When people hear that OrangeTill generates QR codes for Bitcoin payments, a reasonable question follows: what does OrangeTill see? Can the company see your wallet? Your balance? Your transaction history? Could someone at OrangeTill access your funds?

The answer to all of those is no — and that's not a policy decision. It's a structural one. This article explains exactly why, at three distinct levels: the app itself, our backend server, and the blockchain. Each layer has its own reason for being blind, and together they form something more trustworthy than a promise: a system where access is technically impossible.

₿
Hodl’s note: This article gets into how the app actually works under the hood. If you want the short version: we are a display tool. We show a number and a QR code. A payment happens between two wallets on the blockchain. We are not in that chain. We never were.

The three layers of blindness

🔋 Layer 1 — The App

Your settings never leave your device

Wallet addresses, display currency, tip settings, and note shortcuts are stored in your browser’s own localStorage — on your device. The charge screen, QR code generation, and crypto equivalent calculations all happen locally. When a payment is made, it happens directly between your customer’s wallet and yours. OrangeTill is not in the middle.

☁️ Layer 2 — Our Server

The Worker knows almost nothing

Our backend handles authentication and subscriptions — not payments. It stores your email address, your plan status, and optionally your wallet addresses if you’ve enabled a public profile. It has never received a payment notification, never observed a transaction, and has no way to know whether anyone has ever paid you.

🔗 Layer 3 — The Blockchain

Even your wallet address is the wrong thing to worry about

A wallet address is public by design. Anyone can see it — that’s how someone sends you money. But seeing an address gives you nothing. Moving funds requires a private key, which OrangeTill has never seen, never stored, and never asked for. A wallet address without the private key is like a transparent mailbox: you can see what’s inside, but you cannot open it.

What the app actually does

When a merchant enters a dollar amount on the charge screen, OrangeTill does two things: it fetches the current exchange rate from a public API (blockchain.info for Bitcoin, Coinbase for other coins), and it generates a QR code that encodes a payment URI pointing directly to the merchant’s wallet address. That’s it.

The payment URI looks something like this for Bitcoin:

bitcoin:bc1qexampleaddress123?amount=0.00042&label=OrangeTill

When your customer scans that QR code with their wallet app, their wallet reads the URI and initiates a payment directly to your address. OrangeTill is never part of that transaction. No payment data passes through our servers. We never know the transaction happened.

For comparison: when you process a credit card through Square or Stripe, the payment processor is in the middle of every transaction — receiving funds, holding them briefly, then forwarding them minus fees. OrangeTill has no equivalent role. There is no middle. The blockchain connects two wallets directly, and we are a display tool on one side of that connection.

What our server actually stores

We want to be completely transparent about what the OrangeTill backend does and doesn’t hold. Here is the exact list:

Data Stored? Where Why
Your email address Yes Cloudflare KV Authentication & subscription management
Your subscription plan & status Yes Cloudflare KV Verifying active access to the app
Your wallet addresses (optional) Only if you enable a public profile Cloudflare KV Powering your public-facing payment page at orangetill.io/u/[slug]
Your payment history No Your device only Stored in browser localStorage, never sent to our servers
Transaction amounts or details No N/A We never receive this data in any form
Private keys or seed phrases Never N/A Never requested, never transmitted, never stored
Your PIN (if set) Hashed only Your device only SHA-256 hash stored locally — the original PIN is never stored anywhere
Incoming payments or confirmations No N/A The blockchain handles this directly between wallets

Note the wallet address entry specifically: if you don’t use the public profile feature, your wallet addresses never leave your device at all. They’re entered in Settings and stored in your browser’s localStorage. If you do enable a public profile, those addresses are stored on our server so we can display your payment page — but they are, as we’ll explain below, public information by design anyway.

A word about your PIN and SHA-256

If you set a PIN to protect your OrangeTill session, that PIN is never stored as plain text anywhere. Before being saved, it is run through SHA-256 — the same cryptographic hash function that secures Bitcoin itself.

SHA-256 is a one-way function. You can run any input through it and get a fixed-length output (a hash). But you cannot run it backwards. Given a SHA-256 hash, there is no mathematical operation that recovers the original input. So even if someone could read our entire database — which Cloudflare's infrastructure makes extremely difficult — they would see a string of characters that reveals nothing about your actual PIN.

We apply to your PIN the same cryptographic principle that makes Bitcoin transactions tamper-proof. We don’t store secrets. We store evidence that you knew the secret.

Why a wallet address isn’t the thing to protect

People sometimes worry that sharing a wallet address is a security risk. It isn’t — and understanding why requires a brief detour into how Bitcoin wallets actually work.

Every Bitcoin wallet has two keys: a public key and a private key. Your wallet address is derived from your public key. It’s designed to be shared — that’s literally its purpose. When someone pays you, they’re sending funds to that address. The fact that it’s visible to the world is not a vulnerability. It’s the mechanism.

