Privacy Policy
Last Updated: 30/08/2026
1. Who We Are
Quriq ("we," "us," "our") provides a clinic queue management platform used by doctors and clinics ("Clinic," "you," when referring to our direct customer) to manage patient queues, appointments, and related operations. This policy also covers how we handle information about patients who interact with a Clinic through Quriq (e.g., via a tracking link), even though the Clinic — not Quriq — is the party a patient directly visits.
Contact for privacy matters:
Email: hello@quriq.in / support@quriq.in
Address: F-401 Poonam Estate Cluster 1, Shanti Park, Mira Road - 401107, Maharashtra, India
Under the DPDP Act, Quriq acts as a Data Fiduciary for the account/business data of Clinics, and generally as a Data Processoron behalf of Clinics for the patient data Clinics input into the platform (the Clinic determines what patient data is collected and why; Quriq processes it on the Clinic's instructions).
2. What Information We Collect
2.1 From Clinics and Their Staff
- Name, email address, phone number
- Business details (clinic name, address, city, state, pincode)
- Login credentials (passwords are stored securely hashed — Quriq never stores or has access to your plain-text password after account creation)
- Payment and subscription information (processed via Razorpay — see Section 5)
2.2 From Doctors (entered by Clinics)
- Name, speciality, phone number, email (optional)
- Consultation timing preferences
- Profile photo (optional, if uploaded)
2.3 About Patients (entered by Clinic staff on a patient's behalf)
- Name, phone number, age, gender
- Visit reason (optional, entered by Clinic staff)
- Queue status and visit history at that specific Clinic
- Appointment date/time information
Quriq does not collect patient data directly from patients themselves in most cases — this is entered by Clinic staff. A patient interacting with a tracking link or WhatsApp notification is receiving a message the Clinic has authorized Quriq to send on its behalf.
2.4 Automatically Collected Information
- Basic usage/analytics data (e.g., via Vercel Analytics) — page views, general usage patterns, not tied to patient identity
- Device/browser information standard to any web application
3. How We Use Information
We use the information described above to:
- Provide and operate the queue management service (adding patients, managing queues, generating tracking links)
- Send appointment/queue status notifications via WhatsApp and email
- Process subscription payments and generate receipts
- Provide analytics and insights to Clinics about their own patient flow (aggregated data about a Clinic's own patients, visible only to that Clinic)
- Maintain platform security and prevent misuse
- Communicate with Clinics about their account, billing, or support needs
- Comply with legal obligations
We do not sell personal data to third parties, and we do not use patient data for advertising purposes.
4. Legal Basis for Processing
Under the DPDP Act, we process personal data based on:
- Consent — Clinics consent to this policy when creating an account; patients receive notifications as part of a service their Clinic has arranged, which is a legitimate use incidental to the Clinic's own service to the patient
- Contractual necessity — processing needed to provide the subscribed service
- Legitimate use — for basic security, fraud prevention, and legal compliance
5. How Information Is Shared
We share information only as necessary to operate the service, with the following categories of service providers (sub-processors):
| Purpose | Provider | What's Shared |
|---|---|---|
| Payment processing | Razorpay | Payment details (Quriq does not store full card numbers) |
| Database & hosting | Supabase | All platform data (encrypted at rest and in transit) |
| Email delivery | Resend | Email address, for receipts/notifications |
| WhatsApp notifications | Meta (WhatsApp Business Platform) | Patient phone number, appointment details, for sending confirmation messages |
| Application hosting | Vercel | Standard hosting/technical data |
We do not share personal data with any other third party for their own independent use, and we do not sell personal data under any circumstances.
We may disclose information if required by law, court order, or to protect the rights, safety, or property of Quriq, our users, or others.
6. Data Security
We take the following measures to protect information:
- Row-Level Security (RLS): Each Clinic's data is technically isolated at the database level — one Clinic cannot access another Clinic's patient data, even in the event of a bug affecting one account
- Encryption: Data is encrypted in transit (HTTPS) and at rest
- Access controls: Staff access to a Clinic's data is limited to authenticated, authorized personnel of that specific Clinic
- Restricted internal access: Quriq's own administrative access to raw patient data is limited by design — day-to-day platform operation does not require or provide browsing access to patient records across clinics
- Regular security review: including dependency vulnerability scanning and access-control audits
No system can guarantee absolute security, but we take reasonable, documented technical and organizational measures consistent with DPDP Act requirements.
7. Data Retention
- Queue and visit records: retained for up to 3 years to support Clinic analytics and historical reporting, after which they are automatically deleted
- Payment/subscription records: retained as a permanent transaction history for accounting and legal purposes; failed or abandoned payment attempts are automatically deleted after a shorter period
- Account data: retained for as long as the Clinic maintains an active account, and for a reasonable period after closure for legal/accounting purposes
Clinics or patients may request earlier deletion of specific data, subject to any legal retention obligations (see Section 8).
8. Your Rights (Data Principal Rights under DPDP Act)
If you are a Clinic, doctor, or patient whose data we process, you have the right to:
- Access the personal data we (or a Clinic, via us) hold about you
- Correct inaccurate or incomplete data
- Erase data that is no longer necessary for the purpose it was collected, subject to legal retention requirements
- Withdraw consent at any time (for Clinics: by closing your account; for patients: by contacting the Clinic directly, as they control what data is entered)
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
- Grievance redressal — raise a complaint with us directly, and if unresolved, with the Data Protection Board of India
Patients specifically:Since Clinic staff enter patient information on the patient's behalf, requests to access, correct, or delete patient data should generally be directed to the Clinic first, as they control this data. Quriq will assist Clinics in fulfilling such requests.
To exercise any of these rights, contact: hello@quriq.in
9. Children's Data
Quriq's platform is intended for use by Clinic staff (adults). Patient records may include minors, entered by Clinic staff as part of legitimate healthcare administration (e.g., a parent booking a child's appointment). We do not knowingly collect data directly from children, and Clinics are responsible for ensuring appropriate consent is obtained from a parent/guardian when a minor's information is entered.
10. Cookies and Analytics
Our website and application may use basic cookies/local storage necessary for login sessions and core functionality, and limited analytics (e.g., Vercel Analytics) to understand general usage patterns. We do not use third-party advertising trackers.
11. Data Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Rules, and take immediate steps to contain and remediate the breach.
12. International Data Storage
Data may be stored on servers located in South East Asia/Singapore.
13. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to Clinics via email or an in-app notice. Continued use of Quriq after changes take effect constitutes acceptance of the revised policy.
14. Grievance Officer
In accordance with the DPDP Act, our Grievance Officer can be reached at:
Name: Jacky Yadav
Email: jacky@quriq.in
Response time: We aim to respond to all privacy-related queries within 7 business days.
If a complaint is not resolved to your satisfaction, you may approach the Data Protection Board of India.
15. Governing Law
This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, and is subject to the exclusive jurisdiction of the courts in Thane/Maharashtra.
