Skip to Main Content
QsslyM3 Theme
Security & Privacy First

Privacy Policy

Effective Date: [EFFECTIVE DATE] | Version: 1.0.0-draft

At Qssly, privacy is built directly into our systems, not just our policies. This Privacy Policy details how we handle the database records and configurations submitted to our multi-tenant headless booking engine. We are committed to protecting the privacy of both our business clients ("Tenants") and the customers who book appointments, stays, or classes through them ("End-Customers").

1. Roles: Processor vs. Controller

Qssly operates under a two-sided structural model depending on whose data is being processed:

  • Qssly as a Data Processor: For any End-Customer personal data collected, scheduled, or managed on behalf of our Tenants, Qssly acts strictly as a data processor / service provider. The Tenant is the data controller, and their respective privacy policies govern the data collection and usage.
  • Qssly as a Data Controller: For account details of the Tenants' staff, billing details, waitlist submissions, and feedback submitted directly via our portal and in-app beta widgets, Qssly acts as a data controller.

2. Data We Collect

We process only the data necessary to provide a reliable, conflict-free scheduling service:

  • End-Customer Information: Collected during booking—includes name, email, phone number, booking slot selections (dates, times, service selection, resource assignment), and any custom intake-form metadata schemas defined by the Tenant.
  • Tenant Details: Organizational configurations, business names, industries, settings, and staff account details (names, email addresses, hashed passwords).
  • Waitlist & Feedback Submissions: Information supplied voluntarily via the platform's in-app beta widgets (name, email, role, and text feedback).

3. Multi-Tenant Data Isolation & Protection

Unlike typical platforms that rely on simple application-level locks, Qssly segregates and isolates organization and customer records with strict tenant isolation boundaries. Every data request is dynamically verified and bound to the authenticated organization identity—ensuring one business account physically cannot access or read another organization's records under any circumstance.

4. Payment Processing & Secrets Protection

Qssly is not a merchant-of-record. We never store, transmit, or process credit card details:

  • Payments from End-Customers are processed directly by the Tenant's own gateway accounts (Razorpay or Stripe) using their respective hosted checkout widgets.
  • Tenant payment gateway credentials and API keys stored in our systems are securely protected by encryption at rest. Plaintext secrets are never stored inside our database tables.

5. Cookies, Auth & Trackers

We believe in lean, private-by-default software engineering:

  • No Tracking: We run no web analytics tools, ad cookies, behavioral trackers, or third-party advertising scripts.
  • Authentication: End-customers authenticate using secure one-time email OTP codes. Tenant staff authenticate via email/password.
  • State Storage: Hashed authentication and session tokens are stored locally in the browser's localStorage. No persistent HTTP tracking cookies are set by the platform.

6. Retention & Deletion Rights

We retain personal data only for as long as necessary to provide service availability. Qssly utilizes soft-deletion for records to preserve audit histories and prevent accidental data loss. Complete database purging and deletion of Tenant or End-Customer accounts is performed upon request. Please email your request to [CONTACT EMAIL].

7. Subprocessors

To provide the booking SaaS, we share relevant details with the following third-party infrastructure subprocessors:

  • Hosting & Infrastructure: Amazon Web Services (AWS) & Managed Database Service
  • Transactional Communications: SMTP Mail Gateway & Twilio SMS
  • Payment Processing: Stripe, Inc. and Razorpay Software Private Limited
  • DPO Contact: [email protected]

8. Regional Rights & Compliance

We provide privacy guarantees based on standard data protections. Depending on your location, you may have rights under regional regulations (such as GDPR, CCPA, or DPDP). You can request data access, correction, or withdrawal by contacting us at [email protected].

Qssly is owned and operated by Qssly Technologies.