Security at Loc8ID
We take the security and privacy of your location data seriously. Here's how we protect your information.
SSL Encrypted
All data transmitted via HTTPS
Privacy by Design
You control your data
Regular Backups
Automated daily backups
Our Security Measures
Data Encryption
Your data is encrypted in transit and at rest. All connections use HTTPS/TLS, and the database sits on encrypted-at-rest storage.
- HTTPS/TLS for all connections
- Encryption at rest for the database
- Automated daily backups with retention + off-site copy
Secure Authentication
We employ multiple layers of authentication security to protect your account from unauthorized access.
- Bcrypt password hashing with per-user salts
- Two-factor authentication (2FA) available
- OAuth integration with Google and Facebook
- Session token management with automatic expiration
- Rate limiting to prevent brute force attacks
Secure Infrastructure
The app runs on reputable cloud hosting, behind a CDN with a web application firewall, and with automated patching.
- Automated security patching and updates
- DDoS protection + Web Application Firewall (via Cloudflare)
- Automated error alerting on the application logs
Access & Team Controls
Access to production is limited and least-privilege, and shared team workspaces have their own roles.
- Team roles & permissions for shared workspaces
- Least-privilege access to production systems
- Audit logging for team actions
What we do — and don’t — with your data
Privacy isn’t a setting here — it’s the default. The specifics:
- Photos are stripped of EXIF & GPS metadata before they’re stored — your camera’s hidden coordinates never ride along.
- We don’t store visitors’ IP addresses. Visit stats are coarse only (approximate country / region, device, referrer) — never a raw IP.
- No ads, no third-party ad trackers. Our usage analytics are first-party and cookieless.
- We make money from subscriptions, not from your data. We never sell it or hand it to advertisers.
- No account or app needed to open a link — anyone opens it in a browser.
- You stay in control — expire or delete any link anytime; deleting your account removes all associated data (export available on request).
Responsible Disclosure
We value the security research community and welcome responsible disclosure of security vulnerabilities.
How to Report a Vulnerability
- Email us at security@loc8id.com with details of the vulnerability
- Include steps to reproduce the issue and potential impact
- Give us reasonable time to address the issue before public disclosure
- Do not access or modify data belonging to others
Our Commitment
- We will respond to your report within 48 hours
- We will keep you informed of our progress
- We will credit you in our security acknowledgments (if desired)
- We will not take legal action against good-faith security research
Your Privacy Rights
Access & export
See what we hold and get a copy of your data on request.
Delete anytime
Delete a link or your whole account — deletion removes all associated data.
Questions About Security?
We're happy to discuss our security practices and answer any questions.
Contact Our Security Team