Trust
Pizzy is designed so check-in is hard to fake, presence is meaningful, and event data does not outlive its purpose.
Host QR codes refresh on a short interval. Expired tokens are rejected so screenshots cannot grant lasting access.
Hosts can require attendees to be near the venue. Location is used for verification context, not continuous tracking.
Hosts choose how long event data remains after the event ends. Ephemeral by design — rooms are not permanent archives.
Authentication is handled through a managed auth provider with industry-standard session handling. Billing is processed by Paddle.
Responsible disclosure
If you believe you have found a security issue, contact admin@techandhi.com with enough detail for us to reproduce it. Please avoid testing against live events you do not own.