Send Listy

Feature: Privacy Safeguards

  • Invitation and Payment Privacy Safeguards

    Plan invitations

    • Invitation tokens are signed; raw long random tokens are not stored as the invitation identity.
    • Invite codes exclude ambiguous characters.
    • Invitations expire and become one-use after acceptance.
    • Targeted invitations are restricted to the intended account or email.
    • Exact-user search requires an exact email address or username and is rate-limited.
    • Invitation QR codes are generated locally in the browser instead of sending the invitation URL to an external QR service.

    Payment processing

    Payment operations use server-side permission and request checks, current plan pricing, verified provider callbacks, duplicate-event protection, and secret redaction. Payment-provider credentials are kept inside the billing integration rather than exposed to the general account interface.

    Scope

    These are safeguards supported by the current Send Listy implementation. They do not replace the site’s legal Privacy Policy, payment-provider terms, or other legal disclosures.