Customer Privacy Policy
This Privacy Policy explains how QueueIn, a service operated by Effortless Engine Sdn. Bhd. (Company No. 202601018243 / 1680340-K) ("QueueIn", "we", "us"), and the business (e.g. clinic, café, or restaurant) that you are joining a queue with (the "Business") handle your personal data when you use QueueIn to join a queue, receive queue updates, or interact with related notifications including WhatsApp messages.
This policy is written for customers — the individuals who join queues. It is separate from any agreement that QueueIn has with the Business.
STOP at any time to turn off WhatsApp updates without leaving the queue.
1. Who is responsible for your data
QueueIn is a multi-tenant platform. Several parties may be involved in handling your data:
- The Business you are queuing with decides how its queue operates and which authorised staff can access queue records.
- QueueIn, operated by Effortless Engine Sdn. Bhd. (Company No. 202601018243 / 1680340-K), hosts the software, stores queue data, applies security controls, and delivers notifications for the Business.
- Meta Platforms, Inc. ("Meta") operates the WhatsApp Business Platform and processes information needed to transmit messages and provide delivery-status events under Meta's WhatsApp Business Policy and WhatsApp's Privacy Policy .
The legal controller/processor role can depend on the processing activity and applicable agreement. This policy describes what happens to your data without assigning one role label to every activity.
2. Personal data we collect
| Data | Source | Required? | Why |
|---|---|---|---|
| Name (or nickname) | You provide it on the join queue form. | Required | So staff can call you when it is your turn. |
| Mobile phone number (Malaysian +60 format) | You provide it on the join queue form. | Required | To send queue updates by push notification, in-app message, or WhatsApp. |
| Party size (number of people) | You provide it on the join queue form (if shown). | Optional / per outlet | So the Business can prepare the right capacity (e.g. table size). |
| Language preference (en / ms / zh) | Detected automatically from your browser; you can change it. | Automatic | To show the queue page and notifications in your language. |
| Consent records (timestamps, what you agreed to) | Recorded when you accept the queue privacy notice or send the pre-filled WhatsApp
Track message. |
Required where consent is collected | Evidence of your consent under PDPA. |
| Browser push token / device token (if granted) | Generated by your browser or device when you enable notifications. | Optional | To deliver in-browser queue updates. |
| Queue activity (queue number, join time, status) | Generated automatically as you use the queue. | Automatic | To run the queue and produce wait-time estimates. |
| Limited technical data (IP address, user agent, audit log entries) | Captured automatically by our servers. | Automatic | Security, abuse prevention, fraud detection, and PDPA audit obligations. |
We do not ask you for your identity card number, full date of birth, payment details, or login credentials.
3. Clinical and other information we do not collect
Some Businesses on QueueIn operate in healthcare settings (such as clinics). Queue participation may indirectly reveal a relationship with a Business, so we minimise the data used for WhatsApp updates and follow Meta's WhatsApp Business Policy .
QueueIn therefore commits to the following:
- We do not store the name of a specific doctor, dentist, therapist or practitioner you are visiting in any field that is sent to Meta or shown in queue notifications.
- We do not ask you about, store, or transmit your medical condition, diagnosis, symptoms, treatment, medication, or the clinic department / specialty you are visiting.
- We do not ask for your religion, ethnicity, political opinions, sexual orientation, or any other special-category data.
- WhatsApp messages from QueueIn are intentionally generic — for example, "Your turn is coming up", "Please head over now", or "You have been removed from the queue". They will not reveal sensitive context about why you are in the queue.
4. Why we use your data (purposes)
- To put you in the queue and show you your number, position and estimated wait.
- To notify you about queue events: turn coming up, called, no-show, queue closed.
- To deliver these notifications by your chosen channel: in-app status page, browser push notification, or (if you opt in) WhatsApp.
- To allow the Business to manage its operations — e.g. seat you, mark you as served, or record a no-show.
- If you choose to join the Business's VIP / loyalty list, to let the Business contact you again about future visits and offers.
- To keep the platform secure: rate-limiting, abuse detection, audit logging.
- To meet our legal obligations under PDPA, including responding to requests from regulators or law enforcement that have lawful authority.
- In aggregated / de-identified form only, to improve QueueIn's wait-time estimates and overall service quality.
5. Notice and consent
Before a public or kiosk queue join is accepted, you must affirm the QueueIn privacy notice. That acknowledgement is separate from the optional choices below:
- WhatsApp updates — you opt in only by sending the pre-filled
Trackmessage from WhatsApp. - VIP / loyalty list — where offered, this requires a separate choice.
We also process the minimum operational and security information needed to run and protect the queue service. QueueIn is built with PDPA-style consent and privacy-conscious data handling; this is not a claim of formal legal certification.
6. WhatsApp notifications — data sharing with Meta
Track <token> message to opt in for that
queue. Keeping the waiting page open works without WhatsApp.
What we share with Meta
- Your mobile phone number, so Meta can deliver our message to you on WhatsApp.
- The generic content of the message itself (e.g. "Your turn is coming up").
- Technical routing and delivery-status information required by the WhatsApp Business Platform.
What we do not share with Meta
- Your medical condition, treatment, or department.
- The name of any specific doctor, practitioner or staff member you are seeing.
- Your full identity card number, payment details, or login credentials.
- Clinical or treatment information.
How Meta uses the data
Meta processes the shared data under its own terms and policies to operate the WhatsApp Business Platform. Meta may process your phone number, generic queue updates, and related technical information outside Malaysia. See the WhatsApp Privacy Policy .
