Security & privacy

ID checks: what Veni records and what it never keeps

← All guides

Security & privacy · 2 min read · from the Veni help library

When a building checks visitor IDs at the desk, the most important thing to know is what Veni does not keep: there is no photograph of anyone's ID anywhere in the system. Veni records the result of the check and a small amount of information about the document, and nothing else.

How a check works

With Visitor ID check set to Optional or Required, the front desk scans the barcode on the back of the visitor's driver's licence or state ID using the Bluetooth scanner paired to the desk. The tablet's own camera faces the desk, not the counter, so it is never used for this.

The scan is read on the device. Veni compares the name to the name on the guest pass, then keeps the result. It does not run facial recognition, and it takes no picture.

What is kept, and what is discarded

Kept, tied to that entry:

  • The visitor's name, encrypted.
  • The result of the check: matched, recorded, mismatch, or skipped, and the reason if it was skipped.
  • A few facts about the document itself: the issuing state, whether it is REAL ID compliant, whether it is a licence or a non-driver card, and the month it expires. None of these identifies a person on its own.

Read on the device and immediately discarded, never sent to Veni:

  • Date of birth
  • Licence number
  • Address

The expiry is stored to the month rather than the day on purpose. A full expiry date sitting next to a name is meaningfully identifying, and month precision does everything the record is for.

Retention and purge

Under Building Settings → Privacy & retention you set the ID-check retention window: 30, 60, or 90 days. When a record reaches the end of its window, Veni deletes it. Because there is no image and no file, the purge is a straight delete of the record itself, with nothing left behind in storage.

Who can see it

Every time someone reveals the name on an ID-check record, Veni writes an audit entry recording who looked and when. Audit ID-check access is always on and cannot be turned off.

The Document access rules in the same section control which roles can open visitor document artifacts at all, with separate settings for ID checks and Signed forms.

Turning Visitor ID check on requires an admin to accept an acknowledgement first, covering signage, who may access records, audit logging, and retention. Its wording is worth repeating here: Veni records the match result, not a picture of the ID.