Privacy notice
Last reviewed: July 25, 2026.
This notice is maintained by the Visits Record team. It describes how the product handles personal data. Individual customers (site owners) are the data controllers for their own visitor records; we act as the processor.
Who we are
Visits Record is operated by the Visits Record team. Contact: privacy@visitsrecord.com.
Data we collect from account holders
- Email address, name, hashed password.
- Company + site metadata you enter.
- Log data: IP address, user agent, timestamps (for security and abuse prevention).
Data collected from visitors (on behalf of our customers)
- Name, phone number, purpose of visit, host name, entry/exit time.
- Optional selfie image.
- Optional custom fields the site owner configures (vehicle number, ID upload, NDA acceptance, etc.).
Lawful basis
Site owners rely on legitimate interest (security and premises safety) as the primary lawful basis, with the balancing test documented in their own DPIA. Consent is captured for optional fields.
Retention
Default retention is 90 days; site owners may configure per-site windows up to statutory maximums. Data older than the window is hard-deleted, including any linked selfies in object storage.
Sub-processors
- Supabase (Postgres, Auth, Storage) — hosting.
- Vercel — application hosting and edge network.
- Email provider — transactional email (OTP, notifications).
Your rights
Under GDPR (EU/UK) and DPDPA (India) you may request access, rectification, deletion, and portability of your personal data. Contact privacy@visitsrecord.com; we reply within 30 days.
Cookies
We use only essential cookies for authentication. No advertising or analytics cookies are set by the platform.
Changes
We update this notice as the product evolves. Material changes are announced in-app.