On this page
1. Authorized access and account safety
Use an individual account with the permissions your Company has granted. Do not share credentials, impersonate staff, retain unauthorized access or use a private recovery, support or pairing link belonging to someone else. Keep private links, API keys and provider credentials confidential and revoke them when they are no longer needed.
Do not bypass session locks, Company approval, counter commissioning, package eligibility, paid coverage, location restrictions or provider enrollment. A phone scanner grant authorizes only its scanning session; it is not a general staff account or permission to add inventory. A preview or test environment is not authorization to transact in a live Company.
2. Lawful records and respectful content
Collect and enter only information you are entitled to use for the relevant business purpose. Provide required privacy and sales notices, obtain required permissions and respect customer rights. Do not upload stolen credentials, unnecessary sensitive personal information, malicious files or content that unlawfully violates privacy, copyright or other rights.
Public shop pages, product descriptions, images, card lists, event notices and support messages must not contain unlawful threats, harassment, fraud, exploitation or deceptive claims. Do not use the platform to facilitate prohibited goods, money laundering, sanctions violations or activities forbidden by a connected provider. The Company is responsible for confirming the rules applicable to its products and location.
Do not claim that a CardCounter grading estimate is a professional certificate, fabricate stock condition or sales evidence, or use another shop’s customer information for unsolicited outreach. Respect third-party artwork, catalog licenses, attribution requirements and marketplace policies.
3. Sales, stock and provider actions
Review the seller, location, item, amount, destination and effect of an operation before submitting it. Do not create false purchases, refunds, audit evidence, stock movements, labels or account approvals. Do not change an address, credential or device setup in a way that evades an existing approval requirement.
When an operation is pending or its outcome is uncertain, use its supported status or recovery flow. Repeatedly creating a new request can cause duplicates or inconsistent records. A recoverable draft is not a completed sale. A test payment, test reader or sandbox credential must not be represented as a live financial result.
4. APIs, quotas and system integrity
Use the API only within the authorized Company, key scope, package and published contract. Keep keys server-side where the integration requires it. Apply reasonable request limits, follow retry guidance and protect returned data. Do not rotate identities or keys to evade quotas, scrape restricted records or redistribute licensed catalog or market datasets without permission.
Do not probe another Company’s records, overload the service, send destructive payloads, introduce malware or interfere with requests and background jobs. Do not exploit a vulnerability, attempt unauthorized access or collect private data as part of a security report. Contact us first to agree the scope of testing that goes beyond your own account.
5. Reports, enforcement and review
Report suspected misuse through support with the relevant public URL, approximate time and a concise description. Provide only the minimum evidence needed; do not forward secrets or expose another person’s private records. A rights holder should identify the affected material, their authority, the claimed right and a reply contact so we can assess the concern.
We may investigate reports and restrict an account, key, connection, public content or operation where proportionate to the risk and permitted by the agreement and law. Urgent security or legal containment can occur before notice. Where practical, we will explain the issue and the steps needed for restoration. You may request review through the same support conversation, and mandatory legal rights remain available.
We do not require harmful testing to prove a concern. A good-faith report made within an expressly agreed testing scope is assessed differently from exploitation or abuse. The Security page describes the initial reporting route; it does not grant unrestricted testing permission or promise a bounty.
Contact CardCounterPOS
CardCounterPOS operates CardCounter. Our business location is Windham, Connecticut, United States.
For a platform question, privacy request, billing request or legal notice, open the staff sign-in page and choose Contact support. You do not need to sign in to open that form. Choose Something else and give your message a clear subject, such as Privacy request, Subscription cancellation or Legal notice. Existing workspace users can also open Support from their workspace.
Provide a reply email, the relevant company or shop, and enough detail to identify the request. Do not send passwords, one-time codes, API keys, full payment card details or unnecessary customer information. We may ask for proportionate proof of identity or company authority before disclosing or changing records.