Security is core to what Deposiq does: we sit at the moment money and trust first change hands. This page describes, in plain English, how we protect your data.
The Service runs on dedicated infrastructure hosted in the European Union (Hetzner, Germany/Finland). Data is not transferred outside the EU/EEA.
All traffic is encrypted in transit over TLS/HTTPS, with HSTS enforced. Data is encrypted at rest, and backups are encrypted.
Deposiq never stores card numbers and never holds your funds. Card deposits are processed by Stripe or Mollie on your own connected account; PCI-DSS obligations for card data are met by these certified providers.
Every photo or document attached to a deposit is fingerprinted with SHA-256, and every action is timestamped in an audit trail — so evidence can be justified in a dispute and cannot be quietly altered afterwards.
Data is backed up regularly to encrypted, off-site storage, so it can be restored after an incident.
If you believe you have found a security vulnerability, please email security@deposiq.com. We welcome good-faith reports and will respond promptly. Please do not access data that is not yours or disrupt the Service while testing.
Cookies. We’d like to use Google Analytics to understand how the site is used. Nothing runs unless you accept — and you can change your mind anytime. See our Privacy Policy.