| Payment records | As required by Stripe and applicable financial regulations |
Security
- 🔒 HTTPS/TLS encryption for all data in transit
- 🔒 Bcrypt password hashing for kiosk credentials
- 🔒 Row-level security on all database tables
- 🔒 Environment-scoped secrets and service role key isolation
If you believe you’ve found a security vulnerability, contact us at security@walkinque.com.
Your rights
Depending on your location, you may have the right to access, correct, delete, or export the personal data we hold about you, and to object to certain types of processing.
To exercise any of these rights, contact privacy@walkinque.com. We respond within 30 days.
Cookies
WiQ uses session cookies to keep you logged in. We do not use third-party tracking cookies or advertising cookies.
Children’s privacy
WiQ is not directed at children under 13. We do not knowingly collect personal information from children.
Changes to this policy
If we make material changes, we’ll notify account holders by email at least 14 days before the change takes effect. Continued use of WiQ after that date constitutes acceptance of the updated policy.
Contact
Privacy inquiries: privacy@walkinque.com
Security concerns: security@walkinque.com
Walk-in Que, Pittsburgh, PA
