On this page
1. Roles and scope of processing
The Company is responsible for deciding the purpose and lawful basis of its shop processing and supplying appropriate customer and staff notices. CardCounterPOS processes the Company’s shop personal information to deliver the service on its documented instructions. Our separate controller activities, such as our own billing, website inquiries and security administration, are described in the Privacy policy.
The subject matter is the Company’s use of hosted inventory, sales, buying, customer, storefront, order, event, rewards, reporting and authorized integration features. The duration is the service term and any authorized retention necessary to complete return or deletion, resolve transactions or meet legal requirements. Processing includes collecting, storing, organizing, retrieving, transmitting, reconciling, exporting, restricting and deleting records as the selected features require.
| Processing detail | Scope |
|---|---|
| Individuals | The Company’s staff, customers, event participants, suppliers and other contacts whose details the Company lawfully enters. |
| Information | Contact and account details, role/location permissions, sales and customer activity, delivery details where required, business records and limited technical/audit information. |
| Purpose | Operate the Company’s selected shop workflows, requested connections, authorized support and reliable records. |
| Excluded intended use | Unnecessary health data, government identifiers, biometric identification, full payment credentials in free text and other sensitive information the service does not request. |
2. Instructions and Company responsibilities
The Company’s agreement, selected settings, authorized staff actions and permitted support instructions document its processing requests. We process shop personal information for those requests and the agreed service, rather than using it to build unrelated advertising profiles. If law requires a different processing action, we will notify the Company where legally permitted.
The Company must ensure its instructions are lawful, necessary and within the service’s intended scope. It is responsible for the accuracy of records, staff permissions, privacy notices, any required consent, connected-account authority and the retention decisions it is entitled to make. It must not upload unnecessary sensitive information or instruct us to bypass safeguards.
If we believe an instruction conflicts with applicable data protection requirements or cannot be safely performed within the service, we will raise the concern and work with an authorized Company contact on an appropriate alternative. We may decline a request that would disclose another Company’s records, erase mandatory evidence or require unauthorized provider access.
3. Confidentiality and security measures
Access to shop personal information is limited to authorized service functions, personnel and providers who need it for the agreed work and are subject to appropriate confidentiality obligations. Supported safeguards include encrypted hosted transport, scoped authentication and sessions, role and location authorization, server-side input and permission checks, protected provider-token storage, audit records and controls for retries and financial state.
Security measures are proportionate to the service and can evolve as risks and implementation change. The public Security page describes current controls rather than a certification or guarantee of absolute security. Companies share responsibility for staff access, devices, passwords, local exports, safe uploads and connected-provider configuration.
4. Subprocessors and selected integrations
The Company authorizes the core service providers needed to deliver the agreed service as listed on the provider page, subject to its executed agreement. We use appropriate contractual protections for processors handling Company data on our behalf and remain responsible for their processing obligations as required by the applicable agreement and law.
We keep the public list under review. Where a Company agreement requires advance notice of a new subprocessor or an objection period, we will follow that process and address a reasonable data protection objection with the authorized Company contact. A change to the public list does not replace a required contractual notice or consent.
A provider the Company separately chooses and contracts with, such as a payment processor, marketplace or carrier, can act independently under its own terms. Authorizing such a connection instructs CardCounter to transmit the information needed for that connection; it does not make CardCounter responsible for every independent use by that provider.
5. Rights requests, incidents and assistance
Where reasonably available through the service, we assist the Company with access, correction, restriction, export and deletion requests relating to its shop records. A request received directly from a shop customer is referred to the responsible shop unless law requires another response. We verify authority and avoid releasing information about other people or Companies.
We notify the authorized Company contact without undue delay after becoming aware of a personal data breach affecting the Company’s processed information, with the information reasonably available at that time and updates as the investigation develops. Any stricter deadline in an executed agreement or applicable law controls. A routine error or blocked attack is not automatically a confirmed personal data breach.
We provide reasonable available information needed for the Company’s required security assessment, impact assessment, regulator consultation or processor compliance review. Scope, confidentiality, safe access and any additional work are arranged with the Company. An audit must not expose other customers’ information, production credentials or create unsafe testing.
6. Return, deletion and records that must remain
Before termination, the Company can use available authorized exports and ask support about records not covered by those exports. After the service ends, we handle the Company’s authorized request to return or delete processed personal information, subject to the executed agreement and applicable legal retention requirements.
Deletion can involve removal, de-identification or restricted retention depending on the record. Financial transactions, tax evidence, refund reconciliation, fraud prevention and audit records may need to remain for a lawful purpose. Provider backups and immutable operational evidence can expire through their applicable retention process instead of being immediately erased. We explain relevant limitations to the requesting Company.
Disconnection of a provider, uninstalling the Windows app or closing a staff account is not a request to erase all Company records. The Company should identify the affected dataset and required action. External providers retain their own records under their own agreements.
7. International transfers and special requirements
CardCounterPOS is based in the United States, and authorized providers can process information in countries where they operate. This public page does not promise a specific hosting region, execute standard contractual clauses, appoint a foreign representative or establish a regulated-sector agreement.
If the Company needs EU/UK transfer terms, a particular residency commitment or another specific regulatory arrangement, it must raise that requirement before submitting the relevant data. Required safeguards must be confirmed in the Company and provider agreements. Contact support to discuss the arrangement and available information; do not infer compliance certification from a feature’s availability.
Contact CardCounterPOS
CardCounterPOS operates CardCounter. Our business location is Windham, Connecticut, United States.
For a platform question, privacy request, billing request or legal notice, open the staff sign-in page and choose Contact support. You do not need to sign in to open that form. Choose Something else and give your message a clear subject, such as Privacy request, Subscription cancellation or Legal notice. Existing workspace users can also open Support from their workspace.
Provide a reply email, the relevant company or shop, and enough detail to identify the request. Do not send passwords, one-time codes, API keys, full payment card details or unnecessary customer information. We may ask for proportionate proof of identity or company authority before disclosing or changing records.