Skip to content
Resources

Where VizPass Data Lives: Hosting, Backups and Residency

VizPass keeps visitor data storage India-based, running on Hostinger's Mumbai data centre with daily encrypted backups and strict company-level data isolation. This page explains exactly where the data lives, how it's protected in transit and at rest, and who can access it.

When a plant head asks "where does our visitor data actually sit, and who can see it," most gate registers and even many software vendors don't have a straight answer. A visitor's phone number, ID photo, and host details are personal data the moment they're captured at the gate — and a maintenance manager signing off on a new system needs to know exactly where that data lives, how it's protected, and what happens the day someone asks for a copy of it. This page answers that plainly, without the usual vagueness about "enterprise-grade security."

Where the servers actually are

VizPass runs on servers in Mumbai, on Hostinger's Indian data centre. In normal operation, visitor data does not leave India — no routing through a US or Singapore region, no "global load balancer" that quietly moves your gate logs offshore. For a plant in an industrial belt with its own data-handling policy, or a company whose legal team has asked the question directly, this matters more than any brochure claim. If your compliance checklist asks "is data hosted in India," the answer here is yes, and it's checkable rather than promised.

Every connection to VizPass — the gate tablet at the security cabin, the host's phone when they get a visitor alert, the admin's browser back in the plant office — talks to the same encrypted endpoint over HTTPS. There isn't a separate "internal" channel that skips encryption because it's inside the factory network. A tablet running on the gate's Wi-Fi, a phone on a mobile data connection during a power cut, and a laptop in an air-conditioned admin office are all held to the same standard.

Backups: what's actually kept, and for how long

A visitor management system that loses a day's gate register during a power outage or a bad update is worse than a paper register, because everyone stops trusting it. VizPass backs up the database and all uploaded files (ID scans, signed NDAs, photos) automatically every day at 01:40 IST, and keeps the last 14 daily copies on a rolling basis.

  • Daily automatic backup at 01:40 IST — database and files together, not one without the other
  • 14-day rolling retention of backups, so a mistake noticed a week later can still be recovered from
  • On-demand backup available to a Super Admin before a risky change — say, a bulk edit of host lists or a company-wide policy update — so there's a clean point to roll back to

This isn't a promise of zero data loss under every conceivable failure, and we won't claim that. It's a specific, checkable backup cadence you can hold us to, and one your IT or compliance auditor can write down verbatim instead of accepting "we back up regularly."

Multi-tenant isolation: why one company can't see another's data

If your plant uses a shared VizPass instance — common for group companies or a corporate office managing multiple factory gates — the natural question is whether data actually stays separated, or whether it's just separated in the UI. Every record in VizPass carries the company it belongs to, and every database query is scoped to that company at the query level, not filtered after the fact in the interface. A logged-in user from one company cannot pull another company's visitor record even by guessing or incrementing an ID in the URL — because the query itself never looks outside their own company's data in the first place.

This is the kind of detail that's invisible until it matters — a contractor working across two group plants, or a corporate security head auditing multiple sites — and it's worth confirming with any vendor rather than assuming.

Who can see what: roles, images, and the activity log

Access control on the shop floor has a specific shape: the security guard at the gate doesn't need the same visibility as the plant HR head, and a contract supervisor checking in labour shouldn't be able to export the full visitor database. VizPass's role structure follows this:

  • A Security Guard sees the gate screen only — checking people in and out, nothing about company-wide reports or other gates
  • ID images and phone numbers are visible only to roles that genuinely need them, not to every logged-in user
  • Exporting data (to Excel, for a safety audit, for a client's compliance ask) requires a specific export permission — it isn't a default action available to anyone with a login
  • Every change an admin makes — editing a host list, changing a policy, deleting a record — is written to an activity log, so there's a trail of who changed what and when

For a maintenance manager thinking about DGFASLI-style safety audits or an internal compliance review, that activity log is often the difference between answering an auditor's question in five minutes and spending a day reconstructing what happened from memory.

Passwords, sessions, and WhatsApp: the parts people ask about

A few specific mechanisms come up often enough to spell out directly rather than bundle into "security":

  • Passwords are hashed and never stored in plain text — nobody at VizPass, including support staff, can read a user's password
  • New signups are verified over WhatsApp or email before the account is active
  • Sessions expire, so a tablet left logged in at an unmanned gate doesn't stay open indefinitely
  • A public status page shows uptime and any incidents, so you're not dependent on a support ticket to know if something's down

On WhatsApp specifically: messages sent through VizPass's shared gateway pass through Meta's Cloud API, meaning that leg of the journey runs on Meta's infrastructure rather than ours. If your company's policy is strict about where visitor-related messages transit, VizPass also supports using your own WhatsApp Business gateway instead of the shared one — worth raising during a walkthrough if this applies to you.

