We use cookies and similar technologies to run the site, keep you signed in, remember your preferences, and understand how the site is used. See our Cookie Policy and Privacy Policy.

Manage
Loading recent #names…
Web3 — Gigi Geo Portals

← Back to app

Security Overview

Last updated: April 10, 2026

1. Overview

hashtag.org is built for a public, location-based platform with accounts, creator monetization, messaging, and real-time communication. Security is integral to protecting users, payments, and content. This page summarizes our practices at a high level. It is not an exhaustive contract or guarantee; see our Terms of Service for limitations of liability.

2. Encryption in transit

We use HTTPS (TLS) for connections between your browser and our services where standard deployments are configured correctly. Always check for the padlock in your browser and avoid entering credentials on untrusted networks without a VPN.

3. Accounts and authentication

  • Passwords are stored using strong one-way hashing—we do not store plaintext passwords.
  • Session cookies or tokens used for authentication are configured with security attributes appropriate to our stack (for example HTTP-only cookies where applicable to reduce exposure to script).
  • You are responsible for choosing a unique password and keeping devices secure.

4. Payments and card data

Card and bank payment details for subscriptions, vault purchases, creator payouts, and similar flows are handled by certified payment processors (for example Stripe). We typically receive tokens and transaction metadata—not your full card number. PCI DSS obligations for card data rest primarily with those processors and their integration patterns.

5. Infrastructure and operations

We apply reasonable administrative and technical measures appropriate to our stage of service: access controls for production systems, dependency and security updates as practicable, logging and monitoring for operational and abuse-detection purposes, and rate limiting on sensitive APIs where implemented.

6. User content and communications

Messages, portal media, and call signaling pass through our systems and/or third-party providers (for example real-time video). You should treat highly sensitive information with care; no online service can promise absolute confidentiality against all threats.

7. Your responsibilities

  • Use unique passwords; consider a password manager.
  • Enable OS and browser updates on devices you use for the Service.
  • Report suspected account compromise to the site operator promptly.
  • Be cautious of phishing: we will not ask for your password by email.

8. Reporting vulnerabilities

If you believe you have found a security vulnerability in hashtag.org, please report it responsibly via our security contact form with enough detail to reproduce the issue. Avoid accessing or exfiltrating user data beyond what is necessary to demonstrate the flaw. We appreciate coordinated disclosure and will work to address valid reports in line with our capacity.

9. Privacy

For what data we collect and why, see our Privacy Policy and Cookie Policy.