Legal
Privacy policy
Who we are
As Counted is operated by Ryan James Spencer, a sole trader in Australia, trading as As Counted (“As Counted”, “we”, “us” or “our”).
This policy explains how we handle personal information when you visit ascounted.com, use the As Counted app at app.ascounted.com, or use its command line tool (CLI) and MCP server. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth) and, for people in the European Union and the United Kingdom, the GDPR and UK GDPR.
Your data and your customers' data
We play two roles, and this policy is mostly about the first.
- Account data. Information about the people who sign in and how they use the service. We decide how it is used, so we are responsible for it (under the GDPR, we are its controller).
- Customer data. Everything a business puts into As Counted: items, stock, orders, suppliers, customers, imports and the record of changes. We handle it only to provide the service, on the business's instructions. The business is responsible for it (its controller) and we are its processor. Our data processing agreement covers this. If your information is in someone else's As Counted organization, please contact that business first.
What we collect and why
When you sign in
As Counted signs you in with Google. Google tells us your name, email address and profile image, and a Google account identifier. We store these, with the tokens Google returns at sign-in, to create your account and recognise you next time. We do not receive or store your Google password.
Your organization and team
The organizations you create or join, your role in each (owner, manager or staff), and invitations, which hold the invited person's email address and role.
Sessions and devices
When you sign in we create a session and record the IP address and browser user agent it was created from. We use this to keep you signed in and to protect accounts.
What your organization records
Items, locations, bills of materials, orders and other documents, the names of the customers and suppliers on them, stock movements, and spreadsheet imports. For an import we store the file name, the rows as the commands they become, and any rows that could not be imported.
The record of who did what
Every change is logged with who made it, how (the web app, the CLI, an MCP client, the API or an integration, with the client's or system's name), what was asked, when, and the outcome. This lets a business explain every number and see who changed it.
CLI and MCP clients
When you connect the CLI or an AI agent, we store the client's registration (its name and where it returns after sign-in), the permissions you granted it, and the access and refresh tokens it uses.
Integrations
If an owner connects an integration such as Airtable or Salesforce, we store the access grant that system issues (encrypted), the connection's status, links between records on each side, and any sync problems.
Service logs
Our hosting provider records requests to the service, such as the time, address requested, IP address, browser user agent and any errors. We use these logs to run, secure and fix the service.
Messages you send us
If you email us, we keep the message and our reply so we can help you.
Payment details
Billing is not set up yet, and we do not collect payment details. We will update this policy before we do.
Why we use it
We collect only what we need to provide, secure and support the service, and we use it only for those purposes and to meet our legal obligations. We do not sell personal information, use it for advertising, or build profiles of you. For the GDPR, our legal bases are: performing our contract with you or your business; our legitimate interests in keeping the service secure and working, which we balance against your rights; and complying with the law.
Cookies and tracking
This website (ascounted.com) sets no cookies and uses no analytics or advertising trackers. The app uses only the cookies it needs to sign you in and keep you signed in. There are no marketing cookies. The sign-in library's usage reporting (telemetry) is turned off.
Who we share it with
We use a small number of service providers to run As Counted. They handle information only on our instructions. The current list, and what each one does, is on our subprocessors page. In short:
- Cloudflare hosts the website and app, stores the database, runs background jobs such as imports, keeps service logs and routes email sent to our addresses.
- Google signs you in.
Integrations are different. If your organization connects Airtable or Salesforce, we send data to that service because your organization told us to. Those services are not our subprocessors; your organization's own agreement with them governs what they do with it.
We may also disclose information where the law requires it, or to protect the rights, safety or property of our customers, ourselves or others. If As Counted's business is transferred, for example to a company formed to run it, the information would transfer with it under this policy.
Where it is kept
As Counted runs on Cloudflare's global network, and its database is hosted by Cloudflare. Information may therefore be stored or processed outside Australia, including in the United States and other countries where Cloudflare and Google operate. We are based in Australia and access information from there. We take reasonable steps so that these providers handle personal information consistently with the Australian Privacy Principles.
For customers in the EU or UK, transfers of personal data to Australia and to our subprocessors are covered by the safeguards in our data processing agreement, including the European Commission's standard contractual clauses and the UK addendum to them.
How long we keep it
We keep account data while your account is open, and customer data for as long as the organization it belongs to exists, including the record of who did what, which is part of how a business explains its stock. When an account or organization is closed we delete or de-identify its data, unless we need to keep some of it to meet a legal obligation or resolve a dispute. Service logs are kept for a short period set by our hosting provider and then deleted.
How we protect it
Every request is checked against the person's role and, for CLI and AI clients, the permissions granted to them. Integration grants are encrypted. All traffic is encrypted in transit. There is more on our security page. If a data breach is likely to cause serious harm, we will tell the people affected and, where required, the regulator.
Your rights
You can ask us for a copy of the personal information we hold about you, and ask us to correct it. You can see and update much of it in the app. You can also ask us to delete your account.
If you are in the EU or UK, you also have the right to have your data erased, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent, you can withdraw it at any time.
To make a request, email privacy@ascounted.com. We may need to confirm who you are first. We will not charge you for a request, and we will reply within the time the law sets. If your request is about customer data, we will pass it to, or help, the business responsible for it.
Automated decisions
We do not make decisions about people by automated means, and we do not personalise, profile or retarget. As Counted calculates stock availability, which is about items, not people.
Changes to this policy
We will post any change on this page with a new date. If a change is significant, we will also email account owners before it takes effect.
Contact and complaints
For privacy questions or complaints, email privacy@ascounted.com. We will look into your complaint and reply. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, in the EU or UK, to your local data protection authority.
The service is for businesses and is not directed at children.