Archived Privacy policy
QueueRove Privacy Policy
This policy explains what data QueueRove collects and why, and separates QueueRove-controlled account data from device-local mobile data and customer-controlled HaloPSA records.
- Version 2026-08-02.1
- Effective date: August 2, 2026
- SHA-256
790f40d65b7b3d11b0eaaed9a93628214f3d3bdf5e752232f173f95e61f9fd1a
Archived version
This is the current published version of this document. Material changes receive a new immutable version, a new content hash, and an archive entry.
The content hash is derived from the versioned structured source rendered on this page. Material changes receive a new version, an archive entry, and, where required, reacceptance.
View the current stable route → · View all archived documents
1. Scope and roles
ITECS Outsourcing, LLC operates QueueRove and is responsible for the QueueRove-controlled data described in this policy. An MSP organization remains responsible for its users, its business instructions, and its own systems, including its HaloPSA environment.
HaloPSA records are outside this policy's control-plane scope
The QueueRove control plane does not store HaloPSA tickets, customer records, notes, photos, time entries, or credentials. The mobile apps connect directly to the customer-configured HaloPSA environment, and that data is governed by the customer's agreement with HaloPSA.
2. QueueRove-controlled data
- Account identity and profile data, including provider issuer/subject identifiers, name, email, identity-verification state, and security state.
- Organization, membership, composable grants, primary Owner, invitation, named technician assignment, licensed-capacity, and active-organization context data.
- Session metadata, MFA recency, security events, immutable audit events, abuse controls, request identifiers, and application/access logs.
- Billing projections, entitlement transitions, invoice references, tax and contract evidence, and provider object/event references; QueueRove does not store complete card details.
- Legal versions and acceptance evidence, including exact version, effective-date status, and content hash.
- Privacy, export, correction, deletion, support, security, and 50+ sales intake records and correspondence.
- Essential session, invitation, security, and checkout cookies when the applicable feature is enabled.
3. Mobile app data
The QueueRove iPhone and Android apps sign in through the QueueRove control plane to verify identity and licensing. The apps store HaloPSA connection settings, access credentials, working caches, and queued tickets and time entries locally on the device so technicians can keep working with limited connectivity.
Ticket and time-entry content moves directly between the device and the customer's HaloPSA environment; QueueRove servers do not store that content. Uninstalling the app or clearing its data removes device-local state, so confirm queued work reached HaloPSA first. The apps do not include advertising or third-party analytics SDKs.
4. Sources and purposes
Data may come from the user, an authorized organization administrator, the identity provider, configured billing and email providers, the application, and security/operations processes. QueueRove uses it to authenticate users; isolate organizations; authorize roles and seats; administer invitations, billing, entitlement, privacy, support, and legal acceptance; prevent abuse; reconcile state; provide notices; and meet legal and recordkeeping obligations.
QueueRove does not use analytics, advertising, tracking pixels, or non-essential cookies. If that changes, this policy will be updated first and consent obtained where required.
5. Disclosure and subprocessors
QueueRove discloses only the data needed to the service providers on the Subprocessor List, the relevant MSP organization, professional advisers, authorities when lawfully required, or a successor in a lawful transaction. QueueRove does not sell personal data or share it for cross-context behavioral advertising.
The public Subprocessor List identifies the service providers used to operate QueueRove. The DPA defines the narrow processing scope offered for customer agreements.
6. Retention
| Data class | Retention |
|---|---|
| Active identity, organization, membership, and assignment | Until applicable deletion completes, subject to holds |
| Billing, tax, refund, invoice-reference, and contract records | 7 years |
| Terms and commercial acceptance evidence | 7 years after organization closure |
| Audit and security events | 24 months unless held |
| Privacy and deletion request evidence | 24 months |
| Support records | 24 months |
| Terminal invitation email and delivery metadata | 90 days |
| Expired/revoked encrypted session payload | 24 hours |
| Minimal expired/revoked session metadata | 90 days |
| Application and access logs | 30 days |
| Rate-limit and abuse-control records | 90 days |
| General Stripe webhook and idempotency evidence | 24 months |
| Financially required Stripe event subset | 7 years |
| Generated export artifact | 24 hours |
| Encrypted backups | 35 days with deletion tombstones reapplied after restore |
| 50+ sales lead | 12 months unless converted or another lawful retention applies |
7. Access, correction, export, and deletion
Every user may request access, correction, personal export, or personal deletion. Only the primary Owner may request an organization export or deletion. Authenticated exports require recent MFA, are delivered as encrypted authenticated control-panel artifacts, and expire after 24 hours. QueueRove does not email export attachments or use bearer-only public links.
The public Account Deletion intake is for locked-out or uninstalled users. It is non-enumerating and requires identity verification before QueueRove reveals or changes account state. Email or a support ticket alone is not deletion authority.
8. Deletion boundaries
- A personal request cannot complete while that person is the primary Owner of any organization; automated ownership transfer is not currently available.
- Organization deletion has a 7-day cooling-off period and a 28-day completion target after identity verification, subject to lawful holds or permitted extensions.
- Completion distinguishes deleted, anonymized, retained with category/reason, provider-controlled, and outside-QueueRove data.
- QueueRove does not claim deletion of legally retained financial evidence, device-local data, HaloPSA data, backups before their cycle completes, or data controlled by another party.
- Device-local mobile data is removed by the device user; see the Mobile app data section above.
9. Security, location, and transfers
QueueRove uses server-side authorization, tenant isolation, session controls, audit evidence, redaction, encrypted transport, and operational safeguards appropriate to the data described in this policy. The service is hosted in the United States, and data may be processed there by the providers on the Subprocessor List. No method of transmission or storage is completely secure, and QueueRove cannot guarantee absolute security.
10. Children and policy changes
QueueRove is a B2B service for adults acting for MSP organizations and is not directed to children. Material policy changes receive a new version and content hash and, where required, trigger reacceptance. Archived versions remain publicly accessible.
11. Privacy contact
Contact ITECS Outsourcing, LLC at support@itecsonline.com with the subject QueueRove privacy request, or use the dedicated Privacy Choices and Account Deletion paths. Initial privacy/deletion response target: 2 business days during published business hours. This is a response target, not a resolution SLA.
Related resources
Questions may be sent to support@itecsonline.com with the subject “QueueRove privacy request”.