ImpelZoneBack to home
Legal

Privacy Policy

ImpelZone is built so that we cannot read what you store, where you store it, or your history. This policy explains exactly what our servers do hold, why, and what you can do about it.

Effective

1. Who we are and what this covers

This policy covers the ImpelZone mobile app, the website at https://iz.queuelessapp.com, and the web dashboard used by dealers and administrators (together, the “Service”). The Service is operated by ImpelZone (“ImpelZone”, “we”). You can reach us at privacy@queuelessapp.com.

ImpelZone is a habit and reminder app for keeping secure storage a routine. You record when something is taken out and put away, set a return time, and optionally let a small group know if you run late. It is not a lock and does not control access to anything.

2. How the app is designed to protect you

The app encrypts your private information on your phone before anything is sent to us. The keys that protect it are generated on your phone and never leave it. We hold the encrypted result so that the app can sync and so that reminders can run even when your phone is off, but we have no way to decrypt it.

This has a consequence you should know about: if you lose your phone and have not verified a phone number to move to a new device, we cannot recover your data for you. Nobody can.

3. Information we hold but cannot read

The following reaches our servers only as ciphertext. We store it, we can delete it, and we cannot read it:

  • The contents of every activity record: which item, which storage location, notes, destinations, checklist details.
  • The details attached to a check-out timer.
  • Encrypted location shares sent during an elevated check-out, if you enable that feature, and the encrypted keys exchanged with members of your group.

4. Information we hold in readable form

To run the Service, some information has to be readable by our servers. This is the complete list.

WhatDetails and why
Device identityA random device identifier, the platform (iOS or Android), the app version, and when the device was last seen. This is how the app signs in without an email address or password.
Push notification tokenOnly if you allow notifications. Used to deliver reminders and alerts through Apple or Google push services.
Your phone numberOnly if you choose to verify one. It is required to join a group and to move your account to a new phone. We store the number and a hashed form of it. We do not use it for marketing.
Phone numbers of people you inviteWhen you invite someone to your group you enter their phone number. We store it, with a hash, so we can send the invitation and recognise them when they accept. This is personal information about someone else, so please only invite people who have agreed to it. Unanswered invitations expire after 14 days.
Activity metadataFor every record: its type (for example “checked out”, “stored”, “reminder”), the time it happened and the time we received it, a random reference for the item and the location, an expected return time where relevant, and a flag if the app detected an anomaly. In plain terms: we can see that something was checked out at 21:04 and put away at 23:10. We cannot see what it was or where.
Check-out timersThe expected return time, the grace period, and the escalation state of an open check-out. Our servers run the overdue reminders, so they must know when a return is due.
AcknowledgementsIf a member of your group acknowledges an alert, we record who acknowledged and when.
Plan and activationYour plan tier, how it was obtained (store purchase, dealer activation code, or manual), when it was activated, and which dealer code was used. Dealers can see how many of their codes were used. They never see your items, locations, history, or group.
Notification recordsFor each reminder or alert we send: the channel (push or SMS), the kind of notification, whether it was delivered, and the provider’s message identifier. The text of these messages is generic and identical for every recipient; your phone assembles the real wording.
Security and audit recordsSignificant actions such as sign-ins, device removals, activations, and deletions, with the acting account’s internal identifier, the time, and the IP address the request came from.
Server logsOur web server records the IP address, request path, response status and timing of each request. It never records request contents.
Web accountsDealers and administrators who use the web dashboard have a name, an email address, a hashed password, and sign-in times. App users do not have these.
One-time codesWhen you verify a phone number we store the number, a hashed copy of the code, the requesting IP address, and an expiry. These records are consumed or expire within minutes.

5. Information that stays on your phone

  • The household key that encrypts your records, the key used to sign your printed tags, and your private group key.
  • The names and details of your items.
  • The names of your storage locations and the map coordinates of their zones.
  • Your readable history.

The app opts out of Android backup and device-to-device transfer, so this information does not leave your phone by those routes either. Uninstalling the app removes it.

6. Location

The app uses your phone’s location for two features: reminding you when you arrive home while something is still out, and choosing the zone of a storage location on a map. Both are processed on the phone. Zone coordinates never leave it. Because the reminder needs to work while the app is closed, the app may ask for permission to use location in the background.

