1. Introduction
MyCounter ("we", "our", or "us") operates the MyCounter platform: the MyCounter Management web platform and its staff applications — MyCounter POS (point of sale, iPad), the Kitchen Display app, and the Waiter app. This Privacy Policy explains how we collect, use, and protect information across all of them.
These are business (B2B) applications used by restaurant staff. Accounts are issued by the venue that employs them; they are not consumer sign-ups. We do not use the data for advertising, and we do not track users across other companies' apps or websites.
2. Information We Collect
We may collect the following types of information:
- Account Information: Name, email address, phone number, and business details when you create an account.
- Business Data: Restaurant information, menu items, inventory data, orders, sales records, and staff schedules that you enter into the platform.
- Device Information: Device type, operating system, and app version for providing technical support and improving our services.
- Usage Data: How you interact with our app to improve the user experience.
- Staff Sign-in Data (POS / Kitchen / Waiter apps): The employee's work email address, a numeric cashier PIN (stored only as a one-way hash — never in readable form), and a terminal label that identifies the tablet so a shift and its cash drawer can be attributed to the right device.
- Your Customers' Details: If a venue chooses to attach a customer to an order (for example to redeem cashback), the customer's name, phone number and loyalty balance are shown to the cashier. This information belongs to the venue and is entered by the venue — we process it on the venue's behalf and never use it for our own purposes.
2.1 Device Permissions in the POS App — and Why
The MyCounter POS app requests a small number of device permissions. Each one is used only for the stated purpose, and the app remains usable if a permission is declined:
- Bluetooth: To connect to a thermal receipt printer at the counter and to open a connected cash drawer. We do not scan for or record any other nearby devices. Without a printer, the app simply reports that none is connected.
- Local Network: To send new orders to Kitchen Display screens on the same restaurant Wi-Fi, so the kitchen keeps working even if the internet drops. No data leaves the venue's own network through this channel.
- Camera: Used only to scan a pairing QR code shown by the manager's admin app when setting a tablet up, and to scan item barcodes. Images are processed on the device and are never stored or uploaded.
The POS app does not request access to your location, contacts, photo library, microphone, or health data.
2.2 Data Stored on the Device (Offline Mode)
So a venue can keep serving customers during an internet outage, the POS app keeps a copy of the working data on the tablet itself: the menu, table layout, the current shift, and any orders that have not yet been uploaded.
- This data stays in the app's private storage on the device and is uploaded to the venue's account as soon as the connection returns.
- Payment card numbers are never stored, entered, or processed by the app. Card payments are handled entirely by the venue's certified payment provider or terminal; the app only records the payment method, an approval reference, and the amount.
- Signing out of the app after all data has synced clears the local copy.
2.3 Device Permissions in the Kitchen Display App — and Why
The Kitchen Display app runs on a fixed tablet in the kitchen. Two of its permissions behave differently from the POS app's, so they are described separately here rather than being covered by section 2.1:
-
Camera — recipe access records: A venue may protect its recipes. When that is switched on, the front camera takes a small number of still photos of whoever is standing at the screen while a protected recipe is open, and those photos are uploaded to the venue's own account as evidence of who opened it. The number of photos and how long they are kept are set by the venue. This feature is off unless the venue's owner turns it on. By default the employee is also told on screen — before entering their PIN — how many photos will be taken and how long they are kept, and must acknowledge it before the recipe opens; a venue can switch that acknowledgement step off, and is responsible for informing its staff by other means if it does. The photos are reviewed by a human at the venue: we do not perform facial recognition or matching, and we do not create or store any biometric template. The camera never records audio.
-
Location — keeping the tablet in the restaurant: A venue may require that a kitchen tablet only work inside the restaurant, so a device taken home cannot open orders or recipes. When that is switched on, the app sends its coordinates with its requests so the server can allow or refuse them. The coordinates are used for that check and to record refused attempts; they are not used to build a movement history and are never used for advertising. This is also off unless the venue turns it on.
-
Device identifier: The app generates an identifier for the tablet itself (not for a person) so a manager can pair it to a branch and block it remotely if it is lost or stolen.
The Kitchen Display app does not request access to your contacts, photo library, microphone, or health data.
3. How We Use Your Information
We use the information we collect to:
- Provide and maintain our restaurant management services.
- Process orders, inventory tracking, and business analytics.
- Send important notifications about your account or service updates.
- Improve and optimize our application.
- Provide customer support.
4. Data Security
We take appropriate security measures to protect your information against unauthorized access, alteration, disclosure, or destruction. All data is transmitted using SSL/TLS encryption and stored on secure servers.
5. Data Sharing
We do not sell, trade, or rent your personal information to third parties. We may share data only in the following cases:
- With your explicit consent.
- To comply with legal obligations or court orders.
- To protect the rights and safety of our users and the public.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide our services. You may request deletion of your account and associated data at any time by contacting us.
Recipe access records (section 2.3) are kept for a period the venue chooses — 90 days by default, and never longer than one year, whatever the venue sets. They are deleted automatically once that period passes. The venue's owner can also view and delete any individual record at any time before then, and an employee may ask their employer to delete a record of themselves.
7. Your Rights
You have the right to:
- Access your personal data.
- Correct inaccurate data.
- Request deletion of your data.
- Withdraw consent at any time.
- Export your data in a portable format.
8. Children's Privacy
Our services are not directed to children under 13. We do not knowingly collect personal information from children under 13 years of age.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.