Legal

Privacy Policy

Quest Queue Inc. · Effective Date: October 2, 2026 · Last Updated: September 28, 2026

Introduction

This policy explains what information we collect, why we use it, and the choices you have.

Quest Queue Inc. (“Quest Queue,” “we,” “us,” or “our”) is headquartered in Alberta, Canada. We provide the Quest Queue website and mobile applications (together, the “Services”) to users in Canada and the United States, and we do not direct them elsewhere. If you use the Services from anywhere else, you do so on your own initiative.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Services. It applies to personal information we handle in connection with the Services, no matter how you access them.

We follow applicable Canadian and US privacy laws. If the law where you live gives you additional rights or imposes different requirements, those requirements apply.

By using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, please do not use the Services.

We may update this policy as our practices or the law change.

When we make changes, we will update the Last Updated date and post the revised Policy on our website and in the application. For material changes, we will provide prominent notice, such as a banner, in-app notification, or email, and obtain consent where applicable law requires it. Please review this Policy periodically. Continued use after changes are posted is subject to any required consent.

A French version of this Policy arrives before Chapter 0.

1. Data We Collect

In this Policy, “personal information” means information about an identifiable individual under PIPEDA (the Personal Information Protection and Electronic Documents Act), Alberta’s PIPA (Personal Information Protection Act), Quebec’s Law 25, and applicable US state privacy laws.

1.1 Data You Provide To Us

You provide information when you create an account, use the Services, or contact us.

To create an account we collect your email address, a username, a password, and your date of birth. You may add a mobile phone number to verify your account. Every account chooses an avatar from a library we provide. The Services do not collect your legal name, a mailing address, or a photograph of you, and at this time there is no photo or file upload. If we add uploads, this Policy will describe them first.

On your profile you may choose to add optional information. The games and platforms you play, the games and badges you choose to feature, and your discoverability tags (such as playstyle, availability, languages, and platforms) exist so that other players can find you, and they are public. Personal fields (country, time zone, an age range, gender, pronouns, a short bio, and links to your streaming or social channels) are private until you open them, and you control who sees each one. Gender and pronouns can reveal information that some privacy laws treat as sensitive. They are optional, you decide whether to add them, and adding them is your consent for us to store them and show them to the audience you choose.

As you use the Services we collect the content you create: session listings and descriptions, session coordination details (the “Rally Point”: invite links, lobby codes, notes, and, for in-person sessions, the venue), text chat messages, the votes and comments you give other players, reports you file, your conversations with our assistant (“QQ”), and your messages to support. We also keep the lists you build: your friends, and the players you have blocked. Both lists are private to you.

When paid features activate, we collect the information needed to process purchases and payouts. Full payment-card details are handled by our payment processor and are not stored on our systems. Players who sell paid sessions provide the identity, payout, and tax information that our payment processor and tax law require.

1.2 Data Collected Automatically

Your device and activity help us operate, secure, and improve the Services.

We automatically collect device information such as device type, operating system, device identifiers, browser type and version, screen resolution, and settings. We also collect log and usage data, including IP address, access times, pages or screens viewed, actions taken, features used, and the platform’s own records of sessions (when a session started and ended, and who attended). We may infer approximate location from your IP address. We do not collect precise geolocation from your device.

We use cookies and similar technologies. Today we use only strictly necessary technologies, which support login, security, and the operation of the Services. One of them is the captcha that protects signup and login from automated abuse (Google reCAPTCHA), which reads device and browser information to tell a person from a bot. You cannot opt out of these technologies because the Services cannot function without them. If we add analytics, performance, or advertising technologies, we will update this Policy, describe them here, and obtain consent where applicable law requires it. For Quebec users, non-essential cookies are off by default and require explicit opt-in consent under Law 25. US users may opt out of non-essential cookies and tracking through our settings, browser settings, the Global Privacy Control (GPC), or a “Do Not Sell or Share My Personal Information” link, where available. Third-party privacy policies apply to third-party technologies.

1.3 Data From Third Parties

We may receive information from services you use with Quest Queue.

We may receive information from the app store you downloaded the application from (for example, purchase confirmations), from our payment processor (for example, the result of a seller’s identity verification), and from analytics providers if we add them. Where the law of your location requires it, the app store or your device’s operating system may send us an age category signal. We use it as a check and do not store it. If you back our crowdfunding campaign, we receive from the campaign platform the information we need to deliver your rewards on the platform (your name, email address, and pledge level). The Services do not offer social sign-in today. If we introduce sign-in through another platform, or the option to link a game platform account to your profile, we will describe here what we receive from it. Links you type into your own profile are your content, not information received from those platforms.

