Legal
Privacy Policy
This Privacy Policy explains what personal data KounterPe processes, why, with whom, for how long, and how you can exercise rights. It is limited to what the production Service actually does today. We do not claim ISO 27001, SOC 2, PCI DSS, GDPR certification, or a US “sale of data” programme, because we do not operate those certificates or programmes.
Controller contact. Trading name: KounterPe. Privacy and grievance email: contact@kounterpe.com. Registered company name and CIN are not published on this page; the operator is the person or entity running this Service at the email above (same rule as in the Terms). Address: Shastri Nagar, Kadma – 831005, Jamshedpur, Jharkhand, India.
Grievance Officer — contact@kounterpe.com. Under the SPDI Rules, 2011, Rule 5(9), a body corporate must publish the name and details of a Grievance Officer. Until a named natural person is published here, grievances sent to this email are the designated channel and will be handled by the operator’s grievance function.
1. Scope and who this Policy covers
This Policy applies to:
- visitors of the public marketing website (this portal);
- account holders and staff who sign in to the POS / application;
- personal data of your end-customers that you type or scan into the Service (we process that as your processor — section 2).
It does not apply to websites or apps we do not operate, or to a payment aggregator’s own collection of card or UPI credentials on their hosted checkout.
2. Roles: Fiduciary and Processor
| Dataset | You | KounterPe |
|---|---|---|
| Owner login, tenant name, invoice profile you save, security logs of your login | — | Data Fiduciary (we decide why this account data is processed) |
| Staff name, email, role, location access | Data Fiduciary (you invite staff) | Data Processor, and Data Fiduciary for the login credential we issue |
| Your customers’ name, phone, optional email, notes, visit and spend totals | Data Fiduciary | Data Processor on your instructions (the product features) |
| Card PAN / CVV / UPI VPA at checkout | Your customer relationship | Not collected by us. Collected by the payment provider if you enable live UPI/card |
Where you are Data Fiduciary, you must have a lawful ground to give us the data (consent or another ground the law allows). We will not use processor data for our own marketing.
Legal sourceDigital Personal Data Protection Act, 2023, section 2(i) “Data Fiduciary”, section 2(k) “Data Processor”, section 8 (processor on behalf of a Fiduciary). Until DPDP operational duties fully commence, the same split is how we treat SPDI Rules duties: you are the body corporate collecting your customers’ SPDI; we provide the platform.
3. Laws that apply — and laws we do not claim
3.1 India (primary)
Privacy is a fundamental right under Article 21 of the Constitution of India, as held in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1. That judgment is not a licensing regime; it is the constitutional baseline. Statutory rules we follow or prepare for:
- Now: Information Technology Act, 2000, section 43A, and the SPDI Rules, 2011, for sensitive personal data we handle (passwords as SPDI; we do not hold card PAN). Section 43A remains in force until DPDP Act section 44(2) commences (Gazette phased timetable: that omission is in the 18-month tranche from 13 November 2025, i.e. 13 May 2027 unless changed).
- DPDP Act, 2023 and DPDP Rules, 2025 (notified 13 November 2025, G.S.R. 846(E)): institutional provisions are in force; Consent Manager related provisions are scheduled 12 months after notification (13 November 2026); most operational rules (consent notices, reasonable security as specified, Data Principal rights procedures, grievance timelines as specified) are scheduled 18 months after notification (13 May 2027). We design this Policy to be usable under SPDI now and under DPDP when those duties apply to us. We do not claim that every DPDP operational duty has already commenced, and we do not claim we have been notified as a Significant Data Fiduciary (DPDP Act section 10). If we are later so notified, we will publish the extra duties (DPO, audit, DPIA as required).
- CERT-In Directions dated 28 April 2022 on ICT logs and incident reporting, as they apply to service providers / body corporates.
3.2 European Union and United Kingdom
We do not claim GDPR or UK GDPR compliance as a general badge. We have not appointed an Article 27 (EU) or UK representative. We do not offer Standard Contractual Clauses off the shelf. You must not upload EEA/UK personal data unless the Terms section 22 is satisfied. If GDPR applies to us by its own extra-territorial rules (GDPR Article 3) despite that, we will still handle a Data Principal request sent to contact@kounterpe.com in good faith, but the absence of an Article 27 representative and of SCCs is a limitation we disclose rather than hide.
3.3 United States
We do not claim CCPA/CPRA “business” status for every dataset. If CCPA applies to data you store about California residents, we treat that data as a service provider as set out in the Terms and in section 16 below. We do not sell personal information as “sale” is defined in Cal. Civ. Code § 1798.140. We do not claim HIPAA applicability; do not store protected health information in the Service.
Legal sourceConstitution of India, Article 21; Puttaswamy (2017) 10 SCC 1. IT Act, 2000, s.43A; SPDI Rules, 2011. DPDP Act, 2023; DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025). CERT-In Directions, 28 April 2022. GDPR (EU) 2016/679; UK GDPR; Cal. Civ. Code § 1798.100 et seq.
4. Personal data we collect
4.1 Data you give us (account)
- Business / tenant name, optional slug, first location name and code;
- Owner name, email, password (stored as a hash only);
- Optional invoice profile: legal name, address, city, state, PIN, country (default India), GSTIN, PAN, phone, email, logo, footer text;
- Staff name, email, role, location scope, when you invite them.
4.2 Data you enter about your customers
- Name and phone (required in the product);
- Optional email and notes;
- Derived visit count, lifetime spend, last visit, and identifiers copied onto orders (name, phone) when you attach a customer to a sale;
- Table reservation name, phone, and note, if you use reservations.
4.3 Data created by use of the Service
- Orders, line items, discounts, tax, tenders, refunds, day-close snapshots, expenses, inventory movements, purchase receipts, supplier names and optional phone, kitchen ticket lines;
- Payment session status and provider reference IDs when UPI/card is used through a PSP;
- Login IP address, user-agent, success/failure, and lockout state; admin audit events (retained on a TTL — currently 180 days in the production design);
- Password-reset token hashes (short-lived, currently 1 hour).
4.4 Data we do not collect in the current product
- Card PAN, CVV, expiry, or saved cards;
- Government ID scans, biometrics, health records, or caste/religion;
- Date of birth or age of your customers;
- Marketing pixels, advertising IDs, or third-party analytics SDKs on the POS;
- Prompts or transcripts to a large language model (no LLM is wired into the production POS).
4.5 Marketing website
The public portal is a static marketing site. It does not create a KounterPe account by itself. Server or host logs may record IP address and user-agent as part of ordinary hosting. We do not run a separate marketing-cookie banner because we do not set non-essential marketing cookies on this portal. If that changes, we will update this Policy before setting them.
5. Sensitive personal data (India, current)
Under SPDI Rules, 2011, Rule 3, “sensitive personal data or information” includes passwords, financial information such as bank account or credit card details, physical/mental health, sexual orientation, medical records, and biometrics.
Of that list, we handle passwords (as hashes) for accounts. We do not handle card or bank account numbers. If you type financial or health details into a free-text note, that is your collection as Data Fiduciary; the product is not designed for that, and you must not do it.
SPDI Rule 5 requires consent for collection of SPDI, a privacy policy, and purpose limitation. Your tick at registration is consent for account SPDI (the password) and for the processing described here. You may withdraw consent by closing the account, subject to data we must keep by law. Withdrawal does not undo processing already completed.
Legal sourceSPDI Rules, 2011, Rules 3, 5, 6 and 8. DPDP Act, 2023 does not use the same “sensitive” list; it regulates digital personal data generally, with extra rules for children (section 9). When DPDP operational provisions apply, this section continues as a description of what we store, and DPDP duties overlay it.
6. Purpose and lawful ground
| Purpose | Ground (India) |
|---|---|
| Create and secure your account, reset password, prevent abuse | Consent at registration; legitimate use to provide the service you requested (DPDP Act section 7, when applicable — “specified purpose” / uses related to the provision of the service) |
| Run POS, stock, tickets, reports for your tenant | Performance of the contract (Terms); as processor, your instruction |
| Send password-reset email only | Contract / consent. We do not send marketing email today |
| Optional CAPTCHA (Cloudflare Turnstile if enabled) | Security of the Service |
| Optional Razorpay payment session | Contract to take payment for your sale; PSP processes payment credentials under its policy |
| Security logs, lockouts, CERT-In-related records | Legal obligation and security (IT Act; CERT-In Directions) |
We do not use personal data for selling, for cross-context ads, or for training a public AI model.
Legal sourceSPDI Rules, 2011, Rule 5 (purpose). DPDP Act, 2023, sections 4–8 (consent and certain legitimate uses) when those sections apply to the processing. We do not rely on a US “legitimate interest balancing test” as a substitute for Indian law.
7. Cookies and device storage
Essential cookies set by the application API (not by this marketing portal):
kp_access— short-lived HTTP-only session cookie;kp_refresh— HTTP-only refresh cookie (longer if you choose “remember me”).
Device storage in the POS browser (localStorage / sessionStorage), used to operate the counter:
- profile without JWTs (
kp_pos_session); - remember-me flag, workspace, receipt paper size, print mode;
- open ticket draft (may include customer name/phone);
- offline cash outbox; short product cache; kitchen sound preference.
These are strictly necessary for a logged-in POS. The marketing portal does not set those cookies. There is no third-party advertising cookie in the current product. If we add non-essential cookies, we will obtain any consent Indian law then requires before setting them.
Legal sourceSPDI Rules, 2011 (information in a privacy policy). DPDP Rules, 2025, when the notice/consent rules that apply to cookies as personal data commence. EU ePrivacy / GDPR cookie consent is not implemented as an EU-style banner because we do not currently target the EEA; if we later do, we will add that consent mechanism before non-essential cookies.
8. Sharing and sub-processors
We share personal data only as follows:
- Razorpay — amount, order/payment-link identifiers, and whatever their checkout collects directly from the payer, when live UPI/card is enabled. Their privacy policy governs credentials they collect.
- Email provider (Resend or your configured SMTP) — recipient email, name, and reset link, for password reset only.
- Cloudflare — if Turnstile CAPTCHA is enabled, their widget processes what Cloudflare states in its CAPTCHA documentation (typically a token and anti-abuse signals).
- Hosting / database / optional queue — infrastructure that stores tenant databases. We do not publish a public list of cloud regions in the application; ask contact@kounterpe.com if you need the then-current hosting location for a data-protection impact assessment you are doing.
- Law enforcement or regulator — when required by Indian law, a competent court, CERT-In, or the Data Protection Board of India, or to protect persons from serious harm.
- Successor — if the operator of the Service is transferred, under the same purposes, with notice where required.
We do not sell personal data. Staff of a tenant see data according to role and location permissions you set.
Legal sourceSPDI Rules, 2011, Rule 6 (disclosure). DPDP Act, 2023, section 8 (processor). We do not treat a PSP as “our” sale of data.
9. Storage location and cross-border
The Service is designed for businesses in India (INR, GSTIN, UPI). Infrastructure may be located in India or in another country depending on how a particular deployment is hosted. DPDP Act, 2023, section 16 allows transfer of personal data outside India except to a country or territory restricted by the Central Government. We will not transfer personal data to a country that is on such a restricted list once that list is notified and applies to us.
SPDI Rules, 2011, Rule 7 (transfer of SPDI) requires the recipient to ensure the same level of protection. Password hashes and security logs will only be processed on systems we control or on processors under contract. We do not currently use EU Standard Contractual Clauses; see section 16 and the Terms before placing EEA/UK data in the Service.
Legal sourceDPDP Act, 2023, section 16. SPDI Rules, 2011, Rule 7. GDPR Chapter V (Articles 44–49) — not claimed as implemented unless a signed transfer tool exists.
10. Retention
- Account and tenant business records: for as long as the account is open, then as long as we must keep them for disputes, tax on any fees we charged you, or other law;
- Password-reset records: until used or expired (designed as 1 hour), then TTL deletion;
- Refresh sessions: until logout, expiry, or password reset (designed with expiry on the order of 30 days if you chose remember-me);
- Auth audit events: designed 180-day TTL, aligned with CERT-In’s rolling 180-day ICT log direction for covered entities;
- Payment sessions: short-lived (designed 20 minutes) plus whatever the PSP retains under its policy;
- Device-local ticket drafts and offline queues: until you clear them, the browser storage is cleared, or they sync.
When you ask us to erase processor data, we will erase or anonymise it unless a law requires keeping a copy (for example an ongoing investigation, or CERT-In logs still in the 180-day window).
Legal sourceCERT-In Directions, 28 April 2022 (180-day logs). DPDP Act, 2023, section 8(7) (erase when purpose ended, when applicable). SPDI Rules, 2011, Rule 5(4) (not retain longer than required). We do not claim a GST “books of account” retention on your behalf; those books are yours.
11. Security
We use reasonable security practices for the nature of the data: password hashing, HTTP-only cookies, tenant isolation in the application design, transport encryption when the deployment is served over HTTPS, login lockout, and role-based permissions. SPDI Rules, 2011, Rule 8 treats IS/ISO/IEC 27001 as a deemed standard. We do not claim that we are ISO 27001 certified. Reasonable security is an ongoing duty, not a guarantee that a determined attacker will always fail.
You must control devices at the counter, staff access, and who can open the browser profile that holds offline drafts.
If we become aware of a personal-data breach that Indian law requires us to report (including CERT-In incident types, and DPDP Act section 8 read with the DPDP Rules when those breach-notice rules apply), we will notify the authority as required and notify affected account holders where the law or a serious risk to them requires it.
Legal sourceIT Act, 2000, section 43A; SPDI Rules, 2011, Rule 8. DPDP Act, 2023, section 8 (safeguards and breach intimation) when in force for that duty. CERT-In Directions, 28 April 2022 (six-hour reporting for specified incidents, as that Direction states).
12. Your rights and how to use them
Write to contact@kounterpe.com from the owner email on the account, or with enough detail for us to verify you. We may refuse a request that is manifestly unfounded, that would harm another person’s rights, or that we are legally forbidden to fulfil.
12.1 Under SPDI Rules, 2011 (in force for SPDI we hold)
You may review the SPDI we hold about you as the account holder and request correction of inaccuracies (Rule 5). You may withdraw consent for further processing of that SPDI, which in practice means closing the account (Rule 5(7)). Grievances: Rule 5(9) — we will address them within one month of receipt.
12.2 Under the DPDP Act, 2023 (when the relevant provisions apply)
Data Principals have rights of access, correction, completion, updating, erasure, grievance redressal, and nomination (DPDP Act, sections 11–14, as commenced). DPDP Rules, 2025, when Rule 14 and related operational rules apply, set a grievance outer bound of 90 days. Until those rules apply, we still use the one-month SPDI grievance period for SPDI, and we will not take longer than 90 days for other verified account-holder requests without explaining why.
12.3 Your customers
If a person whose data you stored (a diner, a walk-in customer) wants access or erasure, they should ask you first. You can edit or remove customer records in the Service according to the product’s features. If they write to us, we will redirect them to you unless we are required to handle it ourselves. We will not delete your entire tenant because one of your customers asked us.
Legal sourceSPDI Rules, 2011, Rule 5. DPDP Act, 2023, sections 11–14; DPDP Rules, 2025, Rule 14 (grievance; 90 days when that rule is in force).
13. Children
The Service is not directed at children. You must be 18 or older to open an account. DPDP Act, 2023, section 2(f) defines a child as under 18 years. Section 9 (when applicable) requires verifiable parental consent and restricts tracking/ads directed at children. The POS has no age field. You must not use customer records to build a profile of a child. If you nevertheless store a child’s data, you are the Data Fiduciary and must comply with section 9; we are not designed for that processing and you must not do it unless you can comply.
Legal sourceDPDP Act, 2023, sections 2(f) and 9; DPDP Rules, 2025, rules on verifiable consent for children, when those rules apply.
14. Automated decisions and AI
The current production POS does not send your data to an LLM and does not make solely automated legal or similarly significant decisions about a Data Principal. Reports are totals and rankings of sales you recorded. Marketing mentions of an AI assistant are not a present processing activity. If that changes, this Policy will be updated first, and we will not silently use account or customer data to train a general public model.
