Skip to main content

Privacy policy

QueueRove Privacy Policy

This draft separates QueueRove-controlled account and administration data from device-local mobile data and customer-controlled HaloPSA records.

  • Version 2026-07-17-draft.1
  • Effective date: Pending Texas counsel approval
  • SHA-256 e1a1901d503c35b2c5dd6102d7b8e7608459fd762610df41cfb59ab4715773dc

Review and release status

Technical draft pending Texas counsel review; production collection and charging also require tax/accounting signoff and explicit launch approval.

This repository-local document is not provider, deployment, counsel, tax, or production evidence. It makes no approval or launch claim.

The content hash is derived from the versioned structured source rendered on this page. Material changes require a new version, archive entry, and the approved reacceptance process.

Open the immutable archive route for this version → · View all archived documents

1. Scope and roles

ITECS Outsourcing, LLC operates QueueRove and is responsible for the QueueRove-controlled data described here. An MSP organization remains responsible for its users, business instructions, and its own systems. Final controller, processor, service-provider, and contracting language remains subject to counsel review.

HaloPSA records are outside this policy's control-plane scope

The website control plane does not claim to control HaloPSA tickets, customer records, notes, photos, time entries, or credentials. Mobile apps connect to the customer-configured HaloPSA environment; native release behavior must be verified independently against the exact signed binary.

2. QueueRove-controlled data

  • Account identity and profile data, including provider issuer/subject identifiers, name, email, identity-verification state, and security state.
  • Organization, membership, composable grants, primary Owner, invitation, named technician assignment, licensed-capacity, and active-organization context data.
  • Session metadata, MFA recency, security events, immutable audit events, abuse controls, request identifiers, and application/access logs.
  • Billing projections, entitlement transitions, invoice references, tax and contract evidence, and provider object/event references; QueueRove does not store complete card details.
  • Legal versions and acceptance evidence, including exact version, effective-date status, and content hash.
  • Privacy, export, correction, deletion, support, security, and 50+ sales intake records and correspondence.
  • Essential session, invitation, security, and checkout cookies when the applicable feature is enabled.

3. Sources and purposes

Data may come from the user, an authorized organization administrator, the identity provider, configured billing and email providers, the application, and security/operations processes. QueueRove uses it to authenticate users; isolate organizations; authorize roles and seats; administer invitations, billing, entitlement, privacy, support, and legal acceptance; prevent abuse; reconcile state; provide notices; and meet legal and recordkeeping obligations.

QueueRove does not add analytics, advertising, tracking pixels, or non-essential cookies in v1. If that changes, a separate privacy review and consent design is required before use.

4. Disclosure and subprocessors

QueueRove may disclose only the data needed to configured service providers, the relevant MSP organization, professional advisers, authorities when lawfully required, or a successor in a lawful transaction. Production provider activation and contracting are external gates; repository references do not prove that a provider currently receives production data.

The public Subprocessor List records the approved technical candidates and evidence status without claiming an unverified production deployment. The DPA defines the narrow processing scope proposed for customer agreements.

5. Retention

Approved QueueRove retention schedule
Data classRetention
Active identity, organization, membership, and assignmentUntil applicable deletion completes, subject to holds
Billing, tax, refund, invoice-reference, and contract records7 years
Terms and commercial acceptance evidence7 years after organization closure
Audit and security events24 months unless held
Privacy and deletion request evidence24 months
Support records24 months
Terminal invitation email and delivery metadata90 days
Expired/revoked encrypted session payload24 hours
Minimal expired/revoked session metadata90 days
Application and access logs30 days
Rate-limit and abuse-control records90 days
General Stripe webhook and idempotency evidence24 months
Financially required Stripe event subset7 years
Generated export artifact24 hours
Encrypted backups35 days with deletion tombstones reapplied after restore
50+ sales lead12 months unless converted or another lawful retention applies

6. Access, correction, export, and deletion

Every user may request access, correction, personal export, or personal deletion. Only the primary Owner may request an organization export or deletion. Authenticated exports require recent MFA, are delivered as encrypted authenticated control-panel artifacts, and expire after 24 hours. QueueRove does not email export attachments or use bearer-only public links.

The public Account Deletion intake is for locked-out or uninstalled users. It is non-enumerating and requires identity verification before QueueRove reveals or changes account state. Email or a support ticket alone is not deletion authority.

7. Deletion boundaries

  • A personal request cannot complete while that person is the primary Owner of any organization; automated ownership transfer is deferred.
  • Organization deletion has a 7-day cooling-off period and a 28-day completion target after identity verification, subject to lawful holds or permitted extensions.
  • Completion distinguishes deleted, anonymized, retained with category/reason, provider-controlled, and outside-QueueRove data.
  • QueueRove does not claim deletion of legally retained financial evidence, device-local data, HaloPSA data, backups before their cycle completes, or data controlled by another party.
  • Native Apple and Google deletion entry points remain separate mobile release gates.

8. Security, location, and transfers

The approved design uses server-side authorization, tenant isolation, session controls, audit evidence, redaction, and operational safeguards. This policy does not claim a certification, penetration-test result, breach-free history, deployed encryption posture, provider region, or international-transfer mechanism before evidence and counsel review exist.

9. Children and policy changes

QueueRove is a B2B service for adults acting for MSP organizations and is not directed to children. Material policy changes receive a new version and content hash and trigger the approved reacceptance gate. Archived versions remain publicly accessible.

10. Privacy contact

Contact ITECS Outsourcing, LLC at support@itecsonline.com with the subject QueueRove privacy request, or use the dedicated Privacy Choices and Account Deletion paths. Initial privacy/deletion response target: 2 business days during published business hours. This is not a resolution SLA.

Questions may be sent to support@itecsonline.com with the subject “QueueRove privacy request”.