Back to overview

Privacy Policy

Zabbu Visit — Kiosk App Privacy Policy

This Privacy Policy explains how the Zabbu Visit Kiosk App, also known as Zabbu Access Point, accesses, collects, uses, stores, and shares information to support visitor check-in, visitor check-out, employee attendance, delivery registration, QR and NFC scanning, visitor photo capture, ID document scanning, device pairing, and related reception workflows at organisational sites.

Last updated: May 7, 2026
For visitors, employees, administrators, and organisations using the Zabbu Visit Kiosk (Zabbu Access Point)

Overview

The Zabbu Visit Kiosk App (also referred to as Zabbu Access Point) is a visitor management kiosk application installed on tablet devices at the reception areas of organisations using Zabbu Visit. On Android, the app is published as Zabbu Kiosk / Zabbu Access Point under package co.zabbu.visitor.

The kiosk supports visitor check-in and check-out, QR and invitation code validation, returning visitor lookup, visitor photo capture, ID document scanning and OCR, employee attendance check-in and check-out, delivery registration, NFC presence workflows, emergency status display, device pairing, and offline queueing when connectivity is unavailable.

In most deployments, the organisation that installs the kiosk is the primary data controller for visitor and attendance records. Serve Digital acts as a data processor on their behalf.

Who This Policy Applies To

  • Visitors who check in or out at a kiosk-equipped reception
  • Employees who use the kiosk for attendance or presence workflows
  • Administrators who pair, configure, or manage the kiosk device
  • Organisations that deploy the app at a physical site or branch

Information the App Accesses or Collects

1. Visitor check-in information

  • Full name
  • Phone number
  • Email address
  • Company or organisation
  • Visitor type, visit purpose, and optional visit notes
  • Name of the host or person being visited
  • Department or site assignment associated with the visit
  • ID number, national ID number, and ID type if typed by the visitor or extracted from an ID scan and confirmed before submission
  • Visitor asset information, such as asset type and description, if the organisation has enabled asset registration
  • Visit identifiers, visit status, check-in time, and check-out time

2. QR, invitation, returning visitor, and check-out data

  • QR codes scanned from visitor invitation emails or pre-registration confirmations
  • Invitation codes entered manually
  • Search terms used to look up returning visitors or checked-in visitors
  • Visitor IDs or visit IDs used to complete check-in or check-out
  • Check-out notes, asset-return status, and asset notes where provided

3. Photo, camera, and ID scan data

  • Visitor photos captured during check-in when photo capture is enabled
  • Camera frames used locally to scan QR codes and guide ID document alignment
  • ID document images captured during the scan flow for on-device OCR and user review
  • Extracted ID scan fields, such as name, ID number, ID type, nationality, date of birth, or expiry date, depending on the document and the fields enabled by the organisation

4. NFC card or badge information

  • NFC badge or card identifier read from the device NFC reader when NFC presence is enabled
  • Presence, visitor, or attendance response returned by the Zabbu backend after the NFC card identifier is submitted

5. Employee attendance information

  • Employee or user ID selected through the employee/host lookup flow
  • Employee name, department, contact details, and current attendance status returned by the backend for lookup and display
  • Check-in and check-out actions, onsite work mode, optional notes, timestamps, and status

6. Delivery information

  • Delivery personnel name
  • Delivery personnel phone number and email address, if provided
  • Package or delivery description
  • Delivery type
  • Recipient host and department
  • Optional notes, status, and timestamps

7. Device, pairing, configuration, and diagnostics

  • Device name, manufacturer, model, operating system type and version, app version, package name, and build number
  • Device identifier used for authentication and session management
  • Pairing code, device authentication token, kiosk configuration, site configuration, feature flags, and cached host data
  • Network and API error information, crash and error reports, app logs, and performance diagnostics
  • Administratively configured kiosk device ID and kiosk/site location label, where configured

8. Support report information

  • App log files
  • A screenshot of the current app screen
  • A free-text description of the issue
  • The time or situation entered by the person submitting the report
  • Optional contact information provided by the person submitting the report

Support report information is collected and shared only when a user or administrator intentionally uses the app's support report workflow.

