VivaPoints
ВойтиНачать

Allowed domains and keeping your embed secure

Why you list the sites allowed to show your widget, and what happens when someone else tries.

Обновлено: 26 июля 2026 г.

Your widget only loads on websites you have listed. Everywhere else, the browser refuses to render it at all. This page explains what that protects you from, and how to read it when something is blocked.

What the list is for

The snippet you paste is not a secret. It is HTML on a public page, so anyone who views your source can copy it — and without a domain list, they could paste your widget onto their own site and collect your customers' email addresses behind a login box that looks like yours.

The list closes that. When a browser is asked to display your widget inside a page, we tell it which websites are allowed to do that. If the page it is embedded on is not on your list, the browser refuses before anything renders. Not an error message the copier could style around — nothing at all.

The check is done by the browser, on instruction from us, not by your website. Someone who copies your snippet cannot disable it by editing their own page, because the instruction does not come from their page.

Listing a website

Website widgetWebsites allowed to show it. One per line.

You wantYou list
example.comexample.com
www.example.com tooAdd it as a separate line
Any subdomain — shop, blog, book*.example.com
A staging site on a different addressAdd it, and remove it when you are done

Write the address only: no https://, no path, no trailing slash.

www counts as a different website. This trips up nearly everyone. If visitors can reach you both ways, list both, or you will get reports that the widget "sometimes" works.

What happens to someone who copies your snippet

They get a blank space. The widget never loads, no sign-in box appears, and no customer of yours can be asked for anything on their page.

What we do on our side

You do not have to configure any of this, but it is worth knowing what is protecting your customers.

  • A code is not a password. It is six digits, expires in ten minutes, can be used once, and stops accepting attempts after five wrong tries.
  • Asking for a code tells an attacker nothing. The widget answers identically whether or not an address belongs to one of your customers, so it cannot be used to test whether someone shops with you. This is also why a customer who typed the wrong address gets no warning — see Adding the widget.
  • Codes are rate-limited, per address and per source, so nobody can grind through guesses.
  • A signed-in session is locked to your business. It carries no access to any other business, and it cannot see the customer's wider VivaPoints profile.
  • We store no readable email address in the code system. Addresses and codes are stored scrambled, one way. A copy of that data would not tell anyone who your customers are.
  • Nothing personal ever travels in a web address. No email in a link, no code in a URL, so nothing lands in your server logs or in a shared browser's history.

Signing everyone out

Sign everyone out in the widget settings ends every customer's signed-in session immediately. They can sign in again with a fresh code, so it is not destructive — use it if you think a shared or public computer has been left signed in, or after you remove a website from your list.

Removing a website from the list stops the widget rendering there straight away.

What to do if something looks wrong

  • The widget shows nothing on your own site. Check the address in the browser bar matches your list, including www, then check the widget is switched on.
  • You find your widget on a site you do not recognise. Check your list first — it is almost always an old staging domain someone added. If the site genuinely is not on your list, it is not rendering for anyone.
  • A customer says they got a code they did not ask for. Somebody typed their address into your widget. The code alone grants nothing, and it expires in ten minutes. If it repeats, tell us.

What this does not cover

The list protects the widget. It does not protect your website — if your own site is compromised, an attacker could add a fake login box that has nothing to do with us. And it says nothing about who works for you: anyone with access to your dashboard can change the list. See Team members.

Читать дальше

Всё ещё не получается?

Напишите нам, и вам ответит человек.

Написать в поддержку