Data & privacy
This page is your privacy control room — your agreement status, how long visitor details are kept before they're auto-deleted, exporting your setup, and handling a visitor's data request.
Your agreement
The data processing agreement card shows whether it's accepted, and when. The agreement itself is published at turnda.com/dpa. In plain terms, you are the data controller for your visitors' information and turnda is your processor — the standard relationship for a tool that handles data on your behalf. Every company that processes data on turnda's behalf, and where that data is stored, is listed at turnda.com/sub-processors.
Retention window
| Setting | Detail |
|---|---|
| Auto-delete after (days) | How long a visitor's name and contact are kept after their visit before they're automatically deleted. |
| Default | 48 hours (2 days) |
| Range you can set | 1 day to 1 year |
| When a change applies | Future visits only — visits already stamped with a deletion time keep theirs. |
| Who can change it | Owner only. |
Short by design — turnda holds visitor personal data only as long as it's useful, then removes it for you.
What your visitors are told, and where
You do not have to write a privacy line for your visitors — turnda puts one on the pages that collect their details, at the moment they are asked.
It is a short sentence with Privacy and Terms next to it, both opening in a new tab so nobody loses what they were typing.
Where the privacy line appears — and doesn't
| Page | What it says |
|---|---|
| The join page | “We use your details only to hold your place and let you know when it's your turn.” Shown whether or not you ask for a phone or email, so a tap-only join page still carries it. |
| The WhatsApp-join page | The same join sentence, on the short form a visitor fills in before WhatsApp opens. That form asks for a name, a party size, what they need, a vehicle and a note. |
| The booking page | “We use your details only to hold your appointment and remind you about your booking.” |
| The counter tablet | The same join sentence — but only if the tablet actually asks for something. A tap-only kiosk collects nothing, so it claims nothing. |
| A visitor's own booking page | Nothing. It shows a booking they already made and asks for nothing new, so there is nothing to disclose. |
| The tracking link | Nothing either — that page asks the visitor for no details at all. |
- It never quotes a deletion period. That is your setting above, and any number here would be invented.
- It links the published Privacy and Terms, not the versions inside the app — those are written for you as the shop owner and would confuse a visitor.
Export & requests
Two more tools live here — Export my data downloads your account configuration as a file, and Visitor data requests lets you look up or erase the data held on one person. Closing the account is also reached from here.