Legal
Privacy Policy
Effective September 30, 2026 Operated by Frontier Global Technologies, Inc.
Summary
- Alto Inspect is operated by Frontier Global Technologies, Inc. ("FGT", "we", "us").
- We collect what the service needs to work: account details, the properties and inspections your team records (addresses, photos, grades, comments and signatures), and the details you give us when you ask for a demo.
- Your organisation (our customer) controls the inspection records it creates. We process them on its behalf and only to provide the service.
- We send marketing only to people who expressly opt in.
- We do not sell personal data. We do not use advertising, analytics or tracking tools on altoinspect.com or in the iOS app.
- You can ask to access, correct or delete your data, or withdraw consent, by writing to [email protected].
1. Who we are and what this policy covers
Frontier Global Technologies, Inc. is a company organised under the laws of the State of Texas, United States, with its address at PO Box 450948, Laredo, Texas 78045, United States. We own and operate Alto Inspect, which includes:
- the website at altoinspect.com (including the demo-request form);
- the web dashboard that team administrators use;
- the Alto Inspect iOS app used by inspectors; and
- tenant self-inspection links that a team can send to a tenant.
This policy explains how we handle personal data in all of these. It is also our privacy notice (aviso de privacidad) for people in Mexico. A Spanish version, structured as an Aviso de Privacidad Integral, is available on this site; if the two versions differ, the Spanish version applies to people in Mexico. Wherever we collect data — the demo form, sign-in and invitation acceptance, and tenant links — we show a short notice that links to this policy.
Our two roles
- We decide how data is used (controller / responsable) for: website visitors, demo requests, the account details of our customers' users, billing and support contacts, and security logs.
- We process data for our customer (processor / encargado) for: properties, inspections, photos, comments, signatures, tenant names and email addresses, and the reports made from them ("Customer Data"). The property manager, brokerage or landlord that uses Alto Inspect decides why this data is collected and is responsible for giving its own privacy notice to tenants and other people it records. Our obligations as processor are set out in our Data Processing Addendum. If you are a tenant, please contact the company that inspected your property first; we will help it answer your request.
Tenants and self-inspection links
Each customer can record the address of its own privacy notice in Alto Inspect. When a tenant receives a self-inspection link, the email and the link page show who is carrying out the inspection and, if the customer has recorded one, a link to the customer's privacy notice. The customer remains responsible for giving tenants its notice before photographing them or their home, collecting signatures or sending a link.
2. The personal data we collect
2.1 Demo requests (website)
When you ask for a demo we collect your name, company, work email address, number of units you manage, your preferred time slot and, if you tick the box, your agreement to receive marketing. The form sends these details by email to our sales inbox. We do not store them in the Alto Inspect database. To stop abuse of the form, we keep a short-lived counter keyed to your IP address for up to one hour.
2.2 Accounts and teams
- Name, email address, password (stored only as a one-way hash), preferred language, and the teams you belong to and your role in each (administrator or editor).
- If you turn on two-factor authentication: the encrypted two-factor secret and recovery codes.
- Team invitations: the invited person's email address and role.
2.3 Billing and support
- Billing: billing contact name and details, company, the tax details needed to issue invoices (for example RFC, tax regime and tax address when we invoice in Mexico), payment status and transaction or reference IDs. When card payments are enabled, the payment provider will process card details directly; we will not store full card numbers or security codes (CVV).
- Support: the emails, messages, screenshots and files you choose to send us when you ask for help.
2.4 Customer Data (inspection records)
- Properties: address, optional name, notes, and the rooms and features of the property.
- Inspections: type, dates, status, the inspector assigned, condition grades and written comments.
- Photos: pictures taken with the app, chosen from your photo library or uploaded in the web dashboard. Photos show rooms and features, but they can also show people, personal belongings or documents if these are in the frame. When a photo is uploaded, we remove the metadata embedded in the file, such as GPS location.
- Signatures: an image of a handwritten signature drawn on the device, the name of the signee and the time of signing. For signatures given through a tenant link we also record the IP address and browser user agent at the time of signing.
- Tenant self-inspection links: the tenant's name, the tenant's email address (optional), when the link was opened and submitted, and the IP address and browser user agent at submission.
- Reports: PDF reports built from the items above, and the email addresses a user enters to send a report.
