Skip to main content

Privacy Policy

Effective date:

Jonot is a cloud-based queue-management service. This policy explains what personal data we collect when you or your customers use it, why we collect it, how long we keep it, and the rights you have over it.

Who we are

The service is operated by Jonot Oy (business ID 3620928-7), a company registered in Finland ("Jonot", "we", "us" in this policy). For privacy matters:

  • Email: info@jonot.io
  • Postal: Jonot Oy, Tenavatie 11B, 00760 Helsinki, Finland

We have not appointed a Data Protection Officer — we are below the GDPR Article 37 thresholds that would require one — but the email above reaches the person responsible for privacy compliance.

What we collect, per role

Jonot is used by three groups of people, and we collect different data about each.

End Users (the people joining a queue)

  • Ticket hash: a random 22-character identifier that stands in for the End User. This is the only credential End Users ever hold — there is no account, no login, no email collected by default.
  • IP address: read at the edge for rate limiting and abuse protection (e.g. to stop one browser from flooding a queue). IPs are not stored in the queue database; they are held only in short-lived request logs.
  • Optional contact details: if the business has configured a kiosk or join flow that asks for a name or phone number (e.g. to call you when it's your turn), that value is stored against your ticket for the life of the queue session.

Staff Users (desk, admin, super-admin)

  • Identity: email, name, avatar, and a user ID. Jonot runs its own authentication on its EU database; your password is stored only as a salted hash — never in plain text, and never visible to us.
  • Permissions: the role(s) granted to your user (e.g. org-manager, desk) — verified on every request.
  • Action audit: a record of administrative mutations (create location, revoke device, etc.) tied to your user ID.
  • Request metadata: IP and user-agent captured in short-lived request logs.

Devices (kiosks, displays)

  • Device-session token hash: a one-way hash of the token we issued during pairing. We never store the raw token.
  • Pairing metadata: the location the device is bound to, a human-readable label, last-seen timestamps.

Why we collect it (legal basis)

Under the GDPR, every processing activity needs a lawful basis. Ours:

  • Contract (Art. 6(1)(b)): staff accounts, ticket issuance, kiosk pairing — all necessary to provide the service our paying Customer signed up for.
  • Legitimate interests (Art. 6(1)(f)): rate limiting, abuse prevention, request logs. Our interest in keeping the service up and fair is not overridden by the minimal intrusion of a short-lived IP log.
  • Consent (Art. 6(1)(a)): any optional contact fields an End User actively types into a kiosk form. You can withdraw consent at any time by emailing us.

Demo accounts

A demo account is a free, unpaid way to try Jonot end-to-end, including with real End Users (for example, a QR code scanned at a real counter). Activating one collects the same Staff User identity data described above, plus whatever End User data flows through the queues you configure — potentially real names and phone numbers, exactly as it would for a paying Customer. We collect the email address used to activate a demo account under legitimate interests (Art. 6(1)(f)), to operate a fair, time-limited free offering and to prevent abuse of it; End User data collected through a demo queue is processed under the same legal bases set out above for a paying Customer. As with a paying Customer, you remain the controller of that End User data, and our Data Processing Addendum applies to it on the same basis.

A demo account and everything inside it are deleted on a fixed, short schedule, not the paid-Customer schedule below: live ticket data after approximately 24 hours; an account that has issued no ticket after approximately 48 hours (logging in and the sample queue data we seed for you do not count as issuing a ticket); and the whole demo organisation — Staff User and End User data alike — approximately 7 days after the demo term ends. A demo account can be extended once, by a further 14 days; that later expiry is what starts the 7-day countdown, so the longest a demo account and its data can exist is approximately 35 days from activation. If you joined a queue that turns out to be a demo, this is the schedule your data follows; you can still reach us at info@jonot.io with any question about it.

Demo signup ledger. When a demo organisation is deleted, we keep one record identifying that a demo was already created from a given email address, so the same address cannot repeatedly activate new demo accounts to work around the term limit. That record holds a salted cryptographic hash of the normalised email address and a creation timestamp — never the plaintext address, and nothing else. Its basis is legitimate interest (Art. 6(1)(f)): preventing repeated circumvention of a time-limited free offering. We keep it for approximately 12 months from creation, independently of how long the demo organisation itself existed, and we decline erasure requests against it during that window, because the record is retained specifically to prevent the abuse that erasing it would re-enable (GDPR Art. 17(1)(c)). You are welcome to ask us about a specific entry and we will explain our reasoning.

Who processes it on our behalf

We rely on a small set of sub-processors to deliver the Service. Each is bound by a data processing agreement and may only process personal data on our instructions:

  • Cloudflare — hosting, database (D1), and edge compute. Queue and account data are stored in the EU (Western Europe); static assets and stateless compute are served from its global edge network.

