AltioraAltiora POSBack to sign in

Privacy Policy

This Policy explains how Altiora I.T Service handles personal information in connection with Altiora POS at altiorapos.com. It covers account registration, business workspaces, and use of the POS. Acknowledging this Policy confirms that you have read the notice; it is not blanket consent for unrelated marketing or every possible use of your information.

1. Who handles your information

Altiora manages information needed to administer its service and account relationships. A business using Altiora POS determines the information it enters about its staff, customers, and transactions and controls staff access within its workspace. For that business information, Altiora provides storage and processing functions on the business’s behalf. Your business administrator is normally the first contact for requests about its records; you can also contact Altiora using the details below.

2. Information processed

  • Account information: name, email address, authentication identifier, sign-in and verification status, staff role, branch assignment, and account activity.
  • Business information: business and owner details, contact information, addresses, registration details if provided, products, inventory, sales, refunds, shifts, cash movements, notes, and uploaded images.
  • Agreement records: the account identifier, email address, agreement wording, Terms and Privacy Policy versions, and the server-recorded acceptance time.
  • Technical information: information needed to deliver and secure the service, such as requests, errors, sessions, browser storage, and logs maintained by the hosting and authentication providers.

Google Firebase Authentication handles passwords and Google sign-in. Altiora’s business database does not store account passwords. Do not enter card security codes, full payment-card details, or unnecessary sensitive personal information into POS notes or other free-text fields.

3. Purposes and grounds for processing

Information is used to create and authenticate accounts, provide business workspaces, apply staff permissions, record transactions and inventory, generate reports, support users, investigate errors or misuse, and meet applicable obligations. Depending on the activity, processing may be necessary to provide the service or carry out an agreement, comply with law, protect legitimate service and security interests subject to applicable safeguards, or rely on consent where required. A business entering other people’s information is responsible for its own notices and lawful grounds.

4. Access and service providers

Authorized business users can access information according to their roles. Altiora’s authorized administrators may access records to operate, support, or protect the service. The service uses Google Firebase for authentication and ChatGPT Sites/OpenAI and Cloudflare infrastructure for hosting, database and file storage. Providers process information needed for their functions and may use infrastructure outside the Philippines. Disclosures may also be required by law or necessary to address security incidents or legal claims. Information sharing must be limited to a lawful purpose.

5. Cookies and offline storage

Altiora POS uses a secure session cookie and browser storage for sign-in, settings, carts, cached resources, and offline operation. Offline transactions can remain on the device until synchronized. These device records are tied to the browser and domain. Synchronize pending work before clearing storage, uninstalling the app, changing devices, or switching domains. Use appropriate device access controls on shared terminals.

6. Retention and deletion

Account and business records are retained as needed to provide the service, maintain transaction and audit history, resolve disputes, and satisfy applicable legal obligations. Retention depends on the type of record, its purpose, and any applicable business or legal requirements. Closing access, deactivating a user, or deleting a business through the interface does not automatically erase all underlying records.

Contact Altiora or the relevant business administrator to request access, correction, or erasure. We will review the request, verify identity as appropriate, and explain any grounds for retaining records. Local copies and exports held on your devices or by your business must also be managed by their holders.

7. Security

The system uses HTTPS, Firebase authentication, server-side access checks, branch and business permissions, and audit records to help protect information. Security also depends on your account credentials, assigned permissions, and devices. No internet service can guarantee absolute security. Report suspected account misuse or exposure promptly to Altiora.

8. Your privacy rights

Subject to applicable conditions, Philippine data protection law provides rights to information, access, correction, objection, erasure or blocking, and data portability. Where processing relies on consent, you may withdraw it without affecting prior lawful processing. Some information may still be needed under another lawful ground. You may raise concerns with Altiora and lodge a complaint with the National Privacy Commission.

For a request, email Altiora with the account or business concerned and the assistance needed. Do not include your password. We may need proportionate information to confirm your identity or authority before providing or changing records.

9. Updates

We will identify policy updates with a revised effective date and version, provide notice of material changes, and seek consent where applicable. Read this Policy alongside the Terms of Use.

Contact Altiora

Altiora I.T Service · Iloilo, Philippines
Email: altioraitservices@gmail.com