Security & Trust

How we protect your data, your identity, and the platform.

Last updated: June 2026

Data security

๐Ÿ”
TLS 1.3 in transit
All data transferred between clients and quiXzoom servers is encrypted with TLS 1.3. Older protocol versions are not accepted.
๐Ÿ—„๏ธ
AES-256 at rest
All stored data โ€” including images, metadata, and personal data โ€” is encrypted at rest using AES-256.
๐Ÿ–ผ๏ธ
Encrypted image storage
Submission images are stored in encrypted S3 buckets with strict access controls. Pre-signed URLs with short expiry are used for delivery.
๐Ÿ”‘
API authentication
OAuth 2.0 for user authentication. HMAC-SHA256 signatures on all webhook payloads โ€” verify them on your side before processing.
๐Ÿšซ
No third-party data sharing
We do not sell or share your data with third parties without explicit consent. Sub-processors are listed in our DPA.

Identity & payments

๐Ÿชช
Zoomer identity verification
All Zoomers complete KYC via Stripe Identity before they can accept missions or receive payouts. Government ID + liveness check required.
๐Ÿ’ณ
PCI DSS Level 1 payment processing
All payments processed via Stripe Connect. We never store, process, or transmit payment card data on our own servers.
๐Ÿฆ
Payout infrastructure
Zoomer payouts via Stripe Connect. SEPA for EU Zoomers, SWIFT for international. Bank details are stored and managed by Stripe โ€” not by quiXzoom.

GDPR

Data protection details
Topic Detail
Data controller quiXzoom / LandveX AB, Sweden
Legal basis (Zoomers) Contract performance โ€” processing necessary to fulfil the Zoomer service agreement
Legal basis (Organisations) Legitimate interest โ€” providing the data collection service requested
Data retention Active account data kept while account is active + 7 years (EU accounting obligations)
Right to erasure Submit requests to privacy@quixzoom.com โ€” processed within 30 days. Some financial records retained for legal obligations.
DPA Data Processing Agreement available for enterprise customers โ€” contact legal@quixzoom.com
International transfers Data processed within the EU/EEA. Where sub-processors are outside EEA, Standard Contractual Clauses (SCCs) apply.

Compliance

๐Ÿ‡ช๐Ÿ‡บ
GDPR (EU 2016/679)
General Data Protection Regulation โ€” governing collection, storage, and processing of personal data of EU residents.
๐Ÿ“‹
DAC7
EU directive on platform economy tax reporting. quiXzoom reports Zoomer earnings to relevant tax authorities as required under DAC7.
๐Ÿ”
AML / KYC
Anti-money laundering and Know Your Customer requirements fulfilled via Stripe Identity and Stripe Connect's compliance infrastructure.

Responsible disclosure

Found a security issue?

We take security reports seriously. Please email security@quixzoom.com with a description of the issue, steps to reproduce, and your contact details.

โฑ๏ธ
48-hour response
We commit to acknowledging all good-faith security reports within 48 hours.
๐Ÿค
No legal action
We do not pursue legal action against researchers acting in good faith. We ask that you do not access, modify, or expose user data beyond what is needed to demonstrate the issue.
๐Ÿ’ฐ
Bug bounty
No formal bug bounty program yet. Launching August 2026

Contact

๐Ÿ”’
Security issues
โš–๏ธ
Legal & DPA
๐Ÿ›ก๏ธ
Privacy & GDPR