Skip to policy
How it worksDevelopersHelpGuidesCompareSign in
Sign in
Home/Legal & trust/Privacy policy
CARDCOUNTERPOS POLICIES

Privacy policy

This policy explains how CardCounterPOS handles personal information across the public website, company workspaces, Windows app, support, bookings and connected services. It also explains the different responsibilities of CardCounterPOS and the shops using the platform.

Effective and reviewed October 6, 2026 · Operator: CardCounterPOS
  • Shop records stay under the shop’s instructions
  • Optional website analytics starts after consent
  • Rights requests are available through support
← All policies
On this pageWho is responsible for your informationInformation we collect and its sourcesWhy we use informationCameras, scanning and grading photographsWhen information is disclosedAddress suggestions and shippingeBay and other shop connectionsCookies, device storage and analytics choicesRetention and deletionSecurity and international processingYour privacy rights and requestsChildren and changes to this policyContact CardCounterPOS
On this page
Who is responsible for your informationInformation we collect and its sourcesWhy we use informationCameras, scanning and grading photographsWhen information is disclosedAddress suggestions and shippingeBay and other shop connectionsCookies, device storage and analytics choicesRetention and deletionSecurity and international processingYour privacy rights and requestsChildren and changes to this policyContact CardCounterPOS

1. Who is responsible for your information

CardCounterPOS, located in Windham, Connecticut, United States, operates CardCounter. We determine the purposes of processing our own website inquiries, walkthrough bookings, platform account administration, software billing, security and support records. In privacy laws that use these terms, we act as a controller for those activities.

A shop decides why it collects and uses its customer and business records. We process those records to provide its workspace and requested features, under the shop’s instructions. The shop is normally the controller or business responsible for those records, and we act as its processor or service provider. A payment provider, marketplace or carrier can separately determine how it uses information under its own notice.

If you bought from a shop using CardCounter, its privacy and sales policies also apply. Contact that shop about your purchase, rewards, store credit, event registration or customer profile. You can contact us if you need help identifying the relevant shop or have a concern about CardCounter’s own processing.

Data processing termsService providers

2. Information we collect and its sources

The information depends on the features used and the information a Company or individual supplies. We obtain it directly from you, from authorized Company staff, from a shop’s customers using its public features, from connected providers you authorize and from the devices and systems delivering the service.

2. Information we collect and its sources
CategoryExamples and source
Platform and staff accountsNames, usernames, contact details, role and location permissions, password verifiers, recovery and session records; provided by the account holder or authorized administrator.
Company and billing recordsBusiness and contact details, selected package, licensed locations, approvals, agreements, invoice amounts and status, payment and provider references; supplied by the Company and its billing provider.
Shop operationsInventory, buying and trade records, receipts, returns, store credit, till activity, orders, shipments, events, rewards and audit history; entered by staff, customers or authorized integrations.
Shop customer informationNames, email addresses, telephone numbers, customer numbers, account preferences, purchases, card lists and delivery details where a feature requires them; collected by or for the shop.
Support and booking detailsName, reply email or phone, shop, subject, message, relevant attachments, chosen appointment, time zone and cancellation or rescheduling history; supplied by you and generated by the requested workflow.
Technical informationSession and device information, browser settings, request timestamps, errors, security events and network metadata such as IP addresses available to hosting and service providers.
Optional public-site analyticsPage and visit information, approximate device/browser information, referral information and cookie identifiers when you allow analytics on cardcounterpos.com.
  • Do not submit payment card security codes, passwords, one-time codes, API secrets, government identifiers, health information or other sensitive details in free-text fields or support attachments. Where a protected feature requires a credential, use that feature’s secure entry flow.
  • Information required for a requested service is marked or checked by that flow. If it is missing, we may be unable to create an account, reply to an inquiry, fulfill a booking or perform the requested transaction. Optional analytics is not required to use the website.

3. Why we use information

We use platform account and Company information to deliver the agreed service, verify authorization, manage package and location access, provide software billing and respond to service requests. We process shop records to perform the shop’s requested inventory, sales, buying, customer, website, event, reporting and integration workflows.

We use security and operational information to protect accounts, investigate errors, prevent abuse, keep audit evidence, recover uncertain operations and maintain the service. We use inquiry and booking information to reply, arrange a requested walkthrough and manage its changes. Where a notification is part of a requested account or transaction flow, we use the relevant contact details to deliver it.

Optional website analytics helps us understand which public pages are useful and where visitors encounter problems. The website’s Google tag is blocked until analytics is allowed. We do not use this tag inside staff workspaces or merchant customer websites, and we do not send shop customer records, staff usernames, payment details or uploaded card photographs as analytics events.

Where a law requires a legal basis, our own processing relies on performing a contract or taking requested pre-contract steps, complying with legal obligations, or legitimate interests in operating and protecting the service and responding to business inquiries. Optional analytics relies on your consent. You may object to processing based on legitimate interests, and you may withdraw analytics consent at any time. A shop determines the basis for processing its own customer records.

4. Cameras, scanning and grading photographs

Camera permission is requested by your browser or device when you start the scanner. Continuous card recognition processes camera frames and optical character recognition locally in the device. It sends extracted card details and recognition cues to the authorized catalog or market lookup service, rather than sending the continuous video or captured card photo.

Captured comparison photos and grading photos used for local inspection remain in browser memory for that inspection. They are not part of the durable shared scanner queue and are not automatically uploaded to the computer or stored in the shop database. Leaving the inspection page clears its local images. A phone’s extracted match results can be shared with its paired shop computer for staff review.

A file deliberately uploaded as shop media, a listing image or a support attachment follows that feature’s upload and retention rules instead. If you export a local grading image or report, the exported file is under your control. Keep unrelated people, addresses and documents outside the camera frame and remove unnecessary information before an upload.

Recognition and grading estimates do not automatically make legal or similarly significant decisions about an individual. Staff review is required for stock and trading decisions. A grade estimate is not biometric identification or professional card certification.

Scanning and grading help

5. When information is disclosed

Authorized Company users can access records according to their roles and location permissions. Public shop content becomes visible when the shop publishes it. Information needed for the service is handled by providers for hosting, databases, email delivery, support operations and other enabled infrastructure. The provider list explains their roles.

When a Company connects a payment, storefront, marketplace, address or shipping service, the information needed for that connection is sent to its authorized provider. Payment entry is handled by the relevant payment provider; CardCounter retains transaction amounts, status and provider references needed for reconciliation. We do not ask you to send a full payment card number in support.

We may disclose information when required by law or lawful process, to protect people and the service, or to establish or defend legal claims. We assess requests and disclose only the information reasonably needed. A merger, acquisition or business transfer may involve relevant records, subject to this policy, confidentiality and any notice or rights required by law.

We do not sell shop customer lists or use shop records for cross-context behavioral advertising. Our public website does not enable advertising storage, Google signals or personalized advertising through its analytics tag. Optional analytics still involves disclosure to Google when allowed, so visitors can reject it. We do not combine different shops’ customer records to create advertising profiles.

Provider and subprocessor listCookie policy and choices

6. Address suggestions and shipping

When you request address suggestions through Google, the address text, country selection and a random session token are sent to Google. Selecting a suggestion requests its address details; it does not itself save the shop settings. You can enter an address manually to avoid a suggestion request. CardCounter does not retain unselected suggestions or provider coordinates as business settings. The address you deliberately save is retained with the relevant shop record.

An alternate OpenStreetMap/Photon suggestion provider, where selected by a deployment, receives the typed address and country selection for that request. Provider availability and attribution are shown in the address flow. These providers have their own terms and privacy practices.

Where an authorized shipping workflow is enabled, the seller’s chosen provider receives the sender, recipient, parcel and service information necessary for rates, labels, tracking and related carrier operations. The seller’s account funds postage. A buyer may pay the seller a delivery charge, or the seller may offer free shipping and absorb the postage. Those payment choices do not remove the delivery information needed by the carrier.

