Product Idea Sheet · 2025

FaceFlow

A unified facial recognition layer for Property Management Systems and Point of Sale — enabling frictionless guest check-in, room charge payments, loyalty rewards, and secure staff authentication.

PMS Integration POS Payments Loyalty Programme Staff Auth Institutional Dining
<0.8s
Recognition speed
99.7%
Match accuracy
4
Core use cases
0
Cards / PINs needed

01 — Property Management System

Guest Check-In & Check-Out

Replace the front-desk queue with a seamless face-first workflow. Guests are recognised the moment they approach the kiosk or desk terminal, pulling their reservation, room assignment, and ID-verification status automatically.

📷

Camera Capture

Guest approaches kiosk. Live frame captured, liveness detection confirms physical presence.

🔍

Face Match

Biometric vector compared against enrolled guest profile. <0.8 s match time.

🏨

PMS Action

Reservation retrieved, room assigned, key card or digital key issued. Receipt sent to guest email.

Check-In Features

  • Pre-enrolment via app — Guests upload a selfie during online check-in, face vector stored 24 hrs before arrival
  • Walk-up enrolment — First-time guests enrol at the kiosk with ID document scan + live face capture
  • Reservation auto-pull — PMS record surfaced instantly; staff can review or override
  • Room assignment — Preferred room types, floor requests, and upgrade eligibility shown automatically
  • Digital key dispatch — Mobile key pushed to guest's phone immediately on match
  • Multi-room bookings — Each travelling party member enrolled and mapped to shared folio

Check-Out Features

  • Express check-out kiosk — Face scan retrieves final folio; one-tap approval settles the bill
  • Itemised charges review — Guest sees full itemised bill on screen; can dispute line items
  • Room charge settlement — Folio auto-settled against card on file; no card retrieval needed
  • Loyalty points posted — Stay points calculated and applied at the moment of check-out
  • E-receipt delivery — Folio emailed / SMS'd immediately after settlement
  • Key deactivation — Physical and digital keys deactivated instantly on check-out confirmation
🔔

VIP Recognition

Returning guests and loyalty members are flagged to front-desk staff on approach — name, tier, and preferences surface before a word is spoken.

🚪

Room Access

Optional: face-unlock integration with compatible door locks (RFID + camera combo) so guests can access their room without any physical key.

📋

Housekeeping Alerts

When a guest face is matched departing the property, housekeeping queue is automatically updated to mark the room for service.

⚠️

Watchlist / DNC

Do-Not-Check-In flags linked to face profiles. Security team alerted silently if a flagged individual is recognised at any terminal.

02 — Point of Sale

Dining Payments & Room Charges

Guests settle their dining bill or charge it to their room with a glance at the POS camera — no card, no phone, no signature. Servers see the guest's name, room number, dietary preferences, and loyalty tier the moment a face is recognised.

In-Restaurant Payment Flow

  • Face-pay at tableside — Server presents tablet or fixed terminal; guest looks at camera to authorise payment
  • Room charge — Charge posted directly to the PMS folio with outlet, timestamp, and itemised detail
  • Card-on-file settlement — Settled against the card stored in the PMS guest profile, no card handling
  • Split-bill support — Multiple guests at a table each authorise their own portion by face
  • Gratuity prompt — Tip selection screen shown post-recognition before final authorisation
  • Receipt preference — Paperless by default; email / SMS sent to guest's profile address

Server & Outlet Benefits

  • Guest name display — Server greeted with guest name and photo thumbnail on POS screen
  • Loyalty tier badge — Gold / Platinum guests highlighted for service prioritisation
  • Dietary & allergy flags — Stored preferences shown on the server POS before order is taken
  • Stay context — Check-in date, room number, and departure date visible to outlet staff
  • Spend analytics — Per-guest F&B spend tracked across all outlets and linked to their profile
  • Faster table turns — Average payment time reduced from ~4 min to under 30 seconds
🍽️

Multi-Outlet Support

Restaurant, bar, pool bar, spa, and room service can all share the same biometric engine — guest identity and folio consistent across every touchpoint.

🔐

Payment Authorisation Limits

Property-configurable thresholds: charges above a set amount (e.g. $200) require a secondary PIN or card confirmation alongside the face match.