1.4 Sensitive Personal Information

We do not generally collect sensitive personal information, and we ask before using it.

If we need to collect or process sensitive information, we will obtain explicit opt-in consent where required. Sensitive information may include racial or ethnic origin, religious or philosophical beliefs, health information, biometric or genetic data, precise geolocation, sexual orientation or sex life, citizenship or immigration status, financial-account details beyond payment processing, government-issued identification numbers, and personal data of a known child where applicable. Gender and pronouns on your profile are optional, are provided by you, and are shown only as you choose. Where required by US state law, you may limit our use of sensitive personal information to what is reasonably necessary to provide the Services.

1.5 Account Verification and Age

Quest Queue verifies email addresses, encourages phone verification, and is for adults only.

Every account verifies its email address. Phone verification is optional and strongly encouraged. It is how we keep to one verified person per account, and some features require it. By entering a phone number you agree to receive one-time verification codes by text message at that number. We keep your verified phone number while your account exists, so that we can enforce one account per person and let you update your number. It is used only to send verification codes and for account security, never for marketing or notifications. Internet-based (VoIP) numbers are not accepted. Phone verification confirms control of a phone number, not a name, an age, or an identity. After account deletion, we keep only a hashed form of identifiers, to prevent banned or duplicate accounts from returning and to connect earlier reports and enforcement to a returning account. Quest Queue never stores identity documents such as passports, driver’s licences, or government-issued identification cards. If the law of your location ever requires an age or identity check, or we have reason to believe an account belongs to someone under 18, a verification provider performs the check and we keep only the result, never the document. We never use facial or other biometric verification without first giving you the notice and obtaining the consent that the law requires.

Your date of birth is required at registration and is kept for the life of your account. It locks at signup, and changing it requires review by us. We use it to keep the Services for adults and to show the age information you choose to display. Our age assurance works in layers: your date of birth, collected neutrally; the age category signal an app store or an operating system provides where the law of your location requires it; phone verification; automated flags on chat that suggests an account belongs to someone under 18, reviewed by a person; and deletion of any account we learn belongs to a person under 18, from any source.

1.6 Honor and Reputation

Quest Queue operates a public reputation system called Honor.

Honor is generated by the platform from your session activity and from the votes other players give you: showing up, completing sessions, hosting, and the upvotes and downvotes of the people you played with. Titles, badges, and related reputation data are derived from it. Honor, Title, and Sessions Completed are visible to other users by design. This is a core feature of the platform, it has no privacy setting, and you know this when you create an account.

The votes you receive are shown only to you, and the identity of a voter is never disclosed to you or to anyone else. What other users see is what votes produce: your Honor and Title, flair that marks broad vote milestones, and, if you sell paid sessions, the percentage of upvotes among the votes you received in paid sessions, which is shown on your listings. Because Honor is built from other players’ votes and the platform’s attendance records, it cannot be erased or reset at your request while your account is live. It changes only as the platform rules describe, including the reset between chapters and the reset that comes with a suspension. You may challenge an enforcement action or a no-show vote through the appeal process in the Players Code of Conduct. You may request a copy of your Honor data at any time by contacting the Privacy Officer, or download it in the Services where that feature is available. Honor is deleted with your account, and vote records are retained only in anonymized form after deletion.

1.7 What Other Players Can See

Your gaming identity is public by design. Anything that points to you as a person starts private.

