Privacy Policy
Last updated: July 14, 2026
This Privacy Policy describes how General Computer Solution Company Limited ("we", "us") collects, uses, and shares information when you use the Aires website at https://aires.club and the Aires Monitor, Aires Notify, Aires Meet, Aires Web, Aires Monitor Lite, Sidekin, Aires Attendance Pro, Aires Support, Aires Sentinel, มาดามหลิว (Madam Liew), and สั่งอาหาร (Food Time) mobile applications (collectively, the "Service").
1. Data we collect
When you create an account or use the Service, we collect:
- Name and email address — to identify and authenticate your account.
- Phone number — when you choose to verify your phone via SMS / Firebase Phone Authentication. Used solely for verification and (if you enable it) for SMS-channel monitor alerts.
- Account identifier (User ID) — an internal numeric ID assigned at sign-up.
- Device push token (Device ID) — a unique token issued by Apple (APNs) or Google (FCM) when you install the mobile app, used only to deliver push notifications you have subscribed to.
- Customer support messages — chat messages between you and our support team via the in-app chat.
- Restaurant orders, reservations and loyalty points (มาดามหลิว / Madam Liew only) — the menu items you order, pickup/delivery contact details you enter at checkout, table-reservation details (party size, date and time, contact), and your loyalty-point balance and history.
- Marketplace shops and orders (สั่งอาหาร / Food Time only) — the food shops you browse and order from, the menu items you order, pickup/delivery contact details and the delivery map pin you set at checkout, dish ratings you leave, and — if you open a shop — your shop profile (name, location, menu, photos, PromptPay receiving ID) and its staff/rider membership.
- Monitor configurations and probe results — the URLs, intervals, and thresholds you configure, plus the up/down history we generate by probing them.
- Attendance records (Aires Attendance Pro only) — clock in/out timestamps, regular and overtime durations, and optional shift, QR check-in, and geofence data. If you join a team, the team owner/administrator can view your attendance summary, individual punches, and — where geofencing is enabled — the location at which you clocked in or out.
- Location (Aires Attendance Pro only) — when you tap clock in or clock out, and only if your employer has enabled geofencing for your team, the app reads your device GPS location once to confirm you are inside the designated workplace. Location is read only at the moment you punch; the app never tracks your location in the background or while it is closed. See section 3.
- Sentinel telemetry (Aires Sentinel only) — the battery level, charging state, network type, environment-sensor readings, app version, and device model of the spare phone you deploy as a Sentinel, plus the probe results for the internal targets you assign to it. See section 7.
- Tamper photos (Aires Sentinel only, off by default) — a single still image captured by the Sentinel phone's camera, only if you enable Tamper photos for that Sentinel or press Snapshot on your dashboard. See section 7.
2. How we use your data
We use the data above only to operate the Service: to authenticate you, deliver notifications you have subscribed to, run scheduled checks against the URLs you configure, provide customer support, and — in Aires Attendance Pro — record your work hours and, where your employer enables it, confirm you are at the workplace when you clock in or out. We do not sell your data, share it with data brokers, or use it for third-party advertising.
3. Location data (Aires Attendance Pro)
This section applies only to Aires Attendance Pro. The other Aires apps do not request your location.
- When it is collected — only at the instant you tap Clock in or Clock out (including overtime), and only when your employer/team has turned on geofenced attendance. There is no continuous, background, or "always" location access.
- What is collected — a single GPS coordinate (latitude and longitude) and its accuracy, captured at the moment you punch.
- How it is used — to measure the distance between you and the workplace your team configured and decide whether the punch is allowed (you must be at the workplace to clock in or out). The coordinate is stored on that attendance record so your team owner can confirm where the punch happened.
- Sharing — location is visible only to you and, if you belong to a team, to that team owner/administrators. It is never sold, shared with data brokers, or used for advertising.
- Control — you grant location permission through your operating system and can revoke it at any time in iOS or Android Settings. If geofencing is not enabled for your team, the app does not request location at all.
- Retention — clock in/out coordinates are kept as part of your attendance history and are erased when you or your team owner delete the record, or when you delete your account.
4. Third-party services
To deliver the Service we rely on the following processors:
- Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM) — to deliver push notifications to your device.
