Skip to content

Security and privacy

Your contacts are other people's data. We treat them that way.

Nexus holds the details people share when they meet you. Here is exactly how we protect them, where they live, who helps us run the service and how you stay in control.

Primary data regionEuropean Union
  • Encrypted field by field

    AES-256-GCM on contact details, lead submissions, activation codes, integration tokens and webhook secrets, with key rotation.

  • TLS everywhere, HSTS on

    Every connection is encrypted in transit. A strict content security policy limits what any page can load.

  • Hardened sign-in

    Scrypt password hashing, breached-password checks, optional two-factor codes, rate limits and session control.

  • No tracking cookies

    Anonymous analytics with daily-rotating salted hashes. Visitor IP addresses are never stored.

  • Hosted in European Union

    Database, backups and uploaded files stay in our primary region.

  • GDPR rights built in

    Export and deletion on request, consent recorded with a timestamp, and a DPA for business customers.

Encryption in transit

All traffic to Nexus, including the marketing site, the dashboard, public profiles and APIs, is served over TLS. We send HTTP Strict Transport Security (HSTS) so browsers refuse to connect without it.

Pages are served with a strict Content Security Policy using a per-request nonce, plus framing protection, so injected scripts and clickjacking attempts are blocked by the browser.

Encryption at rest

Our database and file storage are encrypted at rest by our infrastructure providers. On top of that, we encrypt the most sensitive fields ourselves, in the application, before they reach the database:

  • Contact details people share with you (name, email, phone, company, message)
  • Lead form submissions
  • Card activation codes
  • Integration tokens, such as HubSpot connections
  • Webhook signing secrets

These fields use AES-256-GCM with keys held outside the database. Keys carry an identifier so we can rotate to a new key without downtime; older records stay readable and are re-encrypted over time.

To look up an encrypted email address without decrypting everything, we store a blind index: a keyed hash that lets us find an exact match but can't be reversed into the address.

Accounts and sign-in

  • Passwords are hashed with scrypt, a deliberately slow, memory-hard algorithm. We never store or see your password.
  • New passwords are checked against known data breaches using a privacy-preserving range query; only a short prefix of a hash ever leaves our servers.
  • Optional two-factor authentication with an authenticator app (TOTP), plus single-use backup codes.
  • Sessions expire after 14 days, you can see and sign out other sessions, and resetting your password signs out every other session.
  • Sign-in, password reset and other sensitive endpoints are rate limited.

Application security

  • Rate limiting on sign-in, contact exchange, lead forms and sales requests, enforced across every server.
  • Bot protection on public forms, using hidden honeypot fields and minimum fill times, without third-party captchas that track visitors.
  • Uploads are re-encoded. Every image that appears on a profile is decoded and re-saved by our servers, which strips EXIF metadata, including GPS location, and neutralises malformed files. Print files you send us for your card are checked by content, stored privately and only ever opened by our production team.
  • Least privilege. Server code checks ownership on every request; people can only ever reach their own profiles, cards and contacts, or their team's.
  • Audit log. Security-relevant actions such as sign-ins, plan changes and administrative changes are written to an audit log.

Privacy-first analytics

Profile analytics tell you how many people viewed your profile, saved your contact or opened a link. They're designed so we never need to identify visitors:

  • No cookies, local storage or fingerprinting scripts on public profiles.
  • To count unique visitors, we combine the request's IP address and browser with a random salt that changes every day, hash the result, and store only a short hash. Salts are deleted after two days, so hashes can't be linked across days or reversed.
  • The IP address itself is never stored with analytics. Country and city are looked up in memory at request time and only the result is kept.

Infrastructure, region and backups

Nexus runs on managed infrastructure in our primary data region, European Union. The database, its backups and uploaded files are kept in that region.

Backups are encrypted and retained for a limited period so we can recover from failure. Access to production systems is limited to a small number of named engineers and administrators.

Staff access to customer accounts for support is restricted to administrators and time-limited to 30 minutes per session. Administrative actions are recorded in the audit log.

GDPR and your data

Who is responsible for what

For your own account (your name, email, profile and billing), Nexus is the controller.

For contacts and leads collected through your profile, you are the controller and Nexus is your processor. We process that data only to provide the service to you, under our data processing agreement.

Lawful basis and consent

When someone shares their details through Exchange or a lead form, they must tick a consent box that names you. We store the time consent was given alongside the submission, so you can show where every contact came from.

Your rights

  • Access and portability (Art. 15 and 20): export your profile, contacts and analytics from the dashboard, or ask us for a full copy.
  • Erasure (Art. 17): delete individual contacts yourself, or delete your whole account. We also act on requests sent to hello@nexustap.co.
  • Rectification (Art. 16): edit your profile and account details at any time.

Business customers can review and accept our data processing agreement, which includes standard contractual clauses where needed.

Retention

  • Analytics events: about 25 months, then deleted automatically.
  • Daily analytics salts: deleted after 2 days.
  • Rate-limit records: deleted after 1 day.
  • Webhook delivery logs: 30 days.
  • Closed sales requests: 2 years.
  • Account data, profiles and contacts: kept while your account is active and deleted when you delete your account, apart from what we must keep by law (such as invoices).

Subprocessors

We use a small number of carefully chosen providers to run Nexus. Each is bound by a data processing agreement. We'll update this list before adding a new subprocessor that handles personal data.

Subprocessors used by Nexus
ProviderPurposeData involvedWhen it's used
RailwayApplication hosting and databaseAll service dataAlways
CloudflareDNS, content delivery and R2 file storageRequests, uploaded images and filesAlways
ResendTransactional emailEmail address, email contentWhen we send you email
StripePayments and invoicingBilling name, email, payment detailsWhen card payments are enabled for your account
HubSpotCRM syncContacts you choose to syncOnly if you connect your HubSpot account
Google and AppleWallet passesThe profile details on the passOnly when a visitor chooses to add your card to their wallet

Responsible disclosure

Found a vulnerability? Please email hello@nexustap.co with the details and steps to reproduce. We'll acknowledge your report, keep you updated and credit you if you'd like.

Please don't access other people's data, run denial-of-service tests or use automated scanners against production. Our security.txt follows RFC 9116.

Need more for your security review?

We're happy to answer questionnaires, walk your team through our architecture and sign a DPA.