1. Scope and controller
This Privacy Policy describes how QueueTempo handles personal information on its public website, authenticated Service, AI-assisted drafting, official social Connections, scheduling and publishing workflows, billing, support, and operations.
QueueTempo is the controller for the account, billing, support, and operational data it holds, and acts as a processor or service provider for customer-directed content that you supply and publish. Customers remain responsible for privacy notices and lawful authority relating to people described in their Customer Content.
2. Information QueueTempo processes
Account and authentication data
Name, email address, email-verification state, authentication method, password hash where applicable, session and recovery records, optional identity-provider identifiers, security events, and account preferences.
Organization and membership data
Organization name and domain, timezone, locale, settings, Billing Account, invitations, membership, roles, ownership changes, permissions, and audit events.
Brand and content data
Brand profiles, audience, products and services, voice traits, required or prohibited phrases and topics, factual claims, calls to action, hashtags, links, Content recipes, Knowledge sources, imported URL snapshots, source provenance, prompts, drafts, edits, posts, Variants, uploaded media, and alt text.
Social Connection data
Provider identity, authorized account and Channel identifiers, granted scopes, encrypted access and refresh tokens, token lifecycle, capability and health state, provider limits, OAuth state, revocation, and reconnect history. QueueTempo does not ask for or store social passwords.
Scheduling and publishing data
Tempos, recurrences, timezones, posting windows, exclusions, Occurrences, Queue items, approval decisions, consent records, attempts, provider response category, external post identifier and safe link, retry history, failure state, idempotency keys, and pause actions.
Billing and usage data
Stripe customer and subscription identifiers, plan and entitlement snapshots, billing-period state, checkout and portal events, invoice status, AI-credit ledger, publishing allowance, adjustments, and related audit records. Stripe, rather than QueueTempo, handles full payment-card details.
Support and communications
Organization, category, safe issue description, optional request or event ID, consent to retrieve redacted diagnostics, communications, delivery status, and any screenshot or attachment you deliberately provide after reviewing it.
Device, usage, and security data
IP address, user agent, request and correlation identifiers, approximate region where needed for security or routing, timestamps, route and action category, normalized error, duration, retry count, rate-limit state, session security, and consent or preference records.
3. How QueueTempo receives information
- directly from you when you create, configure, upload, write, or contact us;
- from members who invite or manage you inside an Organization;
- from social providers after official OAuth authorization;
- from Stripe and other service providers supporting the requested workflow;
- automatically from the Service for security, reliability, and audit;
- from public URLs you deliberately submit as Knowledge sources.
4. Why QueueTempo processes information
QueueTempo uses information to:
- create, verify, secure, recover, and support Accounts;
- enforce Organization membership, roles, and tenant boundaries;
- build Brand profiles and retain source provenance;
- generate, validate, moderate, and deduplicate requested draft Variants;
- calculate schedules and materialize Queue items;
- authorize, publish, reconcile, retry, and record provider outcomes;
- track consent, entitlements, credits, allowances, and billing state;
- send service, security, failure, connection, and billing notifications;
- prevent abuse, investigate incidents, and enforce policies;
- monitor performance, reliability, and queue health using minimized telemetry;
- comply with law, resolve disputes, and protect rights and safety.
Where a legal basis is required, QueueTempo relies on contract performance for the Service you sign up for, legitimate interests in securing and improving it, legal obligations where they apply, and your consent for optional marketing or non-essential analytics.
5. AI-assisted drafting and OpenAI
When you request AI drafting, QueueTempo can send the minimum selected brand context, source excerpts, Content recipe, destination constraints, and instruction needed to an AI provider. That provider is OpenAI, called only from server-side systems.
QueueTempo records safe model, prompt, Brand-profile, Content-recipe, and source provenance, but does not expose or store hidden model reasoning in customer logs. See the AI Disclosure.
QueueTempo does not use customer prompts, private brand facts, generated drafts, unpublished posts, uploaded media, or private analytics as general QueueTempo marketing inventory. QueueTempo does not use that content to train a QueueTempo-owned general model unless a customer separately and explicitly opts in to a future, clearly described program.