Your username, avatar, banner and profile colours, Honor, Title, Sessions Completed, your discoverability tags, your earned badges (including the chapter badge that marks a Pro subscription), the games you feature on your profile, and your activity statistics (the date you joined, your most-played games, sessions hosted, and your completion rate) are visible to other users, and there is no setting that hides them. You choose which games and badges to feature, and you can change them at any time. Your earned badges always appear on your badge wall. Visitors without an account see a preview of a player that shows the username, avatar, banner, the badges the player chose to feature, Honor, Title, and Sessions Completed. Session listings you post are visible to anyone browsing, including visitors without an account, and anyone viewing a session can see who has joined it, although a player in Incognito mode appears without their identity. Every personal profile field, and every link you add to your streaming or social channels, starts private. You can open each one to friends only or to everyone, and change it back at any time. Once you verify your phone number, you appear in player search by default whenever your presence is not offline. A search result shows only information that is already visible to other users, and a field you keep private can never be searched or filtered on. You can remove yourself from player search at any time in your settings, and we show you that setting when you start. Rally Point details are shown only to the participants the host has accepted, are never included in notifications, and are destroyed when the session closes. Chat messages are visible to the people in that chat. Your presence state (online, away, do not disturb) is visible to your friends and in player search. Your friends list and your block list are private to you. Incognito mode hides who you are from other players in a session and hides your presence from everyone. It never hides you from the platform: votes, reports, blocks, and enforcement still reach your account.

2. How We Use Your Data

We use personal information for the purposes we describe when we collect it.

Under PIPEDA and Alberta PIPA, we identify those purposes at or before collection. We will not use your personal information for a materially different purpose without notifying you and obtaining consent where the law requires it.

2.1 Providing and Improving Services

We use your information to provide, support, and improve Quest Queue.

This includes creating, maintaining, and securing your account; operating the website and application; running sessions, votes, reports, and the Honor system; processing transactions and sending confirmations or invoices; responding to questions and providing support; developing products, features, and functionality; and monitoring trends, usage, and activities connected with the Services.

2.2 Communications

We send service messages and marketing only in the ways allowed by law.

We may send technical notices, updates, security alerts, support and administrative messages, and push notifications with your device-level consent. We send commercial electronic messages, including marketing emails, newsletters, offers, and event information about us or others, only with express or implied consent as permitted by CASL (Canada’s Anti-Spam Legislation) and, for US users, the CAN-SPAM Act. Marketing consent is a separate, optional choice at signup and in your settings. Each message will identify Quest Queue and include contact information, use a clear and easy unsubscribe mechanism, and avoid misleading sender information, subject lines, or URLs. We will process unsubscribe requests within 10 business days and will not install a computer program on your device without express consent where CASL requires it. We never send marketing by text message. The only text messages we send are the one-time verification codes you ask for.

2.3 Safety and Security

We use information to keep our Services, users, and community safe.

We use information to detect, investigate, and prevent fraud, illegal activity, and suspicious activity; to run the platform’s trust systems, including vote-manipulation detection, duplicate-account detection, and content flagging for human review; to protect the rights, privacy, safety, and property of Quest Queue, our users, and the public; to enforce our Terms of Service and the Players Code of Conduct; and to respond to lawful requests from public authorities. When a paid session is disputed, the person who decides it reviews the platform’s records of that session, including the ready check, the session’s timing, and its chat, and anything the people involved send us.

2.4 Advertising and Marketing

We do not serve advertising today. This section describes what happens when advertising activates.

Quest Queue does not currently serve advertising in the Services and has never sold or shared personal information for targeted advertising purposes. When advertising activates for free accounts, we may deliver advertising and marketing, measure campaign effectiveness, and understand how people use the Services, subject to your preferences and applicable law. We do not sell personal information. If we ever make information available for targeted advertising in a way that a US state law treats as a “sale” or “sharing,” this Policy will say so first and you will be able to opt out under Section 4.2. We never use the information of anyone we know, or should know, is under 18 for targeted advertising, and we never sell it.

2.5 Research and Development

We study usage to make Quest Queue more useful.

We may conduct research, testing, analytics, and analysis to understand our users, evaluate performance, identify trends, and develop or improve products, services, features, and functionality.

We use information when necessary to comply with law and protect our rights.

This includes complying with laws, regulations, legal processes, and governmental requests; enforcing agreements, including for billing and collection; protecting against legal liability; meeting tax reporting obligations for players who sell paid sessions; and supporting a merger, acquisition, reorganization, bankruptcy, receivership, or sale of assets. We may use or disclose information without consent where applicable law permits or requires it.

2.7 Our Data Promises

Quest Queue makes the following commitments regarding your data.

No sale of personal data. We do not sell your personal information, and we do not share it with anyone for targeted advertising. If that ever changes for advertising, this Policy will say so first and you will be able to opt out. A transfer of your information with the business, as Section 3.5 describes, is not a sale of your information.

No external AI training. User content is never provided to outside companies to train artificial intelligence models. This is a clear and unequivocal commitment.

Internal AI use only. Quest Queue uses artificial intelligence within the platform for the in-app assistant, for flagging chat, vote comments, and session coordination content for human review, for detecting vote manipulation and duplicate accounts, and for preparing support and moderation cases. Insights derived from platform data are used solely to operate, secure, and improve Quest Queue. We do not train artificial intelligence models of our own on your content today. If that ever changes, this Policy will say so first.

Honor stays here. Your Honor and reputation data are never shared with any outside service, other than the service providers that run the platform for us (Section 3.1). If we ever offer a way to share your reputation with another platform, it will be a choice you turn on.

Reputation data is portable. A player may request a copy of their reputation data, including their Honor score, at any time by contacting the Privacy Officer, and may download it in the Services where that feature is available. Reputation data is deleted with the account as Section 4.6 describes.

3. How We Share Information

We share personal information only for the purposes described in this Policy.

The recipients and circumstances below describe the main ways we may disclose personal information.

3.1 Service Providers

Service providers help us run Quest Queue.

We may share information with cloud-hosting and infrastructure providers; our software development partner, which maintains the platform under contractual confidentiality and data-protection obligations; payment processors and financial institutions; verification-code and email delivery providers; the push-notification services of Apple and Google (they handle the delivery of notifications to your device and never receive Rally Point content); age or identity verification providers, if the law of your location ever requires a check; the artificial intelligence provider that powers our assistant and content flagging, under terms that prohibit training on our data; customer-support and communications platforms; analytics and data-processing services if we add them; security and fraud-prevention services, including the captcha provider (Google); and marketing and advertising platforms if advertising activates. They must use the information only to provide services on our behalf and under our instructions, and may not use or disclose it for another purpose.

3.2 Other Players and the Public

Some information is shared with other players by design.

Other players see the public information described in Section 1.7 and the profile fields you choose to open. Anyone viewing a session can see who has joined it, although a player in Incognito mode appears without their identity. Participants in a session see each other’s identity as shown in the session, the session chat, and the Rally Point details. Visitors without an account see session listings and the player preview described in Section 1.7. If you delete your account, chat messages you sent remain visible to the people in those chats, shown as “Deleted User.”

3.3 Business Partners

We may work with partners to offer joint products, services, or promotions.

When we do, we share only the information needed for the agreed purpose, and those partners must use it consistently with that purpose.

We may disclose information when the law or safety requires it.

We may disclose information to comply with law, regulation, legal process, or a governmental request; to enforce our Terms of Service, this Policy, or other agreements; to detect, prevent, or address fraud, security, or technical issues; to meet mandatory reporting obligations, including the reporting of child sexual abuse material to the designated Canadian organization and to law enforcement; or to protect the rights, property, or safety of Quest Queue, our users, or the public, as required or permitted by law.

When an authority asks us for a user’s information, we require valid legal process from a court or agency with jurisdiction, and we disclose only what that process requires. In an emergency involving an imminent risk of death or serious physical injury, we may disclose the information needed to address it without waiting for process. We may preserve an account’s records when an authority asks us to, for the period the law allows. Authorities outside Canada are asked to use the legal channels that apply between their country and Canada. Where the law allows and it is safe to do so, we tell you when your information has been requested.

3.5 Business Transfers

If Quest Queue is part of a transaction, your information may move with the business.

In a merger, acquisition, reorganization, bankruptcy, receivership, or sale or transfer of all or part of our assets, personal information may be transferred as part of the transaction. We will provide notice, such as by email or a notice on the Services, and explain any choices you may have where applicable.

We share information with other parties when you ask us to or consent.

We may disclose personal information to other third parties when we have your express consent or when you direct us to do so.

3.7 Aggregated or De-identified Data

We may share information that no longer reasonably identifies you.

We may share aggregated or de-identified information without restriction when it cannot reasonably be used to identify you. We maintain and use de-identified data in that form and do not attempt to re-identify it, except to confirm that our de-identification processes are adequate.

4. Your Choices and Obligations

This section explains how you can manage your information and use the Services responsibly.

The rights available to you depend on where you live and the law that applies. You can contact our Privacy Officer to ask questions, make a request, withdraw consent, or raise a complaint.

We use the form of consent that fits the information and the purpose.

Under Canadian law, we generally rely on consent and may obtain it expressly (orally, in writing, or electronically), implicitly where the purpose is obvious and you voluntarily provide the information, or through an opt-out for certain non-sensitive purposes such as marketing. At signup, agreeing to the Terms of Service, confirming that you have read this Policy, and choosing whether to receive marketing are three separate choices, and no box is checked for you. For Quebec residents, consent must be clear, free, informed, specific, and separate for each purpose; we do not bundle it with terms, use deceptive practices, or enable non-essential cookies without explicit opt-in. We explain our practices in plain language.

You may withdraw consent at any time, subject to legal or contractual limits, by contacting our Privacy Officer. We will explain the possible consequences, including that some Services may no longer be available; withdrawal does not affect processing that occurred before withdrawal. We may collect, use, or disclose information without consent where permitted by law, including to protect an individual’s interests when consent cannot be obtained promptly, detect fraud or support law enforcement, comply with legal demands, establish, exercise, or defend claims, or use publicly available information.

4.2 Your Privacy Rights

You can ask what we know about you, correct it, delete it, or move it, and you may have additional choices based on where you live.

Depending on applicable law, you may request access to or confirmation of processing; the categories and specific pieces of personal information we hold; correction of inaccurate information, including having a requested correction noted in our records if we cannot correct it; deletion or erasure, subject to exceptions such as completing a transaction, providing a service you are still using, protecting security and the integrity of the platform, complying with a legal obligation, or establishing, exercising, or defending legal claims; a structured, commonly used, and portable copy; withdrawal of consent; opt-out of sale or sharing, targeted advertising, and profiling; limitation of sensitive personal information to purposes reasonably necessary to provide the Services or goods reasonably expected; and non-discrimination. You may also challenge our compliance, request information about disclosures including service providers outside Canada, and appeal a denied request where the law provides an appeal right.

An access request never reveals the identity of another player. The votes and reports about you are personal information about you, but the identity of the player who voted or filed a report is that player’s information, and we withhold it as the law permits.

Quebec residents have additional rights, including data portability in a structured, commonly used, and technologically neutral format, with transmission to another organization where technically feasible; erasure where information was collected contrary to law, the purpose has been fulfilled, or the retention period has expired, subject to legal retention requirements; requests to cease dissemination or de-index a hyperlink where permitted; and clear information about our privacy practices and transborder transfers. US residents in applicable jurisdictions may opt out of the sale or sharing of personal information; other rights and exceptions vary by state.

If you live in a country where we do not offer the Services and its privacy law nonetheless gives you rights over your information, you may exercise them by contacting our Privacy Officer, and we will honour them as that law requires.

To exercise your rights, contact our Privacy Officer. We may authenticate requests. We respond to Canadian access and correction requests within 30 days, with extensions as law permits and notice; Quebec requests are acknowledged and answered within 30 days, with a further 30 days in complex cases and notice; and US requests are confirmed within 10 business days and answered within 45 days, with one further 45-day extension where the law allows and we tell you. If we deny a request where an appeal is available, contact us within 30 days; we will respond as required and explain how to complain to the applicable regulatory authority.

4.3 Age Restriction

The Services are intended solely for individuals aged 18 and older.

Quest Queue does not knowingly collect personal information from anyone under the age of 18. Under-18 signup is blocked at the product level through the date of birth collected at registration. If we learn that an account belongs to an individual under 18, through any source, we will promptly delete the account and all associated personal information. If you believe that we have inadvertently collected personal information from someone under 18, please contact our Privacy Officer immediately so that we can take appropriate action. The Terms of Service also require that you have reached the age of majority where you live, where that is higher than 18.

4.4 Automated Systems and Decision-Making

Automated tools help us keep the platform safe. People make every enforcement decision.

We use automated processes for account security (such as identifying suspicious login attempts), for fraud and duplicate-account detection, for flagging chat, vote comments, session coordination content, and vote patterns for human review, and, if advertising activates, for advertising subject to your opt-out rights. Honor itself moves by the platform’s rules: session records and other players’ votes change it automatically, including the Honor cost of a late cancellation or a no-show. You can ask us for the information used in any of those changes, and you can challenge a no-show vote through the appeal process, where a person reviews it. Enforcement is different. No decision to warn, suspend, or remove a user, and no adjustment of reputation made as part of enforcement, is made solely by automated means. A human reviews every flag and makes every enforcement decision, and every decision is logged with its reason. The one automated content action is that content reported as an intimate image shared without consent, or as child sexual abuse material, is hidden immediately pending human review. When that happens, the person who posted the content is told that it was hidden and why, can ask for the reasons and the information used, and can respond to the person who reviews it. Where a decision about you is made exclusively by automated means, Quebec Law 25 gives you the right to be informed, to receive information about the personal information used and the reasons and principal factors, and to have the decision reviewed by a qualified person who may modify it. Where applicable US law provides a right to opt out of profiling that produces legal or similarly significant effects, you may exercise that right. Contact our Privacy Officer to request information or human review.

4.5 Data Retention

We keep personal information only as long as we need it or the law requires.

Retention depends on the purpose, sensitivity, and risk of the information, applicable legal, tax, accounting, and reporting requirements, legitimate needs such as disputes or enforcing agreements, and our relationship with you. As general examples, account information is kept while your account is active and for a reasonable period afterward; transaction records are kept as required, generally seven years; support records may be kept for up to three years; identifiable usage data, other than the session records described below, may be kept for up to 24 months and then aggregated or de-identified; marketing preferences remain until changed; and cookie data varies by cookie type. When information is no longer needed, we securely destroy, erase, or anonymize it.

The platform also has specific retention rules, so that no request surprises anyone:

  • Rally Point details (invite links, lobby codes, notes, and in-person venues) are destroyed permanently when the session closes, including from logs and analytics, with backup copies clearing on the normal backup rotation. If a report about that content is filed while it exists, one copy is preserved inside the report case and destroyed when the case closes. A legal preservation demand overrides deletion.
  • Session records (the sessions you hosted or joined, when they ran, and who was in them) are kept while your account exists, because your Sessions Completed and your completion rate are built from them.
  • When you delete your account, your identity is removed from session records at the end of the 30-day cooling-off period, and your place in them shows as “Deleted User.” If a report that names you, or a legal demand, arrives before then, the records that case needs are kept inside the case until it closes, or for as long as the law requires.
  • Records of enforcement actions taken by our administrators are permanent, because they are the record of what we did, and they survive account deletion.
  • Reports about a player persist after that player’s account is deleted. Reports filed by a deleted account persist in anonymized form as moderation evidence.
  • Records preserved for a mandatory reporting obligation, or at the request of an authority, are kept for the period the law requires.
  • Your conversations with our assistant (“QQ”) are kept while your account exists and deleted with it.
  • Session chat and friend chat are kept for as long as the chat exists. A session chat never closes on its own, so its messages remain for the people in it until they leave, and your own messages are deleted from your account’s data when your account is deleted, showing as “Deleted User” to the others.

4.6 Account Closure

Closing your account stops account services, but some information may remain when we need it for legitimate reasons.

You may delete your account at any time, in two ways. In the application, through the account settings. On the web, by emailing our Privacy Officer at privacy@questqueue.com from the email address on your account, with the subject line “Delete my account” and your username; we confirm the request within 30 days, usually much sooner, and if you no longer have access to that email address, tell us in the message and we will verify your identity another way. This section is linked from our app store listings as the account-deletion resource, and deletion requests are processed in accordance with Apple App Store and Google Play requirements.

Deletion has a 30-day cooling-off period. During those 30 days your account is suspended from normal use, and logging in cancels the deletion. At the end of the 30 days we delete your profile (avatar, banner, bio, and every optional field), your tags, your friends list, your Honor and reputation data, and subscription billing data after the final invoice closes. We retain: enforcement records (Section 4.5); vote data and session records in anonymized form, with your identity removed; hashed identifiers used to prevent banned or duplicate accounts from returning and to connect earlier reports and enforcement to a returning account; and information we must keep for legal, tax, accounting, security, fraud-prevention, dispute-resolution, billing, or agreement-enforcement purposes, as permitted or required by law. Chat messages you sent remain visible to the people in those chats, shown as “Deleted User.” Your username is held for 12 months after deletion to prevent impersonation, then released. Deleting your account does not cancel a subscription billed by an app store; cancel it in the store. We may close an account with no activity for 24 months, after notice to the email address on the account, and the same deletion rules then apply.

5. Other Important Information

These provisions cover security, transfers, incidents, links, and how to contact us.

5.1 Security

We use reasonable safeguards to protect your personal information.

