MisafirPro

Privacy Policy

How MisafirPro handles personal information — both the accounts of the organisations who use it, and the visitors who sign in at their receptions.

Last updated 22 September 2026

Who we are

MisafirPro is a trading name of IDARA ONE PTY LTD, a company registered in Australia. Where this policy says “we” or “MisafirPro”, it means that company — the one responsible under the Australian Privacy Principles for the information described here.

Two kinds of information, and who is responsible for each

This distinction runs through everything below, so it comes first.

  • Your account. When an organisation signs up, MisafirPro decides what is collected and why — the account holder's name, work email, and the organisation's own details. For this, MisafirPro is responsible.
  • Visitor records. When someone signs in at a customer's reception, that customer decides what is asked and why, how long it is kept, and who may see it. MisafirPro only stores and processes it on their instructions. For this, the customer organisation is responsible, and MisafirPro acts on their behalf.

If you signed in as a visitor at a building and want your record corrected or removed, contact that organisation — they control it. We can't change their records for them, but we will help them do it if they ask.

What we collect about your account

  • To create and run your account: your name, work email address, the organisation and office names you choose, your timezone and language.
  • To sign you in: a password, stored only as a scrypt hash — never in a form we could read. If you sign in with Google or Microsoft we receive only your verified email address from them, and never your password.
  • Optionally, a profile photo, if you upload one.
  • Security and audit records: which administrator changed what and when, failed sign-in attempts, and the IP address a request came from, so that abuse can be rate-limited and investigated.

What is collected about visitors

A visitor signing in at a customer's kiosk is asked for their first name and surname, and optionally the organisation they are from and the person they are visiting. The time they signed in and out is recorded, along with which office and which tablet.

A badge may be printed with those details. The customer's chosen recipients may receive a daily email summarising the previous day's visitors, and administrators can export the visitor log as a spreadsheet — every export is recorded in that organisation's audit log.

We do not sell personal information, we do not use it for advertising, and we do not use visitor records to train anything. Visitor names are never written to our application logs.

Who else is involved

MisafirPro uses a small number of specialist providers to run the service. Each is bound by contract to process data only to provide its part of the service, and for nothing of its own. They are:

  • Data storage. A managed database service holds all service and visitor records.
  • Hosting. A cloud hosting provider runs the application and serves the site.
  • Email delivery. An email delivery provider sends invitations, password resets and daily summaries.

We do not otherwise disclose personal information to anyone, except where the law requires it of us.

Your records are stored in Australia. The site is delivered through a global network, so a request may be routed via a server outside Australia, but the records themselves are held here.

A customer who needs to know which providers we use — for their own privacy assessment or procurement — can ask us at support@misafirpro.com and we will tell them.

How it is kept separate and secure

Every organisation's data is isolated in the database itself, not only in application code: each row is tagged with its organisation and the database refuses to return rows belonging to another, even if the application asked for them. Staff see only the offices they have been assigned.

  • Passwords are stored as scrypt hashes; tablet tokens, pairing codes and email links are stored only as hashes.
  • All traffic is encrypted in transit, and email is sent over an encrypted connection that will not fall back to plaintext.
  • Sessions expire, and you can end every other session from your account page.
  • Every administrator action that changes data is recorded in an audit log the organisation can read.

No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your data we will tell you, and will notify the Office of the Australian Information Commissioner where the law requires it.

Cookies

MisafirPro sets no advertising or analytics cookies, and does not track you across other websites. The cookies it does set are the ones without which it cannot work:

  • Your session — keeps you signed in.
  • A kiosk's identity — set once when a tablet is paired, so it knows which office it belongs to.
  • A short-lived sign-in cookie — used only during Google or Microsoft sign-in, and deleted immediately afterwards.
  • Your cookie choice — so the notice on your first visit doesn't appear again.

Every one of these is needed for the service to work, and cookies of that kind don't require your consent. We ask anyway, and record your answer: if we ever add anything optional — analytics being the obvious candidate — it will be switched off unless you chose “Accept all”. Today the two answers set exactly the same cookies.

How long it is kept

  • Visitor records are kept until the customer organisation deletes them or closes its account — they decide, because the records are theirs.
  • Expired sessions, spent password-reset links, unused pairing codes and abandoned signups are cleared automatically every hour.
  • Audit records are kept for as long as the account exists, because they outlive the things they describe.
  • When an organisation's account is deleted, its offices, users, devices and visitor records are deleted with it. This cannot be undone.

Your rights

Under the Australian Privacy Principles you may ask for a copy of the personal information we hold about you, ask us to correct it, or complain about how it has been handled. Write to support@misafirpro.com and we will respond within a reasonable time, and within 30 days where the law sets that limit.

Administrators can export their organisation's offices, users, devices and settings from Settings at any time, and its visitor records from the Visitor Log, without asking us.

If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes to this policy

If we change this policy we will update the date above, and we will tell account holders by email before any change that materially affects them takes effect.

Contact

Questions about this policy, or a privacy request: support@misafirpro.com. Our Terms of Service set out the rest of the agreement.