On this page
1. Current safeguards
Controls differ by feature and can change as we improve the platform. This description is not a claim of SOC 2, ISO 27001, PCI certification for CardCounterPOS, a guaranteed recovery time or a security warranty. A provider’s certification does not automatically certify our entire service. Contractual security commitments are established in the Company agreement.
- Hosted connections use HTTPS. Authentication and server-side checks control access to staff, customer, administration and integration operations.
- Company, package, role, location, session and operational approval requirements are checked by the relevant server workflows. A visible control is not itself authorization to perform its action.
- Sensitive session cookies use HttpOnly and appropriate secure/same-site settings where supported. Sessions, recovery links and scanner-pairing grants expire or can be revoked. A paired phone is limited to its scanner session and cannot commit stock as a staff user.
- Supported provider credentials are handled server-side and protected in storage. Secret keys do not belong in client bundles, screenshots, public documentation or support messages.
- Financial and stock workflows use permission checks, provider status, audit records, bounded requests and supported idempotency/recovery controls to reduce duplicate or unauthorized actions. Review is still required when an outcome is uncertain.
- The public marketing site is deployed with a limited route boundary and without tenant database or private provider credentials. Public documentation screenshots use sample information.
2. Company and user responsibilities
Use individual staff accounts, appropriate roles and strong private credentials. Remove access for departing staff, protect unlocked computers, keep Windows and browsers updated and review connected-account permissions. Use the available account security options and follow the Company’s own access policy.
Keep downloaded exports, locally captured images and printed receipts secure. Do not store secrets or unnecessary sensitive customer information in notes or uploads. Only use approved app downloads, equipment and provider setup flows. Contact support promptly when access, credentials or transaction status appears compromised.
3. Report a vulnerability or suspected incident
Open Contact support on the staff sign-in page; signing in is not required for the form. Choose Something else and use Security report as the subject. Describe the affected public URL or feature, approximate time, your own account context where relevant and a minimal, safe reproduction. Give a reply contact so we can arrange a suitable channel for any sensitive evidence.
Do not include passwords, API keys, live session cookies, customer records or full payment details. Do not access another Company’s information, modify or delete data, interrupt service or continue testing after encountering private information. Stop and report the minimum details needed to explain the concern.
Testing beyond normal use of your own authorized account requires an expressly agreed scope. This page is not blanket authorization for production penetration testing, a legal safe-harbor promise or a bounty program. We assess good-faith reports and coordinate appropriate verification and remediation.
4. Handling concerns and service incidents
We assess the report, contain a confirmed issue where needed and work with the affected Company or provider on recovery. The information available can change during an investigation. We provide notices required by applicable law and any executed Company agreement, and avoid disclosing other customers’ information.
A submitted support request is not a promise of a fixed response time. If you suspect an active compromise, also revoke affected credentials through the appropriate account/provider controls and involve your Company administrator. Follow the supported transaction recovery process for uncertain payments, refunds, stock changes or labels.
Contact CardCounterPOS
CardCounterPOS operates CardCounter. Our business location is Windham, Connecticut, United States.
For a platform question, privacy request, billing request or legal notice, open the staff sign-in page and choose Contact support. You do not need to sign in to open that form. Choose Something else and give your message a clear subject, such as Privacy request, Subscription cancellation or Legal notice. Existing workspace users can also open Support from their workspace.
Provide a reply email, the relevant company or shop, and enough detail to identify the request. Do not send passwords, one-time codes, API keys, full payment card details or unnecessary customer information. We may ask for proportionate proof of identity or company authority before disclosing or changing records.