Privacy Notice
Effective from 1 October 2026 · Version 1.0
Pride Tech Solutions ("Countr") is the Data Fiduciary for the personal data described here, under the Digital Personal Data Protection Act, 2023.
1. What we collect, and why
| What | Why | On what basis |
|---|---|---|
| Mobile number | To identify you, sign you in, and tell you about your coins and transactions | Your consent, given at signup |
| Name, if you give it | To address you | Consent |
| Your transactions — shop, bill amount, discount, coins, time | To apply the discount, keep your coin balance, resolve disputes, prevent fraud, and give shops a count of visits | Consent; and our legal obligations for accounting and tax |
| Device identifier | To keep you signed in and detect multiple accounts | Consent |
| Approximate location, only when you allow it | To show shops near you, and to flag transactions far from the shop for review | Consent; refusing only means the nearby list is less useful |
| Your neighbourhood, if you give it | To decide where to onboard shops | Consent |
We do not collect: payment card details, bank details, your income, your identity documents, or your contacts.
If you fill in a form on our website
Our website has a form for shops that want to join Countr and a form for people who want to know when they can use it. A form sends us only what you type into it, plus the following:
| What | Why |
|---|---|
| For a shop: the shop's name, the owner's name, a mobile number and the shop's category and neighbourhood; on the longer form also whether we may use WhatsApp, a monthly sales range and how you heard of us | To contact you about the shop joining Countr |
| For a member: a mobile number, your neighbourhood and the kinds of shop you would use | To contact you about using Countr near you |
| Your consent to be contacted, and separately your consent to marketing, each with the time you gave it | To show what you agreed to, and when |
| The page the form was on, and any campaign tags (utm) in the link you followed to it | To know which page or campaign reached you |
| Your internet address, in a count of form submissions per address per hour | To stop automated abuse of the forms |
We use what a form sends only to contact you about joining Countr, as a shop or as a member. We send you marketing only if you also ticked the separate box for it.
Your internet address is not stored with what you submitted. It is kept only in the hourly count, which is deleted as clause 5 sets out.
2. Consent, and how to withdraw it
2.1We ask separately for:
(a)consent to run your membership — without this we cannot provide the service; and
(b)consent to send you marketing — entirely optional.
2.2You can withdraw marketing consent at any time in the app, without affecting your membership.
2.3Withdrawing consent to run your membership closes your account.
3. What shops see
3.1A shop sees the transactions approved at its own counters, and aggregate counts.
3.2A shop never receives your name, your mobile number, or any record of what you have done at any other shop.
4. Who else we share with
We use these processors, each under a written agreement limiting them to acting on our instructions:
| Processor | For | Where the data sits |
|---|---|---|
| Supabase | Database hosting | India (Mumbai) |
| Railway | Application hosting | Singapore |
| Cloudflare | Content delivery, security | Global edge |
| Cloudflare R2 | Storing shop photographs and logos only — never personal data. Photo metadata (EXIF), including GPS location, is stripped before a file is stored, so no location data is kept | Asia-Pacific |
| MSG91 | One-time codes by SMS | India |
| Meta / BSP | One-time codes by WhatsApp | Global |
Our database is in India. Some processing happens outside India, which the DPDP Act permits except to countries the Government has restricted. We do not transfer personal data to any restricted country.
We do not sell your data. We do not share it for advertising.
5. How long we keep it
| What | How long | Why |
|---|---|---|
| Transaction records | 8 years from the transaction | Accounting and tax law. After you close your account these records are kept but stripped of anything identifying you. |
| Mobile number, name, device | Deleted within 90 days of you closing your account | No longer needed |
| One-time code records: the number a sign-in code was sent to, when, from which internet address, and how many attempts were made — never the code itself | 24 hours from when the code was sent, then deleted by an automated job | A code signs you in once and stops working after 10 minutes. The record is kept for a day so repeated guessing can be stopped and a failed sign-in can be looked into |
| Website form counts per internet address | 48 hours, then deleted by an automated job | Stopping automated abuse of the forms |
| What you send us through a form on our website | 24 months from when you sent it, or 90 days after you ask us to remove it, whichever is sooner | To contact you about joining Countr |
| Marketing consent record | While consent stands, plus 3 years | To show consent existed |
Deletion is done by an automated job, not on request alone.
6. Your rights
You can, at any time:
- See the data we hold about you, and who we have shared it with
- Correct or complete anything inaccurate
- Delete your account and your personal data
- Nominate someone to exercise your rights if you die or become incapable
- Complain to us, and then to the Data Protection Board of India
The first three are available in the app, under Account. We do not require you to write to us.
7. What deleting your account does
7.1Your name, mobile number and device records are scrubbed straight away, and the remainder is removed within 90 days.
7.2Your transaction records are kept for 8 years as clause 5 requires, with everything identifying you removed.
7.3Unused coins are cancelled and cannot be restored.
8. Children
Countr is for people aged 18 and over. We do not knowingly collect data about children. If we learn we have, we delete it.
9. Security
We protect your data with encryption in transit, access controls, hashed credentials, audit logging of every administrative action, and least-privilege database access. No system is perfectly secure, and we do not claim ours is.
10. If there is a breach
We will tell the Data Protection Board of India and every affected person, as the DPDP Act requires, describing what happened, what data was involved, and what we are doing about it.
11. Changes
We will tell you of a material change at least 15 days before it takes effect. Every version is dated and kept; ask us for the one in force on any date.
12. Grievance Officer
Madhu
[email protected] · +91 94493 52311
We acknowledge within 2 working days and resolve within 30 days. If you are not satisfied you may complain to the Data Protection Board of India.