Privacy Policy: Visitor Sign-In Kiosk

Last updated: 27 September 2026

Visitor Sign-In Kiosk ("the app") is published by DIGITAL SHIJIL LLC ("we", "us"). This policy explains what the app does with information. Contact: contact@digitalshijil.com

Who is responsible for visitor data

The app is a tool that an organisation (a business, school, clinic, studio or similar) installs on a tablet at its reception. That organisation is the controller of the visitor data the kiosk holds. It decides which details to ask for, how long to keep them, and answers visitors' requests. We do not receive, see or process any visitor data, so we cannot look it up or delete it for you; please ask the organisation you visited.

What the app stores, and where

When a visitor signs in, the app stores on that tablet only: - the details the organisation's form asks for: name, and optionally company, who they are visiting, the reason for the visit, vehicle registration, phone number and email address; - the time they signed in and out, and how they signed out; - if the organisation turned it on, the site rules they accepted and their finger-drawn signature; - if the organisation turned it on and the visitor agreed, a photo taken with the tablet's own camera app; - a random six-character badge code, printed on their badge as text and as a QR code (the QR holds only the code, never the name).

The organisation's settings (its name, logo, hosts list, sign-in form, rules text, privacy notice, retention period and a hashed staff PIN) are stored on the tablet too.

All of it stays in the app's private storage on that one tablet. The app has no internet permission and never uploads, syncs or sends it anywhere. Android backup is switched off, so it is not copied to cloud backup or to another device either.

Automatic deletion

Visit records, with their signatures and photos, are deleted automatically once they are older than the organisation's retention period: 90 days unless the organisation chooses another. The check runs every day and whenever the app starts. The organisation can also delete one visitor's records on request, or delete everything with "Delete all data". Uninstalling the app deletes everything.

Before a visitor signs in

Every visitor is shown a privacy notice before typing anything. The organisation can edit it; the standard wording says the details stay on the tablet and when they are deleted.

Exports

Staff can save the visitor history as a spreadsheet or PDF, print badges and the roll call, or export all data as a JSON file, from the PIN-protected staff area only. Where those files go is the organisation's choice and responsibility.

Purchases and Google Play

Pro is sold through Google Play Billing. Google handles payment and receives the purchase details under Google's own privacy policy; we never see card or payment details. Google Play Billing also reports purchase-flow diagnostics to Google. For Play's Data safety form this is declared as: App info and performance > Diagnostics: collected, not shared, required.

What the app does not do

No account or sign-in. No ads. No analytics, tracking or crash-reporting SDK. No location. No contacts access. No camera permission (photos go through the tablet's camera app). No messages to hosts. No facial recognition and no identity-document scanning.

Children

The app is a business tool for adults and is not directed at children. The organisation decides who signs in at its reception.

Record-keeping

For personal record-keeping. Not an official document. The roll call and badges help an organisation know who is on site; they are not a certified fire-safety or access-control system.

Changes

If this policy changes, the new version is published at https://apps.digitalshijil.com/visitor-kiosk/privacy/ with a new date.

Contact

DIGITAL SHIJIL LLC ยท contact@digitalshijil.com