QueueIn sends free-form queue updates only within the current customer-initiated 24-hour WhatsApp service window. A future business-initiated message outside that window would require an approved WhatsApp template and the required permission.
Your right to opt out of WhatsApp notifications
At any time, you can stop receiving WhatsApp notifications from QueueIn by doing any of the following:
- Reply
STOP(orUNSUBSCRIBE,CANCEL,BERHENTI) to any WhatsApp message we send you. This disables WhatsApp updates for every active QueueIn queue linked to that sender under the same WhatsApp Business Account. - Block the QueueIn WhatsApp number from your phone.
- Contact us using the details in section 12. We will process the withdrawal and apply the retention schedule below.
Opting out of WhatsApp does not remove you from any queue. Each affected waiting page will
offer WhatsApp opt-in again. Sending a new Track message from one waiting page
restores updates only for that queue. To remove queue records as well, see the
Data Deletion Instructions.
7. Other people who may see your data
- Staff of the Business you are queuing with — they see your name, phone number, party size, queue number, and queue status, so they can serve you.
- QueueIn personnel — only authorised staff with a need to know, for support, debugging, and security investigations. Access is logged.
- Sub-processors we use to run the platform, under written contracts that
require them to protect your data:
- Cloud hosting and database providers (for storage and computation).
- Authentication providers (for the Business's staff login — not for customers).
- Push notification providers (e.g. Firebase Cloud Messaging) for browser notifications, if you grant permission.
- Meta Platforms, Inc., for WhatsApp message delivery, only if you opt in.
- Regulators or law enforcement, where we are required to disclose data by a valid legal request under Malaysian law.
We do not sell your personal data, and we do not share it with advertisers for advertising purposes.
8. Cross-border transfers
Meta and some infrastructure providers may store or process information outside Malaysia.
WhatsApp is optional: sending the pre-filled Track message allows Meta to process
your phone number and generic queue updates overseas for that service. QueueIn reviews vendor
terms and minimises the information sent, but cannot control Meta's own retention or processing.
9. How long we keep your data
| Data | Retention |
|---|---|
| Non-VIP queue customer data (name, phone, party size) | Directly identifying fields are minimised after the queue item is inactive and at least 24 hours old. Pseudonymous queue and operational records may be retained longer for service operation, security, and accountability. |
| VIP / loyalty list customer data (only if you explicitly opted in to that Business's list) | Retained while the Business's QueueIn account is active and you remain on the list, or until you ask to be removed. |
| Browser push / device tokens | Deleted shortly after the relevant queue item becomes inactive. |
| Waiting-link credentials | Waiting links stop working when their queue entry becomes inactive or its queue closes. Legacy signed links additionally expire after 24 hours. Short-link credentials are subsequently cleared from QueueIn's primary database by scheduled retention cleanup. |
| Active WhatsApp messaging authority | Expires immediately when QueueIn processes STOP or another supported
withdrawal keyword. Otherwise it expires at the applicable session expiry or queue
closure. |
| Minimised WhatsApp consent, withdrawal, outbound-outcome, and webhook replay/deduplication evidence held by QueueIn | Scheduled for hard deletion from QueueIn's live/primary database no later than 72 hours after the applicable event or terminal trigger. These records do not retain the raw message, raw recipient/phone number, or raw webhook payload. |
| Audit logs and security records | Routine logs are deleted after a short period (typically 30 days). Records connected to a security incident may be retained longer. |
The 72-hour schedule above does not promise deletion of copies held by Meta or another provider, and does not claim verified deletion from infrastructure backups. General security records, incident records, contracts, and non-personal governance documents follow separate schedules.
10. Your rights under PDPA
You have the following rights with respect to your personal data:
- Right of access — ask what data we hold about you.
- Right to correct — ask us to fix inaccurate data.
- Right to withdraw consent — for example, opt out of WhatsApp, leave a VIP list, or revoke consent for further processing.
- Right to limit processing — ask us to stop using your data for specific purposes such as marketing.
- Right to delete — ask us to delete your data, subject to legal obligations that may require us to keep some records (such as proof of consent).
- Right to lodge a complaint — with the Personal Data Protection Commissioner of Malaysia.
To exercise any of these rights, contact the Business directly (they hold your active queue data) or contact QueueIn using the details in section 12. For step-by-step deletion instructions, see the Data Deletion Instructions. We will respond within the timeframe required by PDPA.
11. Security
We protect your data with measures including:
- TLS encryption for all data in transit between your device, QueueIn, and Meta.
- Encryption at rest for personal data in our database, plus blind-indexed lookup columns so we can match records (e.g. find your queue by phone number) without storing readable copies.
- Role-based access control for Business staff, with audit logging of sensitive actions.
- Automatic minimisation of directly identifying non-VIP queue fields after the item is inactive and at least 24 hours old.
- A documented breach response procedure, including notifying the Business and, where required, affected customers and regulators.
12. Contact us
For privacy questions, requests under PDPA, or to opt out of any communication channel:
- Effortless Engine Sdn. Bhd. (Company No. 202601018243 / 1680340-K), operator of QueueIn — [email protected]; phone +601111550235.
- Or contact the Business you joined directly — their staff can also relay your request to QueueIn.
13. Children
QueueIn does not identify or verify whether the person in a queue is a patient, minor, guardian, or other dependent, and does not collect age or relationship documents. The person providing a contact number confirms they are authorised to receive generic queue updates at that number. Contact us if a number was provided without authority.
14. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page always reflects the current version. If a change is material (for example, a new category of data sharing), we will provide additional notice on the QueueIn join queue page or by direct notification before the change takes effect.