← Countercheck

DATA HANDLING

Your records, with clear boundaries.

The operator’s legal identity, privacy contact, retention schedule and approved privacy policy are not yet configured. This data-handling summary is not a substitute for that policy. Use sample data during early access.

Information the application stores

Signed-in user identifiers, names and emails; organization membership and roles; supplier contacts and bank records; change requests and payment values; evidence notes, references and attachments; review decisions and audit timestamps. Invitation tokens and session-cookie values are stored as hashes. Provider session tokens are encrypted in storage. Sign-in records include timestamps and a browser/device description.

Who can access it

Active members of the organization can read its records according to their role. Administrators manage membership and billing. The service operator and hosting provider administer the underlying service and storage. Private access does not mean the operator is technically unable to access stored records.

Providers

Customer sign-in uses Supabase Auth and its configured email provider when activated. Application records use Cloudflare D1. Private evidence files use R2 when storage is activated. This service is hosted in the operator’s own Cloudflare account. When billing is activated, Stripe handles checkout and payment details. No bank-verification provider is currently connected. The application does not use an AI service to process supplier records.

Exports and account access

Team members can export accessible records; administrators can download complete workspace backups including attachment contents. Removing a team member blocks their subsequent authenticated access but preserves the historical record of their actions. Downloaded exports are outside the application’s access controls and must be handled securely by the recipient.

Retention and deletion

Records remain stored until the operator processes an approved deletion request. No automatic purge or self-service destructive reset is provided for organization data in this release. The operator must agree and publish a retention policy and deletion process before accepting live customer data.