At a glance
Countr is a shop-management product operated by Countr Technologies Pvt. Ltd. This Privacy Policy explains how we collect, use, disclose, retain and protect personal data when you use the Countr website, mobile application, APIs and related services.
This policy is written for Countr's current product model and should be kept aligned with the actual app, backend, analytics, payment, voice-processing and support systems used in production.
1. Scope and our role
This policy applies to personal data processed through Countr's website, mobile application and related services, except where a separate privacy notice is expressly provided.
For personal data for which Countr determines the purpose and means of processing, Countr Technologies Pvt. Ltd. is responsible for complying with applicable data-protection requirements. Where a shopkeeper enters information about customers, suppliers, employees or other persons into Countr, that information may be processed on the shopkeeper's instructions to provide the service.
2. Information we collect
Depending on the features you use, Countr may process the following categories of information:
Account and authentication information
- Name, mobile number, email address or other account identifiers you provide.
- Authentication, account-status and security information.
- Information needed to verify access to your account, such as OTP-related records.
Shop and business information
- Shop name, business type, address and other business details you choose to enter.
- Products, prices, quantities, inventory and stock information.
- Sales, purchases, expenses, payment records and other transaction information.
- Khata entries, customer names, balances, notes and related records that you create.
- Reports, preferences and settings generated through your use of Countr.
Information about other people entered by you
If you use Countr to maintain a customer's or other person's name, phone number, balance, transaction or similar information, that information may constitute personal data. You should only enter information that you are authorised or otherwise permitted to provide for use in the service, and should use Countr in accordance with applicable law.
Voice and audio information
Countr may receive voice input when you use voice features. Depending on the particular implementation, voice input may be converted to text and used to interpret a command such as creating a Khata entry, recording a payment, updating inventory or generating a report.
We will not describe raw audio as permanently stored or immediately deleted unless that is how the production feature actually works. The exact speech-to-text provider, whether raw audio is retained, processing location and retention period must be reflected in the applicable product implementation and vendor documentation.
Device, technical and security information
- Device type, operating system, app version and technical identifiers.
- IP address, timestamps, diagnostic information and server or security logs where collected.
- Crash reports, performance information and security-event information.
- Information relating to sessions, authentication attempts and suspected abuse or unauthorised access.
Support and communications
If you contact Countr, we may receive the information in your message, attachments, screenshots and related correspondence. We may also retain records needed to manage support, privacy requests, complaints and security incidents.
3. How and why we use personal data
We use personal data for purposes such as:
- Providing, operating and maintaining Countr and the features you request.
- Creating and managing accounts, shops and authorised user access.
- Recording, displaying and synchronising Khata, inventory, sales and other business information.
- Processing voice or manual commands that you initiate.
- Providing customer support and responding to requests.
- Detecting, preventing and investigating fraud, abuse, security incidents and unauthorised activity.
- Diagnosing errors, monitoring reliability and improving the service.
- Sending service-related communications, including security alerts, account notices and material service changes.
- Sending promotional communications where permitted and, where required, based on your applicable consent or preferences.
- Complying with applicable law, lawful requests and regulatory obligations.
We do not use shop data for unrelated purposes merely because it is stored in Countr. If we introduce a materially different purpose, we will provide the notice or obtain consent required by applicable law.
4. Consent and your choices
Where Countr relies on consent as the legal basis for processing personal data, we seek consent through a clear notice or consent mechanism and use the data for the stated purpose. Where applicable, you may withdraw consent using the mechanism provided by Countr or by contacting us.
Withdrawal of consent does not affect processing that was lawfully completed before withdrawal. Some features may stop working where the requested processing is necessary to provide that feature.
Service-essential processing, security processing and processing required by law may continue where permitted or required by applicable law.
5. When we share personal data
We may disclose or provide access to personal data where reasonably necessary to operate Countr, perform a service you request, protect the service, or comply with law.
Service providers and data processors
Depending on the production configuration, we may use providers for hosting, databases, cloud infrastructure, authentication and OTP delivery, analytics, crash reporting, communications, payments, notifications, customer support, speech processing and other technical functions.
We aim to limit provider access to what is necessary for the relevant function and to use appropriate contractual, technical and organisational safeguards. A current internal vendor register should identify the providers actually used by the production system.
Legal, regulatory and safety purposes
We may disclose information where required by applicable law, valid legal process, court or governmental order, or where reasonably necessary to investigate fraud, abuse, security incidents or threats to rights and safety.
Business transactions
If Countr or relevant business assets are involved in a merger, acquisition, financing, restructuring or sale, personal data may be transferred as part of that transaction subject to applicable law and appropriate safeguards.
We do not sell personal data as a product.
6. Third-party services, links and payments
Countr may use third-party services to provide specific functions. Those providers may process information on our behalf or under their own applicable terms, depending on the service.
If you use a third-party service, app store, payment service or external website, its own privacy policy and terms may also apply. We do not control the privacy practices of independent third parties.
For payments, Countr may use a third-party payment provider. Countr should not store payment-card authentication data such as CVV unless there is a lawful and technically necessary reason to do so. The exact payment-provider data flow should be reflected in our production vendor documentation.
7. Storage, transfers and retention
Countr may use infrastructure located in India or other jurisdictions depending on the services and vendors used. Where personal data is processed outside India, Countr will apply the safeguards and transfer requirements applicable to that processing.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide the service, maintain required business records, resolve disputes, enforce agreements, protect security, or comply with legal obligations.
Different categories may have different retention periods. Countr should maintain an internal retention schedule covering account data, transaction records, support records, security logs, analytics data and backups. Where deletion is requested, data will be deleted or anonymised where applicable, subject to information that we are required or permitted to retain under law or for legitimate security, fraud-prevention, dispute-resolution or record-keeping purposes.
8. Account deletion and data deletion requests
Countr provides or will provide an account-deletion/request mechanism through the app or another designated channel. A deletion request may require identity or account verification.
Where deletion is applicable, Countr will take reasonable steps to delete or anonymise personal data from active systems within the applicable process. Copies in backups may remain for a limited period until normal backup rotation, subject to our retention and security procedures.
Deletion may not remove information that Countr is legally required to retain or is otherwise permitted to retain for security, fraud prevention, dispute resolution or compliance purposes.
9. Security safeguards
We use reasonable technical and organisational safeguards appropriate to the nature of the information and risks involved. Depending on the system component, these may include:
- Encryption in transit and appropriate protection of stored data.
- Authentication, access controls and role-based permissions.
- Tenant and object-level authorisation controls intended to prevent unauthorised access to another user's business data.
- Security logging, monitoring, rate limiting and abuse detection.
- Secure handling of credentials, tokens and application secrets.
- Backups and recovery procedures.
- Vulnerability management, security testing and software-dependency review.
No internet-connected service can be guaranteed to be completely secure. Users should protect their devices, authentication information and account credentials and should promptly report suspected unauthorised access.
10. Security incidents and data breaches
Countr maintains an incident-response process for suspected security incidents. Depending on the incident and applicable requirements, this may include containment, investigation, preservation of logs and evidence, credential rotation, remediation and notification to affected users or authorities where required.
Where an incident falls within applicable CERT-In reporting requirements, Countr will follow the reporting and cooperation requirements applicable to the incident.
11. Your privacy rights and requests
Subject to applicable law, you may have rights relating to your personal data, including rights to obtain information about processing, request correction, request erasure/deletion where applicable, withdraw consent where consent is the basis for processing, and seek grievance redressal.
To submit a privacy request, use the contact details below. We may need to verify your identity before processing a request. If you are making a request concerning information belonging to another person that you entered into Countr, we may need additional information to establish your authority to make the request.
12. Grievance redressal
Countr provides a channel for privacy and service complaints. We will review and address grievances according to applicable law and our internal procedures.
Privacy / Grievance contact: support@countr.in
13. Children's information
Countr is intended for businesses and their authorised users and is not designed as a service for children. We do not knowingly seek to create business accounts for children. If you believe that personal data relating to a child has been provided to Countr inappropriately, contact us so that we can review the matter and take appropriate action.
14. Cookies and similar technologies
Our website may use cookies or similar technologies for essential functionality, security, preferences and, where enabled, analytics or marketing. The actual technologies used should be recorded in Countr's cookie inventory.
Where applicable, Countr will provide appropriate notice and consent controls for non-essential cookies or similar tracking technologies. You can also control cookies through your browser settings, although disabling certain cookies may affect website functionality.
15. International processing
Some service providers may process information outside India. The availability and location of such processing depends on the providers and configuration actually used by Countr. Where applicable, Countr will follow the requirements governing such processing and transfers.
16. Indian data-protection and cyber-security framework
Countr operates in India and will comply with the Indian data-protection and cyber-security requirements applicable to its activities. The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 establish India's framework for processing digital personal data. The Rules were notified on 13 November 2025 and provide a phased commencement timeline. Countr will update its implementation as each applicable provision comes into force and as the service changes.
Countr will also follow applicable cyber-incident reporting, logging and cooperation requirements, including requirements issued by CERT-In under the Information Technology Act, 2000, to the extent applicable to Countr.
17. Changes to this Privacy Policy
We may update this Privacy Policy when our product, data practices, service providers, security controls or legal requirements change. The updated version will be posted on this page with a revised effective date and version number. If a change is material and additional notice is required, we will provide that notice through an appropriate channel.
18. Contact
Organisation: Countr Technologies Pvt. Ltd.
Website: countr.in
Privacy / Grievance contact: support@countr.in
Registered / correspondence address: Unitech Cyber park Sector 39, Gurgaon, Haryana
When contacting us about privacy, include enough information for us to understand and verify your request, but do not send passwords, OTPs, API keys or other authentication credentials.
Important: This policy is a product-ready compliance draft, not a substitute for advice from an Indian privacy/corporate lawyer. Before publication, replace the marked contact details and verify the actual production data flows, vendors, international transfers, retention periods and deletion process against Countr's systems.