Privacy Policy
Last updated: July 9, 2026
This Privacy Policy explains how Visit Verificator ("we," "us," "the Service") collects, uses, and protects information when an organization uses our visitor management platform — the web admin console, the visitor dashboard (web and Android), and the mobile app.
Visit Verificator is provided to organizations ("Customers") who operate their own visitor reception. Visitors, guests, and delivery couriers interact with the Service on behalf of a Customer, who controls what information is collected at their location. If you are a visitor with a question about your information, please contact the organization you visited — we act as their service provider.
1. Information We Collect
Visitor check-in information. When you check in at a visitor dashboard: your full name, organization/company name, phone number, email address, the purpose of your visit, and who you are visiting. We also record your check-in and check-out times.
Identity verification codes. A short one-time code sent to your email or phone number to confirm it's really you before completing check-in. Codes expire automatically after 10 minutes and cannot be reused.
Delivery records. For package or courier drop-offs: the courier's name, courier company, and who or what the delivery is for.
Pre-registered visits. If a host or administrator invites you ahead of time, we store the name, email, phone number, organization, and purpose supplied for that invitation.
Administrator and staff accounts. If you manage or work reception for an organization on CheckIn Eagle, we collect your name, email address, and role. Authentication is handled by our infrastructure provider, Supabase.
Visitor dashboard device information. To keep visitor dashboards online and support them remotely, we record basic device information (device type, browser, operating system, screen resolution, app version) and a device pairing identifier for each paired visitor dashboard device. This describes the device, not the people using it.
Administrative activity logs. Actions administrators take in the console (for example, changing settings) are logged with the acting administrator's name, for accountability and security review.
1.1 Browser Storage (Cookies and Local Storage)
Visit Verificator uses browser-based storage technologies to improve your experience and maintain your session:
- Session tokens. When you sign in as an administrator or staff member, we store your session token in your browser's local storage. This allows you to remain logged in as you navigate the application. Your session token is automatically cleared when you log out.
- Device pairing credentials. When a visitor dashboard device is paired to your organization, we store a pairing token in the device's browser local storage. This allows the device to authenticate with our servers on subsequent visits without requiring manual re-pairing.
- Functionality cookies. We do not currently use third-party cookies for tracking or analytics. However, we may use secure, first-party cookies in the future to support essential functionality like load balancing or security features.
All stored data is encrypted in transit via HTTPS/TLS and remains scoped to your organization. You can clear your browser's local storage at any time through your browser settings; doing so will log you out and require you to sign in again.
2. How We Use Information
- To operate visitor and delivery check-in/check-out, including identity verification via one-time codes.
- To notify hosts or reception staff when a visitor arrives or a delivery is logged.
- To let an organization's administrators review their own visitor logs for security, safety, and compliance purposes.
- To maintain, troubleshoot, and secure visitor dashboard devices and administrator accounts.
3. Data Storage and Your Choices
Clearing your session. You can log out at any time through the application interface to clear your session token from your browser. For visitor dashboard devices, only an administrator can reset the device's pairing credentials.
Do Not Track. Visit Verificator does not respond to Do Not Track signals, as we do not engage in cross-site tracking or targeted advertising.
4. How Information Is Shared
We do not sell personal information. Information is only visible to the organization you are checking in with — organizations cannot see one another's visitor records.
We rely on the following service providers to operate CheckIn Eagle:
- Supabase — hosts our database, authentication, and backend functions, in the EU (Ireland).
- Resend — delivers transactional emails, including one-time verification codes, visit confirmations, and host notifications.
- Termii — delivers SMS messages, if an organization enables text-message verification codes.
We may also disclose information if required by law, or to protect the rights, property, or safety of CheckIn Eagle, our customers, or the public.
5. Data Retention
We retain visitor, delivery, and account information for as long as necessary to provide the Service, as configured by the organization you are checking in with, and as required by law. Organizations can set a preferred retention period in their dashboard settings. You may ask the organization you visited, or contact us directly, to request that your information be reviewed or deleted sooner.
6. Your Choices and Rights
Depending on where you live, you may have rights to access, correct, or delete your personal information, or to object to certain uses of it. Because the organization you visited controls the collection of your information, we ask that you first contact them. You're also welcome to contact us directly using the details below, and we will coordinate with the relevant organization.
7. Security
Each organization's data is isolated using row-level security in our database, so one organization can never read another's records. Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider. One-time verification codes expire automatically, and administrator access is scoped to each person's assigned role.
8. Children's Privacy
CheckIn Eagle is intended for use by adult visitors, employees, and couriers at business premises, and is not directed at children. We do not knowingly collect information from children.
9. International Data Transfers
Our infrastructure is hosted in the European Union (Ireland). If you visit an organization located outside the EU, your information will be transferred to and processed in the EU in order to provide the Service.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above.
11. Contact Us
Questions about this policy or your information can be sent to help.fraseryouthcoding@gmail.com.