Google privacy policy (opens a new tab)Google Maps terms (opens a new tab)OpenStreetMap privacy policy (opens a new tab)USPS privacy policy (opens a new tab)

7. eBay and other shop connections

When a seller authorizes eBay, CardCounter stores the authorized seller ID or username, encrypted access and refresh tokens, selected marketplace, inventory location and seller shipping, payment and return policy selections. The seller chooses the inventory and listing information sent to eBay, including approved public product images.

The current eBay order import stores listing and order identifiers, status, quantities, totals and timestamps needed for stock and sales reconciliation. It does not import or store buyer names, addresses, email addresses or payment instruments through that order-import feature. Buyer shipping and buyer refunds for those eBay orders remain in eBay. This distinction is specific to the current eBay import; an enabled direct shop-shipping feature can require recipient details as described above.

An authorized eBay account deletion notification removes its tokens, displayed identity, setup and connection bindings, and replaces retained account identifiers with non-identifying values. Minimal transaction and stock evidence and a hashed deletion marker can remain to prevent duplicate processing and preserve required records. CardCounter does not use eBay customer information to build advertising profiles.

Other enabled providers, such as Stripe and Shopify, receive information necessary for their selected payment, catalog or order feature. Their own account, privacy and retention terms also apply. Disconnecting a connection does not automatically delete a legally required receipt or a provider’s own records.

eBay privacy notice (opens a new tab)Connected service providers

8. Cookies, device storage and analytics choices

Essential session cookies support sign-in, recovery, paired scanner access and requested transactions. Browser storage also holds display preferences and limited work drafts where a feature supports them. These do not make the Windows app or POS an offline transaction service. Clearing device storage can discard preferences and unfinished local work, but it does not erase saved shop records.

The public website stores your cookie choice for up to 180 days. Analytics is off until you allow it. Reject optional cookies or open Cookie preferences in the footer to change your choice. Withdrawing consent disables subsequent analytics collection in that page and removes accessible first-party Google Analytics cookies; it does not recall data already transmitted. A Global Privacy Control signal keeps optional analytics off, including when an earlier browser choice allowed it.

Our preference applies to this public website and browser, not to an independent provider website or a shop’s own privacy decisions. If storage is blocked, the choice can apply to the current visit without being remembered for the next visit. The Cookie policy lists the categories and limits of these controls.

Cookie policy

9. Retention and deletion

We retain information for the time needed to provide the requested service and resolve operational, contractual, security and legal requirements. There is no single retention period for all records. We consider whether a Company still uses the feature, whether a request or dispute remains open, the sensitivity of the information, applicable financial or tax record requirements, fraud prevention and whether a less identifying record can meet the purpose.

Operational shop records are maintained while needed for the Company’s service and its recordkeeping obligations. Billing, receipt, stock, refund and audit evidence can need to remain after a connection or subscription ends. Support and booking records are retained as needed to deliver the request, resolve issues and document its handling. Security logs and provider backups have separate operational retention; deletion from a live record does not mean instant removal from every retained backup.

Access and recovery tokens expire or are revoked by their workflows. Locally held scanner and grading images clear when their page is left. Public cookie-choice storage expires after 180 days, and optional first-party analytics cookies are configured with a lifetime of up to 180 days, subject to browser behavior and earlier withdrawal.

An authorized deletion request is reviewed for the relevant records and legal exceptions. We can remove, anonymize or restrict information where appropriate and explain records that need to remain. We do not promise automatic deletion of every financial transaction when a staff account, customer profile, provider connection or app installation is removed.

10. Security and international processing

We use access permissions, scoped sessions, secure hosted connections, server-side controls and protected storage for supported provider credentials. No system can guarantee absolute security. Companies must keep credentials private, revoke departed staff access and use appropriate device and network protections. Our Security page explains current safeguards and how to report a concern.

CardCounterPOS is based in the United States. Information can be processed in the United States and other countries where our authorized service providers operate; this service is not presented as an EU-only or UK-only hosting product. Provider locations and transfer terms depend on the service and Company agreement. A public policy does not itself execute standard contractual clauses or establish a required transfer arrangement.

