Turnos is a queue management tool for businesses. We collect the minimum information needed to make queues work — customer names and phone numbers when staff add someone to a queue, and your phone number when you log in as a customer. We do not sell your data. We do not store sensitive business records beyond queue coordination.
This policy is intended to comply with the Digital Personal Data Protection Act, 2023 (DPDPA) of India.
Customers log in using their phone number and a one-time password (OTP). We store the phone number and a name (optionally provided) to identify the customer across visits and to show them their own queue history. We do not store the OTP after it is used.
Front-desk staff enter a customer's name and phone number to register them in a provider's queue. This creates a queue entry with a token number, a timestamp, and the assigned provider. The phone number is used to send SMS or WhatsApp notifications about queue status (e.g., "2 people ahead of you", "it's your turn").
When a business owner registers, we collect their name, email address, and phone number. Providers and staff are added by invitation — we store their name, email, phone, and role within the business. Passwords are hashed and never stored in plain text.
We record each queue entry: the token number, which provider it was for, when the customer joined, their position transitions (waiting → in service → completed/missed/skipped), and the final outcome. This data powers the analytics dashboard for business admins and the visit history shown to customers.
We do not record the service itself. No prescription, diagnosis, financial record, or other sensitive business document passes through Turnos.
SMS and WhatsApp notifications are sent via MSG91 and Meta's WhatsApp Business API. When we send a message, the customer's phone number is passed to these providers. Their own privacy policies govern how they handle that data.
Like any web application, our servers log IP addresses, browser type, and request timestamps. We use this only for debugging and security monitoring — not for profiling or advertising.
Turnos uses WebSockets (Socket.IO) to push live queue updates to all connected devices — customers see their position update in real time, and staff see the full queue state live. The authoritative queue state is stored in PostgreSQL (hosted on Neon). Redis holds only short-lived data such as login OTPs, rate limits, and cached wait-time averages — not the live queue itself.
These connections are encrypted over TLS. Redis entries expire automatically and are never used as permanent storage.
We do not use Google Analytics, Facebook Pixel, or any advertising or tracking SDKs.
Under the DPDPA 2023, you have the right to:
To exercise any of these rights, email us at hello@turnos.in or message us on WhatsApp. We will respond within 30 days.
To stop receiving SMS or WhatsApp notifications, you can reply STOP to any message or contact the business front desk that added you.
All traffic is encrypted over HTTPS/TLS. Passwords are cryptographically hashed. Database access is restricted to the application and is not publicly reachable. We review dependencies regularly for known vulnerabilities.
If we ever discover a breach affecting your data, we will notify affected users promptly and take immediate steps to contain it.
If we make material changes to how we handle your data, we will notify business admins by email before the changes take effect. The effective date at the top of this page will always reflect the current version.
Questions or requests related to your privacy?