📊

Real-Time Folio View

Server or outlet manager can see a guest's running account balance and current folio total before processing a new charge.

🏊

Non-Stay Guest Recognition

Day-spa visitors, club members, and event guests can be enrolled as non-resident profiles, still enabling face-pay without a room charge destination.

03 — Loyalty Programme

Earn, Recognise, Reward

Every recognised interaction — check-in, dining, spa, activity — earns points automatically. No app tap or card swipe required. The face is the loyalty card.

Member

Classic

0 – 4,999 pts / yr

  • 1 pt per $1 spent
  • Face check-in
  • Face pay at POS
  • E-receipts
Silver

Silver

5,000 – 14,999 pts / yr

  • 1.5 pts per $1
  • Room upgrade priority
  • F&B 10% discount
  • VIP recognition flag
  • Late check-out (2 pm)
Platinum

Platinum

40,000+ pts / yr

  • 3 pts per $1
  • Suite upgrade guarantee
  • F&B 20% discount
  • Early + late flex
  • Dedicated concierge
  • Annual free night

Instant Point Accrual

Points credited the moment a face-pay transaction settles at any outlet — no delay, no manual link. Visible in the guest app within seconds.

🎁

Redemption at POS

Guests redeem points directly at the POS by face — server sees redeemable balance and applies discount or free item with one confirmation tap.

📈

Bonus Multiplier Events

Property can define date-range or outlet-specific multiplier events (e.g. 3× on spa Tuesdays) — applied automatically to all eligible face-pay transactions.

🔗

Partner Network

API hooks to connect points earning/burning with external partner platforms (airlines, car hire, third-party hotels) for a wider loyalty ecosystem.

04 — Staff Authentication

Secure Login for PMS & POS

Staff authenticate to both the PMS workstation and POS terminal using their face — eliminating shared passwords, forgotten PINs, and buddy-punching. Every action is tied to a verified individual identity.

PMS Staff Login

  • Workstation lock/unlock — Screen locks when staff steps away; unlocks on return via face
  • Role-based access — Face match triggers the correct permission set (Front Desk, Manager, Housekeeping, Revenue)
  • Shared terminal support — Multiple staff can use one workstation; session switches on each face scan
  • Audit trail — Every PMS action timestamped against the authenticated staff member's face-verified ID
  • Override approvals — Manager overrides (rate adjustments, late check-outs) require a second face scan to authorise
  • Shift start/end logging — Time-and-attendance automatically recorded at each authentication event

POS Staff Login

  • Cashier sign-on — Each server opens their till session with a face scan; drawer totals tracked per individual
  • Quick switch — Server-to-server handover in under 2 seconds; no PIN entry mid-service
  • Void & refund controls — High-risk POS actions (voids, comps, refunds) require manager face re-auth
  • No-show protection — POS terminal auto-locks if no face detected at the terminal for a configurable idle period
  • Tip reconciliation — Tips assigned to verified staff identity for end-of-day payroll accuracy
  • Multi-outlet roaming — Staff face profile valid across all outlet terminals on-property
🛡️

Buddy-Punching Prevention

Time-and-attendance is biometrically locked — staff cannot clock in or out on behalf of another employee. Each record is a verified face event.

🔑

Elevated Actions Gate

Configurable list of actions (rate override, comp authorisation, account adjustment) that require supervisor-level face re-authentication before execution.

📱

Mobile Staff Enrolment

HR or management enrols new staff via a secure mobile flow — name, role, department, and face captured in under 60 seconds, immediately active across all terminals.

📉

Loss Prevention Insight

Every discrepancy or unusual action correlated to the staff identity active at that terminal. Exception reports flag high-frequency voiders or comp issuers.

05 — Institutional Dining

Campus, Corporate & Healthcare

FaceFlow's biometric layer extends beyond hotel F&B into high-volume, account-based dining environments — university campuses, corporate cafeterias, hospital staff canteens, and aged-care facilities — where speed, meal entitlements, and dietary compliance are critical.

🎓

University & College

Meal plan entitlements, resident vs commuter tracking, dining hall access control

🏢

Corporate Campus

Subsidised meals, department cost-coding, executive dining rooms, visitor catering

🏥

Hospital & Healthcare

Patient meal delivery confirmation, clinical dietary flags, staff canteen billing

🏠

Aged Care & Boarding

Resident identification, nutritional compliance, medication mealtime flags

Meal Plan & Entitlement Management

  • Face = meal credential — No card, fob, or app needed. Student or employee looks at the camera; plan balance checked and decremented in real time
  • Meal swipe allowances — Configurable daily / weekly entitlement limits per plan type (e.g. 3 swipes/day, unlimited breakfast)
  • Declining balance accounts — Flex dollars or café credits attached to the face profile; used for à la carte top-ups beyond the included plan
  • Multi-plan stacking — Individuals with multiple entitlements (staff + guest pass) can select which plan to apply at the terminal
  • Plan expiry alerts — Low balance and plan-end notifications pushed to the individual's app or email automatically
  • Guest / visitor top-up — Walk-up visitors enrolled on-the-spot with a one-time face capture and prepaid credit load

Dietary, Allergen & Clinical Compliance

  • Allergen flag display — Cashier terminal shows colour-coded allergen alerts (nuts, gluten, dairy, shellfish) the instant a face is matched
  • Dietary preferences — Vegan, halal, kosher, low-sodium, diabetic-friendly flags stored on profile and visible to serving staff
  • Clinical meal orders — In healthcare settings, patient's prescribed diet order surfaces at the servery — staff confirm delivery against the clinical record
  • Override audit — If a server overrides a dietary flag, the action is logged against their authenticated identity for compliance reporting
  • Nutritional tracking — Optional: each meal transaction linked to nutritional data for population-level reporting to dietitians
  • Medication mealtime sync — Integration hook to pharmacy/nursing systems to alert staff if a medication requires food co-administration

High-Volume Throughput

  • Sub-second recognition — Queue-busting speed essential for peak lunch rushes; single lane can process 600+ covers/hour
  • Multi-lane kiosks — Parallel camera arrays at tray-slide lines; each lane independently authenticated, no bottlenecks
  • Offline resilience — Local cache of enrolled vectors and entitlement data; operates fully during network outage, syncs on reconnect
  • Mobile pre-order integration — Face confirms pickup of a pre-ordered meal; order auto-closes and entitlement decrements simultaneously
  • Queue analytics — Real-time transaction rate dashboards for catering managers to anticipate peak staffing needs

Reporting & Cost Allocation

  • Department cost coding — Each meal charged to the employee's cost centre automatically; finance export at month-end requires no manual reconciliation
  • Subsidy calculation — Configurable employer subsidy rules applied per meal category; employee pays only their portion, employer portion auto-posted
  • No-show & waste tracking — Pre-ordered meals not collected flagged; waste data aggregated for procurement and sustainability reporting
  • Participation reports — Utilisation rates by plan, outlet, day-part, and demographic for contract caterer performance reviews
  • Audit-ready exports — GDPR-compliant transaction logs exportable to CSV / PDF for payroll, finance, and compliance audits
🔒

Access Control Integration

Dining hall entry gates linked to face recognition — only enrolled plan holders gain access during service hours. Integrates with campus access control platforms.

👨‍👩‍👧

Guardian & Parent Visibility

For boarding schools and universities, parents can optionally link to view their child's meal activity and remaining balance — configurable privacy controls per institution.

🍱

Grab-and-Go Lanes

Dedicated express lanes for pre-packaged grab-and-go items; face scan at exit confirms selection against plan entitlement — no cashier required.

📡

ERP & HRIS Integration

Connects to SAP, Oracle HR, Workday, and student information systems — new enrolments and leavers automatically synced; no manual profile management.

🌱

Sustainability Dashboards

Participation data correlated with food waste metrics — caterers can right-size production quantities by outlet and day-part based on verified consumption trends.

🤝

Contract Catering Billing

Automated monthly billing pack for managed dining contracts — verified cover counts, plan utilisation, and subsidy totals all derived from biometric transaction records.

06 — Technical Architecture

How FaceFlow Works

A lightweight biometric middleware layer sits between existing PMS and POS systems — no rip-and-replace required. Integration via standard REST APIs and webhooks.