Where an applicable law requires a particular international-transfer safeguard, it must be addressed in the relevant provider and Company agreements before that processing is used. Contact us to discuss the applicable processing arrangement and obtain information about its safeguards. Do not assume a data-residency or regulatory certification commitment that is not in your agreement.

Security informationData processing terms

11. Your privacy rights and requests

Depending on your location, the law’s scope and the relevant processing, you may have rights to access or obtain a copy of personal information, correct it, request deletion, restrict processing, object to processing or receive portable information. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing. We will not penalize you for exercising a right provided by applicable law.

For shop customer records, contact the shop first because it decides how those records are used. For our own account, website, booking, billing or support records, use the support form with a Privacy request subject. Identify the records and the action you are requesting without sending unnecessary sensitive information. An authorized agent can use the same route; we may verify the agent’s authority and the individual’s identity. We respond within the period required by the applicable law and explain any permitted extension or refusal.

California residents may have rights to know, delete, correct, opt out of sale or sharing, and limit certain uses of sensitive information when the CCPA applies. We do not sell shop customer lists or enable cross-context advertising in the public-site tag; rejecting analytics and Global Privacy Control also keep optional analytics off. The same support route is available for other requests.

Where a state law provides an appeal, reply through the support conversation with Privacy appeal and explain the decision you contest. You may also contact your applicable regulator. Individuals with EU or UK rights can complain to their competent supervisory authority; in the UK, this is the Information Commissioner’s Office. A request may have lawful exceptions, including necessary financial records, security evidence and information about another person.

California privacy rights information (opens a new tab)Connecticut privacy rights information (opens a new tab)UK Information Commissioner’s Office (opens a new tab)

12. Children and changes to this policy

The business platform and Company accounts are intended for adults. We do not knowingly collect personal information directly from children under 13 for our own public website or platform accounts. A shop is responsible for appropriate consent and notices when it runs an event or other customer activity involving minors. Tell us through support if you believe a child’s information was collected inappropriately, so we can review the issue with the responsible shop.

We publish a review date when this policy changes. For a material change in how we use personal information, we will provide appropriate notice and obtain any consent required by law before the change applies. An update to this page does not by itself authorize an incompatible new use of previously collected information.

Contact CardCounterPOS

CardCounterPOS operates CardCounter. Our business location is Windham, Connecticut, United States.

For a platform question, privacy request, billing request or legal notice, open the staff sign-in page and choose Contact support. You do not need to sign in to open that form. Choose Something else and give your message a clear subject, such as Privacy request, Subscription cancellation or Legal notice. Existing workspace users can also open Support from their workspace.

Provide a reply email, the relevant company or shop, and enough detail to identify the request. Do not send passwords, one-time codes, API keys, full payment card details or unnecessary customer information. We may ask for proportionate proof of identity or company authority before disclosing or changing records.

Open the support form on the staff sign-in pageHow to contact support

Related policies

Terms of serviceCookie policyBilling, cancellation & refundsAcceptable use policyData processing termsService providers & subprocessorsSecurity & vulnerability reportingAccessibility statement

Card shop POS, inventory
and collection buying.

Platform

InventoryPoint of saleCollection buying

Your shop

CustomersReportingPurchasing

Compare card shop POS

All comparisonsCardCounter vs BinderPOSCardCounter vs SquareCardCounter vs Shopify POSCard shop POS buying guide

Resources & help

DocumentationGetting startedTroubleshootingShop guidesWhat’s newDevelopersMarket API reference QuestionsClient onboardingSign in
Legal & trustTerms of servicePrivacy policyCookie policyBilling, cancellation & refundsAcceptable use policyData processing termsService providers & subprocessorsSecurity & vulnerability reportingAccessibility statement
© 2026 CardCounterPOS

Pokémon artwork © Pokémon / Nintendo / Creatures / GAME FREAK. Images via TCGdex.
CardCounter POS is independent and is not affiliated with Pokémon.

PRIVACY CONTROLS

Cookie preferences

Optional analytics is off until you allow it. You can change your choice here at any time.

Cookie policyPrivacy policy