Privacy
Last updated August 24, 2026
AcornCheckIn is a product of PerfSpot LLC. This page describes what we collect, how long we keep it, and what we never do with it.
What we collect
From business owners: your email, name, and avatar from the sign-in provider you choose, plus the business names and staff phone numbers you enter.
From visitors who check in: the name they type and the time they checked in. We do not store visitor IP addresses; we keep a salted one-way hash for abuse prevention that cannot be reversed and rotates daily.
From QR scans: our QR partner TangoQR tells us a scan happened, with the country and device type. No IP address or browser fingerprint reaches us.
How long we keep it
Visitor names are automatically deleted 30 days after check-in. The anonymous row (a check-in happened at this time) is kept so your daily counts stay accurate.
If you gave a phone number, it is deleted within 24 hours of your check-in, everywhere we store it, including our own record of the texts we sent you.
What we never do
We don't sell data. We don't run ads. Visitor names are never used for marketing and are never shared with anyone except the business they checked in at.
SMS
If you opt in, AcornCheckIn sends you transactional text messages about your check-in (a confirmation and a "you're up" notice, and where a business has it enabled, one review request afterward). Message frequency varies; message and data rates may apply. Reply STOP to opt out or HELP for help. We do not sell or share your phone number with third parties for marketing.
Processors we rely on
Railway (hosting), Cloudflare (network), Supabase (sign-in), Postmark (email), Telnyx (SMS), TangoQR (QR codes and redirects), Sentry (error reporting).
Questions
Questions? Reach us through our contact page.