Skip to main content
Legal

Privacy Policy

Effective August 23, 2026

ezpila helps businesses run a queue. That means we handle two very different kinds of people’s information: the business owners and staff who hold accounts with us, and the customers who join a business’s line. This policy explains both, in that order, and it applies to our website and app.

The short version: we collect the minimum a queue needs, we never sell personal information, and every business’s data is isolated from every other business’s.

1. Who is responsible for what

For account holders, ezpila is the personal information controller.

For the customers who join a queue, the business running that queue is the controller and ezpila is its processor: we hold and process that data on the business’s instructions. If you joined a line and want your details removed, the fastest route is to ask that business; you can also write to us at privacy@ezpila.com and we will pass the request on and help.

2. What we collect

From business owners and staff

  • Identity and sign-in: name, email address, and authentication details, handled by our identity provider. We never see or store your password.
  • Business profile: business name, branches, queues, service settings, plan tier, and team membership.
  • Operational records: the tickets your queues issue and the actions taken on them (called, served, skipped), used for the live board and wait estimates.
  • Technical data: IP address, browser and device type, and timestamps, kept in server and security logs.

From customers joining a queue

  • Whatever the business asks for on its join form — typically a name or nickname, and sometimes a mobile number so you can be notified or called.
  • Your ticket: the number issued to you, the queue, and the times it moved between states.
  • Technical data: IP address and device type, used to rate-limit the public join endpoints against abuse.

Customers do not need an account, and we do not build advertising profiles of them.

What we never ask for

We do not collect payment card numbers on our own servers, government ID numbers, precise location, or the sensitive personal information categories defined by the Data Privacy Act — health, religion, ethnicity, and the rest. Please do not put such details into a customer name field.

3. Why we process it, and on what basis

  • To provide the Service — issuing tickets, showing the live board, letting staff call the next customer. Basis: performance of our contract with the business; for customers, the legitimate interest of being served in turn, or the business’s own basis.
  • To keep the Service safe — rate limiting, abuse detection, and audit logs. Basis: legitimate interests.
  • To support you — answering your emails. Basis: contract and legitimate interests.
  • To bill paid plans and meet accounting duties. Basis: contract and legal obligation.
  • To improve the product — aggregated, non-identifying usage patterns. Basis: legitimate interests.

We do not use your data or your customers’ data to train advertising models, and we do not sell it to anyone. Ever.

4. Who we share it with

Only with service providers that make the product work, each bound to confidentiality and to processing data only on our instructions:

  • Authentication — our identity provider, for sign-in and account security.
  • Hosting and delivery — our application hosting provider.
  • Database — our managed Postgres provider, where your queue data lives.
  • Email — for transactional messages such as invitations and receipts.

We may also disclose information where the law requires it, to protect people’s safety or our rights, or to a successor if the business is merged or acquired — in which case this policy travels with the data.

5. Where your data is stored

Our providers may store and process data on servers outside the Philippines. Where that happens we rely on contractual safeguards requiring a level of protection consistent with the Data Privacy Act.

6. How we protect it

  • Encryption in transit (HTTPS) everywhere, and encryption at rest at the database layer.
  • Tenant isolation: every query is scoped to one organisation in application code, with row-level security policies in the database as a second, independent barrier.
  • Role-based access — owner, manager, assistant — so staff see only what their role needs.
  • Rate limiting on the public join endpoints.
  • Least-privilege access for our own team, granted only when needed to operate or support the Service.

No system is perfectly secure. If a breach occurs that is likely to seriously harm affected people, we will notify the National Privacy Commission and those affected within 72 hours of knowing, as the Data Privacy Act requires.

7. How long we keep it

  • Ticket history: for the retention window of the business’s plan, after which it is deleted or reduced to non-identifying counts.
  • Account and business records: for as long as the account is open, then deleted or anonymised within 30 days of closure.
  • Security and server logs: a short rolling window, typically 30 days.
  • Billing records: as long as tax and accounting law requires.

8. Cookies and local storage

We keep this deliberately boring. ezpila uses:

  • Session cookies to keep you signed in and to remember which organisation you are working in.
  • Local storage and a service worker to make offline mode work — this stores your queue data on your own device so the line keeps moving without a connection.

These are strictly necessary to run the Service. We do not use advertising or cross-site tracking cookies. Clearing your browser storage will sign you out and discard anything not yet synced.

9. Your rights under the Data Privacy Act

If you are in the Philippines, Republic Act No. 10173 gives you the right to be informed, to object, to access your data, to correct it, to have it erased or blocked, to damages, to data portability, and to lodge a complaint with the National Privacy Commission.

To exercise any of these, write to privacy@ezpila.com. We will respond within 30 days. We may need to verify who you are first, so that someone else cannot request your data.

If you are unhappy with our response you may complain to the National Privacy Commission at privacy.gov.ph.

10. Children

The Service is for businesses and is not directed at children under 18. We do not knowingly collect their information beyond a name on a queue ticket handed over by a parent or guardian. If you believe a child’s data has reached us in another way, write to privacy@ezpila.com and we will remove it.

11. Changes to this policy

When we change this policy we update the effective date above, and for material changes we notify account holders in the product or by email before the change takes effect.

12. Contact us

Privacy questions and data requests: privacy@ezpila.com. Anything else: support@ezpila.com.

Privacy Policy · ezpila