Privacy Policy
Last updated: July 28, 2026
On this page
Introduction
Simply Arrived, LLC (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website or use our check-in platform.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our services.
Information We Collect
Account Information
When an organization creates an account with Simply Arrived, we collect names, email addresses, phone numbers, organization details, and other information necessary to provide our services.
Check-In Data
When clients or visitors check in via our kiosk or mobile app, we collect check-in time, the client’s name, the staff member they’re seeing, and location information. Check-in records are deleted from our database seven days after the check-in. Our text-message provider is configured so that message content is inaccessible to us after seven days (it may remain in the provider’s own systems for up to 30 days after that). Notification emails never contain a client’s name. A notification text, once delivered, stays on the staff member’s phone like any other message, under that person’s control.
Device & Browsing Information
We automatically collect device, browser type, IP address, and usage information using cookies and similar technologies.
SMS Opt-In Data
When a staff member opts in to SMS notifications, we collect their phone number, opt-in timestamp, IP address, device information, opt-in method (email link or invite code), and the record that the number was verified by a one-time code. See SMS Communications & Consent below.
How We Use Information
- To Provide Services — deliver check-in notifications, staff coordination, and reporting
- To Improve Services — analyze usage patterns and optimize our platform
- To Communicate — send service updates, security notices, and support responses
- For Compliance — meet legal and regulatory requirements, including TCPA for SMS
- For Fraud Prevention — detect and prevent fraud, abuse, and security issues
SMS Communications & Consent
What Information We Collect
When a staff member opts in to receive SMS notifications from Simply Arrived, we collect:
- Phone Number — provided by the organization’s administrator
- Consent Record — timestamp, method, and IP address of opt-in
- SMS Activity — delivery status and replies (e.g., “STOP”)
We do not collect a staff member’s email or location data for SMS purposes. Their name is provided by their organization and used only to verify identity during opt-in and route notifications correctly.
Why We Collect This Information
Simply Arrived collects phone numbers solely to:
- Send SMS notifications when clients check in
- Receive your replies, including STOP requests and the optional reply code for a mobile check-in
- Comply with opt-in/opt-out requests (STOP replies)
- Maintain a consent record for legal compliance and audit purposes
We do not use phone numbers for marketing, promotional, or any purpose other than operational check-in notifications.
How We Store & Protect Data
- Phone numbers and consent records are stored in encrypted databases
- Access is limited to Simply Arrived personnel and organization administrators
- Consent records are retained indefinitely for legal and compliance purposes
- Revoked consents (opt-outs) are marked inactive but preserved for audit trails
- All SMS traffic is transmitted through Twilio, a TCPA-compliant SMS provider
No Third-Party Marketing Use
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the categories of information disclosed above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties for any purpose.
Consent & Rights
Opt-In Process. Before receiving SMS notifications, a staff member must explicitly opt in via:
- Email Link — a unique, single-use link sent by their organization admin, opened on our web form
- Invite Code — if no email is on file, the admin provides an 8-character invite code, entered on our opt-in page
- Number Verification — either way, the staff member enters their own mobile number and confirms a one-time code texted to it before the consent statement is shown. Administrators never enter a phone number.
SMS will not be sent unless this opt-in process is completed.
Opt-Out Rights (TCPA Compliance)
Staff members have the unconditional right to opt out of SMS at any time:
- Reply STOP to any SMS — consent is revoked immediately
- Click the opt-out link in any Simply Arrived email (text messages contain no links)
- Contact their organization admin to revoke consent in the dashboard
Once opted out, no further SMS will be sent unless the staff member explicitly opts in again.
SMS Frequency
Message frequency varies. Check-in alerts are sent only when a client checks in to see you, so how many you receive depends on how many people check in. There is no recurring or scheduled send. You will also receive a one-time confirmation when you opt in, and a short confirmation if you text back a reply code. Those are the only messages we send. We do not send marketing, promotional, or unsolicited messages.
Message Rates
Message and data rates may apply. Check with your mobile carrier for details.
Third-Party Processor: Twilio
Simply Arrived uses Twilio to send and receive SMS messages. Phone numbers are shared with Twilio solely to deliver SMS notifications. Twilio’s privacy policy →
Data Retention
- Active Consents — retained indefinitely to enable SMS delivery
- Revoked Consents — retained indefinitely for audit and compliance
- Check-In Records — deleted from our database after 7 days
- Integration Event Logs (contain no client names) — retained 90 days for troubleshooting
- Opt-Out Records — retained indefinitely to prevent re-messaging
Security
Simply Arrived implements industry-standard security measures including encryption, secure authentication, and regular security review. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
Sharing & Disclosure
We do not sell personal information. We may share information with:
- Your Organization — admins can see their staff members’ name and phone number
- Service Providers — Twilio (SMS), Amazon SES (email), and cloud hosting providers
- Legal Requirements — if required by law, court order, or government request
TCPA Compliance Statement
Simply Arrived is committed to compliance with the Telephone Consumer Protection Act (TCPA) and applicable telecommunications regulations:
- ✓ Prior express written consent collected before any SMS is sent
- ✓ Opt-out available via STOP reply, email opt-out link, or admin request
- ✓ No telemarketing or promotional use of SMS
- ✓ Full audit trail of consents, opt-outs, and SMS delivery
- ✓ TCPA-compliant SMS provider (Twilio)
Contact Us
Questions about this Privacy Policy or how we handle information? Contact us:
For SMS-specific complaints, you may also contact Twilio at twilio.com/contact-us.
Related policies
See our Terms and Conditions and SMS Opt-In pages for full details on how this Program operates.