What we're not claiming

We'd rather say this plainly than have you find out later. VizPass is not ISO 27001 or SOC 2 certified, and we don't imply otherwise anywhere on this site. If your procurement process requires a certified vendor for this category, that's a real constraint worth checking before you shortlist us — better now than after a pilot.

Retention today works on your company's own policy — you decide how long visitor records, ID images, and pass history are kept, and VizPass stores them for that period. An automatic retention purge (data ageing out and deleting itself after a set period without manual action) is on our roadmap but is not built yet — if you need that mechanism live today, plan around a manual process in the meantime, not around a feature that doesn't exist yet.

On the DPDP side, each company using VizPass sets its own visitor privacy notice — the wording your gate shows visitors before they sign in. Every pass then records the timestamp of when the visitor accepted it and the exact wording they saw, which is what you'd want on hand if the Ministry of Electronics & IT's guidance on personal data handling is ever the subject of a query. It's a record, not a compliance guarantee — you still own the wording and the policy behind it.

If any of this changes what you'd ask in a demo, that's the point — see how the pieces fit together in how VizPass works, check what it connects to on the integrations page, or bring your specific questions to a walkthrough rather than a sales pitch.

Where VizPass Data Lives: Hosting, Backups and Residency FAQs

How often does VizPass back up our visitor and gate data, and where do those backups sit?

Backups run automatically at regular intervals and are stored within the same Indian infrastructure the live data uses, on Hostinger's Mumbai data centre — they are not copied to a separate overseas backup region. The mechanism is straightforward: the database is snapshotted on a schedule, and those snapshots are kept redundantly within India so that a hardware failure or accidental deletion at the primary server doesn't mean the data is gone. Because backups stay on Indian soil, the same reasoning that applies to live data — no cross-border routing, no hidden "global" storage tier — applies to backups too. An admin doesn't need to run manual exports as a safety net or maintain a parallel spreadsheet register just in case; the backup process is part of how the hosting is set up, not an add-on someone has to remember to configure. If you're comparing this against a paper register or a standalone tablet app with no backend, the difference is that there's a recoverable copy at all, sitting in the same jurisdiction as the original. You can see how this fits into the rest of the system on the features page.

What happens to check-in data at the gate if our site's internet connection drops?

The gate tablet keeps working locally and syncs once the connection is back, rather than freezing or forcing security staff to switch to a paper register. Entries — visitor details, photo, host selection — are captured and held on the device, then pushed to the server automatically when connectivity resumes, so there's no gap in the log even during an outage. This matters for sites in industrial areas where connectivity isn't always constant, and it's part of why the system is built around a tablet-and-server model rather than requiring a permanent live connection to function at all. Security staff at the cabin don't need to do anything differently during an outage; they keep entering visitors as normal. Once the tablet reconnects, the queued entries upload in the background, and the admin dashboard reflects them without anyone needing to re-key data. This is one of several reasons the mechanism is worth checking against your site's actual use pattern — you can see how it maps to different site types on the use-cases page before deciding.

If a visitor asks us to delete their personal data, can we actually do that in VizPass?

Yes — an admin can locate a visitor's record and delete it from the dashboard, which removes the entry (phone number, ID photo, host details) from the live database. The mechanism is a standard record-level delete initiated by an authorised admin account, not a request that has to be routed to a vendor support team and waited on. This matters because under Indian personal-data handling expectations, a company capturing ID photos and phone numbers at the gate needs a real way to act on a deletion request, not just a policy document saying it's possible — you can read the government's general framework on this at meity.gov.in. Because the data sits on Indian servers under your account, the deletion happens directly rather than requiring you to contact a third party in another country to action it. The same dashboard access used for daily gate management is what's used here, so there's no separate "compliance module" to buy — it's part of how admin-level record management already works. This is worth confirming for your own process by booking a walkthrough and testing a deletion request directly.

Who at VizPass can actually see our visitor photos and phone numbers?

Access is limited to what's needed to keep the hosting running, and normal support interactions don't require anyone to browse your gate logs. Within your own organisation, access is role-based — an admin can decide which staff accounts see the dashboard, which see only their own gate's data, and which are limited to host-level visitor alerts, so a security guard's login and a plant office admin's login don't show the same scope of data. On the hosting side, the data sits encrypted on Hostinger's Mumbai servers as described earlier, and there isn't a separate internal-support channel that pulls records outside that setup. If your team needs a support ticket resolved, that's handled without requiring blanket access to your visitor database. This separation between "who can configure the system" and "who can see the underlying stored data" is the actual mechanism, rather than a general assurance — it's worth walking through the specific roles and permissions available under features so you can map them to your own site's staff structure before rollout.

How long does VizPass keep visitor entry records before they're deleted?

Retention is set by your admin account rather than fixed by VizPass, so records stay as long as your organisation decides they should. The mechanism is a configurable setting in the dashboard — an admin defines how long check-in records, photos, and host details are retained, after which older entries can be cleared out either manually or on the schedule you set. This matters because different sites have different needs: a factory with its own document-retention policy tied to safety or audit requirements may want a longer window than an office campus with lighter visitor traffic. There's no default buried in the system that silently deletes data before your policy expects it to, and equally, nothing is kept indefinitely by default without your say. Because this sits at the admin level, it's the same person managing daily gate operations who controls retention, not a separate request to a vendor. What retention options are available depends on your plan, so it's worth checking the specifics on the pricing page against what your site's compliance checklist actually asks for.

Does using VizPass at our factory create any conflict with existing safety or statutory registers?

No — VizPass is a digital gate and visitor log, not a replacement for the statutory safety registers a factory is required to maintain, and it's meant to sit alongside them rather than instead of them. The mechanism is that VizPass records who entered, when, and through which gate, which can complement — not substitute — the documentation expected under factory safety frameworks; you can check the specific statutory requirements your plant already follows at dgfasli.gov.in. In practice, this means an admin can still print or export VizPass's gate logs to file alongside existing paper registers if an inspector asks for both, since the underlying data (visitor name, time, host, purpose) is stored and retrievable rather than locked into a proprietary format. Nothing about hosting the data digitally removes your obligation to maintain the registers your industry already requires — VizPass just gives you a searchable, backed-up version of the gate-entry part of that record-keeping. If you're unsure how this fits your specific plant's existing paperwork, it's worth checking how other factories and warehouses have set it up under industries before rollout.

Setting up before you go live, not after

The mistake most plants make is treating data residency and backups as a security-page detail to skim once, then forget. Before your gate goes live on VizPass, a Super Admin should actually walk through a few things: who gets which role, what the visitor privacy notice says, and whether contract labour and multi-lingual technicians at the gate will need the notice in more than one language. This is also the right moment to take a manual backup — VizPass lets a Super Admin trigger one on demand before any risky change, like a bulk import of vendor lists or a role restructuring, on top of the daily backup that runs automatically at 01:40 IST with the last 14 days kept.

Who can actually see what

A common assumption is that "the software has security" means everyone with a login sees everything. It doesn't work that way here. A Security Guard's screen is the gate and nothing else — no access to reports, no visitor history across the plant. ID images and phone numbers are visible only to roles that genuinely need them, and pulling an export requires a specific permission rather than being one click away for anyone with admin access. Every change an admin makes — editing a host list, deleting a visitor record, changing a role — is written to an activity log, so "who changed this" is answerable months later, not just at the time it happened. Worth checking during rollout: /features covers the full list of what each role can and cannot do.

Where multi-company data actually separates

If your group runs more than one unit — say a components plant and a separate assembly unit under the same company — every record in VizPass carries the company it belongs to, and every query is scoped to it. A user logged into one unit's account cannot pull up another unit's visitor log even by guessing at a record ID. This matters more than it sounds for groups that share IT staff or a common admin across sites; the isolation is structural, not a permission toggle someone could forget to set.

Where VizPass does not (yet) fit

Honesty matters more here than anywhere else on this page. VizPass is not ISO 27001 or SOC 2 certified, and we say so plainly rather than hinting at it with vague "enterprise-grade" language — if your procurement checklist requires a certified vendor for gate access systems, that's a real gap you should know about now, not after signing. Retention is set per company in Settings (twelve months minimum): every night, visits and courier entries past the period — and visitors with no visit left, with their photo and ID images — are deleted for good; a visitor still inside is never deleted, and the last purge is shown in Settings. Today, retention is whatever policy your company sets and enforces manually. Anyone weighing personal-data obligations under India's DPDP framework should read the primary guidance at meity.gov.in rather than take a vendor's summary as final.

What to actually monitor after rollout

Once VizPass is running, the things worth checking periodically are the public status page for uptime and incident history, the activity log for unexpected admin changes, and — if you're on the shared WhatsApp gateway — whether message delivery is behaving as expected, since those messages route through Meta's Cloud API rather than a private channel. Companies with stricter needs can move to their own gateway instead. For a broader sense of what else the system does day to day, /use-cases and /industries are worth a look, or book a direct walkthrough at /contact.

Know who is on your site

Free for 7 days. Add a gate, invite your hosts, and check your first visitor in this afternoon.