Skip to policy
How it worksDevelopersHelpGuidesCompareSign in
Sign in
Home/Legal & trust/Data processing terms
CARDCOUNTERPOS POLICIES

Data processing terms

These terms describe our processing of personal information for a Company using CardCounter. They form part of a Company agreement that incorporates them; a separately executed data processing agreement controls where it specifies different or additional requirements.

Effective and reviewed October 6, 2026 · Operator: CardCounterPOS
  • Company instructions define shop processing
  • Access is limited to the service and authorized support
  • Transfer or special compliance requirements need an appropriate agreement
← All policies
On this pageRoles and scope of processingInstructions and Company responsibilitiesConfidentiality and security measuresSubprocessors and selected integrationsRights requests, incidents and assistanceReturn, deletion and records that must remainInternational transfers and special requirementsContact CardCounterPOS
On this page
Roles and scope of processingInstructions and Company responsibilitiesConfidentiality and security measuresSubprocessors and selected integrationsRights requests, incidents and assistanceReturn, deletion and records that must remainInternational transfers and special requirementsContact CardCounterPOS

1. Roles and scope of processing

The Company is responsible for deciding the purpose and lawful basis of its shop processing and supplying appropriate customer and staff notices. CardCounterPOS processes the Company’s shop personal information to deliver the service on its documented instructions. Our separate controller activities, such as our own billing, website inquiries and security administration, are described in the Privacy policy.

The subject matter is the Company’s use of hosted inventory, sales, buying, customer, storefront, order, event, rewards, reporting and authorized integration features. The duration is the service term and any authorized retention necessary to complete return or deletion, resolve transactions or meet legal requirements. Processing includes collecting, storing, organizing, retrieving, transmitting, reconciling, exporting, restricting and deleting records as the selected features require.

1. Roles and scope of processing
Processing detailScope
IndividualsThe Company’s staff, customers, event participants, suppliers and other contacts whose details the Company lawfully enters.
InformationContact and account details, role/location permissions, sales and customer activity, delivery details where required, business records and limited technical/audit information.
PurposeOperate the Company’s selected shop workflows, requested connections, authorized support and reliable records.
Excluded intended useUnnecessary health data, government identifiers, biometric identification, full payment credentials in free text and other sensitive information the service does not request.

2. Instructions and Company responsibilities

The Company’s agreement, selected settings, authorized staff actions and permitted support instructions document its processing requests. We process shop personal information for those requests and the agreed service, rather than using it to build unrelated advertising profiles. If law requires a different processing action, we will notify the Company where legally permitted.

The Company must ensure its instructions are lawful, necessary and within the service’s intended scope. It is responsible for the accuracy of records, staff permissions, privacy notices, any required consent, connected-account authority and the retention decisions it is entitled to make. It must not upload unnecessary sensitive information or instruct us to bypass safeguards.

If we believe an instruction conflicts with applicable data protection requirements or cannot be safely performed within the service, we will raise the concern and work with an authorized Company contact on an appropriate alternative. We may decline a request that would disclose another Company’s records, erase mandatory evidence or require unauthorized provider access.

3. Confidentiality and security measures

Access to shop personal information is limited to authorized service functions, personnel and providers who need it for the agreed work and are subject to appropriate confidentiality obligations. Supported safeguards include encrypted hosted transport, scoped authentication and sessions, role and location authorization, server-side input and permission checks, protected provider-token storage, audit records and controls for retries and financial state.

Security measures are proportionate to the service and can evolve as risks and implementation change. The public Security page describes current controls rather than a certification or guarantee of absolute security. Companies share responsibility for staff access, devices, passwords, local exports, safe uploads and connected-provider configuration.

Current security safeguards

4. Subprocessors and selected integrations

The Company authorizes the core service providers needed to deliver the agreed service as listed on the provider page, subject to its executed agreement. We use appropriate contractual protections for processors handling Company data on our behalf and remain responsible for their processing obligations as required by the applicable agreement and law.

We keep the public list under review. Where a Company agreement requires advance notice of a new subprocessor or an objection period, we will follow that process and address a reasonable data protection objection with the authorized Company contact. A change to the public list does not replace a required contractual notice or consent.

