Skip to content
TrayVision — EAT · EXPLORE · ENJOY

AlvaSoft · TrayVision

Privacy Policy

Last updated:

This policy explains how AlvaSoft's TrayVision Android application and web management application handle information when used for cafe device management, video playback and order-ready alerts.

Information we process

Mobile devices

The Android app sends a device identifier to its configured TrayVision server. It uses the Android-provided identifier, or a locally generated identifier when that is unavailable. The server associates it with the device's name, assigned number and cafe.

During initial device registration, the app sends the administrator-provided registration code to the server for validation. The entered code is not saved on the device. After successful registration, the app saves the registered device identifier locally so that subsequent launches do not ask for the code again.

While the app is open, it reports battery level, power connection, video playback status and the identifiers of active or dismissed order-ready alerts. The server records the last connection time and the latest reported device state.

The app does not request access to your contacts, precise location, camera, microphone, SMS or telephone call history. An order-ready alert is an in-app notification with sound and vibration; it does not place or record a telephone call.

Web application users

For management accounts, we process the email address and login, name, optional contact and profile information, password hash, roles, access status and account security information. Cafe details, uploaded videos and images, and settings supplied by authorised users are stored to provide the service. Password recovery, when enabled, uses the account email address.

Connection information

Our server and hosting infrastructure receive connection information, such as IP addresses, request details and timestamps. Operational logs may contain this information for service maintenance, security and troubleshooting.

How information is used

Device information allows TrayVision to register devices, assign them to cafes, deliver configuration and media, display battery and connection status, and send or dismiss order-ready alerts. Account information supports access control, administration and password recovery.

Videos and images are supplied by service administrators and may contain advertising. The current mobile app does not include third-party advertising or analytics SDKs and does not use the Android Advertising ID. Device identifiers are used to operate the service, not to build a personal advertising profile.

Access and service providers

Information is sent to the server configured in the app. Authorised users of that TrayVision installation can access device and cafe information according to their permissions. Administrators can manage user accounts.

Infrastructure providers process information as needed to host and operate the service. If password recovery is enabled, the configured email delivery provider processes the recipient address and recovery message. Information may also be disclosed where required by law.

The current mobile app connects to the AlvaSoft TrayVision service at https://adtracker.alva-software.com/. The server address cannot be changed in the app.

Local storage and cookies

The mobile app downloads videos and cafe images into its internal cache before displaying them. It also saves the registered device identifier, latest device configuration and dismissed alert information in local app storage. Outdated media is removed as content is refreshed; Android may also reclaim cached files.

You can clear the app's cache or storage in Android settings. Uninstalling removes its local app data. Android backup or device transfer may include saved settings, depending on the device's backup configuration.

The web application uses essential cookies for sign-in and protection against forged requests. Blocking these cookies may prevent management functions from working. The current application does not include advertising or analytics cookies.

Security

The default TrayVision service uses HTTPS. Web management functions require authentication and role-based authorisation, and account passwords are stored as hashes. Mobile API requests use the device identifier and server-side assignment checks.

The current mobile app requires HTTPS and blocks unencrypted HTTP traffic. Access to devices, hosting systems and management accounts should be limited to authorised people. Earlier app versions allowed custom server addresses including HTTP.

Retention and deletion

Device registrations, cafe assignments, account information and uploaded content remain on the server until managed or removed by the service operator. Device status is updated with the latest report. The application does not apply a fixed automatic deletion period to inactive device or user records.

Disabling or removing a device or user in the management interface can block access while retaining the underlying record. This is not the same as permanent erasure. Clearing or uninstalling the mobile app does not remove server-side records.

To request permanent deletion, use the contact details below. Retention of infrastructure logs and backups depends on the server operator's arrangements and any applicable security or legal requirements. The operator can explain any information that must be retained when handling a request.

Contact and privacy requests

Provider: AlvaSoft.

For privacy questions or requests to access, correct or permanently delete information, contact AlvaSoft at support@alva-software.com.

Include the relevant server address and device identifier or management account email so the record can be located. Do not send passwords. We may need to verify your identity or authority to act for a device or account before handling the request.

Changes to this policy

Updates will be published on this page with a revised date. Review this page when the service or its data handling changes.