Privacy Policy
Effective date: September 23, 2026 · Last updated: September 23, 2026
Joyvill Inc. ("Joyvill," "we," "us," or "our") operates the TurnoutHQ web platform, the Attendly Card member app for iOS and Android, and the Attendly check-in kiosk app for Android and iOS (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
⚠️ Pre-release draft — not for publication
This policy is complete except for two items that are deliberately unresolved and must be closed before it is published. Both are marked in red where they appear:
- The Privacy Officer has not been named. A name and mailing address are required and have not been supplied — see Canada — PIPEDA and Our Privacy Officer.
- One question is with legal, not answered here. Which privacy regime governs your organization's own activities, as distinct from ours as its service provider — see the same section.
Everything else on this page is a statement of current practice and is intended to be relied on.
Contents
- 1. Information We Collect
- 2. How We Use Your Information
- 3. How We Share Your Information
- 4. Mobile Applications
- 5. Cookies and Tracking Technologies
- 6. Data Retention
- 7. Security
- 8. Your Rights and Choices
- 9. Children's Privacy
- 10. International Transfers
- 11. Canada — PIPEDA and Our Privacy Officer
- 12. Changes to This Policy
- 13. Contact Us
Information We Collect
Information You Provide Directly
- ›Account information: name, email address, phone number, password, and role (staff, volunteer, etc.) when you register or are added to an organization.
- ›Organization information: organization name, timezone, locale, and configuration settings entered by administrators.
- ›Attendance and check-in data: session attendance records, enrollment status, check-in timestamps, and check-in method (QR code, NFC badge, location, or manual entry by a staff member).
- ›Location, only if you use location check-in: if you have turned on location check-in in the Attendly Card app, the app takes one location reading at a time, at one of two moments only: when you tap the check-in button, or when you open your card from 30 minutes before one of your classes until that class ends, so that it can offer to check you in. Either way the reading is taken while the app is open on your screen, and it is sent to us so that we can confirm you are at your organization's site. There is no background location, no reading while the app is closed, no continuous tracking, and no trail of your movements between check-ins. A reading taken only to offer you check-in is not stored at all: we use it to answer that one question and keep no coordinates, no accuracy and no entry in the check-in attempt log described below. What follows describes what is kept when you actually check in. Your attendance record keeps only whether you were inside or outside the boundary, together with coarse accuracy and distance ranges — it does not contain your coordinates. A separate check-in attempt log keeps your position rounded to four decimal places (roughly 11 metres), the result, and those ranges for 90 days and then deletes them automatically. No coordinates are kept at all for a reading too imprecise for us to judge, or for one we accepted only because you had produced a better reading minutes earlier. Alongside the position we also keep a scrambled code that stands for the place, which lets us see that several people reported the same spot without any screen showing us where that spot is. That code is a blind, not anonymisation — with the key that protects it, it could be worked back to the place — so we treat it as information about you, we keep it even in the case just described where we keep no coordinates at all, and we delete it on the same 90-day schedule. Because each of those entries carries a time, that log is a limited record of where you were at the moments you checked in during the previous 90 days. Location check-in is optional — see Mobile Applications and Canada — PIPEDA — and the reading is processed outside Canada, as described in International Data Transfers.
- ›Profile photos and session photos: images uploaded or captured through the application.
- ›Communications: messages, notes, or other content you submit through the Service.
- ›Phone number for SMS: when you provide a phone number, we use it to send verification codes, attendance notifications, and bulk messages configured by your organization. Standard message and data rates may apply.
Information Collected Automatically
- ›Log and usage data: IP address, browser type, pages visited, time spent, referring URLs, and other standard server log information.
- ›Device information: device model, operating system version, and unique device identifiers for mobile applications.
- ›Authentication tokens: session tokens and OAuth tokens used to keep you signed in.
- ›Audit logs: records of administrative actions and API calls for security and compliance purposes.
Information from Third Parties
- ›OAuth providers: if you sign in with Google, we receive your name, email address, and profile picture from your Google account.
- ›Registration integrations: data submitted through connected registration forms (e.g., Google Forms) may be imported into the Service.
How We Use Your Information
We use the information we collect to:
- ›Provide, operate, and maintain the Service, including processing check-ins, managing attendance records, and sending automated notifications.
- ›Authenticate your identity and maintain the security of your account.
- ›Generate attendance reports, analytics, and insights for organization administrators.
- ›Send transactional communications such as verification codes, approval notifications, and system alerts.
- ›Fulfill automated workflow actions configured by your organization (e.g., follow-up messages triggered by attendance events).
- ›Detect and prevent fraud, abuse, and unauthorized access.
