PRIVACY POLICY
Last updated: July 5, 2026
1. Introduction
QueTie (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our QR music request and staff approval platform (“the Service”).
By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Staff Account Data
When a staff member creates an account, we collect:
- Email address
- Name (optional)
- Hashed password (never stored in plaintext)
- Organization and venue association
- Role within the organization (Founder, Owner, Admin, Staff)
2.2 Customer Session Data
When a venue guest scans a QR code and uses the Service, we collect:
- An anonymous session identifier (randomly generated, not linked to personal identity)
- Song requests submitted by the guest
- Votes cast on existing requests
- Session timestamps (first seen, last active)
Customer sessions are anonymous by design. We do not collect names, phone numbers, email addresses, or any personally identifiable information from venue guests.
2.3 Automatically Collected Data
Like most web services, we automatically collect certain information when you access the Service:
- IP address (used solely for rate limiting and abuse prevention)
- Browser type and version
- Pages visited and timestamps
- Referring URL
3. Soundtrack Credential Handling
When a venue owner connects their Soundtrack account to QueTie, the following process occurs:
- The owner enters their Soundtrack email and password through a secure, founder-only admin page.
- QueTie transmits these credentials directly to Soundtrack’s API over HTTPS to exchange them for access tokens.
- The returned tokens are encrypted using AES-256-GCM encryption with a key known only to the QueTie server.
- The encrypted tokens are stored in our database, scoped to the venue owner’s organization.
- The plaintext email and password are immediately discarded from server memory and are never written to disk, logs, or any persistent storage.
Soundtrack credentials are never exposed to venue staff below the Founder role, never shown in the admin dashboard after initial setup, and never transmitted to customer-facing pages.
4. How We Use Your Information
We use the collected information to:
- Authenticate staff users and maintain login sessions
- Process song requests, votes, and staff approvals
- Forward approved requests to the venue’s Soundtrack account
- Generate anonymous analytics (request counts, approval rates, popular tracks)
- Maintain audit logs for compliance and troubleshooting
- Prevent abuse through rate limiting
- Communicate service updates and changes to account holders
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
- Soundtrack API:Approved song requests are forwarded to Soundtrack’s API using the venue’s encrypted access tokens. No staff or customer personal data is included in these API calls.
- Service Providers: We may engage third-party companies to facilitate the Service (hosting, database, analytics). These providers have access to data only to perform tasks on our behalf and are obligated not to disclose or use it for any other purpose.
- Legal Requirements: We may disclose information if required to do so by law or in response to valid legal requests by public authorities.
6. Data Retention
- Staff accounts:Retained for the duration of the account’s existence. Deleted upon account termination.
- Customer sessions: Anonymous session data is retained for up to 90 days after the last activity for analytics and abuse prevention, then automatically purged.
- Song requests:Retained for the life of the venue’s account for audit and analytics purposes.
- Audit logs:Retained for the life of the organization’s account.
- Rate limit counters: Retained for up to 24 hours, then automatically expired.
7. Data Security
We implement industry-standard security measures to protect your information:
- Passwords are hashed using PBKDF2 with unique per-user salts
- Soundtrack access tokens are encrypted at rest using AES-256-GCM
- All data in transit is encrypted via HTTPS/TLS
- Session cookies are HTTP-only and SameSite-restricted
- Rate limiting is enforced on all authentication and API endpoints
However, no method of electronic storage or transmission is 100% secure. While we strive to protect your data, we cannot guarantee its absolute security.
8. Cookies
We use the following essential cookies:
- quetie_staff: An HTTP-only, SameSite-lax session cookie containing a signed user identifier. Required for the admin dashboard to function. Does not track users across sites.
- quetie_session: An HTTP-only, SameSite-lax cookie containing a randomly generated anonymous session identifier. Used to link song requests and votes to a venue visit without collecting any personal identity. Expires after 1 year of inactivity.
- quetie_human: An HTTP-only, SameSite-lax cookie set after successful completion of a human verification challenge. Prevents repeated challenge prompts during a single venue visit. Expires after 4 hours.
We do not use advertising cookies, analytics cookies, or any third-party tracking cookies.
9. Human Verification (Cloudflare Turnstile)
To protect the Service from automated abuse and spam, we use Cloudflare Turnstile for human verification on song request submissions. Turnstile is a privacy-preserving CAPTCHA alternative that runs non-intrusive browser challenges without collecting personal information or tracking users across sites.
When Turnstile is active on a venue page, Cloudflare may process certain technical data (such as browser characteristics and interaction signals) to determine whether the user is human. This processing is subject to Cloudflare’s Turnstile Privacy Addendum and Cloudflare Privacy Policy.
Turnstile is only loaded on venue pages where a guest submits a song request. It is not present on the landing page, admin dashboard, or any staff-only pages.
10. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Data portability
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
11. Children’s Privacy
The Service is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete it immediately.
12. International Data Transfers
Your information may be transferred to and processed on servers located outside of your country of residence. We take appropriate safeguards to ensure that your data remains protected in accordance with this Privacy Policy and applicable data protection laws.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify account holders of material changes via email or through the Service. The updated policy will be posted on this page with a revised date.
14. Contact
For questions about this Privacy Policy or our data practices: