Privacy policy.
The short version
- Counterbook keeps your data on your own device. There is no Counterbook account and no Counterbook server.
- Elevven11 does not receive, see or store your sales, customers, staff or any other business data.
- The app has no third-party advertising, no analytics and no tracking. It shows one small text promotion for Elevven11's own products (see Promotions).
- The only time data leaves your device is when you choose to: a backup you save or share, an export, a receipt you send, devices you pair on your own network, or a backup you upload to your own Google Drive.
Who we are
Counterbook is made by Elevven11 Studio ("we", "us"). Contact: the contact page or elevven11studio@gmail.com, or the support page linked from More > Support Counterbook.
Your role and ours
For the information you put into Counterbook about your own customers, staff and suppliers, you decide why and how it is used. You are the one responsible for it under data protection laws such as the Nigeria Data Protection Act 2023, the GDPR, or whatever applies where you operate. Because we never receive that data, we are not a processor of it either. We only provide the software.
What Counterbook stores, and where
All of the following stays in an encrypted database on your device.
| Information | Examples | Why it is stored |
|---|---|---|
| Business details | Name, address, phone, tax settings, currency | Receipts and reports |
| Staff | Names, roles, PIN (stored only as a salted hash), activity | Access control and accountability |
| Products and stock | Names, prices, costs, quantities, barcodes | Selling and stock control |
| Customers | Name, phone, email, credit limit, balance, purchase history | Credit sales, receipts, follow-up |
| Suppliers | Name, contact details, orders, payments | Purchasing |
| Sales and cash | Items, amounts, payment methods, shifts, expenses | Records and reports |
| Activity log | Who did what, when, from which device, and the network address of web-till browsers | Preventing and investigating fraud and mistakes |
| Device details | A device name and a random device ID | Keeping synced devices apart |
We do not collect precise location, contacts, photos, microphone recordings, advertising IDs or browsing history. Links in the app (support, donations, promotions, the support page) open in your browser, and that website's own privacy policy applies from then on.
Camera. The Counterbook app does not use the camera. If you open the web till in a phone's browser, the browser may ask to use the camera so you can scan barcodes. That permission is the browser's. The picture is read inside the browser and is not stored or sent anywhere. Barcode scanners that plug in by USB or Bluetooth type into the app like a keyboard and need no permission.
Permissions the app asks for
| Permission (Android) | Used for |
|---|---|
| Network access, Wi-Fi state, multicast | Sharing the web till and finding other Counterbook devices on your network, and Google Drive if you connect it |
| Foreground service, wake lock, notifications | Keeping the web till running on an Android phone while it is shared, and showing that it is running |
| Storage or file access | Saving and opening backups, exports and receipts you ask for |
Who can see your data
- People in your shop, according to the roles you set. Owners and managers can see more than cashiers.
- Other devices you pair to the same business, on your network.
- Anyone you give a backup, export or receipt to. Backups are encrypted. Exports and PDFs are not, so treat them with care.
- Google, only if you connect Google Drive. See below.
We cannot see it.
The QR code on receipts
Each printed receipt has a QR code. It is a web address on Elevven11's site (elevven11studio.github.io/counterbook/r/). The receipt's contents, which are the shop name and phone, receipt number, date, items, totals and payment methods, are packed into the part of the address after the #. Web browsers never send that part to a server, so we do not receive or store the receipt. Anyone who scans the code, or finds the paper, can read what is on it. It contains no customer name and no staff name.
When a customer scans it, their phone loads one static page from our site, which is hosted by GitHub Pages. As with any website, GitHub and our host can see that a page was requested, along with the visitor's IP address. The page contains no analytics or advertising and reads the receipt in the browser only.
If a sale has too many items to fit, the code carries totals only, and for the smallest codes just a reference.
Promotions
At the foot of the More screen there is one labelled text promotion, picked from a short fixed list inside the app (our own products, a sponsor slot, a request for support). It is chosen without using any business data, the app makes no network request to fetch it, and it never appears on the till. If you tap it, the link opens in your browser and includes utm_source=counterbook, so the website you land on can tell the visit came from Counterbook. Nothing about your business is added. You can turn it off under More > Support Counterbook > Show house ads.
Google Drive (optional)
If you connect Google Drive:
- Counterbook asks Google for the
drive.filepermission, which lets it see only files it created itself. - Backups are encrypted on your device before upload, so Google stores only encrypted files.
- Your Google sign-in token is kept in the device's secure storage.
- The OAuth client you use is yours, from your own Google Cloud project, not ours.
- Google's own terms and privacy policy apply to what Google does with files you store there.
- You can disconnect at any time in the app, and revoke access in your Google account settings. Files already in Drive stay until you delete them.
Web till and sync on your network
When you share the web till or pair devices, data moves between devices on your own network over HTTPS. It does not pass through the internet or through us. Browsers using the web till may keep a copy of products and queued sales in their own storage so they can work offline; sign out and clear site data on shared devices.
Security
Data is encrypted at rest (SQLCipher, AES-256), PINs are hashed, backups are encrypted, and sensitive actions are logged. See Security for details and for your part in it. No system is perfectly secure, and we cannot protect data from someone who has your unlocked device, your PIN or your recovery phrase.
How long data is kept
Counterbook keeps your data until you delete it or remove the app and its data. We hold nothing, so we cannot delete anything on your behalf. Backups and exports you made stay where you saved them until you delete them.
To remove everything: delete any backups and exports you made, remove copies in Google Drive, then uninstall the app and delete its data (on Windows, remove Counterbook's data folder; on Android, choose Clear data before uninstalling). Counterbook has no in-app "erase business" button yet. Do this on every device that holds a copy, including paired devices.
Your customers' rights
Your customers may ask what you hold about them, or ask you to correct or delete it. Counterbook lets you find a customer, edit their details, export a list, and delete a customer. Respond to requests as the law where you operate requires. Records you must keep for tax or accounting purposes, such as past sales, may need to stay even when a customer asks for deletion.
Tips for keeping the right amount of data:
- Collect only what you need. A name and phone number are usually enough.
- Tell customers why you keep their details, for example on a sign at the till.
- Do not use customer contact details for marketing unless they agreed.
- Delete customers and old exports you no longer need.
Children
Counterbook is a business tool and is not directed at children. Do not record children's personal information beyond what a sale needs.
Changes to this policy
When the app changes how it handles data, we will update this page and the version above. Updates ship with new versions of the app.
Contact
Questions about this policy: the contact page or elevven11studio@gmail.com.