Security & Data Protection
Version 1.0 ยท effective 02/10/2026
This page explains, at a high level, how WithOpp protects your account and your business data, and what you can do yourself.
1. Signing in
- You sign in with your email and a password. Your email is confirmed before your first sign-in.
- Passwords must have at least 8 characters, including letters and numbers. They are stored hashed; nobody at WithOpp can see them.
- Changing your password requires your current password first.
- Two-step verification is not available yet.
2. Devices and sessions
In Account security you can see every device signed in to your account and when it was last used, and sign any of them out - one at a time, or all except the one you are using. Sign-ins, sign-outs, signed-out devices and password changes are recorded in your security history.
3. Who can see what
- Every business is completely separate: no business can see another's data. This is enforced inside the database itself, not just on screen.
- Each team member has a role that decides what they can see and do, checked on every action.
- The owner can suspend a team member instantly.
- WithOpp staff open a business's data only when needed, and every time it is recorded.
4. Protecting data
- All traffic between your device and WithOpp is encrypted (HTTPS/TLS).
- Stored data is encrypted by our database provider (AES-256).
- The system's secret keys stay on our servers only; they are never in the app on your device.
5. Records and monitoring
- The audit log records who added, changed or deleted what. It cannot be changed or deleted.
- Stock and customer/supplier balance records cannot be edited; mistakes are corrected with a new, visible entry.
- Sign-in events are recorded.
6. The offline till
So the till works without internet, the product list and unsent sales are kept on the device. Keep till devices locked with a PIN or password, and sign out a lost device from Account security.
7. If a security incident happens
If we discover that data was leaked or accessed without permission, we act to contain it, and notify the Personal Data Protection Commission (PDPC) and the affected businesses without undue delay - aiming for within 72 hours.
8. What you can do
- Use a strong password you do not use anywhere else, and never share it.
- Give each team member their own account.
- Remove anyone who leaves straight away.
- Check your signed-in devices from time to time, and sign out any you do not recognise.
9. Reporting a security problem
Use the "Report a security problem" button in the Legal & Trust Center, or write to withopp.bis@gmail.com. Good-faith reports are welcome (see the Acceptable Use Policy, section 2).