2.5 Technical data
- Web sessions: your IP address, browser and operating system (user agent) and last activity time.
- iOS app: an access token linked to a random identifier that the app creates for your device. This identifier is not your device's advertising or hardware identifier. The app does not register push-notification tokens and does not collect crash or diagnostic data.
- Server logs: technical records (for example IP address, time, the page requested and error details) that keep the service secure and help us find faults.
2.6 Sensitive personal data
The service is not designed to collect sensitive personal data (for example, data about health, religion, ethnic origin or sexual life), and we do not ask for it. Such data may nevertheless appear incidentally in photos or content a customer chooses to upload — for example medication, documents or religious objects visible in a home. In those cases FGT processes it only as a processor, on the customer's instructions, and the customer is responsible for having a lawful basis and, where required, the express consent the law requires. A handwritten signature image is collected as evidence of agreement; we do not use it to identify people biometrically.
2.7 The iOS app and your device
- Camera and Photos: the app asks for permission to use the camera to photograph inspections and to read your photo library so you can attach existing photos. It uses these only when you take or choose a photo. You can withdraw permission at any time in iOS Settings.
- Data on the device: the app works offline. It keeps the inspections, photos and signatures you capture in its own storage on the device until they sync to our servers. Sign-in tokens are kept in the iOS Keychain.
- No tracking: the app does not contain advertising, analytics or crash-reporting SDKs and does not track you across other companies' apps or websites. If you choose in iOS to share analytics with app developers, Apple may give us anonymous crash reports.
2.8 Cookies and similar technologies
altoinspect.com and the web dashboard use only the cookies needed to make them work:
- Session cookie — keeps you signed in; it expires after 120 minutes of inactivity.
- XSRF-TOKEN — protects forms against cross-site request forgery.
- Remember-me cookie — set only if you tick "Remember me" when you sign in.
locale— remembers whether you chose Spanish or English; it lasts up to one year.
Our network provider, Cloudflare, may set a strictly necessary security cookie to tell people and bots apart. We do not use analytics, advertising cookies, tracking pixels or web beacons, and our web fonts are served from our own servers. Because these cookies are needed for the site to work, we do not ask for separate consent for them; you can block or delete cookies in your browser, but signing in will then not work.
3. How we use personal data
3.1 Primary purposes: needed to provide the service or respond to your request
- To create and manage accounts and teams, sign users in and apply their roles.
- To provide Alto Inspect: store and sync inspections, build PDF reports, send reports and tenant links by email when a user asks, and send team invitations and password-reset emails.
- To answer demo requests and arrange the demo you asked for.
- To provide support, bill customers and manage our contract with them.
- To keep the service secure, prevent abuse (for example, rate limiting), and find and fix faults.
- To comply with the law and to establish, exercise or defend legal claims.
Where processing is needed to perform the legal relationship you have with us or with our customer, or to meet a legal obligation, the exceptions to consent in applicable law apply. Otherwise — for example when you send us a demo request — we process your data on the basis of the consent you give by submitting it after seeing this policy.
3.2 Secondary purposes
We send occasional Alto Inspect news and commercial communications only to people who ticked "I'd like to receive occasional Alto Inspect news and commercial communications" on the demo form. The box is unticked by default: if you leave it unticked, we will not use your data for this. If you ticked it, you can withdraw at any time by writing to [email protected] or by using the unsubscribe link in any such message. Saying no does not affect the services you asked for. We do not use Customer Data for our own marketing, and we do not use it to train machine-learning models.
4. Who we share personal data with
We do not sell or rent personal data. We share it only as follows:
- Your team and your organisation. Inspection records are visible to members of the team that owns them, according to their role.
- People you choose to send data to. When a user emails a report or a tenant link, the recipient gets it.
- Service providers that process data for us (subprocessors), under contract and only on our instructions: hosting, network and security, and PDF report rendering. Our subprocessor list names each one, what it does, the data it handles and where. For example, Browserless opens a report page, including its photos, names and signatures, for the time needed to turn it into a PDF.
- Apple, which distributes the iOS app under its own privacy policy.
- Authorities and advisers, when the law requires it or to protect our rights, and professional advisers under a duty of confidentiality.
