AcornCheckIn

Privacy

Last updated July 3, 2026

What we collect

From business owners: your email, name, and avatar from the sign-in provider you choose, plus the business names and staff phone numbers you enter.

From visitors who check in: the name they type and the time they checked in. We do not store visitor IP addresses; we keep a salted one-way hash for abuse prevention that cannot be reversed and rotates daily.

From QR scans: our QR partner TangoQR tells us a scan happened, with the country and device type. No IP address or browser fingerprint reaches us.

How long we keep it

Visitor names are automatically deleted 30 days after check-in. The anonymous row (a check-in happened at this time) is kept so your daily counts stay accurate.

What we never do

We don't sell data. We don't run ads. Visitor names are never used for marketing and are never shared with anyone except the business they checked in at.

Processors we rely on

Railway (hosting), Cloudflare (network), Supabase (sign-in), Postmark (email), Twilio (staff SMS), TangoQR (QR codes and redirects), Sentry (error reporting).

Questions

Email [email protected].