- Firebase Phone Authentication — to verify phone numbers via SMS one-time codes.
- Email, SMS, Telegram, and LINE providers — only when you enable the corresponding notification channel.
- Payment processors (Stripe, Omise) — only if you create a paid subscription on the website. Payment card data is entered on the processor's page and never reaches our servers.
5. Face data (identity verification)
When you choose to verify your identity from Profile → Identity verification, you upload two images: a photo of your government-issued ID and a selfie taken with your device camera. We use these images solely to confirm that the face on the ID matches your live face. They are processed as follows:
- What is collected — Two images you submit during the verification flow: an ID-document photograph and a selfie. The app derives from them a numeric similarity score (0–10000) and a verification timestamp.
- How it is used — Solely to compute a face-match similarity score and, on a successful match, grant a "Verified" trust badge on your account. Face data is never used for advertising, profiling, or sharing with any third party.
- Where it is processed — Both images are forwarded once to our internal face-comparison service (InsightFace) hosted on our private network in Thailand. The comparison runs server-side and returns only a similarity score.
- Sharing with third parties — Face data is NOT shared with any third party. The comparison runs on our own infrastructure; no cloud face-recognition vendor (AWS Rekognition, Azure Face, Google Cloud Vision, etc.) is contacted, and no image leaves our network.
- Retention — Raw face images are NOT retained. They exist only in a temporary upload directory during the single HTTP request and are deleted immediately after the comparison completes. Only the numeric similarity score and the verification timestamp are stored on your user record. Both are erased when you delete your account (Profile → Delete account).
- Optional and revocable — Identity verification is entirely optional. You can use Aires without it. If you have verified and want the verification removed, email support@aires.club or delete your account.
6. Biometric authentication (Face ID / Touch ID)
Separately from the optional identity verification described above, each Aires mobile app supports unlocking the app with Face ID or Touch ID after your first sign-in. This is a convenience feature distinct from identity verification:
- Implementation — Apple’s LocalAuthentication framework handles the entire biometric check on-device.
- What we receive — Only a Boolean success or failure result. No facial scan, fingerprint, or biometric template is collected by Aires, stored on our servers, transmitted off the device, or shared with any third party.
- Where the data lives — Apple’s biometric system performs the match inside the device’s Secure Enclave; the Aires app is never given access to the underlying biometric data.
- Fallback — If biometric authentication fails or is unavailable, the app falls back to standard email/password sign-in.
- Opt-out — You can disable biometric unlock at any time from iOS Settings → the relevant Aires app → Face ID (or Touch ID).
7. Camera and device sensors (Aires Sentinel)
This section applies only to Aires Sentinel, the app you install on a spare Android phone (a "Sentinel") that monitors your own private network from inside it. The Sentinel is enrolled to your account with a one-time Sentinel Key shown on your dashboard; the app itself has no sign-in and collects no personal profile.
- Device telemetry — battery level, charging state (mains or battery), network type (Wi-Fi or cellular), app version, and device model. Sent with every report so your dashboard can warn you when the phone loses mains power, drops to cellular, or goes silent.
- Environment sensors — battery temperature, ambient light, and accelerometer motion. Used solely to alert you when the phone overheats, is moved, or its enclosure is opened. The app never accesses the microphone and never reads location.
- QR scanning — the camera is used at enrollment to scan your Sentinel Key. The QR frames are processed on-device and are never stored or uploaded.
- Tamper photos — off by default — if you switch on Tamper photos for a Sentinel, or press Snapshot on your dashboard, the phone captures a single still image and uploads it to your account so you can see what triggered a tamper alert. Photos are stored on our private storage (never publicly reachable), are visible only to you, are automatically deleted after 30 days, and are never shared with any third party.
- Your responsibility — you own and position the Sentinel phone. If you enable tamper photos, aim the camera at your own equipment and comply with the laws on camera surveillance that apply at your site.
8. มาดามหลิว (Madam Liew) restaurant app
มาดามหลิว (Madam Liew) is the official mobile application of the Madam Liew restaurant in Bangkok, Thailand. The app is developed and operated by General Computer Solution Company Limited ("we"), and is published on Google Play and the Apple App Store under our Technoway developer account. This section applies only to that app.
