Security
How we protect your account, your codes and the people who scan them.
Last updated
Where your data lives
Accounts, codes and scans are stored with Supabase in the United States, encrypted on disk and sent only over encrypted connections (HTTPS). Every request to the database runs as you, with rules that only let an account read and change its own codes and scans.
Signing in
- Email codes instead of passwords. Sign-in codes have 6 digits, are stored only as a hash, expire after 10 minutes and stop working after 5 wrong tries. How often codes can be requested is limited per email address and per network.
- Optional passwords are stored only as a secure hash by our sign-in provider. We never see them.
- Every account page checks your session on the server before showing anything.
Payments
Payments are handled by Stripe, which is certified to the highest level of the card industry’s security standard (PCI DSS Level 1). Your card details go straight to Stripe and never reach our servers.
People who scan your codes
We count scans without storing IP addresses. Unique scans are told apart with a one-way code that changes every day and can’t be turned back into an address. See the privacy policy for exactly what is recorded.
Files you upload
Uploads are checked for type and size (PDF, PNG, JPEG, WebP or SVG, up to 25 MB) and stored in a folder only your account can change. Because they are meant to be seen by the people who scan your code, files are served from public links that are long and hard to guess — so don’t upload anything you wouldn’t want someone with the code to see.
The website
The site only works over HTTPS and tells browsers to always use it. It sends security headers that block other sites from framing our pages and stop browsers from guessing file types. Everything you send us is checked on the server, and web addresses are limited to normal http and https links.
Monitoring
Errors are reported to Sentry with email addresses, code contents and links removed, and the service’s health is checked around the clock so we hear about problems quickly.
Report a security problem
Found something? Email support@yourqrcode.com with what you found and how to reproduce it. Please give us a reasonable chance to fix it before telling anyone else, and don’t access or change other people’s data while testing.