Legal
QueueMaster Privacy Policy
Effective September 1, 2026. This policy covers QueueMaster on fourthcanal.com, including its lobby routes under /queue.
Information we collect
Lobby owners, admins, and staff candidates sign in through Fourth Canal's Google authentication. QueueMaster uses the profile ID, Google account name, and email needed to identify lobby membership and staff-promotion requests. Guests provide only a first name and desk or car location.
Guest session
QueueMaster stores a random HttpOnly, SameSite=Lax browser cookie for up to 30 days so a guest can resume an active lobby. The database stores only a SHA-256 hash of that token, never the token itself.
How information is used
- Operate the queue, display approved public guest fields, and keep views synchronized.
- Authorize lobby owners, admins, staff candidates, and individual guests.
- Record minimal queue transition events for safety and troubleshooting.
Realtime privacy
Realtime events contain only the lobby ID and revision. They do not contain names, emails, locations, guest tokens, session IDs, or promotion-request IDs. Clients refetch the snapshot they are authorized to see.
Retention
Abandoned active entries expire after 12 hours; completed, cancelled, and no-show entries after 24 hours; guest sessions after 30 days. Closed staff candidate and promotion-request records are retained for 30 days. Operational backups may persist for the provider's normal backup window.
Public site measurement
Fourth Canal uses Vercel Web Analytics and Speed Insights on public QueueMaster information pages to understand basic traffic and performance. QueueMaster excludes dashboard, lobby, authentication, and API paths from this measurement and removes query strings before an event is sent. Participation analytics, individual queue reports, billing, and SMS are not implemented.
Support requests
If you use the support form, QueueMaster receives the category, message, optional name, reply email when supplied, and page path. Cloudflare Turnstile helps prevent abuse. A keyed, non-reversible request fingerprint is used for hourly rate limiting; the form should not contain patient information, grades, passwords, or other sensitive records.
Service providers
QueueMaster uses Fourth Canal's existing Google sign-in, Supabase authentication/database/realtime services, Vercel deployment and public measurement, and Cloudflare Turnstile on the support form. These providers process limited data needed to deliver their services.
Your choices
You can use guest check-in without a Google account, leave a waiting queue, decline a staff request, and opt out of public analytics in this browser by setting the Fourth Canal analytics opt-out preference. Contact support for an access, correction, or deletion request where applicable.
Questions
Use QueueMaster Support for privacy questions. Do not submit medical, educational-record, or other sensitive information through lobby names or queue fields.