Skip to content
Points Dynasty

Security

No loyalty-program passwords required. No bank access needed. You control what you add and what you delete.

What we never ask for

  • Airline or hotel loyalty passwords, or any program login
  • Bank or card credentials, and payment card numbers
  • Access to your email inbox
  • Passport or travel document details

Balances and status are entered by hand. That is enough for every recommendation we make.

How the service is built

  • Encrypted connections everywhere, with HTTP Strict Transport Security.
  • A strict Content Security Policy on signed-in pages, and security headers across the site.
  • You sign in with a one-time email link: no password to steal or reuse. Links expire after 15 minutes, work once, and need a click to confirm. Only a hash of each link and session is stored.
  • Optional two-step verification with any authenticator app. Administrator accounts cannot work without it.
  • Sessions live in secure, HttpOnly cookies. You can see every signed-in device and revoke any of them.
  • Access is denied by default and checked on the server for every protected request. Members can only ever read their own loyalty data.
  • Changes to program data and administrative actions are recorded in an audit log.
  • Analytics are privacy-conscious and never receive your balances, status or profile details.

Your controls

In Settings you can:

  • Export your data.
  • Delete a single program, or your whole account.
  • Change consent and alert preferences, or unsubscribe from any email.

Reporting a vulnerability

If you believe you have found a security issue, email security@points-dynasty.com. Our contact details are also published in security.txt. Please give us reasonable time to fix an issue before disclosing it.