A provider the Company separately chooses and contracts with, such as a payment processor, marketplace or carrier, can act independently under its own terms. Authorizing such a connection instructs CardCounter to transmit the information needed for that connection; it does not make CardCounter responsible for every independent use by that provider.

Service providers and subprocessors

5. Rights requests, incidents and assistance

Where reasonably available through the service, we assist the Company with access, correction, restriction, export and deletion requests relating to its shop records. A request received directly from a shop customer is referred to the responsible shop unless law requires another response. We verify authority and avoid releasing information about other people or Companies.

We notify the authorized Company contact without undue delay after becoming aware of a personal data breach affecting the Company’s processed information, with the information reasonably available at that time and updates as the investigation develops. Any stricter deadline in an executed agreement or applicable law controls. A routine error or blocked attack is not automatically a confirmed personal data breach.

We provide reasonable available information needed for the Company’s required security assessment, impact assessment, regulator consultation or processor compliance review. Scope, confidentiality, safe access and any additional work are arranged with the Company. An audit must not expose other customers’ information, production credentials or create unsafe testing.

6. Return, deletion and records that must remain

Before termination, the Company can use available authorized exports and ask support about records not covered by those exports. After the service ends, we handle the Company’s authorized request to return or delete processed personal information, subject to the executed agreement and applicable legal retention requirements.

Deletion can involve removal, de-identification or restricted retention depending on the record. Financial transactions, tax evidence, refund reconciliation, fraud prevention and audit records may need to remain for a lawful purpose. Provider backups and immutable operational evidence can expire through their applicable retention process instead of being immediately erased. We explain relevant limitations to the requesting Company.

Disconnection of a provider, uninstalling the Windows app or closing a staff account is not a request to erase all Company records. The Company should identify the affected dataset and required action. External providers retain their own records under their own agreements.

Retention information

7. International transfers and special requirements

CardCounterPOS is based in the United States, and authorized providers can process information in countries where they operate. This public page does not promise a specific hosting region, execute standard contractual clauses, appoint a foreign representative or establish a regulated-sector agreement.

If the Company needs EU/UK transfer terms, a particular residency commitment or another specific regulatory arrangement, it must raise that requirement before submitting the relevant data. Required safeguards must be confirmed in the Company and provider agreements. Contact support to discuss the arrangement and available information; do not infer compliance certification from a feature’s availability.

Contact CardCounterPOS

CardCounterPOS operates CardCounter. Our business location is Windham, Connecticut, United States.

For a platform question, privacy request, billing request or legal notice, open the staff sign-in page and choose Contact support. You do not need to sign in to open that form. Choose Something else and give your message a clear subject, such as Privacy request, Subscription cancellation or Legal notice. Existing workspace users can also open Support from their workspace.

Provide a reply email, the relevant company or shop, and enough detail to identify the request. Do not send passwords, one-time codes, API keys, full payment card details or unnecessary customer information. We may ask for proportionate proof of identity or company authority before disclosing or changing records.

Open the support form on the staff sign-in pageHow to contact support

Related policies

Terms of servicePrivacy policyCookie policyBilling, cancellation & refundsAcceptable use policyService providers & subprocessorsSecurity & vulnerability reportingAccessibility statement

Card shop POS, inventory
and collection buying.

Platform

InventoryPoint of saleCollection buying

Your shop

CustomersReportingPurchasing

Compare card shop POS

All comparisonsCardCounter vs BinderPOSCardCounter vs SquareCardCounter vs Shopify POSCard shop POS buying guide

Resources & help

DocumentationGetting startedTroubleshootingShop guidesWhat’s newDevelopersMarket API reference QuestionsClient onboardingSign in
Legal & trustTerms of servicePrivacy policyCookie policyBilling, cancellation & refundsAcceptable use policyData processing termsService providers & subprocessorsSecurity & vulnerability reportingAccessibility statement
© 2026 CardCounterPOS

Pokémon artwork © Pokémon / Nintendo / Creatures / GAME FREAK. Images via TCGdex.
CardCounter POS is independent and is not affiliated with Pokémon.

PRIVACY CONTROLS

Cookie preferences

Optional analytics is off until you allow it. You can change your choice here at any time.

Cookie policyPrivacy policy