Lior Mobile / Legal & support

Updated September 23, 2026

Privacy Policy

This policy explains how Lior Technologies uses personal data to provide Lior Mobile and its connected Lior Core mobile access-control service.

No sale of personal data. No advertising tracking. Lior Mobile does not sell personal data and does not share personal data with advertisers or data brokers.

Data We Use

We process information needed to identify you and provide authorized access. Depending on your account and the information supplied by your organization, this includes your name, email address, profile photograph, organization, assigned sites, doors and elevators, mobile credential details, account and sign-in information, access requests and results, and information you provide when contacting support. These records can be linked to your identity and organization.

Device information may include a device identifier and numeric support Device ID, any nickname previously provided, hardware model, operating system, app version and build, installation identifier, last-seen time, push notification token and permission status, biometric capability and the app's authentication setting, and App Attest status. This information supports device registration, security and administrator device management. We do not receive or store your Face ID, Touch ID or Optic ID biometric templates, or your iPhone passcode.

How Data Is Used

We use this information to sign you in, activate and manage device-bound mobile credentials, restore or transfer eligible credentials when you request it, display assigned access locations, process unlock requests, show recent activity, deliver service notifications, help authorized administrators manage access, investigate security events, and provide support.

Sharing And Service Providers

We do not sell personal data, share it with advertisers or data brokers, or use it for cross-app advertising tracking. Your authorized organization and its administrators can access the credential, device and activity information needed to operate their access-control system.

Service providers may process data as necessary to host, deliver, secure or support the service, including hosting and network providers, email delivery services and Apple's push notification service. We may also disclose information when required by law or as necessary to protect users, the service or legal rights. These operational uses are different from selling data or sharing it for advertising.

Notifications And Device Permissions

Notifications are optional. Declining notifications does not prevent cloud unlock. Authentication with Face ID, Touch ID or your device passcode is used when you enable the corresponding security setting in Lior Mobile; iOS performs that authentication.

The current release does not request Bluetooth, Motion & Fitness, camera or microphone access. You can review or change supported permissions in iOS Settings. Denying an optional permission does not prevent unrelated features from working.

Location For Nearby-Only Access

If your administrator restricts a mobile credential to use near a site, Lior Mobile requests location while you use the app. For that unlock request, the app sends a recent location, its reported accuracy and capture time to Lior Core to check the site's access restriction. Precise Location may be required. Without suitable location access, a nearby-only unlock cannot proceed; credentials without this restriction do not require location.

Lior Mobile does not track location in the background, add coordinates to device heartbeats or save location samples locally. The nearby-access service evaluates coordinates in memory and does not retain or log them. Its security audit may retain the outcome, configured site radius, reported accuracy and sample age, but not coordinates, distance or a movement history. Access activity still identifies the site and door or elevator involved in a request.

Retention

Account, credential, device and access records are retained as needed to operate the service, manage authorized access, investigate security incidents, provide support and meet applicable obligations. Retention of organization-managed access and audit records depends on the organization's policies and applicable requirements. The app displays activity for the last 24 hours; that display window is not a promise that server records are deleted after 24 hours.

Account Deletion And Credential Removal

Signed-in users can start a deletion request in Settings > Privacy & Legal > Data & Privacy. Account deletion includes the Lior Mobile account, its linked Lior ID and linked mobile credentials on every phone. It ends sign-in through that Lior ID, including access to other Lior products using the same identity. Additional confirmation is required when other products are affected. Deletion does not delete your organization's business records.

A deletion request normally has a seven-day cancellation period, followed by processing at the next hourly deletion run. Signing in does not cancel a request; cancellation must be explicitly requested during the allowed period. Processing may be held for renewed confirmation if the affected scope changes, or delayed by a processing failure. A submitted request or an elapsed deadline alone does not prove completion. Contact support if you cannot confirm the status.

Completed deletion removes or anonymizes account identity data and retires the associated mobile credentials, device sessions, push tokens, wallet links and pending mobile invitations. Limited non-usable records may remain for security, audit and required retention. Your organization-managed access-control person record, site and group membership, schedules, physical cards, PIN credentials and panel-user record are preserved. Other people's access is not affected.

Removing a credential from one phone or signing out is not the same as deleting your account or all organization records. Invitation-only users do not need to create a Lior ID to request credential revocation or exercise privacy rights. Contact your organization administrator or [email protected] for assistance with invitation-only access, older app versions, identity-related requests or credential removal. We may need to verify your identity before acting.

Organization Administrators

Your organization controls the sites, doors, elevators, schedules, groups and mobile credentials assigned to you. It also controls any nearby-only access restriction. For questions about an assignment, access event or retention of organization-managed records, contact your administrator. You may also contact Lior Technologies about access to, correction of or deletion of your personal data and other privacy rights available under applicable law.

Security

Lior Mobile stores authentication tokens in the iOS Keychain and communicates with the Lior Core cloud using HTTPS. Door and elevator access requires an authorized device-bound mobile pass, not just an email address and password. We use safeguards designed to protect access-control data, but no system can be guaranteed completely secure.

Policy Updates

We may update this policy when the service or its data practices change. The updated date at the top identifies the current version. Review this page for the latest information.

Contact

For privacy questions, access requests, deletion requests, or permission questions, contact [email protected].