SpotWait

Privacy Policy

Effective August 26, 2026. This policy explains how SpotWait collects, uses, shares, retains, and protects information through its website and web app.

Who this policy covers

SpotWait is published by Les entreprises Keenavio. SpotWait provides live-queue software to businesses and controls how account, website, billing, support, and service-security information is used. When a business uses SpotWait to manage its guests, that business decides what guest information to collect and why; SpotWait processes that information to provide the service on the business's behalf.

Information we collect

We may collect:

How we use information

We use information to authenticate users; create and administer workspaces; operate queues, QR joining, customer status, analytics, notifications, and billing; provide support; enforce plan limits; secure and troubleshoot the service; prevent fraud and abuse; comply with law; and improve SpotWait. Depending on the context, these activities are necessary to provide the service, support our legitimate operational interests, comply with legal obligations, or carry out a choice or consent.

Shopify and Clover integrations

The first marketplace release uses read-only business and location access to identify the installing merchant, connect the correct SpotWait location, verify installation and subscription status, and operate the integration. It does not request order, customer, product, inventory, or payment data. Marketplace OAuth credentials are encrypted at rest and used only for authorized provider API calls. Shopify or Clover may independently process billing and installation information under its own terms and privacy policy.

Google sign-in data

Google account data is used only to authenticate the user, identify the signed-in account, and personalize the SpotWait workspace. SpotWait does not request access to Gmail, Calendar, Drive, contacts, or advertising data through this sign-in flow. Google user data is not sold, used for advertising, or used to train generalized AI models.

Service providers and disclosures

We disclose information only as needed to operate SpotWait, follow a user's or business's instructions, complete a transaction, protect the service or its users, or comply with law. Current service providers include Supabase for authentication, database, storage, realtime, and functions; Vercel for web hosting; Stripe for direct website billing; Shopify and Clover/Fiserv when a business installs or pays through those marketplaces; Twilio when SMS is enabled; and authentication providers chosen by the user. These providers process information under their own service and privacy terms.

We may also disclose information in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and legal requirements. SpotWait does not sell personal information or share it for cross-context behavioural advertising.

Browser storage and analytics

SpotWait uses browser storage and similar technology for authentication, security, language and interface preferences, queue status, and first-party acquisition attribution. We may use privacy-conscious service analytics to understand feature use and reliability. SpotWait does not currently use third-party advertising cookies.

Retention and deletion

We retain account, workspace, queue, and guest information while the relevant account or workspace is active and for as long as reasonably needed to provide the service. Support, acquisition, security, and diagnostic records are kept only while needed for the request, business relationship, service integrity, or abuse prevention. Limited billing, transaction, tax, accounting, dispute, and security records may be retained longer where reasonably necessary or required by law.

When a marketplace integration is uninstalled or disconnected, SpotWait revokes or deletes its stored OAuth credentials and removes the marketplace entitlement. Limited installation, billing, webhook, and security records may remain where needed for service integrity, dispute handling, or legal obligations.

An account owner can request deletion from Settings or through the instructions at /delete-account. If the deleting owner is the only eligible workspace member, SpotWait cancels linked subscriptions and deletes the workspace's live application data. If another authorized member can take ownership, the workspace and its business data remain under that successor and the departing user's membership is removed. Residual copies may remain temporarily in provider backups until overwritten under the provider's normal backup cycle, and providers may retain records they are independently required to keep.

Your rights and choices

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to certain processing of personal information, withdraw consent, or appeal a request decision. You may update many account and business details in SpotWait or contact support. We may need to verify identity and workspace authority before completing a request. Authorized agents may submit requests where permitted by law. We will not discriminate against a person for exercising an applicable privacy right.

Guests should normally direct queue-data requests to the business that collected their information. SpotWait will assist that business where required.

International processing

SpotWait and its service providers may process information in countries other than the one where it was collected. Those countries may have different data-protection laws. We use contractual, technical, and organizational safeguards appropriate to the service and applicable law.

Security and incidents

SpotWait uses managed authentication, tenant access controls, encrypted transport, restricted administrative access, provider-signature checks, monitoring, and operational logging. No online service can guarantee absolute security. If a security incident affects personal information, we will investigate and provide notices required by applicable law.

Children

SpotWait business accounts are not directed to people who cannot legally enter a service agreement. A business that enters information about a minor is responsible for having the authority and any consent required to do so and for limiting the information to what is necessary for the queue.

Changes to this policy

We may update this policy as SpotWait, its providers, or legal requirements change. We will post the updated policy and effective date here and provide additional notice when a change is material and applicable law requires it.