Authentication and staff identity are handled in-house on our own EU database, not by a third party. Billing is handled by Polar as our merchant of record; Polar acts as an independent controller for payment data, not as our sub-processor. Creating an organisation — including a demo — registers a customer record with Polar containing the email address used at signup and an internal reference to the organisation, so Polar can recognise you if you later check out; nothing else is sent — no organisation name, no queue data, no End User data. Starting or extending a demo itself creates no subscription, no charge, and collects no payment details. We will update this list when our sub-processors change.

Where data is processed

  • Queue data: stored in the EU (Western Europe).
  • Static assets and application compute: served from a global edge network. Compute is stateless; no personal data is persisted at the edge.
  • Identity and authentication: handled in-house on our EU database (Western Europe).
  • Billing (via Polar, our merchant of record): may include transfers to the United States under the EU–US Data Privacy Framework.

Where a recipient is not certified under the EU–US Data Privacy Framework, the transfer instead relies on the European Commission's Standard Contractual Clauses; a copy of the clauses is available on request at info@jonot.io.

How long we keep it

  • Queue tickets: retained until the queue session is closed, then for 30 days for dispute resolution, then deleted.
  • Device sessions: retained until the device is revoked; revocation triggers immediate deletion of the token hash.
  • Staff account data: retained for the life of the organisation's subscription, plus 90 days after cancellation, then deleted from our database. Identity records, including the salted password hash, are part of this staff account data and are deleted on the same schedule.
  • Audit logs: 12 months.
  • Request logs: typically 7 days.
  • Demo accounts: live ticket data approximately 24 hours; an account that has issued no ticket approximately 48 hours; the whole demo organisation approximately 7 days after its term (including any single 14-day extension) ends — a maximum of approximately 35 days from activation. See Demo accounts above.
  • Demo signup ledger: approximately 12 months from creation, independently of the demo organisation's own lifecycle.

Your rights

If you're in the EU/EEA (and in most cases regardless of where you are), you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data (subject to legal retention obligations, e.g. invoicing records).
  • Export your data in a portable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent for anything you previously consented to (without affecting processing that already happened).

Email info@jonot.io to exercise any of these. We aim to respond within 30 days; the regulator's statutory limit is one month, extendable once by a further two months for complex cases.

If we're processing data on behalf of a Jonot Customer (for example, your employer), route the request to them first — they are the controller for that data and we act on their instructions.

Cookies and local storage

Jonot apps use browser storage sparingly:

  • Session storage for post-login return URLs so that after sign-in we send you back to where you came from. Cleared as soon as the redirect completes.
  • Identity tokens: ID and refresh tokens held in memory and in secure refresh cookies issued by Jonot's own authentication service.
  • Queue history on your device: the customer app stores your active ticket and a short list of the venues where you have joined a queue, so the installed app still has somewhere to go once your ticket is done. It stays in your browser, is never sent to us, and you can clear it from the app at any time.

We use Google Analytics on our marketing and signup websites and in our customer, staff, kiosk, and display apps to understand how the service is used. We collect the pages you visit, actions you take, the site you came from, and browser and screen information. Page addresses can include identifiers associated with organisations, queues, or tickets. This measurement can take place without cookies. Google also receives your IP address and browser information when your device contacts its services.

On our marketing and signup websites, Google also helps us measure the effectiveness of our advertising from the time you open a page. This measurement does not initially enable advertising cookies, but information about your visit and the advertisement that referred you can still be shared with Google. The marketing website does not enable them. These websites do not display a separate cookie consent banner.

From the second signup step onward, Google can use cookies and other browser storage for advertising measurement and personalised advertising. This also applies when you open or resume a later step directly, and can happen before you create an account or subscription. The signup flow does not offer a separate optional advertising choice. Some advertising cookies can also be used across other Jonot websites and apps.

When a subscription is confirmed, we share its reference number and available amount and currency with Google to measure which advertising leads to paid subscriptions. We also save subscription reference numbers in your browser to avoid counting the same subscription more than once. For Google's data practices, see How Google uses information from sites or apps that use our services.

Children

Jonot is a business-to-business service. We don't knowingly collect data from children under 16. If you believe a child has submitted data via a Customer's kiosk that shouldn't be there, email us and we'll delete it.

Changes to this policy

We'll update this policy as the service evolves. The effective date at the top of the page always reflects the current version; for material changes, we'll notify registered Staff Users at least 14 days in advance via email.

Complaints

If you're not satisfied with how we handle a privacy request, you can complain to a supervisory authority. In Finland that's the Data Protection Ombudsman (tietosuoja.fi). In another EU/EEA country, it's your local DPA.