Privacy Policy & Data Protection
Operated by IT Cyber Work LLC • Last Updated: September 29, 2026. This policy outlines how Impossible POS collects, protects, utilizes, and processes merchant and transactional data across our desktop applications, mobile cloud kiosks, and online services.
Zero Card Data Stored
Full PCI-DSS compliance. We never capture, view, store, or transmit credit card numbers or CVVs.
Transparent AI Usage
AI voice ordering is strictly transactional and includes mandatory audible recording notifications.
Right to Erasure
You own 100% of your local database and can request permanent cloud deletion anytime.
1. Information We Collect & Data We Never Collect
A. Information Collected for Licensing & Support: When you register or purchase an Impossible POS license, IT Cyber Work LLC collects essential merchant credentials including business legal name, primary contact name, email address, physical restaurant address, phone number (WhatsApp or mobile for technical setup), and Hardware Machine ID. This information is utilized strictly to issue encrypted license keys, deliver critical security updates, and conduct remote onboarding sessions.
B. Local Operational Database (Stored On-Premise): Impossible POS is architected as an Offline-First, Local-First operating system. Your menu items, pricing, inventory balances, employee PIN codes, kitchen modifiers, and sales transaction logs are stored locally on your physical Windows terminal inside a local SQLite database (pos.db). IT Cyber Work LLC does not sell, broker, or monetize your store's sales records.
Impossible POS DOES NOT collect, inspect, process, or store raw credit or debit card Primary Account Numbers (PAN), CVV/CVC codes, expiration dates, magnetic stripe track data, or debit PIN blocks. All credit card processing occurs in strict tokenized isolation via certified third-party merchant terminals (such as Stripe, Square, PAX Technology, Clover, or your independent acquiring bank).
2. Artificial Intelligence (AI) Usage & Transparency
In full compliance with United States Federal Trade Commission (FTC) guidelines, state artificial intelligence disclosure laws (including California AB 1524), and international AI safety standards, Impossible POS transparently discloses that our platform integrates optional Artificial Intelligence modules:
- AI Voice Phone Ordering Assistant: An automated voice agent powered by speech-to-text and natural language processing (integrating Twilio, Vapi, OpenAI, and Deepgram) capable of answering incoming restaurant phone calls, interpreting customer food orders, answering menu questions, and injecting tickets into the POS register and kitchen KDS screens.
- Conversational Menu Navigation & Text Processing: Parsing complex spoken food requests and dietary modifiers into structured ticket items.
🛡️ AI Processing Boundaries & Ethical Protections:
• No Automated Financial Charges: AI models never initiate or finalize financial charges or bank debits autonomously. All charges require cashier or in-person payment confirmation.
• No Model Training with Private Proprietary Data: Audio and transcript data processed during food orders are processed ephemerally for order fulfillment and are NOT used by IT Cyber Work LLC or third-party providers to train public foundation models without consent.
• Mandatory Audio Call Recording Disclosure: To comply with federal and state wiretapping and two-party consent laws, the system plays an automated audible notice to callers: "This call is recorded and assisted by AI" prior to conversational engagement.
3. Third-Party Sub-processors & External API Directory
Impossible POS connects with vetted, enterprise-grade third-party service providers to facilitate telecommunications, payment processing, cloud backups, and remote support. Below is the comprehensive directory of our data sub-processors:
| Third-Party Service | Category / Role | Data Processed | Compliance Standard |
|---|---|---|---|
| Stripe / Square / PAX / Clover | Payment Processing Hardware & Gateways | Encrypted payment tokens & authorized transaction totals. (No raw cards stored by POS). | PCI-DSS Level 1 |
| Twilio Inc. | Telecommunications & SMS Dispatch | Phone numbers for SMS order status and incoming voice call routing. | TCPA / SOC 2 Type II |
| Telegram Bot API | Zero-Cost Order Alerts (Optional) | Encrypted Telegram Chat IDs for food readiness alerts. | End-to-End Encrypted |
| OpenAI / Vapi / Deepgram | AI Speech Transcription & Parsing | Voice audio streams and menu order strings (processed ephemerally). | Zero Data Retention API |
| Cloudflare Inc. | Web Security & Edge DNS | IP addresses and web traffic requests for DDoS mitigation and SSL encryption. | ISO 27001 / SOC 2 |
| RustDesk / Remote Support | Merchant Remote Onboarding (Optional) | Temporary desktop view, strictly upon manual merchant invitation for free menu setup. | TLS 1.3 / E2E Encrypted |
4. Right to Deletion & Account Erasure ("Right to be Forgotten")
Under California Consumer Privacy Act (CCPA/CPRA), General Data Protection Regulation (GDPR), and federal privacy guidelines, every merchant and user has the unrestricted legal right to request the complete deletion of their account and associated cloud data:
Local PC Data (Your Machine)
You maintain 100% unilateral ownership of the local pos.db database on your Windows PC. You may export, backup, or permanently delete this file and all software binaries at any time directly through Windows Explorer.
Cloud Account & Backups
To permanently erase your Cloud Owner Portal account, contact information, and mirrored sales ledgers, simply submit an erasure request to our privacy team.
Send an email to support@impossiblepos.com or itcyberwork@gmail.com with the subject line "Data Erasure Request" including your restaurant name or License Key. Our technical privacy compliance officer will execute a permanent purge of your cloud records within 48 to 72 business hours and return a signed digital Certificate of Deletion.
5. Biometric Authentication & Video Surveillance Disclaimers
Biometric Fingerprint Authentication: Impossible POS supports optional USB optical fingerprint scanners for rapid cashier clock-in and drawer authorization. All fingerprint templates are hashed into mathematical checksums locally on the physical terminal. Raw biometric fingerprint images are never saved to disk and are never uploaded to the internet or cloud servers.
CCTV / NVR Video Integration: Where licensed, Impossible POS provides real-time POS transaction text overlay onto local restaurant security cameras (via RTSP). Video streams remain entirely within your private local network and are not transmitted to or hosted by IT Cyber Work LLC.
Questions or Privacy Inquiries?
If you have questions regarding this Privacy Policy, your rights under CCPA/GDPR, or our AI data protection standards, our dedicated compliance team is ready to assist: