Privacy Policy
Last updated 22 August 2026
Cue is point-of-sale software for venues. This policy covers
cue.online, the operator app at
app.cue.online, and the API behind them.
Cue is operated by TO SET — legal entity name, of TO SET — registered address. Reach us at [email protected].
Two kinds of people in this policy
The distinction matters, because your rights differ:
- Operators — the venue's owner, managers and staff, who hold Cue accounts. Cue is the controller of that data.
- Guests — diners whose details a venue enters into Cue, for a booking or a waitlist. The venue is the controller of that data; Cue processes it on the venue's instructions. If you are a guest asking about your details, contact the venue first — they can delete it immediately, and we will help them if they ask.
What we collect
Operator accounts
Name, email address, role, and a password stored only as a hash — we never hold the password itself. If you sign in with Google or Apple we receive your name and email from them, not your password. We keep session records (device, IP address, last-seen time) so you can see and revoke your own sessions.
Venue data
Everything you put into Cue to run service: floors, tables, menu items and prices, staff, orders, tickets, payments, and the reports derived from them. This is your business's data. We store it to provide the service.
Guest data
When a venue takes a booking or adds someone to the waitlist, that record may include a name, phone number, party size, and any note the venue writes. Venues decide what to enter. We ask that they do not enter more than they need.
Payment data
We never see or store card numbers. Card payments are handled by Stripe, and money from a guest goes to the venue's own Stripe account, not to us. We store the non-sensitive references Stripe gives back — an amount, a status, a transaction id — so a check can show as paid. Stripe's handling is covered by Stripe's privacy policy.
Technical data
Ordinary server logs: IP address, browser, timestamps, and which endpoint was called. We use them to keep the service up and to investigate faults and abuse. Cue sets no advertising or tracking cookies and runs no third-party analytics. The only cookie is the one that keeps you signed in.
Text messages to guests
Cue can send a guest an SMS — that a table is ready, or to confirm a booking. These are transactional messages sent at a venue's instruction, not marketing.
- A guest gives their number to the venue for this purpose.
- Reply STOP to any message to stop receiving them, or HELP for help.
- Message frequency depends on the venue and the visit — typically one to three per booking or wait.
- Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
Venues are responsible for having the guest's consent before entering a number that will be texted, and for complying with the TCPA and equivalent state law.
Who else touches the data
We use these providers, and no others, to run Cue:
- Railway — application hosting and the database (United States).
- Cloudflare — DNS, TLS, and serving this website.
- Stripe — card payments and subscription billing.
- Twilio — sending guest SMS, where a venue enables it.
- Mapbox — turning a venue's address into a map. Guest data is never sent.
- Google and Apple — only if an operator chooses to sign in with them.
We do not sell personal information, and we do not share it for advertising. There is nobody else in this list.
Where data is held, and for how long
Data is stored in the United States. We keep venue data for as long as the account is open. Close an account and we delete or anonymise its data within TO SET — retention window, e.g. 30 days, except where we must keep records longer for tax or accounting law. Server logs are kept for a short operational period and then rotate away.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it — write to [email protected]. Operators can export venue data from within the app. California residents have specific rights under the CCPA/CPRA, including to know what is collected and to request deletion; we apply the same process to everyone rather than making you prove where you live. We will not discriminate against you for exercising any of this.
Security
Traffic is encrypted in transit. Passwords are hashed. Access tokens are short-lived and refresh tokens rotate, so a stolen one has a narrow window. Each venue's data is isolated by the venue on your account rather than by anything supplied in a request, so one venue cannot read another's.
No system is perfectly secure, and saying otherwise would be a lie. If we discover a breach affecting your data we will tell you and the relevant authorities as the law requires.
Children
Cue is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 13.
Changes
If this policy changes materially we will update the date above and tell account holders by email before it takes effect.