During an elevated check-out the app can share your last known location with your group. That share is encrypted on your phone; our servers store it and cannot read it. Our servers receive a yes/no anomaly flag when the app detects an unexpected pattern, and nothing about where you were.

The map is drawn by Google Maps. When you open it, your phone sends map requests to Google, which Google processes under its own privacy policy.

7. How we use information

  • To provide the Service: signing your device in, syncing encrypted records, running timers and reminders.
  • To deliver notifications you have asked for, to you and to the group you set up.
  • To apply your plan and entitlements.
  • To keep the Service secure, prevent abuse, and investigate problems.
  • To respond when you contact us.
  • To meet legal obligations.

We do not show advertising, we do not use analytics or tracking SDKs, we do not build profiles, and we do not sell or rent personal information.

8. Who we share information with

RecipientWhat and why
Members of your groupThey receive generic alerts about overdue check-outs and can acknowledge them. They do not see your items, locations, or history. You choose who is in your group and can remove them.
DealersIf you activated with a dealer code, the dealer sees that a code from their batch was used. Nothing else.
Amazon Web ServicesHosts our servers in the United States.
MongoDB AtlasHosts our database in the United States, encrypted at rest.
GoogleFirebase Cloud Messaging delivers push notifications on Android; Google Maps draws the map in the app; Google Play handles purchases and tells us what you are entitled to. We never see your payment details.
AppleApple Push Notification service delivers push notifications on iOS; the App Store handles purchases on iOS.
TwilioSends SMS one-time codes and alerts to phone numbers, once SMS is enabled. Twilio receives the phone number and the generic message text.
SentryReceives crash reports from the app: device model, operating system, app version, and the technical trace of the error. The app is written so that no household information appears in a log line.

We may also disclose information if the law requires it, to protect the rights and safety of people, or as part of a merger or sale of the business, in which case this policy continues to apply to the information transferred.

9. Where information is processed

Our servers and database are in the United States. If you use the Service from elsewhere, your information is transferred there. Encrypted records remain unreadable wherever they are stored.

10. How long we keep information

  • Records tied to your account are kept for as long as your account exists. Deleting your account removes them; see Delete your account.
  • If you remove a device or erase the app without deleting your account, the encrypted records that device created remain on our servers until the account is deleted. We cannot read them, but they exist, and we do not currently apply a separate expiry to them.
  • One-time codes expire within minutes of being issued.
  • Unanswered group invitations expire after 14 days.
  • Security and audit records and server logs are kept after account deletion for security, abuse prevention, and legal purposes. They contain an internal account identifier and IP address, not your phone number or name.
  • Crash reports are retained by Sentry according to our project settings there.

11. Your choices and rights

  • Export: the app’s Privacy centre has an “Export my data” action that returns everything we hold about your account, including the encrypted records.
  • Delete: the app’s Profile screen has a “Delete account” action. It is irreversible and applies to all your devices. People without the app can request deletion by email; see Delete your account.
  • Devices: you can see and remove signed-in devices from the app.
  • Notifications: you can turn push notifications off in your phone settings and set group notification preferences in the app.
  • Group: you can cancel invitations and remove members at any time.

Depending on where you live, you may have legal rights to access, correct, delete, or restrict the use of your personal information, to object to processing, to data portability, and to complain to a supervisory authority. To exercise any of them, email privacy@queuelessapp.com. We will respond within 30 days and may ask you to confirm the request from the verified phone number on the account.

12. Children

The Service is intended for adults responsible for secure storage in their household. It is not directed at anyone under 18, and we do not knowingly collect information from them. If you believe a child has provided us information, contact us and we will delete it.

13. Security

All traffic between the app and our servers uses TLS. Device secrets, passwords, one-time codes, and phone numbers used for matching are stored as hashes. The database is encrypted at rest and reachable only from our servers. Access to production systems is limited to the people who operate them. No system is perfectly secure, which is why the design keeps your most sensitive information off our servers in the first place.

14. Changes to this policy

If we change this policy in a way that matters, we will update the effective date above and, for significant changes, tell you in the app before they take effect.

15. Contact

ImpelZone. Email: privacy@queuelessapp.com.