Security, in the detail your checks will ask for
What a scan records and what it deliberately does not, where it is stored, who can reach it, how long it lives, and which companies process it on our behalf. Written to be read by the person doing the vetting rather than the person doing the buying.
What a scan records
A scan writes the country and region it came from, the hour it happened, the device type and browser family, the referring channel where the browser sends one, and which of your codes was scanned. That is the whole list.
No cookie is set on a scan. The visitor's IP address is used to compute a salted fingerprint and is then discarded rather than stored — it is never written to the database. The salt rotates on a schedule you control (ninety days by default), and when a rotation window closes the fingerprints that used the old salt are nulled, so the ability to recognise a returning visitor expires on purpose.
The consequence is worth stating because it is a real limitation as well as a feature: we cannot tell you who scanned a code, and nor can anybody who compels us. There is nothing in the database that identifies a person.
Where it lives, and who processes it
Everything runs on Cloudflare: the code in Workers, the database in D1, uploaded files in R2, and the redirect cache in KV. Data is encrypted in transit and at rest by the platform.
Four companies process data on our behalf, and there is no fifth. Cloudflare hosts everything described above. Stripe handles payments — no card number ever reaches us, because checkout happens on Stripe's own pages. Resend delivers our outbound email. Cloudflare Turnstile checks that a sign-up is a person.
If your account uses single sign-on or a Google or Microsoft sign-in button, your identity provider is involved by your own choice; we receive only the claims it sends.
Sign-in and account access
Passwords are stretched in the browser with PBKDF2-SHA256 at 600,000 iterations, salted with the account's own address so the result cannot be replayed against another account, and then hashed again on the server with a per-user random salt before storage. A stolen database faces the combined work factor.
Two-factor sign-in is available on every plan. Single sign-on over OpenID Connect is on Enterprise, works with any provider that speaks it, and can be required so passwords stop — with owners exempt, so a provider that breaks on a Friday is recoverable without us.
Sessions and API tokens are stored as hashes, never as values. A token is shown once, at creation; there is no screen that reads one back and no support path that recovers one. Each carries only the scopes you ticked, and no token can invite a person, change a role, or touch billing — those three are refused by the API itself rather than by policy.
Who did what
Every consequential action writes an audit entry: who did it, when, from which address, and what changed. That includes repointing a code, which is the one action that changes what the public sees instantly and everywhere.
Our own operators are audited on the same trail as your team, and the operator console says so on the pages where a person can see customer material.
How long things are kept, and how to end it
Individual scan events are kept for 400 days by default and daily rollups for seven years, both configurable down. Old events are deleted by a nightly job rather than on request.
Everything is exportable as CSV at any time, without asking us. Deleting a company deletes its data — codes, links, pages, cards, forms, files, events, sessions and tokens — rather than hiding it, and the files in storage are removed as the deletion drains rather than left behind.
Downgrading is read-only, never destructive. Codes carry on resolving and carry on recording; what stops is creating more. We do not hold what you have already published hostage to a plan change.
Uptime, and what happens if we miss it
We commit to 99.9% monthly uptime for the resolution service — a scan or click reaching its destination. That is the part you have already printed or published and cannot change quickly, so it is the part we put a number against.
On Enterprise agreements the commitment carries service credits: 10% of the month's fee below 99.9%, 25% below 99.0%, 50% below 95.0%, claimed within thirty days. Every other plan gets the same target and the same engineering without a contractual remedy, because a credit against a low-cost plan is a gesture rather than a guarantee and we would rather say which one you are getting.
The full document, including what does not count as downtime, is on the service level agreement page.
When you need us
Support is answered within one hour, Monday to Friday, 8am to 5pm Central. Outside those hours the answer comes the next business day.
That is a commitment rather than an aspiration, and it is the same for every plan — a free account gets the same hour as a paying one, because somebody stuck on a code that is already out in the world is stuck either way.
You reach us through the contact form or by replying to any message we send you. The reply comes from somebody who can read the code, not from a queue.
What we do not have, said plainly
We are not SOC 2 or ISO 27001 certified. Those are audits of a company rather than of a product, and claiming one we have not been through would be the fastest way to fail the review this page was written for.
What we offer instead is specificity: everything above is checkable, most of it in a minute. Ask us anything this page does not answer and you will get an answer from a person who read the code, not a form response.
One thing we cannot do at any price: tell you which individual scanned a code. The fingerprint is salted, rotated and discarded by design, so per-person identification is not a feature we have withheld — it is a thing that does not exist here.
Questions
Do you store IP addresses?
No. An address is used to compute a salted fingerprint at the moment of a scan and is then discarded; it is never written to the database. The salt rotates on a schedule you set, and old fingerprints are nulled when their window closes.
Do you set cookies on the people who scan our codes?
No cookie is set on a scan. The only cookies we set are the session cookie for somebody signed in to Lynkarr itself, and the theme preference.
Who are your subprocessors?
Cloudflare for hosting, the database, file storage and bot checks; Stripe for payments; Resend for outbound email. If your account uses SSO or a Google or Microsoft sign-in button, your own identity provider is involved by your choice.
Does a card number ever touch your systems?
No. Checkout and the billing portal are Stripe's own pages on Stripe's own domain. We store a customer id, an invoice history, and the brand and last four digits Stripe reports back.
What happens to our data if we stop paying?
Nothing is deleted and nothing stops resolving. Downgrading is read-only: existing codes keep redirecting and keep recording scans, and what stops is creating new ones beyond the free allowances. You can export everything as CSV before, during or after.
Can an AI assistant we connect see everything?
Only what you granted it. A connection carries the scopes you ticked on the approval screen, and three things no connection can ever do: invite or remove a person, change anybody's role, or touch billing. It appears in Settings, API tokens and revoking it there disconnects the assistant immediately.
Do you offer an uptime SLA?
Yes: 99.9% monthly uptime for the resolution service — codes, links, pages, cards, forms and GS1 identifiers resolving. On Enterprise agreements it carries service credits of 10%, 25% or 50% of the month's fee depending on how far we missed. Other plans get the same target without a contractual remedy. The full terms, including exclusions, are at /sla.
How quickly do you answer support?
Within one hour, Monday to Friday, 8am to 5pm Central time. Outside those hours, the next business day. The same on every plan, including the free one.
Are you SOC 2 or ISO 27001 certified?
No, and we will not imply otherwise. Those audit a company rather than a product. What we can give you is the detail on this page, all of it checkable, and a direct answer to anything it does not cover.
Try it with one code
The free plan has no expiry and asks for no card, and the analytics behind it are the same ones a paying customer gets.
Free forever for one person. No card, and scans are never metered.