lobbi
Privacy

Privacy policy

Lobbi keeps a building’s sign-in log. This policy explains what that log holds, what else we collect to run the service, and what we never do with any of it.

Effective October 4, 2026

Who we are

Lobbi (the iPad app, the admin console at app.withlobbi.com and this website) is operated by Skaler Labs LLC (“we”, “us”). Questions and requests about privacy go to hello@withlobbi.com.

Two kinds of people

Admins are the people who set up a building in Lobbi and run it from the console. They’re our customers.

People at the door are the employees and guests who sign in and out on a building’s kiosk. They never create an account. The building decides who’s in its directory and keeps its own visit log; we store and process that log on the building’s behalf. If you signed in at a building and have a question about your records, ask that building’s admin first. We’ll help them answer it.

What we collect

  • Admin accounts: your name and email address from Google or Apple when you sign in (with Apple, this may be a private relay address), the buildings you run and your role in each. We never see your Google or Apple password.
  • Building setup: the building’s name, logo, time zone and settings, and its organizations’ names, colours and logos.
  • The directory: each person’s name and organization, an email address if an admin adds one, how many times they’ve visited and when they were last in. If the building requires PINs, a one-way hash of the person’s PIN. We never store the PIN itself, and no one, admins included, can read it back.
  • Visits: who signed in, when they signed in and out, and how the visit ended (by the person, automatically at the end of the day, or by an admin, in which case which admin). For guests, the name and company they type and the host they choose. Each visit also records which kiosk took it and how long the sign-in took.
  • Kiosks: each paired iPad’s name, model, iPadOS and app version, and when it last checked in. Each iPad holds its own key in its Keychain.
  • Billing: Stripe takes payments. We keep the Stripe customer and subscription identifiers, the plan, its status and dates. We never see or store card numbers.
  • This website: Vercel Web Analytics counts page visits and which buttons were used, without cookies and without following you to other sites. Apple serves the App Store badge image.
  • Operations: our servers keep short-lived request logs (such as IP addresses and timings) to keep Lobbi secure and working, and count requests to the sign-up and pairing endpoints by a hashed IP address to stop abuse.

How we use it

Only to run Lobbi: signing people in and out, showing who’s in, keeping and exporting history, closing forgotten visits at the end of the day, pairing and securing kiosks, billing, preventing abuse and answering support requests.

We don’t sell personal information, show ads, track people across other companies’ apps or websites, or share a building’s records with another building.

The iPad app

The kiosk contains no advertising or third-party analytics code. People signing in only tap their name (and type a PIN if the building asks for one). Admins sign in on the iPad with Apple or Google to set up or pair it; a Google sign-in runs in a private browser session, so the iPad stays signed in to no one.

Who helps us run Lobbi

  • Amazon Web Services stores Lobbi’s data, in the United States.
  • Vercel hosts the console and this website, and provides Web Analytics.
  • Stripe handles subscriptions and payments.
  • Google and Apple verify admins when they sign in.

Each gets only what it needs to do that job. We also disclose information when the law requires it.

How long we keep it

A building’s data is kept until an admin deletes it. Admins can deactivate people at any time, and a building’s owner can delete the whole building account from the console or the iPad. That cancels its subscription, deletes its Stripe customer, unpairs every kiosk, and deletes its people, visits, organizations, logos, kiosks and admin list. Our encrypted backups age out within 35 days. Stripe keeps the payment records the law requires it to.

Request logs are kept only briefly. A record of each account deletion, without personal information, is kept for support.

Security

Everything travels over HTTPS and is encrypted at rest. Each building’s records are kept apart and every request is checked against the building it belongs to. Each kiosk has its own key that an admin can revoke from the console, PINs are stored only as one-way hashes, and admins sign in only through Google or Apple. No service can promise perfect security, but if something goes wrong that affects your data, we’ll tell you.

Your choices and rights

Admins can see, correct, export (as CSV) and delete their building’s data themselves in the console. Anyone can ask us to access, correct or delete personal information we hold, by writing to hello@withlobbi.com. For a building’s visit records we’ll work with that building’s admin, since it’s their log. We won’t treat you differently for asking.

Children

Lobbi is a workplace tool and isn’t directed at children.

Changes

If we change this policy, we’ll post the new version here with a new effective date, and tell admins about significant changes before they apply. Also see our terms.