Account Security
Standfirst
Most account takeovers are not sophisticated. They happen because a password was reused on a site that was later breached, or because someone was persuaded to hand over a code.
Both are preventable, and this page is mostly about those two.
What you control
Use a password you do not use anywhere else. This is the single most effective thing on this page. A password manager makes it practical; a memorable variation of an old password does not, because that is exactly what credential stuffing tries.
Turn on two-step verification. MingleExtra supports a second step by email, so signing in requires both your password and access to your mailbox. That means a leaked password alone is not enough.
Secure the email account itself. Two-step by email is only as strong as the mailbox behind it, and your email is also where password resets go. If your mailbox is compromised, everything else follows.
Review what is on your profile. Your street, building entrance, workplace, car registration and a child's face are the things people give away without noticing, usually in photographs rather than in text.
Log out on shared devices, and be deliberate about staying signed in on a phone that other people use.
What we never ask for
Your password. Your card number. Your CVV. Your PIN. A one time code.
Never, by any channel, for any reason. Not by email, not in chat, not by phone, not by a support agent, not during verification, not to release a payment, and not to unlock an account.
Anyone asking you for those is defrauding you, including anyone claiming to work here. There is no situation in which the request is genuine, so you never have to judge whether this one might be.
Do not use login links sent to you by another member, however plausible the reason. Sign in the way you normally do instead. That is how credentials are harvested.
What we do not store
Card numbers, expiry dates and CVV values are not held on MingleExtra servers. Payment details are entered with our payment provider on their pages and are handled by them.
Verification material is never shown to other members. They see the badge, never the underlying document or photograph, and it is not reachable by a direct link.
Your email address, phone number, date of birth and exact location are never displayed to other members, and distance is deliberately rounded so it cannot be used to work out where you are.
If your account is compromised
In this order, because the order matters:
1. Change your password, to something not used anywhere else.
2. Check your email account. If that has been compromised, the password change will not hold, because resets go there. Change that password too and check its recovery settings.
3. Check your account settings for a changed email address or phone number, which is what someone does to lock you out.
4. Check for anything sent in your name, and warn anyone who received a message asking for money.
5. Contact support, so the account can be secured and anything sent from it can be reviewed.
If money moved, contact your bank or payment provider first, before any of the above, because they are the only ones who can act on the payment and speed decides whether it can be stopped.
What has not been verified
This section exists because the previous version of this page made infrastructure claims that had not been checked, and an unverified security claim is worse than no claim.
[CONFIRM] Transport encryption. HTTPS across all traffic, including redirects and any subdomains, must be confirmed on the production host before it is stated here.
Password storage is confirmed. Passwords are put through password_hash with PHP's default algorithm and stored as bcrypt hashes at cost 11. They are not stored in readable form and cannot be read back, which is why a reset sends you a link rather than telling you your existing password.
[CONFIRM] Monitoring and intrusion detection. No claim about ongoing monitoring should be published until what exists is known.
[CONFIRM] Breach notification. The process and timescale for notifying members belongs in the Privacy Policy, which is pending legal review.
Note: reCAPTCHA is currently disabled in configuration, so no bot protection claim is made on this page.
Related
Account Management help · Privacy and Data FAQ · Account Management FAQ · Payments FAQ · Safety Center · Verification Center
Disclaimer
MingleExtra will never ask you for your password, card number, CVV, PIN or a one time code, by any channel, for any reason. Card numbers, expiry dates and CVV values are not stored on MingleExtra servers. This page describes account security measures available to members; it is not a certification, an audit result, or a guarantee against unauthorised access. Sections marked for confirmation have not been verified against the production environment and should not be relied on. The Privacy Policy is the authoritative statement on how personal data is handled and is pending legal review. MingleExtra is operated by NEX MINGLE HOLDINGS LLC and is for adults aged 18 and over.