The private key is the thing that matters for security. It’s what authorizes spending from your wallet. Anyone who has your private key can move your funds. Anyone who doesn’t — no matter what they can see — cannot touch them.

The transparent mailbox analogy: Imagine a mailbox made of glass. Anyone walking by can see the letters inside. But the lock is controlled by a key only you hold. Seeing the contents gives a passer-by nothing — they still cannot open it. A Bitcoin wallet address is that glass mailbox. The private key is the lock. OrangeTill has never held, seen, or asked for your private key.

This is why the blockchain’s transparency — every transaction publicly visible to anyone — doesn’t undermine security. The blockchain tells you what happened and where funds went. It does not give you the ability to move funds that aren’t yours. Visibility and access are completely separate.

What this means in plain terms

Here’s the practical summary. When a customer pays you in Bitcoin using an OrangeTill QR code:

The funds go directly from their wallet to yours on the blockchain. OrangeTill’s servers receive nothing — no notification, no payment data, no confirmation. We don’t know the transaction occurred. We don’t know the amount. We don’t know the customer’s wallet. We don’t know your balance. We have no mechanism to freeze, delay, reverse, or intercept anything.

This is not a privacy policy. It’s not a promise. It’s an architectural fact. There is no data pipeline for us to abuse, no intermediary role for us to exploit, and no key for us to misuse. The system is blind by design — and that blindness is the point.

Self-custodial by design means the word “custodial” doesn’t apply to us at all. A custodian holds something on your behalf. We hold nothing. Your funds live on the blockchain, accessible only by whoever holds the private key. That person is you.

How this compares to custodial processors

The contrast with custodial payment processors is worth naming directly. When you accept Bitcoin through a custodial service, the processor receives the payment, holds the funds, and releases them to you on their schedule, minus their fee. They can see every transaction. They can hold payments. They can close your account and freeze your balance. They are, by definition, in the middle.

OrangeTill is not in the middle. It cannot be — there is no middle. The QR code is a direct line from your customer’s wallet to yours, with no intermediary to intercept it, fee it, or delay it. We are a display tool. The transaction is yours.

Frequently asked questions

Can OrangeTill freeze or reverse a payment?▼
No. Blockchain transactions are irreversible by design, and OrangeTill has no role in the transaction at all. Once a payment is confirmed on the blockchain, it cannot be reversed by anyone — including us, including the customer, including any government or institution. This is a feature of Bitcoin, not OrangeTill specifically.
If OrangeTill stores my wallet address, can they drain my wallet?▼
No. A wallet address allows people to send funds to you — it has no power to authorize outgoing transactions. Moving funds requires signing a transaction with your private key, which only your wallet holds. OrangeTill has never seen your private key and has no mechanism to request, receive, or store one.
What happens to my data if OrangeTill shuts down?▼
Your payment history lives on your device in your browser’s localStorage — it’s unaffected by anything that happens to OrangeTill. Your Bitcoin funds live on the blockchain — also completely unaffected. The only thing that would change is that your subscription authentication would stop working, meaning you could no longer access the app. Your funds, history, and wallets are all independent of us.
Could a hacker who broke into OrangeTill’s servers access my funds?▼
No. A breach of OrangeTill’s servers could expose email addresses and subscription statuses — the same kind of data a breach of any SaaS company might expose. It could not expose private keys (we don’t have them), payment history (stored on your device), or funds (controlled entirely by the blockchain and your private key). The worst case of an OrangeTill breach is a data exposure equivalent to a mailing list leak — not a financial one.
What is SHA-256 and why does it matter for my PIN?▼
SHA-256 is a cryptographic function that converts any input into a fixed-length string of characters. It’s one-way: you can compute the hash of a PIN, but you cannot recover the PIN from its hash. Bitcoin uses SHA-256 to secure transactions. OrangeTill uses it to store your PIN — we save the hash, not the PIN itself. Even if someone read our entire database, they would see a hash that mathematically cannot be reversed into your original PIN.
Is my payment history stored anywhere other than my device?▼
No. Your payment history is stored exclusively in your browser’s localStorage under the key ot_payments_v2. It never leaves your device. OrangeTill’s servers have never received, stored, or seen a single payment record. If you clear your browser data or switch devices, your history does not transfer — because we never had it.

Accept Bitcoin at your counter — zero fees, zero middlemen.

OrangeTill generates QR codes that point directly to your wallet. We are never in the middle of a transaction. Try it free for 60 days.

Start Free Trial →
Disclaimer: The content on this page is for informational and educational purposes only. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency markets are volatile and carry significant risk. OrangeTill is a payment processing tool, not a financial advisory service. The author may hold positions in cryptocurrencies mentioned. Always consult a qualified professional before making financial or business decisions.