We implement reasonable administrative, technical, and physical safeguards proportionate to the sensitivity of personal information to protect it against unauthorized access, disclosure, alteration, loss, or destruction. Every sign-in uses a password plus a one-time code. No method of transmission or electronic storage is completely secure. You are responsible for keeping your account credentials confidential, using a strong unique password, logging out on shared devices, and notifying us promptly about suspected unauthorized access.

5.2 Cross-Border Data Transfers

Your information may be processed outside your province, territory, state, or Canada.

We may store or process personal information with service providers or other third parties outside Canada, including in the United States and other countries. It may then be subject to foreign laws that allow government or law-enforcement access. Under sections 13.1 and 13.2 of Alberta’s PIPA, we notify you that information may be stored or processed outside Alberta and Canada; a list of the countries where our service providers operate and the purposes of the transfers is available from our Privacy Officer on request.

When we transfer information outside Canada, we use contractual obligations requiring comparable privacy and security protection, assess service providers, apply technical and organizational safeguards, and limit the information transferred to what is needed for the stated purpose.

Before transferring Quebec residents’ information outside Quebec, including elsewhere in Canada or internationally, we conduct a Privacy Impact Assessment that considers sensitivity, purposes, protections and contractual safeguards, the destination’s legal framework, and adequacy. We proceed only where the assessment confirms protection equivalent to Quebec law or where you give express consent after being informed of the risks. Foreign governments, courts, or law enforcement may access information stored abroad; we assess lawful requests and notify affected people where permitted.

5.3 Breach Notification

If a security incident creates a real risk of significant harm, we will act quickly and notify the right people.

We will notify affected individuals as soon as feasible, without unreasonable delay, and in every case within the time the law where you live requires. We will report to the Office of the Privacy Commissioner of Canada under PIPEDA and the Office of the Information and Privacy Commissioner of Alberta under PIPA when required. For Quebec residents, we will notify the Commission d’accès à l’information du Québec (CAI) promptly where Law 25 requires it and there is a risk of serious injury. We will notify applicable US authorities, including state attorneys general, and affected consumers as required by state breach-notification laws, take reasonable steps to reduce harm, and keep a record of all breaches whether or not they are reportable.

5.4 Do Not Track and Opt-Out Signals

Recognized browser signals can help you limit certain advertising and sharing.

If you enable GPC, we will treat it as a valid opt-out of the sale and sharing of personal information and, where required, targeted advertising under applicable US state laws. Some browsers send Do Not Track signals; because there is no universal standard, we honour DNT where applicable law requires it. We also honour other universal opt-out mechanisms recognized under applicable law. You can also use our cookie settings, preference centre, or Do Not Sell or Share link where available, or contact our Privacy Officer.

Links to other services are governed by their own privacy policies.

The Services may link to websites, applications, or services that Quest Queue does not control, including the voice, video, and game platforms players use to play together. This Policy does not apply to them, and we are not responsible for their privacy practices. Please review their policies before using them; a link does not imply endorsement.

5.6 Contact Information and Complaints

Our Privacy Officer can help with privacy questions, requests, and complaints.

Quest Queue Inc. has designated a Privacy Officer under PIPEDA, Alberta’s PIPA, and Quebec’s Law 25. The Privacy Officer is responsible for our compliance with applicable privacy law and this Policy and for handling privacy inquiries and complaints. You may contact the Privacy Officer to ask about our practices, submit an access, correction, or deletion request, withdraw consent, file a complaint, or request information about service providers outside Canada.

Privacy Officer: Quest Queue Inc., Attention: Privacy Officer

Address: 9899 112 Ave, Unit 103, #2056, Grande Prairie, AB T8V 7T2, Canada

Email: privacy@questqueue.com

If you are not satisfied with our response, you may complain to the applicable regulatory authority.

Governing Law and Interpretation

Governing Law

Alberta law generally governs this Policy, subject to the privacy laws that apply where you live.

This Policy is governed by and construed under the laws of Alberta and the federal laws of Canada applicable there, without regard to conflict-of-law principles, except where the privacy laws of another jurisdiction govern the information of its residents.

Interpretation

We aim to keep this Policy consistent across languages and jurisdictions.

If the English and French versions conflict, the English version prevails to the extent permitted by law, except that a Quebec resident, who receives the French version first, may rely on either version. If any provision is invalid or unenforceable, the remaining provisions remain in full force. This Policy does not create contractual or other legal rights for anyone other than Quest Queue and users of the Services.

End of Privacy Policy