Nextivo ← Back to home
Privacy

Privacy Policy

Last updated: July 10, 2026

Nextivo ("we", "us", "our") operates the Nextivo mobile app and the website nextivo.app ("Service"). This privacy policy explains how we collect, use, and protect your information.

What information we collect

Account information

When you create an account, we collect your email address and name via our authentication provider (Keycloak). This is used to identify you and manage your queues.

Device information

The mobile app generates a random device identifier (UUID) that is stored locally on your device. It is used to link your tickets to your device so you can follow your place in the queue. We do not collect hardware identifiers, ad IDs, or device fingerprints.

Camera

The mobile app only requests camera access to scan QR codes to join queues. Camera data is processed locally on your device and never sent to our servers.

Push notifications

If you enable push notifications, we store your Firebase Cloud Messaging (FCM) token to notify you when it is your turn. You can disable notifications anytime in your device settings.

Usage data

We collect basic usage data such as the time you join a queue, status changes, and wait times. This is used to deliver the service and calculate estimated wait times.

How we use your information

We use the information we collect to:

  • Deliver and maintain the queue management service
  • Notify you of your place in the queue and status changes
  • Calculate and display estimated wait times
  • Improve the service and fix errors
  • Communicate with you about your account or the service

Legal basis

We process personal data to fulfil our agreement with you (delivering the queue service — GDPR Article 6(1)(b)), based on legitimate interest (troubleshooting and security — point (f)), and based on consent where you give it explicitly (for example push notifications — point (a)).

Cookies and local storage

The website uses only strictly necessary cookies. We have no tracking or advertising cookies and no third-party analytics — so no consent is required, and the banner you see is informational only. The cookies are:

  • Sign-in session: an anonymous session ID that keeps you signed in. Deleted when you sign out.
  • Device ID ("device"): a random ID that links your tickets — and any loyalty punches on punch-card products — to the browser so you can find them again. Lifetime 1 year.
  • Shared-machine flag ("nextivo.ephemeral"): prevents tickets from being bound to a public or shared machine. Lifetime about 13 months.
  • Language choice ("lang"): set only when you choose a language yourself.
  • Referral code ("ref_code"): set only when you follow a referral link, deleted after use (30 days at most).
  • Banner choice ("cookie_consent"): remembers that you dismissed the information banner. Lifetime 12 months.

Your browser also stores a few settings locally (localStorage), such as whether you turned off help tours, and on configured displays a pairing key and audio settings. This never leaves your device.

The fonts on the website are loaded from Google Fonts. Your browser then contacts Google’s servers, which therefore see your IP address.

Error tracking

To detect and fix bugs, the website sends automatic error reports (including automatically detected layout issues) to our own error-tracking tool (GlitchTip), running on our own servers. Reports contain technical details such as browser type, page name and error message — not your name, email address or anything you typed. The legal basis is legitimate interest.

Information sharing

We never sell your personal information. We only share data in the following cases:

  • With queue operators: your queue number and possibly your name is visible to the business that operates the queue you have joined.
  • With service providers: we use Firebase (Google) for push notifications, Keycloak for login, and Stripe for payments.
  • As required by law: we may disclose information if required by law.

Data processors and third parties

We use the following services to deliver Nextivo:

  • Stripe — payment processing. Card details go directly to Stripe and are never stored by us.
  • Keycloak — sign-in, hosted on our own servers.
  • GlitchTip — error tracking, hosted on our own servers.
  • ntfy — notifications, hosted on our own servers.
  • Firebase Cloud Messaging (Google) — push notifications in the mobile app.
  • Google Fonts — fonts on the web pages.
  • MaxMind GeoLite2 — estimates your country from your IP address to suggest a search country (never to decide search results). This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Data storage

Ticket data is stored for service operation and historical statistics. You can request deletion of your account and associated data by contacting us.

Security

We use industry-standard security measures, including HTTPS encryption, OAuth2 authentication, and secure database storage to protect your data.

Your rights

You have the right to:

  • Access the personal information we have about you
  • Request correction of inaccurate information
  • Request deletion of your data
  • Withdraw consent to push notifications anytime

Changes to this policy

We may update this privacy policy from time to time. We will notify you of changes by posting the new policy on this page and updating the "Last updated" date.

If you have questions about this privacy policy or want to exercise your rights, contact us at support@nextivo.app