Camera Access

The app requests camera access only when a camera-based workflow is used. Camera access supports QR code scanning, visitor photo capture during check-in where enabled, ID document capture for OCR-based form pre-fill where enabled, and local live guidance that helps position an ID document in the scan frame.

The camera is not used for background monitoring, continuous recording, audio recording, or surveillance. The app's camera controller disables audio capture.

Visitor photos captured for a visit are uploaded to Zabbu's backend with the visit record. If the device is offline, the visitor photo may be stored in the local offline queue until the visit can be synchronised.

ID document images captured for OCR are processed by the app so that relevant fields can be extracted and shown for review. The current kiosk app does not upload the ID document image as a document image during the OCR flow; if the visitor continues, only the confirmed fields enabled by the organisation are submitted with the visitor record. Temporary OCR image files are deleted after processing where the app creates them.

NFC Access

If the deploying organisation has enabled NFC-based presence or card workflows, the app may use the device's NFC reader to read the card identifier from a badge or card. The card identifier is sent to Zabbu's backend to update visitor or attendance presence.

The app uses NFC only for configured workplace visitor or attendance workflows. It does not read financial payment card data.

Location Information

The current Zabbu Visit Kiosk App does not request Android location permissions and does not collect GPS coordinates, background location, precise location, approximate location, or movement data from the device.

A site, branch, kiosk name, or kiosk location label may be configured by the deploying organisation or administrator. That configured label may be stored in kiosk configuration, logs, and diagnostic tags so the organisation and Serve Digital can identify which physical kiosk or site is being supported. It is not derived from device location sensors.

How Information Is Used

  • Register and complete visitor check-in and check-out
  • Validate pre-registered visitor invitations through QR code or invitation code workflows
  • Look up returning visitors and checked-in visitors
  • Trigger host notifications from the backend when a visitor check-in is completed
  • Support employee attendance and presence workflows
  • Register deliveries and route them to the selected host or department
  • Maintain an accurate and searchable visitor log for the site
  • Read NFC card identifiers for configured presence workflows
  • Use the camera for QR scanning, visitor photos, and on-device ID scan/OCR workflows
  • Authenticate the kiosk device and maintain a secure pairing with the organisation's account
  • Download and apply kiosk configuration, branding, enabled workflows, form fields, and site settings
  • Synchronise queued offline records to the backend when connectivity is restored
  • Diagnose crashes, API errors, connectivity problems, and technical issues
  • Create support reports when a user or administrator intentionally shares logs and a screenshot
  • Comply with legal obligations and enforce applicable agreements

Offline and Local Device Storage

The app may store information on the device to support kiosk operation, including during periods without network connectivity:

  • Device authentication and pairing tokens
  • Kiosk configuration and site settings
  • Cached host lookup data
  • Queued visitor, attendance, and delivery records awaiting synchronisation
  • Visitor photos stored in the offline queue when a visit with a photo cannot be synchronised immediately
  • Locally generated log files
  • Screenshots generated during support report creation

Locally stored data may remain on the device until it is synchronised, replaced by updated data, cleared by an administrator, or removed when the device is reset or unpaired. OCR temporary image files are deleted after processing where the app creates them.

Information Sharing

Information processed by the kiosk may be shared with:

  • The deploying organisation, which accesses visitor logs, attendance records, delivery records, and kiosk configuration through the Zabbu administrator portal or related workplace systems
  • Serve Digital backend infrastructure, where visitor, attendance, delivery, device, and configuration records are stored and processed
  • Authorised service providers, including cloud hosting providers, who process data on Serve Digital's behalf
  • Sentry, if enabled for the deployed build, for crash, error, and performance diagnostics
  • Support recipients, only when a user or administrator explicitly submits a support report through the app's share workflow
  • Legal or regulatory authorities when required by law, court order, or valid legal process

The app is not designed or intended to sell personal information. The kiosk app does not collect Firebase Cloud Messaging tokens and does not use Firebase Cloud Messaging in the current implementation.

Third-Party Services

Backend API (Serve Digital): Visitor, attendance, delivery, device pairing, configuration, NFC presence, QR/invitation validation, and emergency status data are transmitted to Zabbu's backend API over encrypted HTTPS connections.

Google ML Kit Text Recognition and TensorFlow Lite: Used on the device to support ID document OCR and document detection. The app code processes ID scan images locally for these workflows and does not send the captured ID document image to Google for OCR.

Sentry: Used only if enabled for the deployed build to collect crash, error, and performance diagnostics. The app removes the device identifier and MAC address fields from the Sentry device context, and default personally identifiable information is disabled unless explicitly configured by Serve Digital.

Android system services: Used for camera, NFC reader mode, secure storage, network connectivity, screen wake/brightness behavior, and the system share sheet used for support reports.

Data Retention

Retention of visitor, attendance, delivery, and device records is determined by the deploying organisation's configuration, Serve Digital's service agreements, and applicable legal requirements.

  • Visitor check-in records are retained by the organisation for operational, security, and compliance purposes
  • Visitor photos uploaded with a visit are retained with the relevant visitor record according to the organisation's retention settings and lawful retention obligations
  • Confirmed ID fields submitted with a visitor record are retained with that visitor record; ID scan images used only for OCR are not uploaded as document images by the current kiosk app
  • Employee attendance and delivery records are retained for workplace operational, security, and compliance purposes
  • Device authentication tokens remain active until the kiosk is unpaired or reset
  • Offline queued records remain on the device until successfully synchronised or cleared
  • Log files and support screenshots are stored locally until overwritten, shared, or removed during a device reset
  • Crash and error diagnostics sent to Sentry, if enabled, are retained according to Serve Digital's Sentry configuration and applicable service terms

Organisations are responsible for setting and applying their own data retention policies for visitor, attendance, and delivery records held in the Zabbu platform.

Security

The app uses encrypted data transmission (HTTPS/TLS) between the kiosk and backend, token-based device authentication, secure local storage for device tokens and configuration, local queueing for offline records, and role-based access controls on the backend. No method of transmission or storage is completely secure.

Organisations deploying the kiosk are responsible for physical security of the device, access controls to the reception area, and their own backend security practices.

Visitor Rights

Because the kiosk is deployed and operated by an organisation, requests relating to specific visitor records should generally be directed to that organisation. Visitors may:

  • Decline to provide optional information and request to check in with the assistance of a receptionist
  • Ask the organisation operating the kiosk about access, correction, or deletion of their visit record
  • Contact Serve Digital at info@servedigital.io for questions that cannot be resolved with the organisation

Under the Uganda Data Protection and Privacy Act 2019, individuals have the right to access, correct, and request deletion of their personal information, subject to lawful retention obligations.

Children's Privacy

The Zabbu Visit Kiosk App is deployed for organisational visitor and attendance management. It is not directed at children as a consumer service. Where an organisation deploys the kiosk in a context involving minors, that organisation is responsible for obtaining any required consents and complying with applicable child data protection requirements.

International Data Transfers

Information processed by the kiosk may be stored or transmitted to data centres outside Uganda, depending on Serve Digital's hosting and infrastructure providers. Where required, Serve Digital implements appropriate safeguards for cross-border transfers in accordance with applicable law.

Changes to This Policy

We may update this Privacy Policy from time to time. The most current version is available at the URL provided in the Google Play Store listing for the Zabbu Visit Kiosk App and at zabbu.co/privacy/kiosk/. We encourage you to review it periodically.

Contact

For privacy questions, data requests, or to exercise your rights, contact Serve Digital:

Serve Digital — 4th Floor Acacia Place, Kampala, Uganda. A company of Gold Leaf Holdings (GLH). If your question relates to visitor or attendance records held by the organisation that deployed the kiosk, please contact that organisation directly.