1. Who this policy applies to
This policy applies to guests who check in via Visit Vanta at a partner business, and to business owners and staff using the Visit Vanta Business Portal. Some data types are collected only in one context or the other — where that matters, we call it out.
2. What we collect
From guests, at check-in
- Contact: the name and phone number (or email) the guest voluntarily provides at the kiosk, QR or mobile check-in.
- Visit metadata: the time of arrival, the specific business location, and — if opted in — a small number of guest-provided preferences (e.g. "still water," "sat by window").
- Recognition token: a per-tenant, non-reversible identifier used to recognize returning guests without storing biometric data.
From businesses using the Portal
- Account details (name, email, role).
- Billing information, processed by our payment provider — we don't store card numbers.
- Standard product analytics (feature use, error reports) — never guest data.
We do not collect
- Facial images. Biometric templates. Location beyond the check-in event. Third-party ad-tech identifiers. Anything from data brokers.
3. Why we collect it
Guest data is collected for exactly one purpose: to help the business the guest checked in with remember, recognize, and better serve that guest. That's the entirety of the guest data purpose.
Business account data is used to operate the product, bill correctly, and reach the account holder when necessary.
4. How data is stored & secured
All guest data is stored per-tenant in an encrypted database. Encryption keys are rotated every 90 days and are per-tenant so a compromise of one tenant cannot expose another. In transit, we use TLS 1.3. At rest, AES-256. See the Security page for the full technical detail.
5. Who sees the data
- The business. The tenant that collected the check-in has access to it.
- Their staff. Only through the Portal, with role-based permissions.
- Visit Vanta. Only a small on-call team, only for support requests initiated by the business, and only with a signed access record.
- No one else. We do not share, sell, license, or trade guest data with any third party. Ever.
6. Your rights
Guests can, at any time, ask the business they checked in with to show, correct, or delete their data. If the business can't help within a reasonable time, guests can reach us directly at privacy@visitvanta.com. If you're in the EU, UK, California or another jurisdiction with a specific data protection regime, the standard local rights apply and we honor them.
7. Data retention
Guest data is retained for as long as the business partner has an active relationship with the guest — controlled by the business. On termination of a business's account, all guest data is exported to the business and then irrecoverably deleted from our systems within 30 days.
8. Cookies
See our short Cookie policy for the specific cookies used by visitvanta.com and the Business Portal.
9. Children
Visit Vanta is not directed at children under 16 and we do not knowingly collect information from them. Businesses in categories serving minors are provided age-gating patterns to keep this policy honest.
10. International transfers
Guest data stays in the region it was collected in whenever possible. Where cross-region transfers are unavoidable, we use standard contractual clauses and equivalent legal safeguards.
11. Changes to this policy
We'll update this document when the product changes materially. The version and effective date at the top are always current. Substantial changes are announced to Portal admins by email at least 30 days before they take effect.
12. Contact
Data protection questions: privacy@visitvanta.com
General inquiries: info@visitvanta.com · +1 (551) 222 9609