Legal

Privacy Policy

Effective Date: 7 July 2026

1. The Short Version

Turnos is a queue management tool for businesses. We collect the minimum information needed to make queues work — customer names and phone numbers when staff add someone to a queue, and your phone number when you log in as a customer. We do not sell your data. We do not store sensitive business records beyond queue coordination.

This policy is intended to comply with the Digital Personal Data Protection Act, 2023 (DPDPA) of India.

2. What We Collect and Why

2.1 When a customer logs in

Customers log in using their phone number and a one-time password (OTP). We store the phone number and a name (optionally provided) to identify the customer across visits and to show them their own queue history. We do not store the OTP after it is used.

2.2 When staff add a customer to the queue

Front-desk staff enter a customer's name and phone number to register them in a provider's queue. This creates a queue entry with a token number, a timestamp, and the assigned provider. The phone number is used to send SMS or WhatsApp notifications about queue status (e.g., "2 people ahead of you", "it's your turn").

2.3 Business staff and admin accounts

When a business owner registers, we collect their name, email address, and phone number. Providers and staff are added by invitation — we store their name, email, phone, and role within the business. Passwords are hashed and never stored in plain text.

2.4 Queue and visit data

We record each queue entry: the token number, which provider it was for, when the customer joined, their position transitions (waiting → in service → completed/missed/skipped), and the final outcome. This data powers the analytics dashboard for business admins and the visit history shown to customers.

We do not record the service itself. No prescription, diagnosis, financial record, or other sensitive business document passes through Turnos.

2.5 Notifications

SMS and WhatsApp notifications are sent via MSG91 and Meta's WhatsApp Business API. When we send a message, the customer's phone number is passed to these providers. Their own privacy policies govern how they handle that data.

2.6 Technical data

Like any web application, our servers log IP addresses, browser type, and request timestamps. We use this only for debugging and security monitoring — not for profiling or advertising.

3. Real-Time Features

Turnos uses WebSockets (Socket.IO) to push live queue updates to all connected devices — customers see their position update in real time, and staff see the full queue state live. The authoritative queue state is stored in PostgreSQL (hosted on Neon). Redis holds only short-lived data such as login OTPs, rate limits, and cached wait-time averages — not the live queue itself.

These connections are encrypted over TLS. Redis entries expire automatically and are never used as permanent storage.

4. Who Can See What

  • Customers can see only their own queue entries and visit history — not anyone else's.
  • Service providers can see the queue for their own sessions and their own service history.
  • Front-desk staff can see the full active queue and add or manage customers within their business.
  • Business admins can see analytics, full visit history, and manage staff within their business only. They cannot see data from other businesses.
  • Turnos team can access data only for debugging or support purposes, and only with a legitimate reason.

5. Third-Party Services We Use

  • Neon — PostgreSQL database hosting. All persistent data lives here.
  • Fly.io — Infrastructure hosting for the API and web app.
  • Redis (Upstash or self-hosted) — In-memory store for live queue state.
  • MSG91 — SMS and WhatsApp notifications sent to customers.
  • Meta WhatsApp Business API — WhatsApp message delivery.

We do not use Google Analytics, Facebook Pixel, or any advertising or tracking SDKs.

6. Data Retention

  • Queue / visit history — retained to power the analytics dashboard. You may request deletion at any time.
  • Customer accounts — retained until you request deletion.
  • Business accounts — retained for 30 days after access ends, then permanently deleted unless a longer period is required by law or your agreement.
  • Server logs — retained for 30 days, then purged.

7. Your Rights

Under the DPDPA 2023, you have the right to:

  • Know what personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Withdraw consent for notification messages

To exercise any of these rights, email us at hello@turnos.in or message us on WhatsApp. We will respond within 30 days.

To stop receiving SMS or WhatsApp notifications, you can reply STOP to any message or contact the business front desk that added you.

8. Security

All traffic is encrypted over HTTPS/TLS. Passwords are cryptographically hashed. Database access is restricted to the application and is not publicly reachable. We review dependencies regularly for known vulnerabilities.

If we ever discover a breach affecting your data, we will notify affected users promptly and take immediate steps to contain it.

9. Changes to This Policy

If we make material changes to how we handle your data, we will notify business admins by email before the changes take effect. The effective date at the top of this page will always reflect the current version.

10. Contact

Questions or requests related to your privacy?

Terms & Conditions·← Back to Home