Privacy Policy
In short
- TurnDesk helps clinics take appointments on WhatsApp and manage them in a dashboard.
- We store what that needs: patients' names, WhatsApp numbers and appointments, and clinic staff accounts.
- We do not sell personal data, show advertising, or use analytics or tracking tools.
- The dashboard sets one essential sign-in cookie. This website sets none.
- To see, correct or delete information, write to hello@turndesk.live.
1. Who we are
TurnDesk ("TurnDesk", "we", "us") is software for clinics and doctors, provided as an online
service. Patients book, check, cancel and reschedule appointments by messaging the clinic's
WhatsApp number. Clinic staff see and manage those appointments, and the clinic's schedule,
in the TurnDesk dashboard at app.turndesk.live.
This policy covers the TurnDesk service (the WhatsApp booking assistant and the dashboard)
and this website, turndesk.live.
2. Clinics and TurnDesk
For patient information, the clinic is in charge. A clinic decides to use TurnDesk and decides how it runs its appointments. TurnDesk handles patients' information on the clinic's behalf, only to provide the service to that clinic. Under India's Digital Personal Data Protection Act, 2023, the clinic acts as the data fiduciary for its patients' data and TurnDesk as its data processor.
For clinic staff accounts and this website, TurnDesk is in charge of the information described below.
Each clinic's information is kept separate from every other clinic's. One clinic cannot see another clinic's patients, appointments or messages.
3. Information we handle
Clinics and their staff
- Clinic details: the clinic's name, address, phone number and time zone.
- Doctors: name, specialisation and, if the clinic adds it, a contact number.
- Staff accounts: name, email address, role (owner, admin or staff), whether the account is active, and when it last signed in.
- Passwords: we never store a password itself, only a one-way (bcrypt) hash of it that cannot be turned back into the password.
- Clinic settings: working hours, days off, booking rules, blocked times and reminder settings the clinic configures.
- Staff actions: when a staff member cancels or reschedules an appointment in the dashboard, we record who did it, what changed and when.
Patients
- WhatsApp number: the number a patient messages the clinic from.
- Name: the name given when booking, including a family member's name when booking for someone else.
- Appointments: booking reference, doctor, date and time, token number, status (booked, cancelled, completed) and when it was booked or cancelled.
- The conversation in progress: the step a patient has reached in booking and the choices made so far, and when they last messaged.
- Messages we send: a record of each WhatsApp message TurnDesk sends to a patient (its content, time and the message reference WhatsApp returns), so the clinic can see what patients were told.
We do not keep copies of the messages patients send. We keep only what is needed from them to make or change a booking, as listed above. We do not ask patients for medical information, and the booking assistant has no place to enter it.
Signing in to the dashboard
When a staff member signs in, we create a session that lasts at most 12 hours. We store a one-way hash of the session token (never the token itself), when it expires, when it was last used and whether it was signed out. We do not store staff members' IP addresses or device details with their sessions.
Technical information
Like any website, our servers and hosting providers receive technical information with each request, such as IP addresses and browser details, to deliver and protect the service. Our servers also write operational logs, such as errors and response times, to keep the service working. We keep patient details out of these logs wherever we can; phone numbers, for example, appear only in shortened form. Our hosting provider keeps these logs for a limited period.
Connecting a clinic's own WhatsApp number
If a clinic owner connects the clinic's own WhatsApp Business number to TurnDesk, the owner signs in with Meta in a window that Meta operates and chooses which WhatsApp Business account and number to share. TurnDesk then stores the identifiers of that account and number and the access token Meta issues, which we keep encrypted.
4. How we use it
- To let patients book, check, cancel and reschedule appointments on WhatsApp, and to reply to them.
- To show clinics their appointments and let them manage their schedule.
- To send WhatsApp messages about appointments on the clinic's behalf, such as booking confirmations and replies to patients.
- To keep accounts secure, for example by limiting repeated sign-in attempts.
- To find and fix problems with the service.
We do not sell personal data. We do not use it for advertising, and we do not use analytics, advertising or tracking tools on the service or on this website.
