Stocktakes Online — Barcode Datalink
Security · Barcode Datalink Pty Ltd

Where your data sits, who can reach it, and what we have not got.

If somebody in your business has been asked to check us out before you hand over your stock figures, this page is for them. It is written to be forwarded.

We are a small Australian company under the turnover threshold where the Privacy Act starts to apply, so we are not required to publish any of this. We publish it anyway. You should not have to take a supplier's word for where your data lives — and a supplier who will not write it down is telling you something.

The companion page is Privacy, which covers what we hold and how to delete it. This one covers how it is kept.

Where it lives

Sydney. It does not leave the country.

01

Australia, and only Australia

The portal and its database run in DigitalOcean's Sydney region, on managed PostgreSQL — encrypted on disk, encrypted in transit, with automated nightly backups and point-in-time recovery. Your parts, your bins and your counts are not copied to another country.

02

One database, many companies

We do not run a separate server per client, and we would rather say so than let you assume otherwise. Every read is scoped to your company from the signed session token, not from anything the caller sends. A scanner never transmits a company id, so it cannot reach another client's data by guessing one.

03

Cloudflare carries it, and keeps none of it

Cloudflare answers DNS for our domain, carries our mail and serves this website. DigitalOcean run their platform behind Cloudflare as well, so a Cloudflare edge — in Sydney — passes the portal's traffic through too, and sets one bot-protection cookie. Nothing is stored with them. Your data lives in the database. Nothing else is in the path.

The scanner

A lost scanner carries nothing to lose.

This is the part most people do not expect, and it is worth understanding, because it removes an entire category of risk rather than managing it.

01

No database on the device

There is no local copy of your catalogue, no cache and no queue. Every lookup and every count is a live call to the portal. A scanner left in a taxi holds no part numbers, no quantities and no history — there is nothing on it to extract.

02

No stored credentials

The login screen remembers the company and site, so a scanner living at one warehouse does not have them retyped every shift. It never remembers a username or a password, and nothing a count depends on is held on the device.

03

A count that did not arrive is reported

Because nothing is queued locally, the operator is told at the rack if a count did not reach the portal. This is a data-integrity property first, but it is a security one too: there is no offline store to go missing or to be tampered with.

Signing in

Passwords are not stored anywhere, including here.

01

Hashed, not kept

We hold a scrypt hash and nothing else. scrypt is memory-hard on purpose: a stolen hash cannot be attacked with rented graphics cards the way an older scheme can. We could not tell you your password if you rang and asked, which is why a forgotten one is reset rather than looked up.

02

Guessing is throttled

Five failed attempts inside a minute locks that account for five minutes. It is counted per account, so somebody working through a password list against one login gets nowhere, and a colleague signing in normally is unaffected.

03

Sessions are signed and expire

A session is an HMAC-SHA256 signed token lasting eight hours, then it is finished. Everything is over HTTPS — the scanner app is configured to refuse plain HTTP outright, not merely to prefer HTTPS.

Who can see it

Your people, and one of ours.

01

Your administrators

You create your own logins and decide who is an administrator. Usernames are unique within your company only, so your staff list is yours — another client having a "jason" has no bearing on yours.

02

Turning a login off works immediately

Every request re-checks that the account is still active. Switch somebody off and their session stops on their next tap, not in eight hours' time. It is the answer to "one of our counters walked out mid-stocktake", and it works from your own screen without ringing us.

03

One person here, and he is named

Andrei Spiegel holds the provider account and can open any company, because that is how a client is set up and how a locked-out administrator is rescued. There is no way to sell and support the product without it, so we name it rather than let you discover it.

There is no support team, no offshore contractor and no third-party access to your account. No analytics, no tracking pixels, no advertising tags and no chat widget anywhere on this site or in the portal.

Our sub-processors are short enough to list in full: DigitalOcean, who host the portal and its database in Sydney, and Cloudflare, who answer our DNS, carry our mail and pass traffic through. That is the entire list. Every typeface, script and image is served from our own domain — the fonts came from Google until we moved them here. The Privacy page names the one cookie this site sets and who sets it.

Being straight about it

What we have not got.

If this section decides it against us, that is a fair outcome and we would rather you reached it now than after an invoice.

01

No ISO 27001, no SOC 2

Our host holds those certifications for their platform. We do not hold them for ours, and we will not borrow theirs to imply otherwise. They are a five-figure annual exercise, and buying one before a single customer had asked would put the cost into your invoice for a badge rather than into the product.

02

No two-factor sign-in yet

A username and a password is what stands between somebody and your account. Given that a stocktake runs for days rather than all year, and that a scanner in a warehouse is a poor place to receive a code, it has not come first — but it is honest to say it is not there.

03

No independent penetration test

Nobody outside this company has been paid to attack the portal. What we can say is that the surface is deliberately small, the portal loads no code from anybody else at all, and every tenant boundary is enforced in one place rather than remembered in nineteen.

And we will not tell you nobody could ever get in. Nobody honest says that. What we will say is what we would do: if something happened to your data you would hear it from us — quickly, in plain words, and before you read it somewhere else.

If your own IT people have questions this page does not answer, ring and ask. You will get a straight answer or you will get "I do not know, let me find out" — not a brochure.

Your data stays yours

You can take it out, and you can delete it.

Every report exports to CSV, so nothing is trapped here in a format only we can read. When a stocktake is over you can empty the account yourself, and the Privacy page sets out exactly what that removes and what it cannot undo. There is no notice period, no exit fee and nothing to ask permission for.

Still want to check something?

It is one person, and he answers.

Ring 0414 53 53 95 or email [email protected]. We have been supplying barcode systems to Australian business since 1991 on the basis that what we say is what happens, and this page is held to the same standard as a handshake.

Barcode Datalink Pty Ltd
12 Preston Way, Berowra NSW 2081.