Security
Where the data lives
- The database and the application run on a server we operate ourselves, in Magyarország.
- The service is reachable only over an encrypted (HTTPS) connection. Traffic reaches the server through Cloudflare's network; the server's own address is not published anywhere.
- The cookie that keeps you signed in only ever travels over an encrypted connection.
Every business's data kept apart
- Every member, product, sale and campaign is stored tied to one business, and every query explicitly filters on that one business. Automated tests check that no shop can see or use another shop's data.
- Staff permissions are per business — owner, manager or counter staff — and a team member can be limited to particular locations. When you revoke someone's access, it takes effect on their next click.
- The last owner cannot be removed, so an account can never be left without one.
Sign in
Business staff
- We never store passwords, only an irreversible salted hash of them (PBKDF2). Passwords that are too short, too common or all digits are refused.
- Repeated failed sign-in attempts are slowed down.
- There is no open registration: a staff account is only ever created by setting up a business or through an owner's invitation.
Members
- Members have no password. When they join they receive a 6-digit one-time code, valid for 10 minutes and good for at most 5 attempts. We store the code only as a hash.
- Only a limited number of codes can be requested per hour for one address and from one internet connection.
- None of our pages reveals whether an e-mail address or phone number is registered with us.
The card and the balance
- A card is identified by an unguessable secret link — the same one its QR code encodes. Rewards can only be redeemed at the counter, by the business's signed-in staff.
- A card created at the counter starts collecting straight away, but nothing can be redeemed on it until the member has confirmed their address with the link we e-mail them.
- The balance is an append-only ledger: every credit, redemption and expiry is its own row, which can never be edited or deleted afterwards. A mistake is corrected by an offsetting row, so every balance can be traced back to its movements.
- If the same sale is sent twice — say, by a double tap on the button — it is recorded only once.
Payment
Subscription payments are handled by Stripe. You enter your card details on Stripe's own page; they never reach us, and we do not store them.
Uploaded images
Uploaded logos and pictures are cropped to size and re-encoded. Along the way, the metadata embedded in a photo — such as where it was taken — is dropped.
What we do not keep
- If a business closes its account, we permanently delete its data after 90 days.
- When a member's last membership ends, their personal identifier is deleted after 30 days.
- The privacy notice has the details.
Found a security issue?
Write to us at [email protected]. Please do not publish the details until we have fixed it.