Resources

Security, in the detail your checks will ask for

What a scan records and what it deliberately does not, where it is stored, who can reach it, how long it lives, and which companies process it on our behalf. Written to be read by the person doing the vetting rather than the person doing the buying.

What a scan records

The time. The country, region and city, plus the approximate coordinates and postal code the network reports for that city. The device type, operating system and browser, with versions, and the browser's language. The referrer where one is sent, and which of your codes was scanned. That is the whole list, and it is the same list the privacy policy gives.

Nobody is asked for their location — the browser's permission prompt is never shown, so city-level is as precise as it gets.

No cookie is set. The address a scan arrives from is used to compute a salted fingerprint and then discarded rather than stored, and the salt rotates on a schedule you set. So we cannot tell you who scanned a code, and neither can anybody who compels us — nothing in the scan record names a person.

That is a promise about scanning, and worth saying where it stops. If you use Contacts, the names in it are there because you or somebody filling in your form put them there. Those are yours: export or delete any of it whenever you like, and it goes when the account goes. We process it on your instruction and for nothing else.

Who touches it besides us

Four companies, and there is no fifth. Cloudflare runs all of it, encrypted in transit and at rest. Stripe handles payments on its own pages, so no card number reaches us. Resend delivers our email. Turnstile checks that a sign-up is a person.

If you sign in through your own identity provider, it is involved by your choice and we receive only the claims it sends.

What we do not have, said plainly

We are not SOC 2 or ISO 27001 certified. Those audit a company rather than a product, and claiming one we have not been through is the fastest way to fail the review this page was written for.

What we offer instead is specificity. Everything here is checkable, most of it in a minute, and anything this page misses gets answered by somebody who has read the code.

One thing we cannot do at any price: tell you which individual scanned a code. The fingerprint is salted, rotated and discarded by design, so per-person identification is not a feature we have withheld — it is a thing that does not exist here.

What you can do with it

A scan that identifies nobody

Where and when, on what, and which code — city-level from the network, never from a permission prompt. No cookie is set, and the address it arrived from is used to compute a rotating salted fingerprint and then discarded rather than stored. We cannot tell you who scanned a code, and neither can anybody who compels us.

Credentials that cannot be read back

Passwords are stretched in the browser and hashed again on the server. Sessions and API tokens are stored as hashes, never as values — a token is shown once and there is no screen, and no support path, that recovers one.

A name against every change

Who did it, when, and from where — including repointing a code, which is the one action that changes what the public sees instantly and everywhere. Our own operators are on the same trail as your team.

More in the same place

Passwords worth stealing nothing Stretched in the browser with PBKDF2-SHA256 at 600,000 iterations, salted with the account's own address so the result cannot be replayed elsewhere, then hashed again on the server. A stolen database faces the combined work factor.
Two-factor on every plan Including the free one. Single sign-on over OpenID Connect is on Enterprise, works with any provider that speaks it, and can be required so passwords stop — owners exempt, so a provider that breaks on a Friday is still recoverable.
Tokens that cannot be read back Sessions and API tokens are stored as hashes, never as values. A token is shown once at creation; no screen reads one back and no support path recovers one. Each carries only the scopes you ticked.
Three things no token can do Invite or remove a person, change anybody's role, or touch billing. Refused by the API itself rather than by policy, which means it is also true of any AI assistant you connect.
A name against every change Who, when, from where, and what changed — including repointing a code, the one action that changes what the public sees instantly and everywhere. Our operators are on the same trail as your team.
400 days, then gone Individual scan events are kept for 400 days and daily rollups for seven years, both configurable down. Old events go in a nightly job rather than on request.
Export without asking Everything is CSV at any time, from a button rather than a support ticket. Deleting a company deletes its data rather than hiding it, files in storage included.
99.9%, and what we owe you Monthly uptime for the resolution service — the part that is already out in the world and cannot be changed quickly. Enterprise agreements carry service credits of 10%, 25% or 50% of the month's fee depending on how far we missed.
An hour, and it is not a target Answered within an hour, Monday to Friday, 8am to 5pm Central, and it is the same for every plan — the free one included, because somebody stuck on a code that is already out there is stuck either way. Enterprise accounts and resellers are covered wider: answered within an hour, seven days a week, 10am to 8pm Central.

Questions

Do you store IP addresses?

No. An address is used to compute a salted fingerprint at the moment of a scan and is then discarded; it is never written to the database. The salt rotates on a schedule you set, and old fingerprints are nulled when their window closes.

Do you set cookies on the people who scan our codes?

No cookie is set on a scan. The only cookies we set are the session cookie for somebody signed in to Lynkarr itself, and the theme preference.

Who are your subprocessors?

Cloudflare for hosting, the database, file storage and bot checks; Stripe for payments; Resend for outbound email. If your account uses SSO or a Google or Microsoft sign-in button, your own identity provider is involved by your choice.

Does a card number ever touch your systems?

No. Checkout and the billing portal are Stripe's own pages on Stripe's own domain. We store a customer id, an invoice history, and the brand and last four digits Stripe reports back.

What happens to our data if we stop paying?

Nothing is deleted and nothing stops resolving. Downgrading is read-only: existing codes keep redirecting and keep recording scans, and what stops is creating new ones beyond the free allowances. You can export everything as CSV before, during or after.

Can an AI assistant we connect see everything?

Only what you granted it. A connection carries the scopes you ticked on the approval screen, and three things no connection can ever do: invite or remove a person, change anybody's role, or touch billing. It appears in Settings, API tokens and revoking it there disconnects the assistant immediately.

Do you offer an uptime SLA?

Yes: 99.9% monthly uptime for the resolution service — codes, links, pages, cards, forms and GS1 identifiers resolving. On Enterprise agreements it carries service credits of 10%, 25% or 50% of the month's fee depending on how far we missed. Other plans get the same target without a contractual remedy. The full terms, including exclusions, are at /sla.

How quickly do you answer support?

Answered within an hour, Monday to Friday, 8am to 5pm Central — the same on every plan, including the free one. Outside those hours, the next working day. Enterprise accounts and resellers are covered wider: answered within an hour, seven days a week, 10am to 8pm Central, and they can ask for a call from inside any request.

Are you SOC 2 or ISO 27001 certified?

No, and we will not imply otherwise. Those audit a company rather than a product. What we can give you is the detail on this page, all of it checkable, and a direct answer to anything it does not cover.

Try it with one code

The free plan has no expiry and asks for no card, and the analytics behind it are the same ones a paying customer gets.

Free forever for one person. No card, and 10,000 scans a month included.