Your QR codes. Your data. Protected.
IndiQR is built with security in mind, from how you sign in to how a printed code is redirected. Here is what that means in practice — and what we are not claiming.
- A destination is checked when you save it and again at every scan
- A scan record keeps no IP address and nothing is written to the phone
- Card details are entered on the payment provider's checkout, never here
Security at a glance
Account security
Passwords are hashed, sign-in attempts are rate limited, and changing your password signs every other session out.
QR code protection
Your codes are private to your account, and only you can change where a dynamic code points.
Payment security
Payments run through the payment provider's own checkout. There is no field on this site that takes a card number.
Data protection
Reaching anything in the app means being signed in as the account that owns it, and what a scan records is deliberately coarse.
How your account is protected
Four steps between a sign-in form and your dashboard.
- Sign inPassword or Google
- VerifiedServer side, rate limited
- Your account onlyChecked per request
- DashboardYour codes and reports
Authentication
Passwords are hashed one way, so nobody here can read yours, and repeated attempts are throttled by email and network together. Signing in with Google asks only for your name, email and an identifier, and keeps no token afterwards.
Authorization
Every request is checked against the account that made it. A code, a report or a payment belongs to one account and is only served to it.
Sessions
Signing in relies on a cookie that scripts cannot read, and each change carries a token proving it came from this site. Changing your password ends every other session.
Admin access
The admin area has its own sign-in timeout, so an idle operator is signed out sooner than an ordinary session would be.
QR code security
A dynamic code carries an IndiQR link, so where it goes is managed in your dashboard instead of on the printed code.
Printed code
Stays exactly as printed
IndiQR redirect
The destination is checked again here, at every scan
Destination
example.com/autumn-menu
Yours to change whenever you like
Switching a code off
Pause a dynamic code and a scan lands on a short IndiQR page saying it is inactive. Nothing is opened, the code itself still works, and turning it back on takes effect immediately.
What static codes cannot do
A static code holds its content inside the image, so it cannot be edited, paused or switched off once it is printed. Choose dynamic if you may ever need to.
Payments
Online payments are switched off on this installation, so nothing can be charged here at the moment.
Who can see what
Administrative screens are a separate role, and what they allow is limited to running the platform.
- YouYour dashboard
Your codes, your reports, your billing
- Super adminAdmin panel
Accounts, plans and moderation for the platform
Not everything is visible
Wi-Fi passwords and the details inside contact codes are kept off admin screens.
Suspend, not rewrite
A code can be suspended after a complaint. It cannot be repointed, edited or deleted by an operator.
Written down
Every admin action on another account is recorded, with who did it and when.
Data and privacy
Five kinds of information, and that is the lot. The privacy policy goes through each one field by field.
Account
Your name, email address and how you signed in.
QR codes
The name, type and design of each code, plus the destination of a dynamic one.
Scans
Date, country, sometimes city, device type and browser. No IP address, and nothing written to the scanner's phone.
Messages
Whatever you send through the contact form, and the address to reply to.
Payments
The amount, the plan and the payment provider's reference for it.
What we are not claiming
Everything above is something you could point at in the product. These are the parts that are not there yet.
- No two-factor authentication yet. A password, or your Google account, is all there is.
- No self-serve password reset yet — a lost password has to be sorted out by a person.
- Saved content is not encrypted field by field. A Wi-Fi code holds its network password in readable form, because it has to be readable to go back into an image.
- No certification of our own, no independent audit and no bug bounty. The payment provider's compliance is theirs, not ours by association.
- The connection to the site is encrypted in transit. That is not end-to-end encryption, and we will not describe it as if it were.
- Nothing checks whether your destination is safe. A dynamic code is not vetted for phishing or malware.
Found a security issue?
Please tell us if you find a vulnerability or anything that does not look right. Use the contact form to say what you found and how we can reach you — without the specifics, since a message sent through it is stored as ordinary text. We will reply with a private way to send them.
Two requests while you look: please do not use anybody else's account or data to prove a point, and do not run anything that would take the service down for other people.