Security
No loyalty-program passwords required. No bank access needed. You control what you add and what you delete.
What we never ask for
- Airline or hotel loyalty passwords, or any program login
- Bank or card credentials, and payment card numbers
- Access to your email inbox
- Passport or travel document details
Balances and status are entered by hand. That is enough for every recommendation we make.
How the service is built
- Encrypted connections everywhere, with HTTP Strict Transport Security.
- A strict Content Security Policy on signed-in pages, and security headers across the site.
- You sign in with a one-time email link: no password to steal or reuse. Links expire after 15 minutes, work once, and need a click to confirm. Only a hash of each link and session is stored.
- Optional two-step verification with any authenticator app. Administrator accounts cannot work without it.
- Sessions live in secure, HttpOnly cookies. You can see every signed-in device and revoke any of them.
- Access is denied by default and checked on the server for every protected request. Members can only ever read their own loyalty data.
- Changes to program data and administrative actions are recorded in an audit log.
- Analytics are privacy-conscious and never receive your balances, status or profile details.
Your controls
In Settings you can:
- Export your data.
- Delete a single program, or your whole account.
- Change consent and alert preferences, or unsubscribe from any email.
Reporting a vulnerability
If you believe you have found a security issue, email security@points-dynasty.com. Our contact details are also published in security.txt. Please give us reasonable time to fix an issue before disclosing it.
