Security & Privacy
We build Khatm responsibly and claim only what we can prove today. As our infrastructure matures, we keep this page current — the goal is thoughtful, verifiable protection, never overstated promises.
Encryption & access control
Stored data is encrypted at rest with AES-256 on Supabase. Traffic between your browser and our servers travels exclusively over TLS 1.2 or higher. Every table holding user data is guarded by Row-Level Security, so no account can read another account’s rows.
Contact privacy & consent
You control what your public card reveals. Keep your phone number or contact details private, and they are never exposed just by opening your link or scanning your QR. To reach you, a visitor signs in and sends a connection request — and you choose whether to share. Nothing private is revealed without your consent.
Where your data lives
Our infrastructure runs on Supabase in the Mumbai, India region (ap-south-1). When you sign up, you give explicit consent to this cross-border transfer of your data.
Your rights under PDPL
You can access your data, correct it, delete it, port it to another provider, and withdraw consent at any time. To exercise any of these rights, contact security@qrkhatm.com
What we don't do
We do not sell your data. We do not share it with third parties for marketing. We do not use ad tracking or browser fingerprinting, and we set no advertising cookies.
Security roadmap
Reporting a vulnerability
Found a security vulnerability? Please report it to security@qrkhatm.com before any public disclosure. We aim to acknowledge every report within 5 business days.
This service is operated by XDIGITAL SERVICES (FZE), SPARK Free Zone, Sharjah, United Arab Emirates. Product brand: QR Khatm (ختم).
For any questions, contact us at support@qrkhatm.com