Visitor Desk logo Visitor Desk
← Back to home

Privacy Policy

Effective & last updated: May 2026

Welcome to Visitor Desk, a digital visitor-management platform consisting of a web admin panel and an Android app. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to both surfaces of the platform and to anyone who signs up, signs in, or visits a site managed with Visitor Desk.

Our two privacy modes — at a glance.
Standalone (no business code): visitor data stays on the device; optional Google Drive backup is to your personal Drive.
Attached (approved business): visitor data syncs to your organisation's backend over HTTPS and is visible to the desk manager who controls that business.

What's in this policy

  1. Who we are
  2. Information we collect
  3. How we use information
  4. Offline-first & local storage
  5. Cloud sync & business attachment
  6. QR visitor cards
  7. Google Drive backup
  8. ONLINE / OFFLINE mode
  9. Camera & QR permissions
  10. Data sharing & third parties
  11. Data security
  12. Data retention & deletion
  13. Your rights
  14. Children's privacy
  15. Changes & contact

1. Who we are

Visitor Desk is operated by Black & White Studio. When you use the web admin panel as an owner/manager, we (the operator) are the data controller for your account. When the app is used by staff on behalf of a business, the desk manager who created the business is the controller of the visitor records that flow into that business; we act as a processor for those records.

2. Information we collect

a) Web admin account information

b) Android sign-in (Google)

c) Profile information you provide

d) Device information

e) Business & site data (created by the manager)

f) Visitor records (entered by front-desk staff)

g) Visitor card data (regular-visitor passes)

3. How we use information

4. Offline-first & local storage

The Android app is offline-first. Visitor entries, exits, destinations, incident logs, and history are first written to a local Room database on the device. Most features — entry, exit, search, history, QR generation — work fully without an internet connection.

Important: if you choose to run the app without attaching to a business, your data lives only on the device (and in your own Drive backup, if you create one). It is not visible to any organisation and not protected by our server-side backups. See our offline-only risk guide.

5. Cloud sync & business attachment

To sync records to a business, an app user submits the manager's business code. The manager then explicitly approves, rejects, or later cancels the membership.

6. QR visitor cards

Visitor cards are created by the desk manager in the web admin. Each card carries a unique QR code and identifying details of the cardholder. When the QR is scanned at the front desk, the server records an entry or exit, enforces the card's validity window and entry limit, and returns the result to the device.

7. Google Drive backup (standalone only)

When the app is not attached to a business, Settings exposes a Google Drive backup option. This writes a JSON snapshot of your local database to your own Google Drive (app-data folder) using the drive.appdata scope. We never see the contents of these backups. When the app is attached to a business, this option is hidden because the business backend is the source of truth.

8. ONLINE / OFFLINE mode

The desk manager can set each app user to ONLINE or OFFLINE mode:

When the app starts or resumes its dashboard, it makes a lightweight call to the backend to refresh the user's mode and the active business code. This call also updates the user's "last seen" timestamp visible to the manager.

9. Camera & QR permissions

The Android app requests camera access to capture visitor photos and to scan QR codes (entry/exit, visitor cards). The permission is used only for these features and only while you actively use them. Photos are stored locally and, where applicable, synced with the related visitor record.

10. Data sharing & third parties

We do not sell your personal information or visitor data. Limited data is processed by trusted infrastructure or service providers strictly to operate the platform:

Visitor profiles can be shared by you through other apps (WhatsApp, SMS, email) as text, image cards, or QR codes. Once shared, the destination app and its policies govern that copy.

11. Data security

12. Data retention & deletion

13. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights for data we directly control, contact us using the address below. For visitor records held by a business that uses our platform, please contact the desk manager of that business — they are the controller of those records.

14. Children's privacy

Visitor Desk is intended for use by reception, security, and administrative staff. The app and admin are not directed at children under 13, and we do not knowingly collect data from them.

15. Changes to this policy & contact

We may update this Privacy Policy from time to time. Material changes will be highlighted in the app or admin. The "last updated" date at the top reflects the latest revision.

Questions or requests? Email info@blacknwhiteStudio.com.