Queue9

Privacy Policy

Published by Mindful Malabar Ventures · Operator of Queue9 (queue9.in)

Last updated: 15 August 2026

1. Who this policy covers

This Privacy Policy explains how Mindful Malabar Ventures ("we", "us", "our"), the company that operates Queue9 (queue9.in), collects, uses, stores, and shares personal data through the Queue9 platform.

Queue9 is used by two kinds of people, and this policy covers both:

  • Business owners and staff — the clinics, food courts, salons, and other venues that sign up for a Queue9 account to manage their queues ("Venues").
  • Customers — the patients, diners, and walk-in customers of those Venues, who scan a QR code or receive a booking link to join a queue or book a time slot ("Customers").

Where a Venue collects a Customer's personal data through Queue9 (for example, when a patient checks in at a clinic), the Venue is the Data Fiduciary responsible for that data under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and Queue9 acts as a Data Processor on the Venue's instructions. Where we collect a Venue owner's or staff member's own personal data (for example, when they sign up for an account), we act as the Data Fiduciary for that data.

2. What personal data we collect

2.1 From Customers, at the point they join a queue or book a slot

  • Full name
  • Mobile phone number
  • Email address — optional, only if the Customer chooses to provide it
  • Approximate device location — only for Venues that have enabled geofencing, and only at the moment of check-in, to confirm the Customer is at or near the Venue
  • WhatsApp opt-in status — whether the Customer has agreed to receive queue and order status messages on WhatsApp
  • Feedback and star ratings — optional, submitted after a visit

2.2 From Venue owners and staff

  • Name, email address, and mobile number, provided at signup
  • Business name, address, and business hours
  • Staff login credentials and role (admin or front-desk)
  • Billing and subscription information — processed through our payment partner, Razorpay. Queue9 never receives or stores card, UPI, or other payment instrument details; Razorpay handles and stores this data end-to-end under its own security standards.

2.3 Collected automatically, and cookies

  • Standard technical logs (IP address, browser type, access times) generated by our hosting infrastructure
  • Session cookie for Venue staff logins only — when a Venue owner or staff member logs into the operator or admin dashboard, we set a strictly necessary authentication session cookie (via our backend provider, Supabase) so they stay logged in. This is not set for Customers scanning a QR code or checking their tracker page — that flow does not require login and does not set this cookie.
  • We do not currently use analytics or advertising cookies such as Google Analytics or the Meta Pixel. If we add these in the future, we will update this policy first and, where required, request your consent through a cookie banner before they become active.

3. Why we collect this data

In line with the DPDP Act's requirement that we state specific, itemised purposes — not a vague catch-all — here is exactly what each category of data is used for:

  • Name and phone number: to create a queue token or slot booking, identify the Customer to Venue staff, and send status updates (on-screen and, where opted in, via WhatsApp).
  • Email address: only to send a visit summary or receipt, if provided.
  • Location: only to confirm the Customer is physically at the Venue before allowing check-in, for Venues that use this feature. Never used for any other purpose, never sold, never retained after the check-in decision is made.
  • WhatsApp opt-in: to determine whether we are permitted to send a Customer a message outside the Queue9 tracker page, in line with WhatsApp's own Business Platform policies.
  • Venue and staff account data: to operate the account, provide customer support, process billing, and enforce plan limits (number of counters and staff seats).
  • Technical logs: for security, fraud prevention, and diagnosing service issues.

4. Consent

Where we rely on consent as the basis for processing, that consent is free, specific, informed, unconditional, and given through a clear affirmative action — for example, ticking a WhatsApp opt-in checkbox that is not pre-ticked. We do not bundle consent for one purpose with an unrelated purpose, and providing consent for WhatsApp messages is never a condition of being allowed to join a queue.

A Customer or Venue user may withdraw consent at any time. Withdrawing consent for WhatsApp messages stops future messages but does not delete a queue token already issued. See Section 7 for how to withdraw consent or exercise other rights.

5. Who we share data with

We do not sell personal data. We share it only with the following categories of recipient, and only as needed to operate the service:

  • The Venue where a Customer checked in — they can see the Customer's name, phone number, and queue history at their own venue only. Tenant isolation in our system prevents one Venue from seeing another Venue's data.
  • Wap2b, our WhatsApp Business Solution Provider — processes phone numbers and message content solely to deliver queue and order status messages.
  • Razorpay — processes Venue billing and subscription payments.
  • Supabase, our database and authentication provider — stores platform data, including Customer and Venue records, on our behalf. Supabase hosts this project's data in Singapore. This means personal data is transferred outside India as part of ordinary platform operation. The DPDP Act permits this unless the Central Government has specifically restricted transfers to that country; Singapore is not currently a restricted destination, and we will update this policy if that changes.
  • Hostinger, our application hosting provider — hosts the Queue9 web application and retains standard server access logs, kept only for security and diagnostic purposes.
  • Law enforcement or regulators, only where legally required to do so.

6. How long we keep data

  • Completed or cancelled queue tokens (Customer name, phone, email, queue history): 30 days from the visit date, then automatically deleted.
  • Venue and staff profile data (name, email, login, business details): 7 days after account closure, then deleted.
  • Billing, invoice, and payment records: kept for as long as applicable Indian tax and accounting law requires — this is a separate, longer statutory obligation, independent of the 7-day figure above, and is not shortened by an account closing.
  • Technical/server logs: kept only as long as needed for security monitoring and diagnosing service issues, then deleted.

Retention periods exist to balance a Venue's legitimate need for historical records against the DPDP Act's principle that data should not be kept longer than necessary for the stated purpose.

7. Your rights, and how to exercise them

Under the DPDP Act, a Data Principal (a Customer, or a Venue owner/staff member, depending on context) has the right to:

  • Access a summary of the personal data we hold and how it is being processed.
  • Request correction of inaccurate or incomplete data.
  • Request erasure of personal data that is no longer needed for the purpose it was collected for.
  • Withdraw consent at any time, as easily as it was given.
  • Nominate another individual to exercise these rights on their behalf in the event of death or incapacity.
  • File a complaint with the Data Protection Board of India if dissatisfied with how a request was handled.

To exercise any of these rights, contact our Grievance Officer using the details in Section 9. We will respond as soon as reasonably practicable.

8. How we protect your data

  • Row-level tenant isolation, so one Venue's data is never visible to another.
  • Encrypted data transmission (HTTPS) across the platform.
  • Access to Customer data within a Venue is limited to that Venue's own logged-in staff.

No system is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach likely to cause harm, we will notify the Data Protection Board and affected Data Principals in line with the DPDP Act's breach notification requirements.

9. Grievance Officer

  • Name: Shibin S.
  • Email: privacy@queue9.in
  • Address: Mindful Malabar Ventures, 68/1523, 5th Floor, CM Mathew Brothers Arcade, Chakkorathukulam, Near Westway Hotel, Kozhikode, Kerala 673006, India

10. Children's data

Queue9 is not directed at children, and we do not knowingly collect personal data from anyone under 18 for the purpose of creating their own Venue account. Where a Customer's queue entry is created by a parent, guardian, or clinic staff member on behalf of a minor patient, that data is processed as part of the Venue's own healthcare or service record-keeping, under the Venue's responsibility as Data Fiduciary.

11. Changes to this policy

We may update this policy from time to time. If we make a material change, we will update the "Last updated" date below and, where required, seek fresh consent.

12. Contact us

For any question about this policy or how your data is handled, contact us at privacy@queue9.in or through the Grievance Officer listed in Section 9.

Some clause here is pending lawyer review.