Our commitment
Your receipts contain real financial information. We treat the security of that data with the same seriousness you would. QueueReceipts is built with security as a foundational requirement, not an afterthought.
Encrypted at rest
All receipt data is encrypted using AES-256 before it is written to storage.
Encrypted in transit
All data in transit is protected with TLS 1.2 or higher. Older protocols are disabled.
Regular audits
We conduct regular internal security reviews and periodic third-party penetration tests.
Encryption
Data at rest
All user data stored in our databases and file storage — including receipt images, extracted data, and account information — is encrypted using AES-256. Encryption keys are managed using a dedicated key management service with strict access controls and automatic key rotation.
Data in transit
All communication between the QueueReceipts app, website, and our servers is encrypted using TLS 1.2 or TLS 1.3. We enforce HTTPS across all endpoints and use HTTP Strict Transport Security (HSTS) to prevent protocol downgrade attacks.
Receipt images
Receipt images are stored in encrypted object storage, access-controlled by per-user credentials. Even our own engineering team cannot access the contents of your receipt vault without your authorisation.
Infrastructure
QueueReceipts runs on enterprise-grade cloud infrastructure with redundancy across multiple availability zones. Our infrastructure providers maintain ISO 27001 and SOC 2 Type II certifications.
- Network perimeter protection via managed firewalls and intrusion detection.
- Regular automated vulnerability scanning of all systems and dependencies.
- Infrastructure-as-code with version-controlled, auditable configuration.
- Automated daily backups with point-in-time recovery capability.
- Isolated production and development environments with no shared credentials.
Access controls
We apply the principle of least privilege throughout our organisation. Access to production systems and user data is:
- Restricted to a minimal number of authorised engineers.
- Granted only when required for a specific, documented operational purpose.
- Protected by mandatory multi-factor authentication (MFA) for all staff.
- Logged and audited. All access events are recorded and reviewed regularly.
- Revoked immediately upon employee departure or role change.
We do not grant permanent standing access to any production data. All elevated access is time-limited and requires explicit approval.
Account security
We offer the following features to help you keep your account secure:
- Secure password hashing: Passwords are hashed using bcrypt with a high work factor. We never store plaintext passwords.
- Multi-factor authentication (MFA): Optional TOTP-based MFA is available for all accounts and strongly encouraged.
- Session management: Sessions expire after a period of inactivity. You can view and revoke active sessions from account settings.
- Login notifications: You will receive an email alert when a new device or location signs in to your account.
- Breach detection: We check credentials against known breach databases at signup and login.
We will never ask for your password by email, phone, or any other channel. If you receive a message requesting your password, treat it as fraudulent and report it to us.
Data handling
Receipt data is used solely to provide the Service to you. It is not used for advertising, sold to third parties, or shared with partners outside of the sub-processors required to operate the Service (who are contractually bound to strict data protection standards).
When you delete your account, all associated data — including receipt images and extracted records — is permanently and irreversibly deleted within 30 days. Backups containing your data are purged on the same cycle.
Incident response
We maintain a documented incident response plan that is reviewed and tested regularly. In the event of a security incident affecting your data:
- We will investigate promptly and contain the incident.
- Affected users will be notified within 72 hours of confirming a breach, in accordance with GDPR and applicable data protection laws.
- Notifications will include what happened, what data was affected, what steps we have taken, and what you can do to protect yourself.
- We will report to the relevant supervisory authority (ICO for UK-based incidents) as required by law.
Vulnerability disclosure
We welcome responsible disclosure from security researchers. If you discover a potential vulnerability in the QueueReceipts Service, please report it to us privately before disclosing it publicly.
We ask that you:
- Report the issue to security@queuereceipts.app with sufficient detail for us to reproduce it.
- Allow us a reasonable period (typically 90 days) to investigate and remediate before any public disclosure.
- Avoid accessing, modifying, or deleting data belonging to other users during your research.
We will acknowledge your report within 5 business days, keep you informed of our progress, and credit you publicly if you wish once the issue is resolved.
Report a security issue
If you believe you have found a security vulnerability, or if you have concerns about the security of your account or data, please contact our security team directly:
QueueReceipts Security Team
For urgent account concerns, include "URGENT" in the subject line. We respond to all security reports within 5 business days.
security@queuereceipts.app