Privacy Policy for GuestPass VMS
Effective Date: 15 June 2025
Thank you for choosing GuestPass VMS (“GuestPass,” “we,” “us,” or “our”). This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use the GuestPass mobile application (the “Service”). We are committed to protecting your privacy and complying with Google Play’s User-Data policy. By using the Service, you acknowledge that you have read and understood this Privacy Policy.
Role Clarification: GuestPass operates as a Data Processor on behalf of the facility, estate, or business that licenses the Service (the Data Controller). All data-retention periods and deletion rules ultimately follow the Controller’s instructions.
1. Information We Collect
We collect only the data necessary to deliver secure visitor-management functionality:
a) Visitor Data (entered by guards)
- Full name & phone number – identify visitors and notify hosts.
- National ID / Vehicle plate – verify identity at the gate.
- Photograph – captured via device camera for visual confirmation.
- Purpose of visit – e.g., delivery, maintenance – for security audit and analytics.
- One-Time Password (OTP) – generated for secure exit validation (may be sent via SMS).
b) Resident & System-User Data
- Resident e-mail address and (optionally) resident phone number – used to send visitor-arrival alerts via e-mail and/or SMS.
- Guard/Admin credentials – username and hashed password for authentication.
c) SMS Delivery Metadata (server-side)
- Recipient phone number, message content (alerts/OTPs only), delivery status, timestamps, and provider message IDs.
- We use a third-party SMS gateway to deliver transactional (non-marketing) messages. API keys are kept on our server and are never exposed in the app.
d) Ephemeral Data (processed only in memory)
- ID-card text via on-device OCR – extracted using Google ML Kit; discarded immediately after autofill (never stored or uploaded).
- Camera frame buffer – temporary frames exist only until the photo is saved.
e) Crash & Performance Data (automatic)
- Crash logs – device model, OS version, stack trace (no PII); used to improve performance.
- ML Kit usage metrics – anonymous API-usage stats sent to Google (no images or text).
f) Analytics Data (Firebase Analytics) (automatic)
- App-instance ID (a unique identifier for this app installation).
- App lifecycle events (screen views, sessions, basic interaction events).
- Masked IP-derived coarse location (coarse location inferred from masked IP).
- Device and app information needed to support analytics (e.g., OS/app version, device model).
- Advertising ID: by default, Firebase SDKs can collect the Android Advertising ID.
- GuestPass configuration: we do not use analytics for advertising, do not build ad audiences, and disable advertising features and ad-personalization signals.
g) Crash & Diagnostics Data (Firebase Crashlytics) (automatic)
- Stack traces and crash context (app state, error details).
- Device and app information (device model, OS version, app version).
- We do not intentionally send visitor PII (names/phone/ID numbers) to Crashlytics.
- We do not set Crashlytics user identifiers to phone numbers, ID numbers, or emails.
- Crashlytics supports user identifiers and custom keys; GuestPass will only use non-PII identifiers if used at all.
No Other Data Collected: GuestPass does not collect location data, contacts, or financial/health data. We also do not access, read, or write to your device’s SMS inbox or call logs. SMS messages are sent from our servers via a gateway; no device SMS permission is requested.
Device Permissions: Camera (photos), Storage (temporarily saving images), and Vibrator (notifications) are requested strictly for the purposes described above. We do not request SMS permissions on the device.
2. Why We Collect Data
- Create a tamper-resistant log of all visitor entries/exits.
- Automatically alert residents/hosts of guest arrivals via e-mail and SMS.
- Generate unique OTPs to prevent unauthorised departures (may be delivered via SMS).
- Provide dashboards and reporting for security analytics.
- Authenticate and manage guard/admin accounts.
- Maintain and improve reliability (crash diagnostics, performance metrics).
GuestPass does not use personal data for advertising, profiling, or selling.
Telemetry Controls (Analytics & Crash Reporting)
- Analytics: You can disable “Usage Analytics” in Settings at any time.
- Crash reporting: You can disable “Crash Reporting” in Settings at any time.
3. SMS Notifications
GuestPass sends transactional SMS (e.g., visitor-arrival alerts and OTPs) on behalf of your facility (the Controller). These messages are strictly related to security operations—never marketing.
- Consent & Control: Residents/hosts may opt in or out of SMS alerts through their estate/admin office. Admins can disable SMS per destination or per organisation.
- Frequency: Varies based on visitor activity and estate settings (alerts only when relevant).
- Content: Limited to operational details (arrival notice, OTP codes, brief visit context).
- Gateway: Delivery is performed by a reputable third-party SMS provider. We share only what is needed to send the message (recipient number, message body, and minimal delivery metadata).
4. Data Security
- All data in transit is encrypted with HTTPS/TLS.
- Passwords stored with bcrypt hashing; never in plain text.
- Servers protected by firewalls and strict access controls. SMS API credentials are stored server-side and never exposed in the app.
- Software (including ML Kit) is kept patched against vulnerabilities.
5. Data Retention & Deletion
Personal data is retained only as long as necessary for operational or legal requirements of the Controller. SMS delivery logs (message ID, status, timestamps, recipient) may be retained to verify delivery or investigate issues, and are purged according to Controller policy. Ephemeral OCR and camera buffers are never written to disk. Audit logs of account deletions may be kept for up to 30 days before final purge.
6. Sharing & Disclosure of Data
- Residents (Hosts) – receive visitor details via e-mail and/or SMS.
- Authorised administrators – access visitor logs via secure dashboards.
- Service providers – SMS gateway, e-mail delivery, or cloud hosting, all bound by confidentiality and data-processing terms.
- Service providers (analytics/crash reporting): we share limited analytics and diagnostic telemetry with Google LLC (Firebase) for Firebase Analytics and Firebase Crashlytics, acting as our service provider/processor for app measurement and crash reporting.
- Legal compliance – disclosed only when lawfully required.
- Business transfers – data may transfer to a successor, who must honour this Policy.
No data is sold, rented, or shared with advertising networks or third-party analytics SDKs.
7. Account Deletion
- Visit our Account Deletion page.
- Enter your username and password.
- Click Delete My Account and confirm.
After verification: your personal account data is erased immediately; visitor logs linked to you are anonymised or removed; a deletion audit record is retained for up to 30 days, then purged. Deleting your account is irreversible. Facility records of past visitors remain unless the Controller removes them.
8. Your Rights
You may have rights to access, correct, delete, or object to processing of personal data. Visitors/residents should contact their facility management (Data Controller). Guard/admin users can manage some rights in-app or via the deletion page. We will assist the Controller in fulfilling valid requests.
9. Children’s Privacy
The Service is not directed to children under 13. We do not knowingly collect data from children. Parents or guardians can request deletion of any inadvertent collection (see Contact Us).
10. Changes to This Policy
We may update this Policy periodically. The “Effective Date” will change and significant updates may be highlighted in-app or by e-mail. Continued use after updates constitutes acceptance.
11. Contact Us
If you have questions or requests about this Privacy Policy or our data practices, please contact us.