Data Processing & Security Statement
Last updated: 7/30/2026 · Effective for QR-Powered Identity™ ("the Service")
This statement is a technical companion to our Privacy Policy, for Avatars who want to understand how the personal data they enter — their own account details, their technicians', and their homeowners' — is actually stored and protected.
Roles: controller and processor
For an Avatar's own account and billing information, QR-Powered Identity acts as the data controller. For personal data an Avatar enters about their technicians and homeowners in order to run a dispatch, we act as a data processor on that Avatar's behalf — the Avatar decides what information to collect and why; we process it to make the Service work.
Access controls
- Every Avatar's data is isolated at the database level — row-level security policies scope each account to only its own organization's records, enforced on every query, not just at login
- Internal admin access (for support and platform operations) is gated on every single request, not just once at sign-in
- Passwords are never visible to us in plain text — authentication is handled by our identity provider, Supabase, using industry-standard hashing
Encryption
- Data in transit is encrypted (HTTPS/TLS) between your browser, our application, and our infrastructure providers
- Data at rest is encrypted by our database provider's infrastructure
- We never store full payment card numbers — Stripe handles and stores that directly
Verifying who's really talking to us
Payment, text message, and email events that update your account (a payment succeeding, a text being delivered, an email arriving) come from Stripe, Twilio, and Resend over webhooks. Each of these is cryptographically signature-verified before we act on it, so a request can't spoof its way into changing your account's data by pretending to come from one of these providers.
Untrusted content handling
Inbound email content (from homeowners or anyone else writing to us) is rendered in a sandboxed frame with scripts disabled before an admin ever views it, so a malicious email can't run code in our admin console.
Audit trail
Significant account, dispatch, payment, and notification events are recorded in an internal activity log at the moment they happen, giving us — and, on request, you — a record to investigate any account activity after the fact.
Sub-processors
The same providers listed in our Privacy Policy: Supabase (database and authentication), Vercel (application hosting), Stripe (payments), Twilio (SMS), Resend (email), and Google Maps Platform (address and geocoding, where configured).
Data location
Our primary database is hosted in the United States. If you operate outside the United States, this may mean your data — and any personal data you enter about your technicians or homeowners — is processed and stored in a different country than the one you or they are in.
Security incidents
If we become aware of a security incident that affects your account's data, we will notify you without undue delay once we understand what happened and who's affected.
Your data, your requests
To request a copy, correction, or deletion of data associated with your account, see the "Your choices" section of our Privacy Policy.
Contact us
Security questions or to report a suspected vulnerability: legal@qr-poweredidentity.com
qr-poweredidentity.com