Security
How we protect data
- Bank access is read-only, through a licensed open-banking provider. Dueo never stores bank login details and cannot move money.
- Dueo never collects or holds rent.
- Gift card codes are encrypted and shown only to their owner.
- Points are recorded in a ledger where entries are added, never edited or deleted.
- Payment data is used only to run the rewards programme. It is never sold or shared with partners.
- This website sets no cookies and runs no tracking tools.
Report a vulnerability
If you believe you have found a security issue in Dueo, email [SECURITY EMAIL] with a description and the steps to reproduce it.
- We acknowledge reports within [NUMBER] working days and keep you informed until the issue is fixed.
- Please do not access, change or delete data that is not yours, do not disrupt the service, and give us reasonable time to fix the issue before disclosing it.
- We will not take legal action against research done in good faith under these rules.
Machine-readable contact: security.txt