1. Scope
This draft applies to Turnli’s browser-based queue and waitlist service, including business workspaces, public joining, private Customer Status, TV Queue, Kiosk, restaurant Tables & Floor, business branding, and related administration features.
2. Information Turnli handles
Business account and workspace information
Turnli may process account identifiers and business configuration needed to operate a workspace, such as business name, workspace mode, service configuration, team memberships and roles, operating settings, locations, and business branding settings.
Queue and customer information
When a business or customer creates a queue entry, Turnli may process information the workflow collects, including customer or party name, phone number, email address when enabled, party size, selected service, notes, queue position/state, timestamps, destination or table assignment, and private status identifiers.
Restaurant and operational information
For restaurant workspaces, Turnli may process table names, table capacity, table status, saved floor coordinates, seating state, and related operational timestamps. Turnli also stores operational and audit events required to keep the product reliable and trace important changes.
Business branding uploads
Businesses may upload a logo or background image. Turnli stores the uploaded asset and the workspace branding configuration used to display it on supported customer-facing surfaces.
Technical information
The application may generate technical information needed to operate, secure, diagnose, and improve the service, such as browser/runtime details, connection state, error information, authentication/session events, and application telemetry configured by the current product.
3. How information is used
Turnli uses information to provide the queue service, synchronize state in realtime, generate private customer status, support QR and kiosk joining, display public queue information safely, operate Tables & Floor, enforce workspace roles and plan limits, support administrators, detect failures, and maintain security and auditability.
4. Business and customer relationship
Businesses decide what customer information they collect through Turnli within the options the product provides. Businesses are responsible for using Turnli and customer information lawfully, providing any notices required for their own operations, and limiting access to authorized team members.
5. Infrastructure and service providers
Turnli uses Supabase for authentication, database services, realtime synchronization, and storage. Turnli uses Stripe to process paid subscriptions, invoices, and billing-account management. Stripe receives the payment and billing information needed to provide those services; Turnli does not store full card numbers.
6. Security
Turnli uses authentication, role-based authorization, Row Level Security where applicable, protected backend operations, private customer status identifiers, and audit controls in the current architecture. No internet service can guarantee absolute security, and the final policy should describe the security commitments appropriate for the launched service.
7. Retention
Turnli keeps information for as long as reasonably needed to operate the service, preserve workspace data, support security and auditing, and meet product or legal requirements. Product plan settings may limit how much history is available in the application. Downgrading a plan is designed to preserve business data rather than automatically delete it. Final retention schedules should be reviewed before launch.
8. Customer-facing public information
Turnli is designed so public queue displays use privacy-safe identifiers rather than exposing full private queue records. Private Customer Status uses a private ticket identifier. Businesses should still avoid entering unnecessary sensitive information into free-form notes.
9. Access, correction, and deletion requests
Business users can update many workspace settings through Turnli. A final policy must identify the verified contact process for privacy, access, correction, and deletion requests and explain any jurisdiction-specific rights that apply to Turnli at launch.
Owner/legal review item: Add the final legal entity name, legal/privacy contact method, any required mailing address, jurisdiction-specific rights language, and final retention schedule before launch.
10. Changes to this policy
Turnli may update this policy as the product, infrastructure, or legal obligations change. The final version should state how material changes are communicated and identify the effective date.