Privacy Policy

Last updated: July 16, 2026

VISYRA ("we", "our", "the app") is a visitor management platform used by organizations to manage guest check-ins, host notifications, and access badges at their premises. This policy explains what data we collect, why, and how it is protected — both on the VISYRA web dashboard and the VISYRA mobile app.

1. Who this applies to

VISYRA is used by two kinds of people: staff (admins, receptionists, employees, guards) who have a login, and visitors who are checked in by staff and do not themselves create an account. Each organization's data is kept in a separate, isolated database.

2. Information we collect

Staff accounts

  • Name, email address, phone number, department, and role/permissions
  • Password (stored as a salted hash — we never store or can see your plain-text password)
  • Profile photo, if uploaded
  • A device push-notification token, so you can be notified when a visitor arrives

Visitors

  • Name, phone number, email address, and company name, entered by front-desk staff at check-in
  • A photo taken at check-in, used for the visitor badge and identity verification
  • Purpose of visit, host being visited, vehicle number (if applicable), and check-in/check-out timestamps
  • Precise location (latitude/longitude) at the moment of check-in — only if the organization has enabled geofenced check-in for their site

3. How we use this information

  • To check visitors in and out, and generate QR access badges
  • To notify the relevant host (via push notification, WhatsApp, or email) that their visitor has arrived
  • To verify a visitor's identity at guard checkpoints
  • To let organization admins view visit history and generate reports
  • To operate core account functions: login, password reset, and billing for the organization's subscription

We do not sell personal data, and we do not use it for advertising.

4. Third-party services we use

To operate the app, some data is processed by these service providers on our behalf:

  • Google Cloud Storage — stores visitor and profile photos
  • WhatsApp Business Platform (Meta) — sends visitor badges and approval requests, if enabled by the organization
  • OneSignal — delivers push notifications to the staff mobile app
  • Resend — sends transactional emails (approvals, password resets, invoices)
  • Upstash Redis — short-lived caching of active visit/badge data for fast QR verification

5. Data retention

Visit records are retained by the organization for as long as their subscription is active, or as required by their own record-keeping policy. Temporary caches (badge lookups, visitor photos used for fast QR verification) automatically expire within 24 hours. Staff can request deletion of their account by contacting their organization's admin.

6. Data security

Data in transit is encrypted (HTTPS/TLS). Passwords are hashed, never stored in plain text. Each organization's data lives in an isolated database, inaccessible to other organizations on the platform. Access to staff accounts requires authentication; visitor records are only visible to authorized staff of the same organization.

7. Your choices

Push notification permissions, camera access, and location access are all optional and can be managed from your device settings. Declining them limits certain features (e.g. no photo capture, no geofenced check-in) but does not prevent using the rest of the app.

8. Children's privacy

VISYRA is a business tool and is not directed at, or knowingly used by, children.

9. Contact us

Questions about this policy or your data can be sent to aparnacommunication@gmail.com or via visyra.in.