- Automatic guest account — on first launch the app creates a guest account for you automatically (an internal random identifier), so you can order food, book a table and collect loyalty points without signing up. You can add your real name, email address, and phone number later from the Profile page; until you do, the account contains no personal details.
- Orders and reservations — we store the orders you place (menu items, quantities, amounts, and the contact name/phone/address you enter for pickup or delivery) and the table reservations you make. The app takes no payment: orders are paid at the restaurant, and the app never asks for card or banking details.
- Loyalty points — a points balance and an earn/redeem history linked to your account.
- Chat and calls — messages you exchange with the restaurant team through the in-app chat, as described above. Voice/video calls are not recorded.
- Deletion — deleting your account (Profile → Delete account, or see the deletion page below) removes your profile, orders, reservations, loyalty history, and chat messages.
9. สั่งอาหาร (Food Time) marketplace app
สั่งอาหาร (Food Time) is a food-ordering marketplace application connecting customers with independent local food shops in Thailand. The app is developed and operated by General Computer Solution Company Limited ("we"), and is published on Google Play and the Apple App Store under our Technoway developer account. This section applies only to that app.
- Automatic guest account — on first launch the app creates a guest account for you automatically (an internal random identifier), so you can browse shops and order food without signing up. You can add your real name, email address, and phone number later from the Profile page; until you do, the account contains no personal details.
- Orders — we store the orders you place with each shop (menu items, quantities, amounts, and the contact name/phone/address and delivery map pin you enter for pickup or delivery) and the dish ratings you leave.
- Payments go directly to the shop — the app takes no payment and never asks for card or banking details. When a shop has enabled PromptPay, the app shows you that shop's own PromptPay QR code and you pay the shop directly from your banking app; we never receive, hold, or process the money and we do not see your banking information.
- Location — with your permission, your device location is used to show nearby shops first and to place your delivery pin on the map. If you are a shop rider, your live location is shared with the customer only while you have a delivery on the road.
- Shop owners, staff and riders — if you open a shop we store your shop profile (name, description, photos, address and map location, phone, delivery settings, opening hours) and your PromptPay receiving ID, which is shown to customers only inside the payment QR for their order. Shop membership (owner, staff, rider) is linked to your account.
- Chat and calls — messages you exchange with a shop through the in-app chat, as described above. Voice/video calls are not recorded.
- Deletion — deleting your account (Profile → Delete account, or see the deletion page below) removes your profile, orders, dish ratings, chat messages, and any shop membership.
10. Data retention and deletion
Account data is retained while your account is active. You can delete your account at any time from inside the app (Profile → Delete account) or by emailing the contact address below. On deletion we remove your account, monitors, attendance records, chat history, device tokens, and the face-verification similarity score within 30 days. Aires Sentinel event history and tamper photos are additionally deleted automatically after 30 days even while your account stays active.
11. Subscriptions and in-app purchases
This section applies to the Aires apps that offer an optional paid subscription — Aires Monitor Lite, Sidekin, and Aires Attendance Pro. The other Aires apps do not use in-app purchases.
- Payments are processed by the app store you installed from (Apple App Store or Google Play). We never receive or store your card number, bank details, or billing address — those are handled by Apple or Google under their own privacy policies.
- To unlock paid features we process your subscription status (trial, active, or expired), the product you purchased, and the purchase token or receipt. We verify the receipt with Apple or Google and store the resulting entitlement against your account. We do not use this information for advertising.
- Free tiers and trials are time-limited; no payment is taken until a trial converts to a paid subscription. You can manage or cancel your subscription at any time in your app store account — cancelling stops future renewals and access continues until the end of the period you have already paid for.
12. Security
Data is transmitted over HTTPS. Passwords are hashed using industry-standard algorithms (bcrypt). Push tokens are stored encrypted at rest. Sensitive identifiers such as phone numbers are stored in encrypted form where possible.
13. Your rights
You may at any time request a copy of the data we hold about you, request correction of inaccurate data, or request deletion. Send requests to the contact email below.
14. Children
The Service is not directed at children under 13 and we do not knowingly collect data from them.
15. Changes
We may update this Policy from time to time. Material changes will be announced via email or an in-app banner before they take effect.
16. Contact
General Computer Solution Company Limited
Email: support@aires.club