When people hear that OrangeTill generates QR codes for Bitcoin payments, a reasonable question follows: what does OrangeTill see? Can the company see your wallet? Your balance? Your transaction history? Could someone at OrangeTill access your funds?
The answer to all of those is no — and that's not a policy decision. It's a structural one. This article explains exactly why, at three distinct levels: the app itself, our backend server, and the blockchain. Each layer has its own reason for being blind, and together they form something more trustworthy than a promise: a system where access is technically impossible.
The three layers of blindness
Your settings never leave your device
Wallet addresses, display currency, tip settings, and note shortcuts are stored in your browser’s own localStorage — on your device. The charge screen, QR code generation, and crypto equivalent calculations all happen locally. When a payment is made, it happens directly between your customer’s wallet and yours. OrangeTill is not in the middle.
The Worker knows almost nothing
Our backend handles authentication and subscriptions — not payments. It stores your email address, your plan status, and optionally your wallet addresses if you’ve enabled a public profile. It has never received a payment notification, never observed a transaction, and has no way to know whether anyone has ever paid you.
Even your wallet address is the wrong thing to worry about
A wallet address is public by design. Anyone can see it — that’s how someone sends you money. But seeing an address gives you nothing. Moving funds requires a private key, which OrangeTill has never seen, never stored, and never asked for. A wallet address without the private key is like a transparent mailbox: you can see what’s inside, but you cannot open it.
What the app actually does
When a merchant enters a dollar amount on the charge screen, OrangeTill does two things: it fetches the current exchange rate from a public API (blockchain.info for Bitcoin, Coinbase for other coins), and it generates a QR code that encodes a payment URI pointing directly to the merchant’s wallet address. That’s it.
The payment URI looks something like this for Bitcoin:
When your customer scans that QR code with their wallet app, their wallet reads the URI and initiates a payment directly to your address. OrangeTill is never part of that transaction. No payment data passes through our servers. We never know the transaction happened.
For comparison: when you process a credit card through Square or Stripe, the payment processor is in the middle of every transaction — receiving funds, holding them briefly, then forwarding them minus fees. OrangeTill has no equivalent role. There is no middle. The blockchain connects two wallets directly, and we are a display tool on one side of that connection.
What our server actually stores
We want to be completely transparent about what the OrangeTill backend does and doesn’t hold. Here is the exact list:
| Data | Stored? | Where | Why |
|---|---|---|---|
| Your email address | Yes | Cloudflare KV | Authentication & subscription management |
| Your subscription plan & status | Yes | Cloudflare KV | Verifying active access to the app |
| Your wallet addresses (optional) | Only if you enable a public profile | Cloudflare KV | Powering your public-facing payment page at orangetill.io/u/[slug] |
| Your payment history | No | Your device only | Stored in browser localStorage, never sent to our servers |
| Transaction amounts or details | No | N/A | We never receive this data in any form |
| Private keys or seed phrases | Never | N/A | Never requested, never transmitted, never stored |
| Your PIN (if set) | Hashed only | Your device only | SHA-256 hash stored locally — the original PIN is never stored anywhere |
| Incoming payments or confirmations | No | N/A | The blockchain handles this directly between wallets |
Note the wallet address entry specifically: if you don’t use the public profile feature, your wallet addresses never leave your device at all. They’re entered in Settings and stored in your browser’s localStorage. If you do enable a public profile, those addresses are stored on our server so we can display your payment page — but they are, as we’ll explain below, public information by design anyway.
A word about your PIN and SHA-256
If you set a PIN to protect your OrangeTill session, that PIN is never stored as plain text anywhere. Before being saved, it is run through SHA-256 — the same cryptographic hash function that secures Bitcoin itself.
SHA-256 is a one-way function. You can run any input through it and get a fixed-length output (a hash). But you cannot run it backwards. Given a SHA-256 hash, there is no mathematical operation that recovers the original input. So even if someone could read our entire database — which Cloudflare's infrastructure makes extremely difficult — they would see a string of characters that reveals nothing about your actual PIN.
We apply to your PIN the same cryptographic principle that makes Bitcoin transactions tamper-proof. We don’t store secrets. We store evidence that you knew the secret.
Why a wallet address isn’t the thing to protect
People sometimes worry that sharing a wallet address is a security risk. It isn’t — and understanding why requires a brief detour into how Bitcoin wallets actually work.
Every Bitcoin wallet has two keys: a public key and a private key. Your wallet address is derived from your public key. It’s designed to be shared — that’s literally its purpose. When someone pays you, they’re sending funds to that address. The fact that it’s visible to the world is not a vulnerability. It’s the mechanism.
The private key is the thing that matters for security. It’s what authorizes spending from your wallet. Anyone who has your private key can move your funds. Anyone who doesn’t — no matter what they can see — cannot touch them.
The transparent mailbox analogy: Imagine a mailbox made of glass. Anyone walking by can see the letters inside. But the lock is controlled by a key only you hold. Seeing the contents gives a passer-by nothing — they still cannot open it. A Bitcoin wallet address is that glass mailbox. The private key is the lock. OrangeTill has never held, seen, or asked for your private key.
This is why the blockchain’s transparency — every transaction publicly visible to anyone — doesn’t undermine security. The blockchain tells you what happened and where funds went. It does not give you the ability to move funds that aren’t yours. Visibility and access are completely separate.
What this means in plain terms
Here’s the practical summary. When a customer pays you in Bitcoin using an OrangeTill QR code:
The funds go directly from their wallet to yours on the blockchain. OrangeTill’s servers receive nothing — no notification, no payment data, no confirmation. We don’t know the transaction occurred. We don’t know the amount. We don’t know the customer’s wallet. We don’t know your balance. We have no mechanism to freeze, delay, reverse, or intercept anything.
This is not a privacy policy. It’s not a promise. It’s an architectural fact. There is no data pipeline for us to abuse, no intermediary role for us to exploit, and no key for us to misuse. The system is blind by design — and that blindness is the point.
Self-custodial by design means the word “custodial” doesn’t apply to us at all. A custodian holds something on your behalf. We hold nothing. Your funds live on the blockchain, accessible only by whoever holds the private key. That person is you.
How this compares to custodial processors
The contrast with custodial payment processors is worth naming directly. When you accept Bitcoin through a custodial service, the processor receives the payment, holds the funds, and releases them to you on their schedule, minus their fee. They can see every transaction. They can hold payments. They can close your account and freeze your balance. They are, by definition, in the middle.
OrangeTill is not in the middle. It cannot be — there is no middle. The QR code is a direct line from your customer’s wallet to yours, with no intermediary to intercept it, fee it, or delay it. We are a display tool. The transaction is yours.
Frequently asked questions
Accept Bitcoin at your counter — zero fees, zero middlemen.
OrangeTill generates QR codes that point directly to your wallet. We are never in the middle of a transaction. Try it free for 60 days.
Start Free Trial →