Privacy Policy
Antrian RS is a patient queue app for hospitals, operated by Channel Venesia ("we"). This document explains what data the app stores, why, and your rights over that data.
1. Data we store
| Data | Whose | Purpose |
|---|---|---|
| Hospital name, time zone, subscription start and end dates | Hospital | Running the service, the free promo and the Premium subscription |
| Staff full name, email address and role (admin/staff); password (stored as a hash by the sign-in service, not as plain text) | Hospital staff | Signing in and access control |
| List of clinics (name, number prefix, hours, quota) | Hospital | Issuing and calling queue numbers |
| Queue number, clinic, status (waiting, called, done, skipped), time created/called/finished, the staff member who called it, and a random code for the tracking link on the ticket | Hospital | Running the queue, waiting-time reports, and the patient tracking page |
| A random device code (created once when the app is installed) and a note when a registration looks suspicious | Registering device | Preventing abuse of the free promo. It is not the real device identifier. |
| Invoice number, amount and status of subscription payments; for subscriptions bought through the App Store / Google Play: product, store and expiry date | Hospital | Activating and renewing the subscription |
2. Data we do not store
- Patient names, national ID numbers, dates of birth, addresses, phone numbers or medical data.
- Payment card or bank account numbers. Payments are handled entirely by the App Store / Google Play (in the apps) or Xendit (on the web and Windows).
- Location or hardware identifiers.
3. Patients and the QR code on the ticket
A ticket shows the queue number and, if the hospital enables it, a QR code that opens a tracking page. That page opens without signing in, shows only the number, clinic and position in the queue, and can only be opened by whoever holds the link. A queue number cannot be traced back to a patient's identity.
Patients can also take a number themselves by scanning a poster QR code with their own phone. This only asks them to choose a clinic; no personal information is entered.
4. Third parties involved
- Supabase: database, sign-in and realtime sync. Data of different hospitals is separated with Row Level Security, so one hospital cannot read another hospital's data.
- Cloudflare: hosting of the app's website.
- Xendit: processing of subscription payments on the website and in the Windows apps. Your payment data is governed by Xendit's policy.
- Apple App Store / Google Play and RevenueCat: a Premium subscription bought in the iOS or Android app is processed by the app store. RevenueCat manages the status of that subscription for us and receives the hospital's code (not a name or email) together with its subscription purchase history.
- Google AdMob: during the free promo, the Android and iOS apps show ads on the staff menu screen. To serve and measure ads, Google may collect device identifiers (such as the advertising ID), the IP address (which indicates an approximate location) and ad interaction data, under Google's policy. That data is collected by Google, not stored by us. Hospitals on the Premium subscription get no ads. Ads never appear on the website, in the Windows apps, or on the screens patients look at (kiosk, waiting-room display, ticket tracking page).
- The browser/device voice engine: call announcements (e.g. "Nomor antrian dua puluh tiga, Poli Umum") are read aloud by a voice engine. With Microsoft Edge "Natural" voices, that text is processed by Microsoft's speech service. The text contains no patient identity.
We do not sell data. Ads exist only during the free promo as described above, and they never use patient data (the app does not store any).
5. Retention
- Queue data (numbers and their counters) is deleted automatically every night after 180 days.
- Account and hospital data is kept while the service is in use. If a hospital stops using it, the data can be deleted on request (see section 7).
- Payment records are kept as long as needed for bookkeeping.
6. Security
All access uses HTTPS. Staff passwords are stored as hashes. Access is separated between admins and staff, and clinic staff can only call the patients of their own clinic. No system is completely immune; if an incident affects your data, we will notify the hospital concerned.
7. Your rights
Under the personal data protection rules that apply in Indonesia, you may request access to, correction of, or deletion of your account data. Send your request to channelvenesia@gmail.com. For security we may ask for proof that you own the account or officially represent the hospital.
8. Changes to this policy
If this policy changes, the latest version will be published on this page with a new effective date.
9. Contact
Channel Venesia
Email: channelvenesia@gmail.com