Legal sourceDPDP Act, 2023, does not copy GDPR Article 22 verbatim. GDPR Article 22 is cited only for EEA/UK data, which you must not upload unless Terms section 22 is met. Significant Data Fiduciary algorithmic diligence (DPDP Rules, 2025, Rule 13) applies only if we are notified as an SDF — we are not claiming that status.
15. Grievance Officer
Grievance Officer
Email: contact@kounterpe.com
Office: Shastri Nagar, Kadma – 831005, Jamshedpur, Jharkhand, India
How to complain: send the owner email, tenant name, what went wrong, and what you want us to do. We will acknowledge and investigate. Timeline: not more than one month for SPDI grievances (SPDI Rule 5(9)); not more than 90 days once DPDP Rules, 2025, Rule 14 applies to us. You may also have a right to approach the Data Protection Board of India when that Board’s complaint process is available for the processing, or an adjudicating officer under the IT Act for matters still under that Act.
Legal sourceSPDI Rules, 2011, Rule 5(9). DPDP Act, 2023, section 13 (right to grievance redressal) and Chapter V (Data Protection Board), as commenced. IT Act, 2000, sections 46–47 (adjudicating officer), where still applicable.
16. California, EU, and UK addendum
This addendum applies only if the named law applies by its own terms. It does not expand our market to those regions. It does not waive the restriction in the Terms on uploading EEA/UK personal data without a signed DPA and transfer tool.
16.1 California (CCPA/CPRA)
We do not sell or share (as defined in Cal. Civ. Code § 1798.140) personal information. We do not use sensitive personal information in the CPRA sense for inferring characteristics. Categories we may process as a service provider if you store California residents’ data: identifiers (name, phone, email), commercial information (purchases), and inferences limited to visit counts the product computes. To make a request that California law gives you as a consumer against us as a business (account holders), email contact@kounterpe.com. For data we hold only as your service provider, we will point the consumer to you. We do not discriminate for exercising CPRA rights. We do not currently offer a financial incentive programme.
16.2 EEA (GDPR) and United Kingdom
Until we appoint a representative and sign transfer clauses with you: do not use the Service as a GDPR processor. If you nonetheless send us a GDPR Article 15–22 request about an account we hold as controller (your login), we will respond as far as Indian law and verification allow. We do not operate a lawful EU/UK transfer programme for tenant customer databases without a further contract.
Legal sourceCal. Civ. Code §§ 1798.100–1798.199.10. GDPR Articles 3, 13–22, 27, 28, 44–49. UK GDPR and Data Protection Act 2018. These citations are disclosure of limits, not a statement that we market into those jurisdictions.
17. Changes
We will post the new version on this page with a new effective date. Material changes that affect an existing account will be notified to the owner email or in the product. If we add a new purpose that Indian law treats as requiring fresh consent, we will ask for that consent before using data for the new purpose.
Related document: Terms of Service. Contact: contact@kounterpe.com.
Sources and references
Official or commonly used public texts. These are not KounterPe documents. Where a rule is phased, the Gazette controls.
- Constitution of India, Article 21.
- Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (Supreme Court of India, privacy as a fundamental right).
- Information Technology Act, 2000, especially sections 43A, 46, 72A and 79 — India Code.
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (G.S.R. 313(E)).
- Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) — PRS / India Code.
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), 13 November 2025 — MeitY / Gazette; Rules 1, 2 and 17–21 on publication; Rule 4 at 12 months; Rules 3, 5–16, 22 and 23 at 18 months, as the Rules themselves state.
- Commencement notification of 13 November 2025 for the DPDP Act (phased; section 44(2) omission of IT Act section 43A in the later tranche). We rely on the Gazette, not on law-firm summaries, as the legal source.
- CERT-In Directions dated 28 April 2022 and CERT-In FAQs / clarifications on those Directions.
- Payment and Settlement Systems Act, 2007; RBI PA/PG guidelines (PSP, not KounterPe, as payment aggregator).
- Regulation (EU) 2016/679 (GDPR), EUR-Lex.
- UK GDPR and Data Protection Act 2018 — legislation.gov.uk.
- California Consumer Privacy Act, as amended by the CPRA, Cal. Civ. Code § 1798.100 et seq.
