Last updated: 23 July 2026
This describes how VisitLog handles information. Each facility using VisitLog is responsible for its own notices to its visitors and staff — what a facility must tell the people signing in at its front desk is that facility's obligation, not ours.
Visitors: name, arrival and departure time, who they are visiting, the purpose of the visit, and — where the facility has enabled it — a credential type for visiting professionals. Facilities may also record agreement to their visitor policy.
Employees: name, an optional employee code and role, a hashed clock-in PIN, scheduled shifts, and clock-in/clock-out times.
Everyone: the IP address and browser of devices used to sign in to dashboards, for security purposes.
VisitLog handles two kinds of photograph very differently, and the difference matters:
Visitor photographs are never stored. Where a facility enables them, the image exists in memory only long enough to be placed on the visit form that is emailed or printed, then it is discarded. It is not written to disk, not saved in the database, and not included in the copy the facility keeps.
Clock-in photographs are stored, because their purpose is to let a supervisor verify who punched in. They are kept for a period the facility chooses (30, 90, 180, or 365 days) and then automatically deleted. The time record itself is kept regardless — only the photograph ages out.
VisitLog does not perform facial recognition. No face template or biometric identifier is derived, stored, or compared. These are photographs, not biometrics — though facilities in states with biometric privacy statutes should confirm their own obligations.
Facilities are isolated from one another. A facility's staff and administrators see only their own facility's records. Where one operator runs several homes, they see only the homes they have been granted.
VisitLog staff can access facility data only to operate and support the service. Every administrative action is written to a tamper-evident audit log.
Visitor and time records are retained indefinitely by default, because facilities generally need to produce them during licensing surveys, and federal recordkeeping rules require payroll-related time records be kept for three years. Clock-in photographs are deleted on the facility's chosen schedule. Generated visit-form PDFs are pruned after 30 days.
[REVIEW] State what happens when a facility closes its account, and whether you offer deletion on request.
VisitLog runs on a server in the United States. Encrypted backups are stored [REVIEW — name your backup destination and its location]. Backups are encrypted with AES-256 and are unreadable without a key held separately from the server.
We do not sell personal information. We do not share it with advertisers. We may disclose information where legally required, and we use [REVIEW — list your subprocessors: hosting provider, email provider, backup destination, printing service] to operate the service.
[REVIEW] Depending on where a facility and its visitors are located, people may have rights to access, correct, or delete information. State how someone exercises those rights and how quickly you respond. Note that VisitLog usually acts on the facility's instructions rather than directly for a visitor.
Passwords and PINs are stored hashed, never in plain text. Sessions are bound to the device that created them and expire. Administrative actions are recorded in a hash-chained audit log that makes tampering detectable. Backups are encrypted.
[REVIEW] State how you would notify facilities of a suspected breach, and within what timeframe.
[REVIEW — your contact address for privacy questions]