Keeping your data secure.
It’s fundamental to how we build.
This page describes the security controls Pointerly has in place today: the infrastructure we rely on, how we protect data, and who can access it.
Last updated: October 1, 2026
Infrastructure
Pointerly runs on managed cloud infrastructure. We do not operate our own data centres. Our core providers are:
Supabase (on AWS)
Database, authentication, file storage, and encrypted secret storage (Vault). Enforces row-level security at the database layer.
Vercel
Application hosting, serverless functions, and content delivery network for the website, web app, and short links.
Stripe
Payments. Card details are entered on Stripe and stored by Stripe, which is certified as a PCI DSS Level 1 service provider. Pointerly never receives card numbers.
Production is separated from development and preview environments, and changes reach production through a controlled build and deployment process. Access to production infrastructure is limited to authorized personnel. The full list of providers that process data is on our Subprocessors page.
Encryption and secrets
- In transit: connections to Pointerly and between Pointerly and its providers use TLS.
- At rest: the database and file storage are encrypted at rest by our infrastructure provider.
- Connection tokens and keys: OAuth tokens for connected accounts, Telegram bot tokens, AI provider keys you add, and affiliate partner credentials are stored encrypted in Supabase Vault and decrypted only on our servers when needed. They are not returned to the browser.
- Platform secrets: our own API keys and signing secrets are kept in encrypted environment configuration, not in source code or client-side bundles.
Workspace isolation and permissions
- Row-level security: workspace data is protected by PostgreSQL row-level security policies, so a signed-in user can only read data from workspaces they belong to, even if application code made a mistake.
- Server-side authorization: server actions and API routes check who is calling and which workspace and resource they are acting on before reading or changing data.
- Roles: workspace members have roles, and owners and admins control membership, billing, and connected accounts.
- API keys are scoped to the workspace that created them and can be revoked at any time.
Authentication
- Sign-in is handled by Supabase Auth. Passwords are stored as salted hashes, never in plain text. You can also sign in with Google, Apple, Facebook, and other providers.
- You can turn on multi-factor authentication with an authenticator app.
- Sign-up, waitlist, and contact forms are protected against bots with Cloudflare Turnstile.
- Sessions use secure cookies, described in our Cookie Policy, and you can sign out of sessions from account settings.
Staff and operator access
- Pointerly staff access customer data only when needed to provide support you ask for, keep the service secure, investigate abuse, or comply with law.
- Access to administrative tools requires a staff account with the specific permission for that tool and a session verified with multi-factor authentication.
- Delegated Workspace operators can enter only the workspaces assigned to them, must use a Pointerly company email address and multi-factor authentication, and work within an operator role that excludes billing, members, API keys, and the browser extension.
- Staff access changes and operator assignments are recorded in audit logs.
Application security
- Input is validated on the server before it is processed or stored.
- Database access uses parameterized queries.
- User-provided HTML is sanitized before it is displayed, and React escapes output by default.
- We send security headers such as
X-Content-Type-Options,Referrer-Policy,Permissions-Policy, and framing controls (X-Frame-Optionsor aframe-ancestorspolicy for bio pages). - Actions that the Poppy assistant proposes in your workspace need your confirmation through a signed, single-use token before they run.
- Dependencies are reviewed and updated to address known vulnerabilities.
Integrations and webhooks
- Integrations use OAuth with the permissions each feature needs. You can disconnect them at any time.
- Incoming webhooks, for example from Stripe and Meta, are verified with the provider's signature or a shared secret before they are processed.
- Scheduled jobs and internal endpoints require a secret that is not exposed to browsers.
Link traffic and visitor data
- Short links record the data our customers need for analytics, described in our Privacy Policy. We store only the major version of a visitor's operating system, to limit fingerprinting.
- Clicks from user agents that look automated are flagged as likely bots.
- Short links do not set tracking cookies and do not load our website analytics tools.
Restricted partner data
Amazon Ads API and Creator Connections data is classified as restricted partner data. It is not sold, it is excluded from default automated third-party exports, and any allowed export must be started by the customer to their own connected destination and is recorded with the user, workspace, destination, data type, and time. Partner credentials are stored encrypted and never exposed to the browser. If a security incident involves Amazon information, we report it to Amazon as our agreements with Amazon require.
Logging and audit
- We log sign-in, security, billing, export, and administrative events to detect, investigate, and respond to problems.
- Logs are access-restricted and used for security, support, debugging, and compliance.
- We avoid logging secrets and access tokens.
Incident response
When we learn of a security incident, we:
- contain it and preserve evidence;
- work out which systems, data, customers, and partners are affected;
- rotate or revoke affected credentials;
- notify affected customers, regulators, and partners where the law or our contracts require it;
- fix the cause and review what we should change.
Account deletion
You can delete your account from account settings. Access is revoked immediately and your personal account data is deleted from active systems after a 30-day grace period. Workspaces you own are transferred to a member you choose or archived, and an archived workspace is permanently deleted 12 months later. Copies can remain in encrypted backups for up to 8 days. See our Privacy Policy for details.
Your part
Security is shared. Use a unique password, turn on multi-factor authentication, give workspace members only the access they need, remove people who no longer need access, keep API keys secret, and disconnect integrations you no longer use. Tell us right away at security@pointerly.io if you suspect someone has accessed your account.
Certifications
Pointerly does not currently hold its own security certification, such as SOC 2 or ISO 27001. Our core infrastructure providers publish their own certifications and audit reports. We will update this page if that changes.
Responsible disclosure
If you believe you have found a security vulnerability in Pointerly, email security@pointerly.io with a description, the steps to reproduce it, and its likely impact. We aim to acknowledge reports within 5 business days and will keep you informed while we fix the issue.
When you research vulnerabilities, please:
- use only accounts and workspaces you own or have permission to test;
- not access, change, or delete other people's data, and stop and tell us if you reach it by accident;
- not run denial-of-service tests, spam, social engineering, or physical attacks, and not send messages through connected platforms to people who have not agreed to it;
- give us reasonable time to fix the issue before telling anyone else.
If you follow these rules and act in good faith, we will not take legal action against you for your research and will consider it authorized under our Terms. We do not currently run a paid bug bounty program.
Version history
- October 1, 2026: Rewritten to describe only controls that are in place today, including encrypted token storage, staff and operator access, and a responsible disclosure policy with safe harbour.
- April 30, 2026: Previous version.