VMS Portal — Privacy Policy
Effective date: 21 June 2026
1. Who We Are
VMS Portal is a Visitor Management System (VMS) mobile application operated by MIG Security. The app is used exclusively by authorised security personnel and client administrators at enrolled facilities. It is not available for general public use.
2. Information We Collect
2.1 Visitor Data
Security guards enter the following information about visitors at the gate:
- Full name, phone number, company name
- Vehicle registration number
- Government-issued ID type and number (Aadhaar, PAN, Passport, DL, or Voter ID) — stored in encrypted form, accessible only to authorised administrators of the same facility
- Purpose of visit, host name, and host department
- Transport mode (Vehicle / Walk / Bus / Rapido / Other) and vehicle registration number if applicable
- Visitor photo and government ID photo (captured at check-in, stored on Cloudinary)
- Check-in and check-out timestamps
- Material declaration (if any items are being carried in)
2.2 User Account Data
User accounts (security guards, client administrators, and department members) are created exclusively by the system administrator — there is no public self-registration. Each user receives an auto-generated Employee ID that serves as their login identifier:
- SEC001, SEC002 … — security guards
- CLI001, CLI002 … — client administrators
- DEPT001, DEPT002 … — department members
We store the user's name, Employee ID, role, assigned facility, and hashed password (bcrypt). No email address or personal contact information is collected from app users. Passwords are never stored in plain text.
No sensitive personal information (Aadhaar, PAN, financial data, etc.) is collected from security guards, client users, or department members. Only the data necessary to operate the app in the assigned role is stored.
2.3 Device Permissions
| Permission | Why it is used |
|---|---|
| Camera | Scanning visitor QR codes at the gate, capturing visitor photos and government ID photos during check-in, and scanning patrol checkpoint QR codes for night-round verification |
| Location (while in use) | Attaching your precise location to SOS emergency alerts, and verifying you are physically present at a patrol checkpoint when scanning (anti-spoofing) |
| Notifications | Receiving real-time alerts for visitor approvals, SOS events, and vehicle entries |
| Vibration | Haptic feedback for incoming SOS alerts |
Location is only accessed when you actively trigger an SOS alert or scan a patrol checkpoint QR code. It is never tracked passively or in the background.
2.4 Patrol Checkpoint Data
When a security guard scans a patrol checkpoint QR code, the app records:
- Guard name and Employee ID
- Checkpoint name and unique QR identifier
- Date and time of scan
- Device GPS coordinates at the time of scan (used to verify physical presence)
GPS coordinates are used solely to verify the guard is physically at the checkpoint — they are not displayed to guards, shared outside the facility, or used for any other purpose. Patrol logs are accessible only to the system administrator and the client administrator of the same facility.
2.5 Authentication Tokens
A JWT (JSON Web Token) is issued on login and stored in your device's encrypted secure storage (expo-secure-store). It is never stored in plain text and is deleted when you log out.
3. How We Use Your Information
- Processing and logging visitor check-ins and check-outs
- Sending real-time approval notifications to designated department members
- Recording inbound and outbound vehicle movements at the facility
- Dispatching and tracking SOS emergency alerts
- Generating attendance records for security personnel
- Recording guard patrol checkpoint scans (time, date, location) for night-round audit trails
- Maintaining an audit trail for facility security compliance
We do not use your data for advertising, profiling, or any purpose outside the operation of this visitor management system.
4. Data Sharing
We do not sell or share personal data with third parties. Visitor and vehicle data is shared only between the security guard who enters it and the authorised client administrator of the same facility, within the same organisation.
We use the following infrastructure providers to operate the service:
- MongoDB Atlas — encrypted cloud database for storing all records
- Cloudinary — secure cloud storage for visitor photos and government ID images
- Render.com — hosting of the backend API server
- Expo — build platform and push notification delivery infrastructure
5. Data Retention & Legal Basis
Visitor records, vehicle logs, and SOS records are retained for as long as the facility subscription is active. Visitor and ID photos stored on Cloudinary are retained for the same duration and deleted upon facility account termination.
Visitor records are retained independently of individual user accounts. If a security guard, client user, or department member's account is deleted, the visitor and vehicle logs they created are preserved. This is because these records belong to the facility, not to the individual user, and serve a legal compliance function independent of who recorded them.
Legal basis (India): Industrial and commercial facilities in India are required to maintain visitor entry records for safety audits and regulatory compliance under applicable security and industrial regulations. The collection and retention of visitor identity data (including government ID verification) is performed for the lawful purpose of facility access control and visitor safety verification — not for commercial use. This is analogous to a physical visitor register maintained at a factory gate.
Users may request deletion of their personal account data (name, Employee ID) by contacting us at the email below. Visitor records cannot be individually deleted by security guards as they form part of the facility's security audit trail.
6. Security
All data is transmitted over HTTPS. Passwords are hashed (bcrypt). Authentication tokens are stored in encrypted device storage. The API enforces JWT authentication and rate limiting on all endpoints.
7. Children's Privacy
VMS Portal is a professional tool intended solely for use by employees of enrolled organisations. It is not directed at children under 18. We do not knowingly collect data from minors.
8. Your Rights & Account Deletion
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your user account and associated personal data
- Withdraw consent for location access at any time via your device settings
Important — Account Management: User accounts in VMS Portal are created and managed by your organisation's system administrator, not through self-registration. If you need your account removed, your administrator can delete it directly. Alternatively, you can request deletion by contacting us:
To request account deletion: Send an email to Admin@migsecurityservic.com with subject line "Account Deletion Request" and include your name and Employee ID. We will process your request within 30 days and confirm by email.
Note: Deleting your account removes your login credentials and personal profile data. Visitor and vehicle records you created remain in the facility's security log as required for legal compliance (see Section 5).
9. Changes to This Policy
We may update this policy when the app adds new features. The effective date at the top of this page will always reflect the most recent version. Continued use of the app after changes constitutes acceptance of the updated policy.
10. Contact Us
MIG Security
Email: Admin@migsecurityservic.com