Trust

Security at QueueEZ Retail

Last Updated: 11 July 2026

QueueEZ Retail manages your queue, your team's rotas and your store's performance data. We treat all three as commercially sensitive, and we designed the platform so that the safest option is also the default. This page explains, in plain English, how your data is protected. For how we handle personal data, see our Privacy Policy.

1) Your business data stays yours

Every business on QueueEZ Retail lives in its own isolated workspace. Queue history, serve times, conversion figures, advisor KPIs, rotas and analytics are stored under your workspace alone, and our access rules are enforced server side on every single read and write. There is no query path from one customer's workspace to another's.

  • Performance and queue analytics are readable only by your signed‑in staff.
  • Competitors, customers and the public cannot access your figures.
  • Reporting integrations are read‑only and scoped to your workspace with OAuth.

2) Customer data minimisation, by design

Customers join your queue with a first name and what they need help with. No account, no email, no payment details. The public queue-position feed your customers' phones read is deliberately nameless: it contains positions and counts only, so nobody can harvest who is waiting in your store.

  • Push notification tokens are stored per visit and deleted automatically when the visit ends.
  • Wait estimates are calculated on our servers; the underlying serve history is never exposed to customer devices.
  • We do not send SMS. Customer alerts use push notifications and on‑page updates only.

3) Access control inside your business

Staff sign in with individual accounts and role‑based permissions. Privileged operations, such as changing a team member's role, are executed server side and cannot be performed by editing data directly. Multi‑store businesses can scope staff to their own store.

4) Infrastructure and encryption

QueueEZ Retail runs on Google Cloud (Firebase), with our server compute hosted in London (europe‑west2). All data is encrypted in transit (TLS 1.2+) and at rest by Google's infrastructure, which holds ISO 27001, SOC 1/2/3 and other independent certifications. Data is automatically replicated across multiple availability zones.

5) Operator access

Like any managed platform, our engineering team holds administrative access to the infrastructure. That access is limited to what is needed to operate and support the service, is protected by multi‑factor authentication, and is used only for support, debugging and data‑recovery work, never for analysing or sharing a customer's business data.

6) Retention, export and deletion

  • Customer visit push tokens: deleted at the end of the visit.
  • Your operational data (queue history, performance, rotas): retained while your subscription is active, and exportable from within the product (CSV reports, rota exports).
  • Account deletion: available in‑product via our account deletion page; associated workspace data is removed as described in the Privacy Policy.

7) Subprocessors

We keep our supplier list short:

  • Google Cloud / Firebase – hosting, database, authentication, push delivery (Android and web)
  • Apple – push notification delivery to iPhones (APNs)
  • Postmark – transactional email (account verification, invites)

8) GDPR and data processing

Greenstone Technologies Limited is a UK company and QueueEZ Retail is operated in line with UK GDPR. For your customers' personal data, you are the data controller and we act as your data processor. A Data Processing Agreement is available on request at support@greenstone-technologies.com.

9) Reporting a security concern

If you believe you have found a vulnerability in QueueEZ Retail, please email support@greenstone-technologies.com with the details. We investigate every report and will keep you informed. Please do not access data that is not yours while demonstrating an issue.

Questions from your IT or compliance team? We're happy to walk through any of the above – get in touch.