← CounterlyPrivacyTermsCookies
# Counterly Privacy Policy
**Last updated:** July 30, 2026
**Effective date:** July 30, 2026
**Product:** Counterly POS (`counterlypos.com`)
**Operator:** [INSERT REGISTERED LEGAL ENTITY NAME & ADDRESS] (“**Counterly**,” “**we**,” “**us**,” or “**our**”)
**Privacy contact:** [privacy@counterlypos.com](mailto:privacy@counterlypos.com)
This Policy explains how we collect, use, disclose, and protect personal information when you visit our marketing site, create an organization, use Counterly Admin (`app.counterlypos.com`), Counterly POS apps, related APIs (`pos.counterlypos.com`), or (for authorized Counterly operators only) HQ (`hq.counterlypos.com`).
We provide this notice for transparency under frameworks that may apply to merchants and visitors in the **USA, Canada, UK, EU, Australia, and the Middle East**, including **GDPR**, **UK GDPR**, **CCPA/CPRA**, **PIPEDA**, and the **Australian Privacy Principles**, as applicable.
Our [Cookie Policy](/cookies) describes cookies and similar technologies on the marketing site.
---
## 1. Who we are & roles
Counterly is cloud point-of-sale, inventory, and back-office software for retail operators (liquor, convenience, gas, specialty, and similar).
- **Marketing / account data we control:** Website inquiries, trial signup, billing contacts, and product telemetry we process as a business.
- **Store operational data:** Catalog, sales, staff, inventory, and similar records you enter into Counterly are generally processed **on your instructions** as your service provider / processor. Your organization is typically the controller / business for that store data. A Data Processing Addendum (DPA) is available on request for GDPR/UK GDPR processor engagements — see Admin → Legal or email privacy@counterlypos.com.
---
## 2. Information we collect
### 2.1 Account & commercial data
- Name, email, phone, company/store name, role
- Organization and Store Code identifiers
- Billing contact metadata; payment processing via Stripe (we do not store full card PAN)
- Support messages and optional support bundles you submit
### 2.2 Store operations (tenant data)
- Staff identity, roles, PIN hashes (not plaintext PINs beyond authenticated sessions)
- Catalog, inventory, purchases, sales, tenders (non-PAN), shifts, devices
- Age-check / void / manager-override audit events where enabled
- Capability and industry settings you configure
### 2.3 Technical & device data
- IP address, approximate region, browser/app version
- Register/device ids, printer/terminal pairing endpoints (not card PAN)
- Diagnostics and error logs
### 2.4 AI feature data (when you use AI features)
- Content you submit to Smart Assist, AI invoice/import review, or support-draft tools (e.g., CSV rows, prompt text)
- System telemetry (latency, errors, token/usage metrics)
**Default:** We do **not** use your confidential store data to train third-party foundation models, except as needed to operate the feature you requested or where you agree in writing. Provider APIs may process prompts to return results under their terms.
### 2.5 Cardholder data
Counterly does **not** store full payment card numbers (PAN). Card payments run on the merchant’s terminal or guided tender flow. We may store amounts, tender type, auth/reference codes, and optional last4 if returned by the terminal adapter.
---
## 3. How we use information
- Provide, secure, and support the Services
- Authenticate users (including Store Code → PIN / email login)
- Process subscriptions and trials
- Improve reliability and debug incidents
- Send transactional messages; marketing only where permitted (opt out anytime)
- Enforce Terms, prevent abuse, and comply with law
---
## 4. Legal bases (GDPR / UK GDPR)
Where applicable: **contract** (provide the Service); **legitimate interests** (security, product improvement with appropriate safeguards); **consent** (non-essential cookies / certain marketing); **legal obligation** (tax, accounting, lawful requests).
---
## 5. Sharing & subprocessors
We do **not sell** personal information for money. We share data with processors who help us run Counterly, including categories such as:
| Category | Examples (illustrative) |
|----------|-------------------------|
| Cloud & hosting | AWS (API/data), Vercel (Admin/HQ/marketing web) |
| Payments | Stripe |
| Email / transactional messaging | Providers used for receipts and ops email |
| AI inference (optional features) | Cloud AI APIs (e.g., AWS Bedrock) for prompts you submit — not card PAN |
| Analytics on marketing site | See Cookie Policy |
We require processors to protect data and use it only to provide services to us (or to you, when we act as processor).
---
## 6. International transfers
Data may be processed in the **United States** and other countries where we or our processors operate. For EEA/UK personal data, we use appropriate safeguards such as **Standard Contractual Clauses** / **UK Addendum** where required. Contact privacy@counterlypos.com for more detail.
---
## 7. Retention
| Data | Typical retention |
|------|-------------------|
| Marketing inquiries | Up to 24 months after last contact unless a customer relationship continues |
| Billing / contract records | About 7 years (tax/accounting) |
| Store ops / audit (void, age-check) | About **2 years** default (tenant-configurable where offered) |
| Account after cancellation | Export/deletion on request, subject to legal holds; backups wind down on a short cycle |
| Security logs | Generally 90–365 days |
---
## 8. Security
We use administrative and technical measures appropriate to risk, including TLS in transit, encryption at rest on primary cloud stores (AES-256 or cloud equivalent), access controls, and monitoring. No system is perfectly secure. You are responsible for staff access, Store Codes, PINs, and device physical security.
---
## 9. Your rights
Depending on your location, you may request **access, correction, deletion, portability, restriction, or objection**, and withdraw consent where processing is consent-based. Email [privacy@counterlypos.com](mailto:privacy@counterlypos.com). Store owners manage staff accounts inside Admin.
We will not discriminate against you for exercising privacy rights. California residents may also opt out of “sale”/“sharing” for cross-context advertising via cookie controls and by emailing privacy@counterlypos.com with “Do Not Sell or Share.”
---
## 10. Children
Counterly is a B2B product. We do not knowingly collect personal information from children.
---
## 11. Cookies & apps
See the [Cookie Policy](/cookies). Authenticated Admin sessions use HTTP-only cookies. On the Admin Apple WebView shell we may set `Secure; SameSite=None` on HTTPS so login persists. HQ is web-only.
---
## 12. Changes
We will update this page and the “Last updated” date when material changes occur. Continued use after the effective date constitutes acknowledgment of the updated Policy.
---
## 13. Contact
**Privacy:** privacy@counterlypos.com
**Legal:** legal@counterlypos.com
**Support:** support@counterlypos.com
**Postal:** [INSERT REGISTERED LEGAL ENTITY NAME & ADDRESS]
---
*Operator draft for Counterly POS. Have counsel review before relying on this as final regulated language.*