Get Countr on Google Play →
Countr voice-first khata app logo
countr
Get the app
Security & Privacy

Security is
built in.

Countr handles shop, transaction and customer information. Our security approach is designed around protecting accounts, controlling access, securing data in transit and reducing unnecessary exposure.

Last reviewed: 27 September 2026 · Security overview version 1.1

✓

Countr

Security by design

Focus

Protect access

Approach

Least exposure

Our principles

Security is a
product responsibility.

Countr combines technical controls, access controls and operational practices. The exact controls may evolve as the service changes.

01

Secure access

Authentication and authorization are enforced at the application/backend layer rather than relying only on the client.

02

Protected data

Production traffic is intended to use HTTPS/TLS, while sensitive information stored on supported mobile devices is protected using encrypted storage mechanisms.

03

Abuse resistance

Countr uses server-side validation and access controls, with rate limiting and security monitoring applied where supported by the service.

04

Continuous improvement

Security controls, dependencies, configurations and incident-response practices are reviewed and improved as the product grows.

Technical controls

How Countr protects
the application.

The following describes the security architecture and controls relevant to the current Countr product. It is not a claim of certification or a guarantee that every control prevents every attack.

🔑

Authentication

Short-lived sessions

Countr's API authentication is designed around short-lived access tokens and refresh tokens, reducing the useful lifetime of a stolen access token.

🛡️

Authorization

Server-side checks

Permissions should be checked on the server for protected resources and actions. Client-side controls are not treated as the security boundary.

🔒

Transport

Encrypted connections

Production API communication is designed to use HTTPS/TLS. Cleartext HTTP should not be used for authenticated production traffic.

📱

Mobile security

Protected local secrets

Sensitive mobile credentials are intended to be stored using encrypted device-backed storage rather than plain application storage.

🧱

API security

Validate every request

API endpoints should validate authentication, authorization, input and object ownership before allowing protected operations.

📋

Monitoring

Security visibility

Relevant authentication, application and security events may be logged for troubleshooting, abuse detection, audit and incident response, subject to applicable retention practices.

Your shop data

Access should follow ownership.

Countr is designed as a multi-user service where authenticated users can access the shop information they are authorized to use. Your account credentials should never be shared with other people.

01

Account protection

Use a unique password, protect OTPs and session credentials, and report suspected unauthorized access promptly.

02

Tenant separation

Protected shop resources are intended to be scoped to the authenticated account and its authorized business context.

03

Data deletion

Countr provides account/data deletion mechanisms subject to the Privacy Policy, legal obligations, fraud prevention and necessary records.

Voice & device features

Convenience should not remove control.

Voice features can involve speech processing and third-party technology depending on the implementation. Device security features can also depend on the operating system and device configuration.

Voice processing

Voice input may be processed to convert speech into commands or text. The Privacy Policy explains the categories of information involved and how third-party processing may apply. Countr does not promise that voice recognition will always be accurate.

Device integrity

Where supported and enabled, Countr may use platform security signals to help identify risky or compromised environments. These signals are one part of a broader security model and are not a guarantee against abuse.

If something goes wrong

Security incidents need a process.

Countr maintains an incident-response approach intended to identify, contain, investigate and remediate security events. Where notification is required by applicable law or regulation, Countr will follow the applicable requirements.

01

Detect

Identify suspicious activity through available security signals and reports.

02

Contain

Limit unauthorized access or affected components where reasonably possible.

03

Investigate

Review relevant evidence, logs and system activity to understand the event.

04

Recover

Restore services, remediate the cause and improve controls where appropriate.

Report a security issue

If you discover a suspected vulnerability, unauthorized access or other security issue affecting Countr, please contact the official security/legal contact below. Do not include passwords, OTPs or unnecessary personal data in a report.

support@countr.in

Clear over complicated

No unsupported security promises.

This page is a security overview, not a certification, penetration-test report or guarantee that Countr is immune to every attack.

We do not claim

  • • ISO 27001, SOC 2 or other certification unless separately stated and evidenced.
  • • Perfect security or zero-risk operation.
  • • That every third-party provider uses the same security controls as Countr.
  • • That device-level security can be guaranteed by an application.

We do commit to

  • • Keeping security and privacy documentation aligned with the service.
  • • Applying reasonable technical and organizational safeguards appropriate to the service.
  • • Investigating credible security reports and improving controls when issues are identified.
  • • Handling personal data according to the Privacy Policy and applicable requirements.
🔐

Privacy Policy

The Privacy Policy is the source of truth for personal-data collection, use, sharing, retention, rights and deletion.

Read Privacy Policy →
📄

Terms of Service

The Terms explain the rules, responsibilities, limitations and conditions governing use of Countr.

Read Terms →

Compliance context

Security practices operate alongside applicable Indian requirements.

Countr considers applicable requirements relating to digital personal data protection and cybersecurity, including the Digital Personal Data Protection Act, 2023 and the notified Digital Personal Data Protection Rules, 2025, as applicable to the service and its processing activities. Countr also considers applicable CERT-In cybersecurity directions and incident-reporting requirements. This page does not by itself constitute a certification or a legal-compliance guarantee.

For the current legal position and applicability to Countr's specific processing activities, obtain professional legal advice and keep the product implementation, contracts and policies aligned.

Countr Technologies Pvt. Ltd.

Build your shop
with confidence.

Simple shop management should also mean clear, responsible security and data practices.

Get Countr →