FTC, CCPA/CPRA, GDPR & AI GOVERNANCE COMPLIANT

Privacy Policy & Data Protection

Operated by IT Cyber Work LLC • Last Updated: September 29, 2026. This policy outlines how Impossible POS collects, protects, utilizes, and processes merchant and transactional data across our desktop applications, mobile cloud kiosks, and online services.

Entity: IT Cyber Work LLC Product: Impossible POS Contact: support@impossiblepos.com
🛡️

Zero Card Data Stored

Full PCI-DSS compliance. We never capture, view, store, or transmit credit card numbers or CVVs.

🤖

Transparent AI Usage

AI voice ordering is strictly transactional and includes mandatory audible recording notifications.

🗑️

Right to Erasure

You own 100% of your local database and can request permanent cloud deletion anytime.

1. Information We Collect & Data We Never Collect

A. Information Collected for Licensing & Support: When you register or purchase an Impossible POS license, IT Cyber Work LLC collects essential merchant credentials including business legal name, primary contact name, email address, physical restaurant address, phone number (WhatsApp or mobile for technical setup), and Hardware Machine ID. This information is utilized strictly to issue encrypted license keys, deliver critical security updates, and conduct remote onboarding sessions.

B. Local Operational Database (Stored On-Premise): Impossible POS is architected as an Offline-First, Local-First operating system. Your menu items, pricing, inventory balances, employee PIN codes, kitchen modifiers, and sales transaction logs are stored locally on your physical Windows terminal inside a local SQLite database (pos.db). IT Cyber Work LLC does not sell, broker, or monetize your store's sales records.

⚠️ STRICT ZERO FINANCIAL DATA HARVESTING (PCI-DSS):
Impossible POS DOES NOT collect, inspect, process, or store raw credit or debit card Primary Account Numbers (PAN), CVV/CVC codes, expiration dates, magnetic stripe track data, or debit PIN blocks. All credit card processing occurs in strict tokenized isolation via certified third-party merchant terminals (such as Stripe, Square, PAX Technology, Clover, or your independent acquiring bank).
AI Disclosure

2. Artificial Intelligence (AI) Usage & Transparency

In full compliance with United States Federal Trade Commission (FTC) guidelines, state artificial intelligence disclosure laws (including California AB 1524), and international AI safety standards, Impossible POS transparently discloses that our platform integrates optional Artificial Intelligence modules:

  • AI Voice Phone Ordering Assistant: An automated voice agent powered by speech-to-text and natural language processing (integrating Twilio, Vapi, OpenAI, and Deepgram) capable of answering incoming restaurant phone calls, interpreting customer food orders, answering menu questions, and injecting tickets into the POS register and kitchen KDS screens.
  • Conversational Menu Navigation & Text Processing: Parsing complex spoken food requests and dietary modifiers into structured ticket items.

🛡️ AI Processing Boundaries & Ethical Protections:

• No Automated Financial Charges: AI models never initiate or finalize financial charges or bank debits autonomously. All charges require cashier or in-person payment confirmation.

• No Model Training with Private Proprietary Data: Audio and transcript data processed during food orders are processed ephemerally for order fulfillment and are NOT used by IT Cyber Work LLC or third-party providers to train public foundation models without consent.

• Mandatory Audio Call Recording Disclosure: To comply with federal and state wiretapping and two-party consent laws, the system plays an automated audible notice to callers: "This call is recorded and assisted by AI" prior to conversational engagement.

3. Third-Party Sub-processors & External API Directory

Impossible POS connects with vetted, enterprise-grade third-party service providers to facilitate telecommunications, payment processing, cloud backups, and remote support. Below is the comprehensive directory of our data sub-processors:

Third-Party Service Category / Role Data Processed Compliance Standard
Stripe / Square / PAX / Clover Payment Processing Hardware & Gateways Encrypted payment tokens & authorized transaction totals. (No raw cards stored by POS). PCI-DSS Level 1
Twilio Inc. Telecommunications & SMS Dispatch Phone numbers for SMS order status and incoming voice call routing. TCPA / SOC 2 Type II
Telegram Bot API Zero-Cost Order Alerts (Optional) Encrypted Telegram Chat IDs for food readiness alerts. End-to-End Encrypted
OpenAI / Vapi / Deepgram AI Speech Transcription & Parsing Voice audio streams and menu order strings (processed ephemerally). Zero Data Retention API
Cloudflare Inc. Web Security & Edge DNS IP addresses and web traffic requests for DDoS mitigation and SSL encryption. ISO 27001 / SOC 2
RustDesk / Remote Support Merchant Remote Onboarding (Optional) Temporary desktop view, strictly upon manual merchant invitation for free menu setup. TLS 1.3 / E2E Encrypted

4. Right to Deletion & Account Erasure ("Right to be Forgotten")

Under California Consumer Privacy Act (CCPA/CPRA), General Data Protection Regulation (GDPR), and federal privacy guidelines, every merchant and user has the unrestricted legal right to request the complete deletion of their account and associated cloud data:

Local PC Data (Your Machine)

You maintain 100% unilateral ownership of the local pos.db database on your Windows PC. You may export, backup, or permanently delete this file and all software binaries at any time directly through Windows Explorer.

Cloud Account & Backups

To permanently erase your Cloud Owner Portal account, contact information, and mirrored sales ledgers, simply submit an erasure request to our privacy team.

📧 How to Request Account & Data Deletion:
Send an email to support@impossiblepos.com or itcyberwork@gmail.com with the subject line "Data Erasure Request" including your restaurant name or License Key. Our technical privacy compliance officer will execute a permanent purge of your cloud records within 48 to 72 business hours and return a signed digital Certificate of Deletion.

5. Biometric Authentication & Video Surveillance Disclaimers

Biometric Fingerprint Authentication: Impossible POS supports optional USB optical fingerprint scanners for rapid cashier clock-in and drawer authorization. All fingerprint templates are hashed into mathematical checksums locally on the physical terminal. Raw biometric fingerprint images are never saved to disk and are never uploaded to the internet or cloud servers.

CCTV / NVR Video Integration: Where licensed, Impossible POS provides real-time POS transaction text overlay onto local restaurant security cameras (via RTSP). Video streams remain entirely within your private local network and are not transmitted to or hosted by IT Cyber Work LLC.

Questions or Privacy Inquiries?

If you have questions regarding this Privacy Policy, your rights under CCPA/GDPR, or our AI data protection standards, our dedicated compliance team is ready to assist:

Company: IT Cyber Work LLC
Direct Privacy Officer Email: support@impossiblepos.com