- In a merger, acquisition, reorganisation or sale of the business, we may transfer data to the extent permitted by applicable law. Where such a transfer requires your consent, we will ask for it beforehand.
We require every third party that receives personal data from us to protect it at least as well as this policy and applicable law require.
International transfers
Our service providers may store or process data outside the country where you live, including in the United States. When this happens, we use contracts and measures that give the data the same protection as this policy.
5. How long we keep personal data
- User accounts: while the account is active. When a user deletes their account, we delete their profile, credentials, sessions and access tokens. A team's Customer Data is not deleted when an individual user deletes their account; it stays under the customer's control.
- Customer Data: for as long as the customer keeps it in Alto Inspect. Deleted properties and inspections first go to an archive from which the team can restore them; the customer can ask us to delete them permanently. If the team owner deletes the team, we delete its Customer Data from our live systems. When a contract ends, the customer has 30 days to export its data, after which we delete it from our live systems.
- Backups: deleted data leaves our backups through normal rotation within 35 days.
- Links: links to PDF reports expire after 14 days. Tenant self-inspection links expire after 1 to 30 days (7 days by default) or earlier if the team cancels them.
- Web sessions: expire after 120 minutes of inactivity. App sign-in tokens stay valid until you sign out or your access is removed.
- Demo requests: up to 12 months after our last contact, unless you ask us to delete them sooner.
- Marketing opt-in: until you withdraw it.
- Billing records: for as long as tax law requires; in Mexico, five years under article 30 of the Código Fiscal de la Federación.
- Server logs: kept in automatically rotated files with a fixed size limit; the oldest entries are deleted as new ones are written. We use them only to keep the service secure and to find faults.
- Demo-form rate-limit counter: one hour.
We may keep some data longer where the law requires it or to resolve disputes, restricting its use until it is deleted.
6. How we protect personal data
We maintain administrative, technical and physical security measures to protect personal data against damage, loss, alteration, destruction and unauthorised use, access or processing. They include:
- encryption of data in transit (TLS);
- passwords stored as one-way hashes, and two-factor authentication available;
- access controls, so each user sees only their team's data, according to their role;
- signed or single-purpose links to reports and tenant inspections that expire and can be cancelled;
- restricted, authenticated administrative access to our systems.
No system is completely secure. If a security incident significantly affects your rights, we will tell you and, where we act for a customer, the customer, without undue delay.
7. Your rights and choices
You can ask us to:
- Access the personal data we hold about you;
- Rectify it if it is wrong or incomplete;
- Cancel (delete) it;
- Oppose its use for a specific purpose;
- Revoke consent you gave us, or limit how we use or disclose your data.
How to ask. Send an email to [email protected] with your name, a way to reply to you, a copy of an identity document (or proof that you represent the person), a clear description of the data and of what you want us to do, and anything that helps us find the data. We will reply within 20 days and, if your request is valid, act on it within 15 days after our reply. We may extend each period once by the same length when there is good reason. Making a request is free, except for reasonable costs of copies or delivery.
Deleting your account. Signed-in users can delete their user account from the profile page of the web dashboard, or can ask us by email. If you own a team, you must first delete the team or ask us to transfer its ownership to another member — so one person leaving never deletes the company's records on its own. Team administrators can remove members and delete properties and inspections.
Tenants and other people in inspection records. If your data is in an inspection made by one of our customers, send your request to that customer. If you send it to us, we will pass it on and help the customer answer.
If you are in Mexico and you think we have not respected your rights, you can file a complaint with the Secretaría Anticorrupción y Buen Gobierno, the authority responsible for personal-data protection. If you live elsewhere, you may have similar rights under local law, and you can contact us in the same way.
8. Children
Alto Inspect is a business service for adults and is not directed to children. We do not knowingly collect data from children. If a customer records a minor (for example, a tenant's child in a photo), the customer is responsible for having a lawful basis to do so.
9. Changes to this policy
We will publish any change on this page and update the effective date at the top. If a change is important, we will also tell account holders by email or in the service before it takes effect. Where the law requires your consent to a new use, we will ask for it.
10. Contact
Frontier Global Technologies, Inc.
PO Box 450948, Laredo, Texas 78045, United States
Privacy requests: [email protected]
See also our Terms of Service, Data Processing Addendum and subprocessor list.