1. Who we are
Q Kyun is a queue management service for clinics, diagnostic centres, restaurants, salons, banks, and other venues where people wait in line. We provide a mobile app and web interface that issues tokens, shows queue positions, and sends SMS notifications.
In this policy, "we" and "Q Kyun" mean the operator of the Q Kyun service. "You" means either a venue operator (a business using Q Kyun to run its queue) or a customer (someone who takes a token at such a venue).
We act as the data controller for venue operator accounts. For customer queue data, the venue is the controller and Q Kyun acts as a processor on the venue's behalf.
2. Information we collect
We collect the minimum needed to move a queue along. Nothing more.
From venue operators
- Account details — name, venue or business name, mobile number, email address
- Venue configuration — queue settings, SMS templates, operating hours
- Billing information — subscription plan, invoices, payment reference IDs
We do not store full card numbers, CVVs, or UPI credentials. Payments are handled by our payment gateway, which sends us only a transaction reference.
From customers who join a queue
- Mobile number — captured by missed call, QR scan, or entered at reception
- Token data — token number, queue position, issue and call timestamps
A customer does not need to install the app or create an account. A phone number and a token number are the whole record.
Collected automatically
- Device and diagnostic data — app version, device model, operating system, crash reports
- Log data — IP address and timestamps for security and abuse prevention
This is used to keep the app stable and to detect misuse, such as automated abuse of the missed-call token system.
3. What we deliberately do not collect
Because Q Kyun is used in clinics and diagnostic centres, it is worth being explicit about the categories we designed the system to stay away from.
| Category | Status |
|---|---|
| Medical records, diagnoses, prescriptions | Never collected |
| Reason for visit or treatment details | Never collected |
| Precise location or GPS tracking | Never collected |
| Contacts, photos, files, or call recordings | Never collected |
| Card numbers, CVV, UPI PIN | Never collected |
| Biometric or government ID data | Never collected |
| Data sold to advertisers or data brokers | Never, under any circumstance |
We do not sell your personal data. We do not rent it, trade it, or share it with advertisers or data brokers. Our revenue comes from venue subscriptions, and we intend to keep it that way.
4. Why we use your information
Each piece of data maps to a specific purpose. If a purpose ends, so does the data.
- To run the queue — issue tokens, track positions, and advance the line
- To send notifications — token confirmation SMS and recall alerts when your turn is near
- To prevent abuse — detect and block numbers misusing the missed-call token system
- To provide support — respond when you contact us with a problem
- To bill venue operators — generate invoices and meet tax obligations
- To improve the product — using aggregate, anonymised usage statistics only
We rely on your consent for SMS notifications, on contractual necessity for running the service you signed up for, and on legal obligation for retaining billing records.
6. How long we keep data
We keep data only as long as it serves the purpose it was collected for, then delete it.
If an account remains inactive for more than 90 consecutive days — no sign-in, no tokens issued, no queue activity — we automatically delete the account and all associated personal data. We send a reminder to the registered mobile number first, so signing in is enough to keep it.
| Data | Retention period |
|---|---|
| Customer token records | 90 days from the date the token was issued |
| SMS delivery logs | 90 days |
| Venue operator account | Until deleted by you, or 90 days of inactivity |
| Device and diagnostic data | Up to 12 months |
| Encrypted backups | Purged within 90 days on rotation |
| Billing and tax records | Up to 8 years, as required by Indian law |
| Anonymised aggregate statistics | Indefinite — cannot identify you |
7. Your rights and choices
Under India's Digital Personal Data Protection Act, 2023, and as a matter of our own policy, you can:
- Access the personal data we hold about you
- Correct anything inaccurate or out of date
- Delete your account and associated data at any time
- Withdraw consent for SMS notifications, which ends queue alerts
- Complain to us, or to the Data Protection Board of India if unsatisfied
To exercise any of these, email hello@qkyun.co.in from the registered address or number. We verify identity by SMS before acting on a request, and respond within 2 business days.
8. How we protect your data
- Encryption in transit — all traffic uses HTTPS/TLS
- Encryption at rest — stored data and backups are encrypted
- Access control — staff access is limited to those who need it, and is logged
- Data minimisation — we do not collect fields we do not use
- Breach response — if a breach affects your data, we notify you and the relevant authority as required by law
No system is perfectly secure, and we will not claim otherwise. What we can commit to is collecting little, keeping it briefly, and telling you promptly if something goes wrong.
9. Children's privacy
Q Kyun is intended for use by adults. We do not knowingly collect personal data from children under 18. Where a parent or guardian provides their own mobile number to hold a token on a child's behalf, the data collected belongs to the adult, not the child.
If you believe a child's data has been collected, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the product evolves or the law changes. The "Last updated" date at the top always reflects the current version. For material changes that affect how we use your data, we notify venue operators by email or in-app notice before the change takes effect.
Continuing to use Q Kyun after a change takes effect means you accept the updated policy.
11. Contact us
For any privacy question, request, or complaint, reach us at: