Privacy Policy

Last updated: 29 July 2026

Handcount counts stock. It never sees your customers, it sells nothing to anyone, and what it keeps on a phone it deletes when the count is over. The rest of this page is the detail behind those three sentences.

It covers what happens when a merchant installs the app, when someone counts through a shared link, and when anyone writes to us at handcount.support@gmail.com.

1. The short version

Handcount requests access only to the shop, product, location, and inventory information it needs to count stock. It does not request access to Shopify customer, order, checkout, or payment data, and cannot read them.

It processes limited personal data about the merchant’s staff and the people who count — the name typed on the counting page, and the technical information needed to run and secure the service.

We do not sell personal data, share it for cross-context behavioural advertising, or use it to train AI models. There is no analytics, advertising, session-replay, or AI provider anywhere in the app.

2. Our role and the merchant’s role

For counting information processed on a merchant’s instructions — product details, inventory levels, count records, and the names people type when they join a count — the merchant decides why it is processed. The merchant is the controller; Handcount is its processor.

We act as an independent controller only for what we process for our own purposes: administering the installation, operating and securing the service, responding to support requests, and complying with law.

If you counted through a link a merchant sent you, that merchant may have its own privacy notice and is usually the best first contact.

3. What we process

3.1 Merchant and installation

3.2 Products, locations, and counts

This is business inventory information. It becomes personal data where it is tied to an identifiable staff member or participant.

3.3 People counting

The name is free text. It is not verified and is not linked to any account. Before it is submitted, the page says the store owner will see it next to what that person counted. The counting page creates no account and asks for no password, email address, or phone number.

3.4 Storage on the counting device

So counting survives a dead zone, the page stores this on the phone itself. All of it is scoped to a single count and none of it is used for advertising, cross-site tracking, or profiling.

What is keptWhy
The list of products being counted — titles, SKUs, barcodesSo a scan is recognised instantly, and still recognised where there is no signal
What has been counted so far, and anything not yet sent to the shopSo nothing is lost if the connection drops mid-count, or the page is closed and reopened
The name typed on joining, and a random device numberSo the count can show who counted what, without asking for the name again
Scanning preferencesSo the choices made on the settings screen survive the next visit. No personal information
A copy of the page and the barcode readerSo the link still opens in a cold store or a basement
One cookie, described in section 6So a returning phone is not asked to join again

All of it is erased when the count finishes — as soon as the count is applied or cancelled, the phone is told so and clears everything above. If a count is simply abandoned and never finished, the phone clears it by itself 30 days after it was last opened there.

Clearing the browser’s site data removes everything immediately, at any point.

3.5 Camera

Camera frames are decoded in the page — by the browser’s own barcode decoder, or by one the page carries with it — and then discarded. They are never turned into a file or an image, never sent to our servers, and never attached to an error report. Counting works without camera access, using a Bluetooth scanner or the keyboard.

3.6 Logs and error reports

Our hosting provider keeps a short record of each request — which page was asked for, whether it worked, and how long it took. Where a counting link would appear in that record, it is blanked out before the line is written, so links do not end up in our logs.

When the server hits an error, a report goes to Sentry: the error, its stack trace, the route with any counting-link secret removed, and the environment name. Sentry is configured not to collect the extras it can — no IP address, no user identity — and performance tracking is switched off entirely.

There is no Sentry SDK in the browser at all — so no session replay, no screenshots, no attachments, and no breadcrumbs are collected from the counting page or from a merchant’s browser.

4. What we do not request from Shopify

At install, Handcount asks for three permissions and no others: to read products, to read locations, and to update inventory levels. It has no access to customer names, contact details, addresses, orders, checkouts, payment details, or card information.

If the scopes change, we will update this policy before using anything newly accessible for a new purpose.

5. Why, and on what legal basis

Where we act for a merchant, we process on that merchant’s instructions and the merchant identifies its own legal basis.

Where we act for ourselves, under the GDPR and UK GDPR we rely on performance of a contract for providing and administering the app, and on our legitimate interests in securing the service, preventing abuse, diagnosing faults, and defending legal claims. We do not rely on consent unless we ask for it.

6. Cookies

No advertising cookies, no cross-site tracking, no third-party tag, pixel, or analytics script. The counting page sets exactly one cookie.

NameWhat it doesHow long it lastsWhere it goes
st_joined_ followed by the count’s linkRemembers that this phone already joined this count, so it is not asked for a name a second time30 daysOnly to that one count’s page, and only over an encrypted connection. Never to another site

It is strictly necessary and holds no personal data. The merchant-facing part of the app uses Shopify’s own session cookies, described in Shopify’s documentation. Offline storage is covered in section 3.4.

7. Who we share it with

This is the complete list of providers that process anything:

ProviderPurposeLocation
ShopifyThe platform, authentication, and the inventory APIAs described by Shopify
Fly.ioApplication and database hostingAshburn, Virginia, United States
SentryServer-side error monitoringUnited States

Beyond these, we disclose information only where required by law or a valid legal request, to protect the rights and safety of Handcount, merchants or users, or in connection with a sale of the business under appropriate safeguards.

We do not sell personal data, share it for cross-context behavioural advertising, use it for targeted advertising, or use merchant or count data to train AI models.

8. Where the data is

Handcount runs in the United States. Information from the EEA, the United Kingdom, Switzerland, or elsewhere is therefore transferred to and processed in the United States, whose data-protection laws differ from those where it came from.

Our hosting provider participates in the EU–US, UK, and Swiss–US Data Privacy Frameworks. Our providers publish data-protection terms for their services, including standard contractual clauses for transfers out of the EEA, the United Kingdom, and Switzerland.

If you need a data-processing agreement or details of the safeguards that apply to your own compliance work, write to handcount.support@gmail.com.

9. How long we keep it

InformationRetention
Shopify access token and app sessionWhile installed; deleted when Shopify notifies us of an uninstall
Counts, scan history, participant names, apply and undo recordsUntil the merchant deletes the count, or until shop-data deletion completes after uninstall
Offline data on a counting deviceErased when the count closes, or 30 days after that device last opened it — whichever is first
Database backupsDaily encrypted snapshots, deleted by rotation after 5 days
Request logsHeld by our hosting provider for its retention period and then deleted. We copy them nowhere else
Error reportsHeld by Sentry for our account’s retention period and then deleted. We copy them nowhere else
Emails to usKept no longer than needed to resolve the matter and any follow-up

When the app is uninstalled:

  1. Shopify notifies us and we delete the access token and app sessions immediately;
  2. about 48 hours later Shopify asks us to erase the shop’s data;
  3. we delete everything remaining for that shop — every count, every line in it, every scan, every counter’s name, and the record of what was written back;
  4. backup copies go with the 5-day rotation.

Handcount answers all three of Shopify’s mandatory compliance webhooks. Because it holds no Shopify customer data, the answer to the customer-related ones is that we hold none.

10. Security

No internet service is completely secure and we cannot promise otherwise. If you think you have found a security problem, write to handcount.support@gmail.com.

11. Your rights

Depending on where you are, you may have the right to access your personal data, get a copy, correct it, have it deleted, restrict or object to processing, ask for portability, withdraw consent where consent was the basis, complain to a data-protection authority, and appeal a refusal.

To exercise any of them, write to handcount.support@gmail.com. We may need to verify who you are and what information you mean. Every request is read and answered by a person.

A merchant does not have to wait for us for the everyday cases: any count can be exported as CSV or deleted outright from the Shopify admin at any time. Uninstalling starts the deletion described in section 9.

We aim to answer within the period the law requires; under the GDPR and UK GDPR that is generally one month, with permitted extensions.

If you typed your name into a count a merchant created, that merchant is generally the controller and you can contact it directly. You may also write to us and, where we act as its processor, we will pass the request on or help the merchant as required.

People in the EEA or the UK may complain to the data-protection authority where they live or work, or where they believe something went wrong.

12. United States

Where United States state privacy laws apply: we collect the categories in section 3, use them for the purposes in section 5, and disclose them to the recipients in section 7. We do not sell personal data, share it for cross-context behavioural advertising, process it for targeted advertising, or knowingly use sensitive personal data to infer characteristics. Eligible individuals may exercise access, correction, deletion, portability, opt-out, and appeal rights by writing to handcount.support@gmail.com. We will not discriminate against anyone for exercising a privacy right.

13. Automated decisions

Handcount does not profile anyone or make automated decisions with legal or similarly significant effects.

14. Changes

We will update the date at the top when this changes. Where a change materially affects how personal data is processed, we will tell merchants with the app installed.

15. Contact

For privacy, security, support, or data-rights requests: handcount.support@gmail.com