CounterpassBack to site

Privacy Policy

Last updated: 6 September 2026

This policy explains how Counterpass Ltd (“Counterpass”, “we”, “us”) collects and uses personal data. We are the data controller for the personal data described below, except where we act as a processor on behalf of a business customer (see “Orders placed through a venue”).

Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. Company number: 17432716. If you have any questions about this policy or your data, contact us at privacy@counterpass.co.uk.

1. Who this policy covers

2. What we collect and why

DataWhy we use itLawful basis
Account details (name, email, password)To create and secure your Counterpass accountContract
Business details (venue name, address, hours)To run your ordering page and dashboardContract
Payout bank detailsTo pay out money from orders, via StripeContract / legal obligation
Billing / subscription dataTo take your subscription payment and meet tax dutiesContract / legal obligation
Order data (name, contact, order, slot/table, notes)To process and fulfil ordersProcessed for the venue (see below)
Usage / device dataTo keep the service secure and workingLegitimate interests
Support / feedback messagesTo answer you and improve CounterpassLegitimate interests
Marketing contact (if opted in)To send product news you asked forConsent

3. Orders placed through a venue

When a customer orders through a venue's Counterpass page, the venue decides why the data is collected and is the controller of that order data. Counterpass processes it on the venue's instructions under a data processing agreement. Customers with questions about their order data should contact the venue; we will help the venue respond.

4. Who we share data with

We do not sell personal data. We share it only with the service providers that help us run Counterpass — including Stripe (payments and payouts), our hosting and email providers, and professional advisers or authorities where the law requires it. A current list of our sub-processors is kept on our sub-processors page.

5. International transfers

Some providers may process data outside the UK. Where they do, we rely on UK-approved safeguards such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Clerk and Stripe process some personal data in the United States. Those transfers are covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, which each provider includes in its data processing terms. Supabase, Resend and Vercel process your data in the UK or EU.

6. How long we keep it

We keep personal data only as long as needed for the purposes above. For example: order and billing records are kept for 6 years from the end of the tax year in which the transaction took place (an HMRC record-keeping requirement); account data (venue account and menu data) are deleted 90 days after closure, except records covered by the 6-year rule; support messages are kept for 24 months.

7. Your rights

You have the right to access your data, correct it, ask us to delete it, restrict or object to processing, request portability, and withdraw consent at any time. To exercise any of these, email us at privacy@counterpass.co.uk. We will respond within one month.

8. Complaints

If you have a concern, please contact us first at privacy@counterpass.co.uk so we can put it right. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.

Our complaints procedure

9. Automated decisions

We do not make decisions about you by solely automated means that produce legal or similarly significant effects.

10. Our ICO registration

Our ICO data protection registration number is ZC238105.

11. Changes

We may update this policy and will post the new version here with a revised “last updated” date.