- ›Comply with legal obligations and enforce our terms.
- ›Improve and develop the Service based on aggregate usage patterns.
Mobile Applications
4.1 Attendly Card — the member app (iOS and Android)
Attendly Card is used by a member of an organization to see their own membership card and their own attendance. It is a different app from the check-in kiosk described in 4.2, and it does not check anyone else in.
What it collects and stores:
- ›Your phone number, as the credential: you sign in by entering your phone number, and we send a one-time SMS code to it. There is no password. The number is used to find your membership and to send you that code; our SMS provider receives it in order to deliver the message.
- ›Sign-in tokens, stored on your device: after you sign in, the app keeps an access token and a refresh token in the operating system's secure storage — the Keychain on iOS and the Keystore-backed encrypted store on Android — so you do not have to sign in every time. Signing out or deleting your account removes them.
- ›Your own attendance history: the app fetches the attendance and course enrollments your organization has recorded for you, and nobody else's.
- ›A QR card token, cached on your device: your membership card is a signed token displayed as a QR code. It is cached locally so the card still works when you have no signal. Deleting your account invalidates it.
- ›Camera, to scan a poster: your organization may print a check-in poster. You point the app's camera at it and the app reads the code. The camera is active only while that scanner is open, no image is stored or uploaded, and the app does not take photographs.
- ›Location, only if you choose to check in with it: your organization may let you record your own attendance by tapping check-in in the app. If you use that, the app asks for location permission while you are using the app and takes a single reading when you tap check-in, or when you open your card from 30 minutes before one of your classes until it ends, so that it can ask whether you want to check in. It does the second only if you have already turned location check-in on and allowed location — it never asks you for either by itself — and no more often than once every two minutes. It never asks for background location, it does not read your location while it is closed or in the background, and it does not record where you go between check-ins. The reading is sent to our servers, which decide whether you were inside your organization's check-in boundary (typically 250 metres around its site). When you check in, they record your attendance accordingly. When the app was only asking whether to offer you check-in, they record nothing at all — no coordinates, no accuracy and no entry in the check-in attempt log — and the reading is discarded once that question is answered. What is kept after a check-in is set out in Data Retention, and it is processed outside Canada, as described in International Data Transfers. This is entirely optional: you are asked for it separately, it is off until you turn it on, and you can withdraw it at any time from the app's settings or your device's settings without losing anything else. If you decline it, you can still check in with your QR card, by scanning your organization's poster, or by asking a staff member — and a check-in recorded by location counts toward course completion (수료) in exactly the same way as any other check-in, no more and no less.
- ›A push notification token: if you turn notifications on, the operating system issues a token identifying your installation, which we store so your organization's announcements can reach you. Turning notifications off or deleting your account removes it.
- ›Calendar, only if you ask: if you choose to add a course's schedule to your calendar, the app asks for calendar permission, reads the list of calendars on your device so you can pick one, and writes the course's sessions into it. It does not read your existing appointments, and no calendar data is ever sent to us — the record of what was added stays on your device.
- ›What you fill in: your answers to a registration form your organization has created, and your responses to its polls. Form fields are defined by your organization, so what is asked for varies between organizations.
- ›Preferences, stored only on your device: your language, text size and light/dark setting. These are not sent to us.
Attendly Card contains no analytics, advertising or crash-reporting software. There is no third-party analytics SDK, no crash reporter, no advertising identifier and no cross-app tracking of any kind. It does not request your contacts, your photo library, or health or financial data. It requests your location in one case only — when you yourself have chosen to check in by location, as described above — and then only while the app is open, and only one reading at a time: when you tap check-in, or when you open your card around one of your classes so that it can offer to check you in; it is never read in the background and never used for advertising, profiling, or building a picture of your movements. Nothing it collects is sold, shared for advertising, or used to track you across other companies' apps or websites.
4.2 Attendly — the check-in kiosk (Android and iOS)
This is a separate app, installed by an organization on a device it owns and operates at its own entrance. Members do not install it. It requests the following device permissions:
- ›Camera: used by staff to scan a QR code for attendee check-in and to capture session photos. Camera access is active only while the scanning interface is open.
- ›NFC (Near Field Communication): used to read NFC-enabled badges for contactless check-in. NFC data is read-only and is not written to or stored on badges.
- ›Local storage (encrypted): the app stores attendance data locally in an encrypted database when the device is offline. This data is synced to our servers when connectivity is restored and then removed from local storage per your organization's retention settings.
- ›Network access: used to sync data with TurnoutHQ servers and to authenticate kiosk devices.
The kiosk app does not transmit camera or NFC data to third parties. All captured data is sent only to your organization's TurnoutHQ account.
Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Specifically:
- ›Account data is retained for the lifetime of your organization's account and for up to 90 days after account closure, after which it is permanently deleted.
- ›Attendance records are retained for as long as configured by your organization administrator (default: indefinitely while the account is active).
- ›Audit logs are retained for 12 months for security and compliance purposes.
- ›Attendance records created by location check-in hold the same information as any other attendance record, plus whether you were inside or outside your organization's boundary and coarse ranges for accuracy and distance. They do not contain your coordinates, and they are retained on the same terms as every other attendance record.
- ›Location check-in attempts — your position rounded to four decimal places (roughly 11 metres), a scrambled code standing for that place, the result, and the accuracy and distance ranges — are kept for 90 days and then deleted automatically. No coordinates are kept at all for two kinds of reading: one too imprecise for us to judge, and one we accepted only because you had produced a better reading minutes earlier. The scrambled code is kept in that second case even though the coordinates are not, because it is what lets us see that several people reported one spot. It is a blind, not anonymisation — with the key that protects it, it could be worked back to the place — so it is treated as information about you and is deleted on the same 90-day schedule as the coordinates. Only your organization's administrators can see this log. Each entry carries a time, so it is a limited 90-day record of where you were at the moments you checked in; it is not, and cannot be assembled into, a continuous track of your movements.
- ›A reading taken only to offer you check-in — when you open your card near the time of one of your classes, before you tap anything — is not stored at all. It is used to answer whether you can check in and then discarded: no coordinates, no accuracy, no scrambled code, and no entry in the check-in attempt log. If you then check in, the app takes a fresh reading for that, and it is kept as described above.
- ›Backups may persist for up to 30 additional days after deletion before being purged from backup systems.
You may request deletion of your personal data at any time (see Your Rights).
Deleting your Attendly Card account
Deleting your account permanently erases your name, phone number, and every other personal detail, and you will never be able to sign in again. The attendance records your church has already recorded are kept, but they are no longer connected to your name or to any other way of identifying you. This cannot be undone.
You can delete your account from inside Attendly Card, or ask us to. The full field-by-field list of what is removed and what is retained is on Delete your account.
Security
We implement industry-standard technical and organizational measures to protect your information, including:
- ›Encryption of data in transit using TLS 1.2 or higher.
- ›Encryption of sensitive data at rest (including local mobile storage using AES-256).
- ›Hashed password storage (bcrypt) — we never store passwords in plain text.
- ›Two-factor authentication (TOTP) available for all accounts.
- ›Role-based access controls that limit data access to authorized personnel only.
- ›Regular security reviews and audit logging of sensitive operations.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach, we will notify affected users as required by applicable law.
Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal data:
- ›Access: request a copy of the personal data we hold about you.
- ›Correction: request that we correct inaccurate or incomplete personal data.
- ›Deletion: request that we delete your personal data, subject to legal retention requirements.
- ›Portability: request a machine-readable export of your personal data.
- ›Objection / Restriction: object to or request restriction of certain processing activities.
- ›Withdraw consent: where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at privacy@turnouthq.ai. We will respond within 30 days. Note that some requests may be subject to verification of identity and to limitations under applicable law.
To request deletion of your Attendly account and associated data, you may also use our Account Deletion Request form.
California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know, delete, and opt out of the sale of personal information. We do not sell personal information.
EEA / UK residents have rights under the General Data Protection Regulation (GDPR). Our lawful basis for processing is typically performance of a contract (providing the Service) and legitimate interests (security, fraud prevention, service improvement).
Children's Privacy
The Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@turnouthq.ai and we will promptly delete such information.
Organizations using TurnoutHQ to track attendance of minors (e.g., children's ministry) are responsible for obtaining appropriate parental consent in accordance with applicable laws in their jurisdiction.
International Data Transfers
TurnoutHQ is operated in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to this transfer. We take steps to ensure that transferred data receives adequate protection consistent with this Privacy Policy and applicable law.
If you are in Canada: your information is stored and processed outside Canada, in the United States, by us and by the service providers described in How We Share Your Information. While it is held there it is subject to the laws of that country, and its courts, law-enforcement bodies and national security authorities may be able to compel access to it under their own lawful access powers — in some cases without notice to you, and without the protections you would have under Canadian law. No contractual safeguard we put in place can remove that possibility; we can only limit what there is to disclose.
Why this matters more for location. A location reading taken at a place of worship can support an inference about your religious beliefs, which is precisely the kind of information this notice is about. That is why we ask for your express consent before taking one, keep no coordinates on the attendance record itself, round the coordinates we do keep to roughly 11 metres, and delete them after 90 days — see Canada — PIPEDA and Data Retention. If you would prefer that no location of yours leave Canada, simply do not turn location check-in on: your QR card, your organization's poster, and check-in by a staff member all remain available, and all of them count toward course completion identically.