Layer 1

Capture Device

Near-infrared + RGB dual-camera hardware (kiosk, tablet, or fixed terminal). Liveness detection built into SDK prevents photo spoofing.

Layer 2

On-Device Processing

Face vectorisation runs at the edge device — raw biometric data never leaves the terminal. Only encrypted feature vectors transmitted.

Layer 3

FaceFlow Engine

Hosted matching service compares encrypted vectors against enrolled profile store. Returns match confidence score and linked profile ID.

Layer 4

PMS Connector

REST API adapters for WinCloud & Yellowstone. Reservation and folio data exchanged bidirectionally.

Layer 5

POS Connector

Integrations for Hashmato POS products. Guest profile and payment method pushed on match event.

Layer 6

Loyalty Engine

Points ledger API — earn rules, tier calculation, redemption engine, and partner exchange hooks. Real-time balance pushed to guest app.

Layer 7

Admin Dashboard

Web-based property management UI — enrolment management, terminal health, match logs, exception reports, and loyalty analytics.

Layer 8

Guest Mobile App

Self-service enrolment, loyalty balance, transaction history, point redemption, and digital room key. iOS + Android.

07 — Security & Compliance

Privacy by Design

Biometric data handling governed by GDPR, CCPA, BIPA, and local equivalents. Guest and staff consent is explicit, revocable, and fully audited.

01

No Image Storage

Raw facial images are never persisted. Only encrypted mathematical feature vectors are stored — these cannot be reverse-engineered into a photograph.

02

Explicit Consent

Guests and staff opt in explicitly before enrolment. Consent captured digitally with timestamp and version of privacy policy accepted.

03

Right to Erasure

One-click biometric data deletion for any guest or staff member. All vectors purged across all nodes within 24 hours of request.

04

Liveness Detection

Anti-spoofing via active liveness challenge (blink / head-turn) and passive depth analysis. Prevents photo, video, or mask attacks.

05

Encrypted Transit

All data in transit encrypted with TLS 1.3. Biometric vectors additionally encrypted with per-property AES-256 keys managed in HSM.

06

SOC 2 Type II

FaceFlow engine certified SOC 2 Type II. Annual penetration testing. Data residency options for EU and APAC properties.

08 — Technology Stack

Built On Proven Foundations

FaceFlow is built on a robust, battle-tested open web stack — maximising compatibility with existing hotel infrastructure, minimising hosting costs, and ensuring a wide pool of available development talent.

Backend Language

PHP 8.x

Server-side application logic built in modern PHP 8 — leveraging typed properties, fibers, named arguments, and match expressions for clean, maintainable code. Composer-managed dependencies.

Database

MySQL 8.x

Relational data store for guest profiles, folios, loyalty ledgers, staff records, and audit logs. InnoDB engine with row-level locking for high-concurrency POS environments. Encrypted at rest.

API Layer

RESTful JSON API

Stateless REST endpoints consumed by PMS connectors (WinCloud, Yellowstone), Hashmato POS, kiosk terminals, and the guest mobile app. OAuth 2.0 bearer token authentication on all routes.

Biometric SDK

Face Vector Engine

On-device face vectorisation via hardware SDK (NIR + RGB). Encrypted 128-dimension feature vectors passed to the PHP matching service over mTLS — raw images never stored or transmitted.

Caching Layer

Redis

In-memory session cache for active guest and staff face-match sessions. Entitlement data cached at terminal level for offline resilience. Sub-millisecond lookups during peak service periods.

Web Server

Nginx + PHP-FPM

High-performance Nginx reverse proxy fronting PHP-FPM process pools. Handles concurrent recognition requests from multiple terminals simultaneously with low memory overhead.

Queue & Jobs

Laravel Queues

Asynchronous job processing for loyalty point calculation, PMS folio posting, e-receipt dispatch, and audit log writes — ensuring POS payment response times are never blocked by downstream tasks.

Hosting

Cloud / On-Premise

Deployable to any Linux server, managed cloud (AWS, Azure, GCP), or on-premise hardware. Docker Compose configuration provided for rapid environment provisioning and version-controlled deployments.

Full stack: PHP 8.x MySQL 8.x Laravel Redis Nginx PHP-FPM REST / OAuth 2.0 Docker mTLS / AES-256