6. Sharing and subprocessors
QueueTempo shares information only as needed for the requested Service, security, legal compliance, a business transaction with appropriate safeguards, or at your direction. These are the categories involved:
| Category | Purpose | Provider |
|---|---|---|
| Hosting and compute | Serve pages, APIs, and durable work | Vercel |
| Database | Store Account, Organization, queue, audit, and billing records | Managed PostgreSQL provider |
| AI | Create requested draft Variants and moderation signals | OpenAI |
| Payments | Checkout, subscription, invoice, and billing portal | Stripe |
| Verification, recovery, alerts, and support communications | Transactional email provider | |
| Object storage | Private customer-provided media and secure delivery | Managed private object storage |
| Monitoring | Redacted errors, performance, alerts, and traces | Application monitoring provider |
| Social platforms | Authorize and publish at your direction | X, Meta/Instagram, and any later supported provider |
The subprocessor list names each provider, its purpose, its relevant location, and the change-notice process. QueueTempo does not sell personal information or share it for cross-context behavioral advertising.
7. Logging and telemetry privacy
Normal structured logs may use opaque Account and Organization identifiers, request and work identifiers, provider, normalized state or error, duration, and retry count.
Normal logs must not contain:
- access or refresh tokens, passwords, reset links, or authentication cookies;
- Stripe secrets or full payment details;
- full customer prompts, Knowledge sources, or drafts by default;
- signed asset URLs, webhook secrets, or full signatures;
- full email addresses except in a restricted workflow that requires them.
8. Retention
QueueTempo retains information only as long as needed for the Service, security, audit, support, legal, and contractual purposes. The current defaults are:
- authentication and security logs: up to one year with restricted access;
- Organization audit logs: by plan, with a minimum of 30 days;
- failed raw provider payloads: avoided or redacted and retained only briefly;
- deleted Organization active data: purge within 30 days after a grace period, subject to legal or security hold;
- OAuth tokens: revoke or delete promptly on disconnect or deletion;
- unreferenced uploaded media: purge after a defined grace period;
- encrypted backups: age out under a documented backup-retention schedule;
- billing, fraud, tax, and transaction records: as required by law and legitimate accounting needs.
9. Your choices and rights
Depending on your role, location, and applicable law, you may be able to:
- access, correct, or update Account and Organization information;
- export Account or Organization data in a usable format;
- disconnect a provider and revoke or remove its tokens;
- delete or archive an Organization subject to owner, retention, and hold rules;
- close an Account after resolving ownership and billing obligations;
- object to or restrict certain processing;
- withdraw consent for optional processing without affecting earlier lawful processing;
- appeal or contact a regulator where applicable.
Organization Owners may control business data on behalf of their Organization. QueueTempo may need to direct a request to the relevant Organization when it acts as a processor or service provider.
10. Security
QueueTempo’s required controls include secure sessions, email verification, recent authentication for sensitive changes, server-enforced roles, Organization scoping, CSRF and origin defenses, least-privilege OAuth, encrypted tokens, signed webhooks, safe outbound requests, private media, redacted logs, rate limits, audit trails, backups, testing, and monitored incident response.
No system is perfectly secure. The Security pagesets out the controls QueueTempo operates and is explicit about which third-party certifications it does and does not hold.
11. International transfers
QueueTempo and its providers may process information in countries other than yours. Where a transfer requires safeguards, QueueTempo relies on approved mechanisms such as standard contractual clauses, and lists material processing locations alongside the subprocessors above.
12. Children
QueueTempo is a business publishing tool and is not directed to children. You must be at least 18, or the age of majority where you live, to hold an Account. QueueTempo does not knowingly collect personal information from children; if you believe a child has provided information, contact QueueTempo Support and it will be deleted.
13. Published content and third parties
Content that you publish to a social platform is processed by that platform under its own terms and privacy policy. Disconnecting or deleting QueueTempo data does not automatically remove content already accepted and retained by an external platform.
14. Incidents
QueueTempo requires a documented incident process for containment, investigation, recovery, evidence preservation, provider coordination, and legally required notice. Security-critical notices remain visible in the application if email delivery fails.
15. Cookies and marketing
Service communications are separate from marketing consent. QueueTempo does not need advertising cookies to provide the Service. See the Cookie Notice for essential storage and the rules that must apply before optional analytics is enabled.
16. Changes and contact
QueueTempo will date material updates and provide notice where required. The final policy will identify the legal entity, mailing address, monitored privacy contact, and any required regional representative or data-protection contact.
Until those details are published, use thesecurity or privacy support category for questions without including passwords, tokens, cookies, payment details, or unrelated private content.