Security at Loc8ID

We take the security and privacy of your location data seriously. Here's how we protect your information.

SSL Encrypted

All data transmitted via HTTPS

Privacy by Design

You control your data

Regular Backups

Automated daily backups

Our Security Measures

Data Encryption

Your data is encrypted in transit and at rest. All connections use HTTPS/TLS, and the database sits on encrypted-at-rest storage.

  • HTTPS/TLS for all connections
  • Encryption at rest for the database
  • Automated daily backups with retention + off-site copy

Secure Authentication

We employ multiple layers of authentication security to protect your account from unauthorized access.

  • Bcrypt password hashing with per-user salts
  • Two-factor authentication (2FA) available
  • OAuth integration with Google and Facebook
  • Session token management with automatic expiration
  • Rate limiting to prevent brute force attacks

Secure Infrastructure

The app runs on reputable cloud hosting, behind a CDN with a web application firewall, and with automated patching.

  • Automated security patching and updates
  • DDoS protection + Web Application Firewall (via Cloudflare)
  • Automated error alerting on the application logs

Access & Team Controls

Access to production is limited and least-privilege, and shared team workspaces have their own roles.

  • Team roles & permissions for shared workspaces
  • Least-privilege access to production systems
  • Audit logging for team actions

What we do — and don’t — with your data

Privacy isn’t a setting here — it’s the default. The specifics:

  • Photos are stripped of EXIF & GPS metadata before they’re stored — your camera’s hidden coordinates never ride along.
  • We don’t store visitors’ IP addresses. Visit stats are coarse only (approximate country / region, device, referrer) — never a raw IP.
  • No ads, no third-party ad trackers. Our usage analytics are first-party and cookieless.
  • We make money from subscriptions, not from your data. We never sell it or hand it to advertisers.
  • No account or app needed to open a link — anyone opens it in a browser.
  • You stay in control — expire or delete any link anytime; deleting your account removes all associated data (export available on request).

Responsible Disclosure

We value the security research community and welcome responsible disclosure of security vulnerabilities.

How to Report a Vulnerability

  1. Email us at security@loc8id.com with details of the vulnerability
  2. Include steps to reproduce the issue and potential impact
  3. Give us reasonable time to address the issue before public disclosure
  4. Do not access or modify data belonging to others

Our Commitment

  • We will respond to your report within 48 hours
  • We will keep you informed of our progress
  • We will credit you in our security acknowledgments (if desired)
  • We will not take legal action against good-faith security research

Your Privacy Rights

Access & export

See what we hold and get a copy of your data on request.

Delete anytime

Delete a link or your whole account — deletion removes all associated data.

Questions About Security?

We're happy to discuss our security practices and answer any questions.

Contact Our Security Team