Skip to content

Privacy Policy

Last updated:

1.Introduction and Scope

Welcome to QueueCare.

We provide a cloud-based clinic management software and queue management system as a service, available via queue.care.

This Privacy Policy governs the manner in which we collect, process, use, maintain, and disclose information from users of our Service.

By accessing or using our Service, you agree to the terms of this Privacy Policy.

2.Legal Distinction: Data Controller vs. Data Processor

Due to the nature of our Service, it is essential to define the legal roles concerning personal data under applicable data protection frameworks (such as the General Data Protection Regulation — GDPR):

  • The Client (Clinic/Medical Center): Acts as the Data Controller. The Client determines the purposes and means of processing their patients' data.
  • QueueCare: Acts exclusively as a Data Processor. We process patient data solely on behalf of the Client and in accordance with their documented instructions. We claim no ownership of the patient data inputted by the Client into our systems, nor do we assume any direct responsibility for its content.

3.Information We Collect

We collect information through three primary channels:

  • A. Client-Provided Information (Account Data): Business name, email address, and billing and subscription preferences.
  • B. Patient Data Inputted by the Client (Processing Data): Clients may input end-user (patient) data into the Service, including names, contact details, appointment records, queue statuses, and what was paid for a visit. We dynamically process this data exclusively to facilitate the Service's functionalities.
  • C. Automatically Collected Information (Usage and Device Data): Internet Protocol (IP) addresses, browser type, operating system, timestamp data, and Service interaction metrics. This data is utilized for security monitoring, error detection and resolution, and Service enhancement.

4.The Role of the Merchant of Record (MoR) and Payment Processing

We operate as the software provider. However, the legal entity selling the subscription to you is our designated Merchant of Record (MoR), Dodo Payments.

Financial Data Security: We do not collect, store, or process full credit card numbers or sensitive financial data on our servers.

All payments and transaction-related compliance are securely and directly processed by Dodo Payments. Your financial transactions are subject to the Privacy Policy and Terms of Service of Dodo Payments.

5.Third-Party Sub-Processors

To deliver a seamless and reliable Service, we engage strictly vetted third-party sub-processors. These entities receive only the data strictly necessary to execute their specific functions:

  • Convex — database: Stores every record the Service holds: patient names and contact details, queue and visit status, the daily ledger, and Client account data. Hosted on Amazon Web Services.
  • Railway — application hosting: Runs the QueueCare application servers. All traffic to the Service passes through it.
  • Cloudflare — network and public-site analytics: Sits in front of queue.care, so every request to the website and to the Service's pages and API calls passes through it on the way to Railway. The Service's live connection to its database goes to Convex directly and does not. On the public website only, never inside the Service, it also counts visits with Cloudflare Web Analytics, which sets no cookies and does not identify the visitor.
  • Clerk — staff authentication: Holds the sign-in identity of Client staff: email address, password credential, and Google sign-in identifier. It receives no patient data.
  • Microsoft Azure Speech — the spoken call: Turns the waiting-room call into a voice. Where a centre prints queue numbers the call is the number; otherwise it is the patient's name as the screen displays it, sent to Azure to be said out loud. What the screen displays — and so what is said — is yours to shorten in Settings → Access & Security.
  • OneSignal — push notifications: Sends the push notifications that carry queue updates. Those notification bodies carry the patient's name — "Please send in patient: …" to a reception desk, or "… has been moved to your room" to a doctor — and unlike the waiting-room screen they are not shortened. They go to Client staff, and to a patient's own phone when that patient switches on the alert for their own ticket.
  • Sentry — error monitoring: Receives an automated report when the Service fails: the error and its stack trace, the URL, and browser and device information. It is not used for analytics and receives no patient records.
  • Telegram — operating reports and staff alerts: Carries two different things. The end-of-day and periodic summaries carry the clinic, doctor and room names and aggregate counts. The live alerts carry more: the patient's name, the room, and the text of any note a staff member has written on that patient. Alerts are sent only to the staff accounts that have a Telegram chat linked; where none is linked, nothing is sent.
  • QuickChart — report charts: Renders the charts inside those summaries from the same aggregate figures.
  • Dodo Payments — Merchant of Record: Sells the subscription and processes payment. See the section on the Merchant of Record above.

6.Data Security and Confidentiality

We implement enterprise-grade, commercially reasonable technical and organizational measures designed to protect your personal information and Client-inputted data from accidental loss, unauthorized access, use, alteration, or disclosure. This includes data encryption in transit (HTTPS/SSL) and at rest. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

7.Data Retention and Deletion

  • Account Data: Retained for as long as the Client's subscription remains active. When the Client's data is deleted, the staff accounts and workstation profiles belonging to that Client are deleted with it.
  • Patient Data: On a direct request from the Client (the Data Controller), a 7-day grace window opens during which the request can still be cancelled. After it closes, the Client's data is removed from every table that holds it, together with the files attached in chat and, for a multi-floor centre, its floors.
  • What is kept, and why: One record is kept deliberately: the audit log — the only evidence that the deletion took place. It holds no patient name and no file number; there is no field for either. One piece of free text does reach it: the deletion reason the centre types when it makes the request. Everything else is the event, the time, and which centre it belonged to. It is swept after twelve months, so anything written in that box is kept for that long.
  • Backups: A backup taken before a deletion holds a copy for up to 7 days from the date that backup was taken, after which it expires automatically. We state this rather than omit it: for that period the data is deleted from the live system but not yet gone from the backup.

8.Cookies and Tracking Technologies

We employ essential cookies strictly necessary for the core functionality of the Service (e.g. session management and authentication). We do not utilize third-party advertising cookies within the Service dashboard. You may configure your browser to refuse cookies, though this may impact the functionality of the Service. On the public website, not inside the Service, we count visits with Cloudflare Web Analytics, which sets no cookies and does not identify you.

9.Your Data Protection Rights

Depending on your applicable jurisdiction (including considerations under the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA)), you have the right to:

  • Access, rectify, or erase your personal data.
  • Object to or restrict the processing of your data.

10.International Data Transfers

Information collected through the Service may be stored and processed globally wherever we or our sub-processors maintain facilities. By utilizing the Service, you consent to the cross-border transfer of information in compliance with applicable legal frameworks.

11.Contact Information

For privacy-related inquiries, data deletion requests, or compliance notices, please contact us at: