Skip to content

Article

Visitor Tracking System: What Gets Logged and Stored

A visitor log is a pile of personal data with your name on the deed. Here's what gets recorded at sign-in, where it lives afterward, and how long to keep it.

By InstaCheckin Team Updated August 9, 2026

Every visitor who signs in at your front desk hands you a small file: their name, their employer, who they’re meeting, the minute they walked in, and often a photo plus a signature on an NDA. A visitor tracking system is what turns that into a searchable record instead of a spiral notebook nobody reads back.

It also turns it into a database you now own. That’s the part the sales demos skip.

Feature grids in this category all look the same — kiosk, badge, notification, log. The differences that matter show up in the boring parts: which fields get captured by default, where the records sit afterward, how long they stay there, and who can pull a report at 4pm on a Friday when HR asks who was in the building on March 12th.

What a Visitor Tracking System Records at Sign-In

The standard capture set across the category is short:

  • Name and company — typed by the visitor, or pre-filled if their host pre-registered them
  • Host — pulled from a directory you maintain, not free text, so the notification actually reaches someone
  • Purpose of visit — usually a picklist (interview, delivery, contractor, meeting)
  • Timestamp in, and sometimes out, which is the field most systems handle worst
  • Photo — captured at the kiosk when the system prints a badge with a face on it
  • Signature — attached to the NDA, safety briefing, or site rules the visitor agreed to

Each of those is personal data. Federal guidance treats that as a design constraint rather than an afterthought: the PE-8 visitor access records control requires organizations to maintain, review, and report anomalies in those records, and the PE-8(3) enhancement tells them to “limit personally identifiable information contained in visitor access records” to elements justified by a privacy risk assessment (FedRAMP’s PE-8 visitor access records control text).

Read that as a purchasing rule. Every extra field — home address, license plate, ID number, date of birth — is a field you have to store, defend, and eventually delete. Ask what each one is for. If nobody can answer, turn it off.

Where the Records Live After the Badge Prints

On paper, the answer is “in the binder on the shelf, and also visible to whoever signs in next.” That last part is the real problem with a logbook, and it’s why the 8 things you give up with a paper visitor logbook start with confidentiality rather than convenience.

With software, the record goes to the vendor’s cloud and shows up in a dashboard. What you should check before you commit: who on your team can see the log, whether it’s filterable in ways that match how people actually ask questions, and how the data gets out.

InstaCheckin stores each visit with its timestamps and photo, filterable by location, host, date range, or visitor name, and exports to CSV or PDF. One honest limit worth knowing up front: the dashboard export caps at 200 records per file, so pulling a year for an auditor means exporting visitor records in date-range batches rather than one click. Better to know that before the auditor emails than after.

Export capability isn’t a nice-to-have, either. It’s your exit. A visitor tracking system you can’t get a clean CSV out of is a system that owns your history, and that’s a worse position than the binder.

How Long Should You Keep Visitor Records?

Nobody asks this until legal does, and by then you have four years of check-ins.

There’s no fixed answer in the regulations, which is exactly what makes it uncomfortable. Under the GDPR’s storage limitation principle, personal data can only be stored as long as necessary for the purpose it was collected for, and the European Commission’s guidance on how long data can be kept tells organisations to put an actual retention policy in place rather than defaulting to forever. California goes at it from the disclosure side: California Civil Code section 1798.100(a)(3) requires a business to state “the length of time the business intends to retain each category of personal information… or if that is not possible, the criteria used to determine that period.”

Regulators are enforcing the over-collection end of this, not just the paperwork. The California Privacy Protection Agency ordered American Honda to pay a $632,500 fine in March 2025 for practices that included requiring consumers to hand over excessive personal information to exercise their privacy rights (California Privacy Protection Agency announcement of the Honda settlement).

The practical move: pick a retention period you can justify in one sentence, write it down, and then ask any vendor — us included — exactly how deletion works in their product before you promise it in your privacy notice. A policy your software can’t execute is worse than no policy.

This describes product capabilities and published regulation, not legal advice. Retention obligations depend on your jurisdiction, industry, and contracts — consult counsel before relying on any of this for a compliance decision.

Reports Worth Running

A log you never query is just storage cost. Four reports earn their keep:

Who’s in the building right now. The one that matters at 2am. OSHA’s emergency action plan standard requires “procedures to account for all employees after evacuation” (OSHA standard 1910.38(c)(4)) — employees are the legal floor, and the contractor on the roof is the person nobody can find at the assembly point. Pair the live on-site list with your emergency evacuation plan so the roll call has a source.

Everyone who visited between two dates. The incident report, the insurance question, the HR investigation. Filter by date range, export, done.

Visits per host, per site. Boring and useful. It tells you which desk actually needs a staffed reception and which one can run unattended on a digital visitor management system.

Who signed which document. If you present NDAs at the kiosk, the log has to tie a signature to a visit, not just record that a signature happened somewhere.

Choosing a Visitor Tracking System: Six Questions About the Data

Ask these before the feature demo, not after:

  1. Which fields are collected by default, and can I turn ones off?
  2. Where is the data stored, and who at the vendor can access it?
  3. How do I get a full export, and are there per-file limits?
  4. How does deletion work — per record, per date range, or not at all?
  5. Who on my team can view the log, and is that role-based?
  6. What happens to the archive if we stop paying?

Question four is the one that gets skipped and the one that hurts. Question six is a close second.

FAQ

Is a visitor tracking system worth it for a 30-person office?

Usually, once you have more than a handful of visitors a week or any document to collect at the door. Below that, a sign-in sheet and an alert email work fine. The tipping point is rarely visitor volume — it’s the first time someone needs to find a specific visit from six months ago and can’t.

Does a visitor tracking system replace the receptionist?

It replaces the interruption, not the person. The kiosk captures the details and emails and texts the host directly, so nobody has to phone upstairs or walk over. Offices that keep a receptionist after switching usually reposition the role from gatekeeper to host.

What’s the difference between visitor tracking software and a check-in app?

Mostly emphasis. “Check-in app” describes the visitor’s thirty seconds at the iPad; “visitor tracking software” describes what the business does with the record afterward — search, retention, reporting, audit. Same product, different half of it.

Can visitors see each other’s information?

Not on a well-built kiosk. Each visitor sees only their own form, and the previous entry clears when the session ends. That’s the single biggest privacy gap in a paper logbook, where every name on the page is readable by whoever signs in next.

Do I need to tell visitors what I’m collecting?

Under both the GDPR and the CCPA the direction of travel is toward notice at the point of collection, which for a lobby kiosk means a short data notice on the sign-in screen rather than a link buried in a footer. Keep it plain, name the retention period, and don’t collect fields you can’t explain. Again: product information, not legal advice.

Start With One Desk and One Honest Policy

Pick the retention period first. Decide which four or five fields you genuinely need. Then put a kiosk on the desk and run it for a month before you standardise across sites.

InstaCheckin runs on a single iPad at reception, captures the visit with a photo and any documents you present, notifies the host by email and SMS on arrival, and keeps every record searchable and exportable from the office visitor management system dashboard. Start a free trial on one desk and see what your log actually looks like after thirty days of real visitors.

Frequently asked questions

What is a visitor tracking system?
It's the software that records who entered your building, when, who they came to see, and what they agreed to on the way in. Most run as an iPad kiosk at reception plus a web dashboard where the log is searchable and exportable. The check-in experience is the part visitors see; the log is the part the business actually buys.
What information does a visitor tracking system collect?
The common set is name, company, host, purpose of visit, and arrival timestamp. Systems that print badges usually add a photo, and systems that handle NDAs or safety waivers store the signature and the document version the visitor agreed to. Every one of those fields is personal data, so collect the ones you'd be comfortable defending and skip the rest.
How long should visitor records be kept?
There's no universal number. Under the GDPR's storage limitation principle and California's CCPA retention-disclosure rule, the period has to be tied to a purpose you can state out loud — so 12 to 24 months is a common office default, and regulated sites often hold longer under contract or export-control obligations. Write the policy first, then configure the software to match. This is product information, not legal advice.
Is visitor tracking software the same as access control?
No, and conflating them causes bad purchases. Access control decides whether a door opens — badges, readers, credentials. A visitor tracking system records the human event: who arrived, who hosted them, what they signed. Large sites run both and connect them; most offices under 500 people start with the log and never need the readers.
Can I export the visitor log for an audit?
Yes. InstaCheckin stores every visit in the cloud with timestamps and photos, filterable by location, host, date range, or visitor name, and exports to CSV or PDF. The dashboard export caps each file at 200 records, so a full year usually comes out as several date-range batches rather than one download.

Related reading

Ready when you are

Try InstaCheckin on your iPad — free