VisitorLife

Privacy Policy

Effective and last updated: August 19, 2026

VisitorLife (“the App”) is an organization-managed visitor, event, and queue operations service provided by POI. This policy explains what data the App processes, why it is used, and the choices available to users and participating organizations.

1. Data we process

CategoryExamplesPurpose
Account and organizationName, business email, phone number, user ID, company, site, role, and permissionsAuthenticate users, authorize actions, provide support, and separate organization data
Visitor and appointment recordsVisitor name, contact details, organization, visit purpose, host, party size, vehicle number, optional identity number, approval, check-in, and check-out detailsManage authorized visits, site access workflows, guest books, and audit records
Event and queue recordsEvent details, guest list, RSVP, attendance, categories, seating, facilities, queue numbers, counters, and service statusOperate events, attendance, capacity, and queues
Notes and remindersNotebook title and content, category, sharing choice, reminder title, note, scheduled time, and statusProvide private or organization-shared notes and synchronize requested reminders through ReminderLife
User-provided media and audioInvitation photos or videos and push-to-talk audio selected or recorded by an authorized userCreate event invitations and deliver requested team communications
LocationPrecise coordinates submitted during a configured geofenced check-inVerify that an authorized check-in occurs within the organization’s configured site or event area
Device and service informationPush notification token, app/platform information, session identifiers, timestamps, and security or audit logsDeliver notifications, maintain sessions, troubleshoot, prevent misuse, and secure the service
Purchase informationApp Store product, transaction identifier, subscription validity, refund/revocation status, and Event/Queue credit ledgerVerify purchases, provide paid modules, restore entitlements, prevent duplicate credit delivery, and handle refunds

2. Camera, photo library, microphone, and location

The App asks for camera access only after a user opens a QR scanning action. Photo library access is requested only when an authorized event manager chooses invitation media. Microphone access is requested only when a user intentionally transmits using push-to-talk. Precise location is requested only for an organization-configured geofenced check-in. The App does not continuously access these sensors in the background.

3. Face ID and device storage

Face ID is optional and can be enabled only after successful sign-in. Biometric matching is performed by iOS. VisitorLife cannot access, collect, transmit, or store a face image or biometric template. The App receives only the operating system’s success or failure result.

Session tokens and user preferences may be stored on the device so the App can maintain an authorized session. Users can remove them by signing out, disabling the related feature, clearing the App’s data, or deleting the App.

4. How data is used and shared

We use data to provide requested workflows, enforce role-based access, send operational notifications, maintain audit trails, secure the service, and support users. Data may be visible to authorized users in the same organization and processed by infrastructure providers acting on our instructions. LifeOS identity services manage account access. When a user creates a reminder, its title, note, scheduled time, status, app namespace, and trusted user identifier are processed by ReminderLife solely to store, synchronize, and deliver that reminder.

Digital purchases are processed by Apple through the App Store. VisitorLife receives signed transaction information and stores the minimum transaction and entitlement data needed to activate subscriptions, maintain non-expiring activity credits, restore access, and process refunds. VisitorLife does not receive or store a payment card number.

We do not sell personal data, serve behavioral advertising, or track users across apps or websites owned by other companies. We may disclose information when required by law or necessary to protect users, organizations, or the service.

5. Security and tenant separation

We use encrypted HTTPS/TLS connections, expiring sessions, role permissions, organization-level data separation, audit logging, and restricted operational access. No system can be guaranteed perfectly secure, so users should protect their credentials and promptly report suspected misuse.

6. Retention

Each participating organization controls the business need and retention period for its visitor, event, queue, shared notebook, and audit records, subject to applicable law and contractual requirements. Users can archive or delete their Notebook entries and complete, reschedule, or delete ReminderLife reminders from the App. Account and security records may be retained while an account is active and for a reasonable period afterward for security, dispute resolution, backup, or legal obligations. Push-to-talk audio is retained only as configured for the organization’s communication workflow.

7. Access, correction, and deletion

A signed-in user can initiate permanent account deletion directly in the App from Profile → Account & Security → Delete Account. The App requires layered confirmation to prevent accidental deletion. Login identity and access are deleted or revoked; operational records that an organization must retain for security, audit, contractual, or legal reasons are anonymized where applicable. Users may also contact their organization administrator to correct operational data or request an export, or contact admin@poi.co.id.

8. Children

VisitorLife is a workplace and organization operations tool and is not directed to children under 13. We do not knowingly invite children to create public accounts. Organizations are responsible for ensuring that any event or visitor information they enter is lawful and appropriate.

9. Changes

We may update this policy when the App, legal requirements, or operational practices change. The effective date above will be revised, and material changes may be communicated through the App or organization channels.

10. Contact

Privacy, access, deletion, or support requests: admin@poi.co.id