6. Services we use
TurnDesk runs on the following providers. Each receives only what it needs to do its part, and each handles data under its own terms and privacy policy.
| Provider | What it does for TurnDesk | Data involved |
|---|---|---|
| Meta Platforms (WhatsApp Business Platform, Cloud API) | Carries WhatsApp messages between patients and the clinic's number. Also provides the sign-in used when a clinic connects its own WhatsApp number. | Patients' WhatsApp numbers and the messages exchanged; the clinic's WhatsApp Business account details. |
| Supabase (PostgreSQL database) | Stores TurnDesk's database. | Everything described in section 3 that TurnDesk stores. |
| Render | Runs TurnDesk's server, which answers WhatsApp messages and the dashboard. | The data passing through the service, and operational logs. |
| Vercel | Hosts the dashboard (app.turndesk.live) and this website. |
Dashboard pages as staff use them, and technical request information. |
We do not use analytics services. Patients' use of WhatsApp itself is also covered by WhatsApp's privacy policy.
7. Where data is stored
TurnDesk's database is hosted by Supabase in Mumbai, India. Our server and hosting providers, and Meta when it carries WhatsApp messages, may process data in other countries as part of providing their services.
8. How long we keep it
- Clinic, staff and settings information: for as long as the clinic uses TurnDesk.
- Patient and appointment records: for as long as the clinic uses TurnDesk, so the clinic keeps its appointment history. We do not currently delete them automatically after a fixed period; they are deleted when the clinic asks, when its account is closed, or when a valid deletion request is made (see below).
- Sign-in sessions: stop working after at most 12 hours or when the staff member signs out.
- Operational logs: kept by our hosting provider for a limited period under its settings.
- Backups: we make backup copies of the database so the service can be restored after a failure. Backups contain the same information as the database, so information that has been deleted may remain in older backups until those backups are themselves deleted.
When a clinic stops using TurnDesk, we delete its information, except anything we must keep to meet a legal obligation, and then only for as long as that obligation requires.
9. Deletion and other requests
Patients
Because your clinic manages its own records, the quickest way to see, correct or delete your information is usually to ask the clinic. You can also write to us at hello@turndesk.live with your WhatsApp number and the clinic's name. We will work with the clinic to act on your request, and may need to confirm that the number is yours before we do.
Clinics and staff
A clinic owner can ask us to export or delete the clinic's information, or to close the clinic's account, by writing to hello@turndesk.live from the owner's email address.
We respond to requests within a reasonable time and within any period the law sets. Deleting a patient's information also removes their appointment history with that clinic, and they would need to book again.
10. Security
- All traffic to TurnDesk is encrypted with HTTPS.
- Passwords are stored only as one-way (bcrypt) hashes, and session tokens only as one-way hashes.
- WhatsApp access tokens that clinics connect are encrypted (AES-256-GCM) before they are stored.
- Every message TurnDesk receives from WhatsApp is checked to be genuinely from Meta before it is processed.
- Each clinic's data is kept separate from other clinics', and staff see only their own clinic.
- Staff roles limit who can change appointments and clinic settings, and repeated sign-in attempts are limited.
- The database's public data interface is locked down and returns no data; only TurnDesk's server and administrators can access the database.
No system is perfectly secure. If a breach affecting personal data happens, we will inform the clinics concerned, and anyone else we are required to inform, as the law requires.
11. Your rights
Depending on the law that applies to you, including India's Digital Personal Data Protection Act, 2023, you may have the right to:
- know what personal information is held about you and how it is used;
- have inaccurate or incomplete information corrected;
- have your information deleted;
- withdraw consent where processing relies on it;
- raise a complaint and have it addressed.
To use any of these rights, write to hello@turndesk.live. If you are a patient, we may pass your request to your clinic, which manages your records.
12. Children
TurnDesk is used by clinics and adults. A parent or guardian may book an appointment for a child using the child's name; that booking is handled like any other and managed by the clinic.
13. Changes to this policy
When TurnDesk changes what it collects or who it shares data with, we update this page and the date at the top. For significant changes we will also let clinics know directly.
14. Contact
Questions, requests and complaints about privacy: hello@turndesk.live.