South Korea (PIPA): For users in South Korea, we process personal data in accordance with the Personal Information Protection Act (개인정보 보호법, PIPA). You have the right to request access, correction, deletion, and suspension of processing of your personal data. To exercise these rights, contact us at privacy@turnouthq.ai.
Canada — PIPEDA and Our Privacy Officer
Joyvill Inc. is based in Toronto, Ontario. Where we handle personal information in the course of our commercial activities in Canada, we do so in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where they apply, the substantially similar provincial privacy laws.
⚠️ Under legal review — this paragraph is not a legal conclusion
Your organization — your church, school, or other group — decides for itself what it records about its own members and is a separate organization from us. The privacy law that governs its own activities may not be the same as the law that governs ours as its service provider. We do not decide that question for your organization, and nothing on this page should be read as deciding it. We apply the standards described in this section to our own handling of your information regardless of how it is answered, and you may raise a concern with us about either.
Location is sensitive, so your consent must be express. A record placing an identifiable person at a place of worship says something about their religious practice, and Canadian regulators treat information about religious beliefs as sensitive. We therefore do not rely on implied consent for location check-in. Before the app takes any location reading:
- ›You opt in. You are asked in a separate step, for location alone. It is not bundled into our terms of service, and it is not pre-selected or checked by default — nothing happens until you choose it.
- ›You are asked in your own language. The request is presented in the language your app is set to, in plain words, and it tells you what is kept and for how long before you answer.
- ›You can withdraw at any time. You can turn location check-in off in the app's settings, or revoke the permission in your device's settings, without giving a reason and without losing access to anything else.
- ›It is never a condition of service. We will not require your consent to location as a condition of using the Service, of belonging to your organization, or of completing a course. Checking in by QR card, by scanning your organization's poster, or by asking a staff member does exactly the same thing, and a check-in recorded by location counts toward course completion (수료) no differently from any other. This reflects PIPEDA Schedule 1, clause 4.3.3, under which an organization must not, as a condition of supplying a product or service, require consent to collection beyond what is necessary for the explicitly specified purposes.
Turning it off takes effect at once on the phone you turn it off on, whether or not you have a connection, and that phone stops taking readings from that moment. Updating our own record of your choice needs a connection, so if your phone cannot reach us yet the app says so and offers to try again — the phone has still stopped, and that is the part that decides whether a reading is taken at all. If you use Attendly Card on more than one device, another device finds out the next time it tries to check in or to offer you check-in: it may take one last reading and send it before it learns of your decision, but we refuse it without ever working out where you were and keep no coordinates from it, and that device then stops and asks you to decide again. If you withdraw consent, we stop collecting new location readings from you immediately. Attendance already recorded stays as it is — it is your attendance record, not a location record — and any coordinates already held in the check-in attempt log are deleted on the 90-day schedule described in Data Retention, or sooner if you ask us.
Our Privacy Officer
Questions, access requests, and complaints about your personal information can be directed to our Privacy Officer:
⚠️ PLACEHOLDER — NOT YET SUPPLIED — MUST BE FILLED IN BEFORE PUBLICATION
[PLACEHOLDER — Privacy Officer name and title]
[PLACEHOLDER — mailing address]
Joyvill Inc., Toronto, Ontario, Canada
privacy@turnouthq.ai
The email address above is live and monitored today; the named individual and postal address are outstanding. We acknowledge complaints promptly and respond within 30 days, or tell you why we need longer and when to expect our answer.
If you are not satisfied with our answer. You may complain to the Office of the Privacy Commissioner of Canada. The Commissioner ordinarily expects you to raise the matter with us first, but you do not need our permission to complain and we will not treat you differently for doing so. The Office can be reached at priv.gc.ca or by telephone at 1-800-282-1376.
The rights listed in Your Rights and Choices — access, correction, deletion, and withdrawal of consent — are available to you in Canada as well, and are exercised the same way.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, by sending an email notification or displaying an in-app notice. Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.
We encourage you to review this policy periodically to stay informed about how we protect your information.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Joyvill Inc.
Toronto, Ontario, Canada
support@turnouthq.ai
We aim to respond to all privacy inquiries within 30 days. For urgent security concerns, please include "URGENT" in your subject line.
If you are in Canada, Canada — PIPEDA and Our Privacy Officer names our Privacy Officer and the route to the Office of the Privacy Commissioner of Canada.
This Privacy Policy is governed by our Terms of Service.