Privacy Policy — VisitaSmart
Effective Date: March 10, 2026
Last Updated: August 7, 2026
1. Introduction
VisitaSmart ("we," "our," or "the App") is a residential access control and visitor management platform operated for Homeowners Associations (HOAs). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the VisitaSmart mobile application.
By using VisitaSmart, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide Directly
| Data Type | Purpose | When Collected |
|---|---|---|
| Full name | Account identification and display within your HOA | Registration |
| Email address | Authentication and account recovery | Registration |
| Phone number (optional) | Contact information for your HOA | Registration |
| Password | Account authentication (stored as a secure hash, never in plain text) | Registration |
| Unit / house number | Association with your residential unit | Registration / Admin assignment |
| HOA registration code | Verification of community membership | Registration |
2.2 Information Generated Through App Usage
| Data Type | Purpose |
|---|---|
| Visitor pass data | Names, ID numbers, dates, times, and vehicle information of guests you register |
| QR code data | Generated codes linked to visitor passes for access verification |
| Entry/exit logs | Timestamped records of visitor access events at the gate |
| Delivery records | Provider names and receipt confirmations |
| Event information | Event names, dates, times, and guest counts |
| Guard session data | Guard name, PIN hash, login timestamps, and assigned access point |
2.3 Information Collected Automatically
| Data Type | Purpose |
|---|---|
| Device language | To set the default app language |
| App usage timestamps | Session management and security |
| Push notification identifier | So we can deliver notices to this device — see below |
Push notifications (native apps only)
If you grant notification permission, the app obtains a device identifier (a notification token) and stores it against your account, so we know which phone to send notices to. Alongside the token we store the device model and the app version, so we can diagnose delivery problems.
Three important clarifications:
- This does not apply if you use VisitaSmart from a browser. The web version (m.visitasmart.gt) does not request that permission, obtains no token, and cannot send push notifications. Anyone using VisitaSmart on an iPhone today is in that situation: they receive notices by email only.
- The token is not an advertising identifier. It is not the IDFA or the AAID, it is not shared with advertisers, and it is not used for profiling or targeting. It exists solely to deliver the notice.
- It is deleted when it stops applying: on sign-out, on uninstall, or when the delivery service tells us the device no longer exists.
You can turn notifications off at any time from Settings → Notifications inside the app, or from your phone's settings.
Web analytics (visitasmart.gt and app.visitasmart.gt only)
Our websites — the public site and the admin dashboard — use Google Analytics 4 to understand how they are used. The mobile app contains no analytics tooling at all: nothing described here applies if you only use the app.
| Data Type | Purpose |
|---|---|
| Pages viewed and traffic source | To learn which content is useful and where visitors come from |
| Device and browser type | To prioritize which screens we test changes on |
| Approximate location (country or city, derived from IP) | To understand which markets show interest |
| Analytics session identifier (cookie) | To tell new visits apart from returning ones |
About this analytics:
- We do not send personal data to Google. Dashboard page addresses are trimmed before being sent, so no identifier travels in them. We never send your name, email, phone, or any resident or visitor data.
- If you are signed in to the dashboard, activity is associated with an anonymous internal identifier (a UUID), never your email or name.
- We do not enable Google Analytics advertising features (Google Signals, remarketing, or demographic reports). The data is not used for profiling or ad targeting.
- You can block it with any browser extension that blocks analytics; the sites work the same either way.
2.4 Information We Do NOT Collect
- We do not collect location data (GPS)
- We do not collect device identifiers (IDFA, AAID) for advertising
- We do not use analytics or advertising SDKs in the mobile app (our websites do use Google Analytics, described in §2.3). The mobile app does include a notification delivery SDK (Expo and, underneath it, Google's Firebase Cloud Messaging): it exists to get notices to your phone, not to measure your behaviour or for advertising
- We do not collect biometric data
- We do not access contacts, photos, or files beyond explicit user actions (CSV import, QR sharing)
3. How We Use Your Information
We use the information we collect exclusively to:
- Provide the service — Create and manage visitor passes, verify access at gates, and enable HOA administration.
- Authenticate users — Verify your identity when you sign in.
- Communicate within the HOA — Display emergency alerts and event notifications set by your HOA administrator.
- Maintain security — Log entry/exit events and prevent unauthorized access.
- Improve the service — Fix bugs and improve app functionality.
We do not use your information for advertising, profiling, or any purpose unrelated to the residential access management service.
4. How We Share Your Information
4.1 Within Your HOA
Your information is shared with other members of your HOA as necessary for the service:
- HOA Administrators can see your name, unit, email, phone number, and membership status.
- Guards can see visitor names, pass types, unit numbers, and resident names when verifying passes at the gate.
- Other residents cannot see your personal information.
4.2 Third-Party Service Providers
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase (Backend) | Database hosting, authentication, and real-time services | All app data (encrypted in transit and at rest) |
| Google Analytics (websites only) | Measuring use of visitasmart.gt and the web dashboard | Pages viewed, traffic source, device type, approximate location by IP. No personal data — see §2.3. Not used in the mobile app |
| Resend (email delivery) | Delivering platform email: password recovery, and administrative invitations and notices | Your email address and the message content |
| Expo (notification delivery) | Routing push notifications to your phone | The device identifier and the notice text |
| Google Firebase Cloud Messaging (Android) | Actual delivery of the notification on Android phones | The device identifier and the notice text |
4.3 We Do NOT
- Sell your personal information to third parties
- Share data with advertisers
- Transfer data to data brokers
- Use your data for purposes outside this Privacy Policy
4.4 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency).
5. Data Storage and Security
- All data is stored on Supabase cloud infrastructure with encryption at rest and in transit (TLS 1.2+).
- Passwords are hashed using industry-standard algorithms and are never stored in plain text.
- Guard PINs are stored securely and are only accessible to HOA administrators.
- QR codes contain only a pass identifier — no personal information is embedded in the QR code itself.
- Row-Level Security (RLS) policies ensure that users can only access data relevant to their role and HOA.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data (profile, email) | Until you request account deletion |
| Visitor passes | Until you delete them or request account deletion |
| Entry/exit logs | Retained by the HOA; subject to the HOA's data retention policy |
| Guard accounts | Until removed by the HOA administrator |
7. Your Rights
You have the following rights regarding your personal data:
- Access — Request a copy of your personal data.
- Correction — Update your name, password, and other profile information directly in the app.
- Deletion — Request complete deletion of your account and associated data (see Section 8).
- Portability — Request your data in a machine-readable format.
- Withdraw consent — Stop using the app at any time.
- Stop receiving notices — Turn email or phone notifications off from Settings → Notifications, or via the unsubscribe link in every notice email. Essential account email — such as password recovery — is still sent, because without it you could not regain access.
To exercise these rights, contact your HOA administrator or email us at the address listed in Section 11.
8. Account Deletion
You may request the deletion of your account and all associated data at any time. Upon deletion:
- Your profile, email, and personal information will be permanently removed.
- Your visitor passes will be deactivated and deleted.
- Entry/exit logs associated with your passes will be anonymized.
- Your membership in all HOAs will be revoked.
To request account deletion:
- Contact your HOA administrator, or
- Send an email to our support address (see Section 11) with the subject line "Account Deletion Request."
Deletion will be processed within 30 days of your request.
9. Children's Privacy
VisitaSmart is not intended for use by children under the age of 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Updating the "Last Updated" date at the top of this policy.
- Displaying a notice in the app if the changes are significant.
Your continued use of the app after changes are posted constitutes your acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact:
VisitaSmart Support Email: support@visitasmart.gt
12. Device Permissions
VisitaSmart requests the following device permissions:
| Permission | Purpose | Required? |
|---|---|---|
| Camera | Scanning QR codes at the gate (Guards only) | Yes (Guards) |
| File access | Importing CSV files for unit management (Admins) and saving QR images (Residents) | Optional |
| Sharing | Sharing QR pass images via WhatsApp or other apps | Optional |
All permissions are requested only when needed and can be revoked at any time through your device settings.
This Privacy Policy applies to the VisitaSmart mobile application available on iOS and Android.