The people who scan your code

  • Every editable code's destination is looked up in Google's lists of harmful links when it is saved, and a daily check goes over the destinations again, the longest unchecked first. A destination found there disables its code at once.
  • A link whose site's name is in letters that are not Latin, with which a well-known name can be imitated, is shown behind a warning page.
  • Every page qrme.to hosts for a code carries a “Report abuse” link, and a report reaches us at once.
  • The IP address of a person who scans is not written to the scan's record, and opening a short link sets no cookie, except for a code protected by a password. The detail is in the privacy notice.
  • No advertisement between the scan and its destination, and no page other than that warning.

Your account

  • A password has at least 12 characters and is stored in a form that cannot be read; repeated failed sign-ins are held back for a while.
  • Two-step sign-in with an authenticator app, and recovery codes. An organization's owner may require it of every member.
  • Your account page says on how many other devices you are signed in, and signs you out of all of them in one press.
  • Each member of an organization has a role, and every change to codes and members is recorded under the name of whoever made it.

Your data

  • Every connection to the site is encrypted (HTTPS), and browsers are told to use nothing else.
  • Cloudflare's network stands in front of the server, and the server answers nobody else.
  • Each organization's data is kept apart from the others', and automated tests check it before every update of the service.
  • Backups of the database and the files every night, encrypted on the server before they leave it.
  • An uploaded picture is checked by its content, not its name, and then encoded again: what your visitors are shown was made by us, not the file that was uploaded.
  • The server and the files are in Germany. Cloudflare's network handles requests in its centres around the world, and the encrypted backups are kept at Dropbox.

What we do not claim

  • Payment is not open yet. When it opens it will be by card, through a company that sells in its own name and handles the tax: we do not accept mada as a local network, and we do not issue a Saudi tax invoice.
  • The servers are in Germany, not in the Kingdom.
  • We hold no SOC 2 or ISO 27001 certificate.
  • The menu shows the fields that the rules of the Saudi Food and Drug Authority list; it is not “approved by the SFDA”.
  • No company can promise to exist for ever. If the service ever closes, we tell you at least 12 months before, and that period is written in the terms. Tying your codes to a domain you own, which is the complete guarantee, is not available yet.

Reporting a security flaw

If you find a flaw in qrme.to, write to security@qrme.to, in Arabic or English. Give the address affected, the steps that reproduce it, and what an attacker could do with it.

What we commit to:

  • We confirm that we received your report within five working days, and tell you what we decided about it.
  • We take no legal action against anybody who researches in good faith and keeps to what follows.
  • We name you when the fix is out, if you wish. We pay no bounties.

What we ask of you:

  • Test on your own account and your own codes, and look at other people's data no further than proving the flaw needs.
  • Do not disrupt the service, flood it with requests, or deceive account holders or our team.
  • Give us a reasonable time to fix it before you publish anything.

Reporting an abusive code

A code that leads to fraud or malware is not a flaw in the service; report it on the report page: give its short link there, and we review it.