Summary
- This website sets no cookies and runs no analytics, advertising or tracking scripts.
- The co-signer app contains no advertising, analytics or tracking software, and we never sell personal data.
- The app talks only to the optitor deployment of the organization you pair it with. Its approval key is created in your phone's secure hardware and never leaves it.
- Your biometrics (Face ID, Touch ID, fingerprint) are handled entirely by your phone's operating system. Neither we nor your organization ever receive them.
Who is responsible
This website, optitor.com, is operated by 3-102-954669 Sociedad de Responsabilidad Limitada (a limited liability company registered in Costa Rica), referred to here as “optitor”, “we” or “us”. We are the controller for personal data processed through this website.
optitor is software that organizations deploy and operate themselves. When you use the co-signer app, the organization that runs the optitor deployment you pair with — usually your employer — decides why and how the data sent to that deployment is used, and is the controller for it. Where we operate a deployment ourselves on an organization's behalf, we process that data on the organization's instructions. Questions about how your organization uses this data should go to your organization first; we will help where we can.
This website
What we process
- Server logs. Like any web server, ours records technical data for each request — IP address, requested page, date and time, browser user agent and the response status. We use these logs to keep the site secure and running, which is our legitimate interest.
- Messages you send us. The contact form does not send anything to us by itself: it opens your own email program with a message you can edit and send. If you send it, or email us directly, we receive your name, email address, company and whatever you write, and use them to reply and to follow up on your inquiry.
What we do not do
We set no cookies, use no local storage for tracking, load no third-party scripts, fonts or embeds, and use no analytics, advertising or social-media pixels.
The co-signer app
The optitor co-signer app (iOS and Android) lets members of an organization approve actions in that organization's optitor deployment. It processes the following.
Stored only on your phone
- Approval key. A private key generated inside the Secure Enclave (iPhone) or the Android Keystore — in StrongBox where available. It cannot be exported and is never transmitted.
- Pairing details and session tokens. The address of your organization's deployment and the tokens that keep the app signed in. Tokens are kept in the iOS Keychain or in Android app-private storage.
- Biometrics. Approvals are unlocked by your phone's own Face ID, Touch ID or fingerprint check. The app only learns whether the check succeeded.
Sent to your organization's deployment
- Device enrollment: the approval key's public key, a device identifier, the platform (iOS or Android) and the user account you are pairing as.
- Approvals: your decisions and the signatures your device makes over exactly what you approved.
- Push token (if your organization uses push notifications): a token from Apple Push Notification service or Firebase Cloud Messaging so the deployment can wake the app. Notifications carry identifiers only — never amounts, addresses or key material.
- Device attestation (if your organization requires it): a statement from Apple App Attest, or from Google Play Integrity and Android Key Attestation, that the app and device are genuine. Your organization's deployment checks it and keeps only whether it passed.
Camera and other permissions
The camera is used only to scan pairing codes, and images are processed on the device and not stored. On Android, scanning uses the Google Play services code scanner. The app does not access your contacts, photos, location or microphone.
What the app does not contain
No advertising, analytics, crash-reporting or tracking software, and no data is collected for advertising or sold. The app does not track you across other companies' apps or websites.
Sharing and transfers
We share website personal data only with service providers that host and operate it for us, under contracts that limit their use to that purpose, or where the law requires it. App data goes to your organization's deployment and, only when your organization enables those features, to Apple and Google as the providers of push notifications and device attestation, under their own privacy terms. Where data is transferred internationally, we rely on appropriate safeguards required by applicable law.
Retention and security
We keep website logs only as long as needed for security and operations, and correspondence as long as needed to handle your inquiry and meet our legal obligations. Data held by your organization's deployment is retained according to your organization's policies. Deleting the app removes everything it stored on your phone; revoking the device in the console stops it from approving anything further.
We protect data with encryption in transit, access controls and the security model described on our security page.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to complain to a data-protection authority. To exercise these rights for this website or our correspondence, write to hello@optitor.com. For data held by your organization's optitor deployment, contact your organization; we will assist them in responding.
Delete your data
Your co-signer data lives in two places: on your phone, and in your organization's own optitor deployment.
- On your phone. Open the optitor co-signer app, go to Device & security → Reset this device, or uninstall the app. This deletes the approval key, the pairing and everything else the app stored on the phone. Nothing on the phone can be recovered afterwards.
- In your organization's deployment. Ask an administrator of your organization's optitor console to revoke your device and remove your account under Users & Devices. That deletes your device record (device ID and public key) and your sign-in. Records of approvals you already gave are part of your organization's audit trail and may be kept for as long as its legal obligations require.
- Need help? Write to hello@optitor.com with the name of your organization. We will forward your request to it and help it respond. We hold no co-signer data ourselves.
Children
This website and the co-signer app are intended for professional use and are not directed to children.
Changes and contact
We will update this policy when our practices change and show the effective date at the top. For any privacy question, write to hello@optitor.com.