Protecting your account and sign-in
For: Venues · Professionals · Private individuals
Your account is protected from two sides: Sunworker limits sign-in attempts and only stores passwords as a hash, and you keep your sign-in details to yourself.
At a glance
- What protects your account: a password of at least 10 characters or a passkey, limited sign-in attempts and a database that only Sunworker's server accesses.
- What you do: keep your sign-in details secret, don't share your account and tell Sunworker straight away if you suspect someone else is using it.
- What Sunworker never does: ask you for your password.
Ways to sign in
- Email and password: You sign in with the address you registered with. The password has at least 10 characters.
- Passkey: You sign in without a password; your device confirms it's you by fingerprint, face or device PIN. You create a passkey while signed in and once your email address is confirmed. It only works for the address it was created under.
- Google or Apple: provided the sign-in page shows the button for it. The first time, an account without a role is created. Sunworker receives your name, email address and an identifier; with Apple, only a forwarding address if you wish.
The individual steps are in the Help Centre: Signing in with a password, passkey, Google or Apple.
What Sunworker does for your account
- After 10 failed attempts within 15 minutes, Sunworker temporarily blocks further sign-in attempts for that email address.
- “Forgotten password” always gives the same response, even if there is no account for an address. That way nobody finds out who is registered with Sunworker.
- Confirmation and password emails can be requested no more than 5 times per hour per address.
- Passwords are only stored as a hash in the sign-in service. Connections are TLS-encrypted, and only Sunworker's own server accesses the database, never your browser.
- With a passkey, Sunworker only stores a public key and an identifier. Your biometric data never leaves your device.
- If you pay as a client, you enter card and bank details directly into fields provided by Stripe; they never reach Sunworker. For your payout account, Sunworker does not store your IBAN, only the last four digits and the name of the bank.
What you can do yourself
- Use a password of your own that you don't use anywhere else – not even for your email inbox.
- A password manager remembers it for you and fills it in on the sign-in page.
- Sign out of other people's or shared devices when you've finished. Your session then also ends on the server, not just in the browser.
- Don't share your account; it is not transferable. Other users at your venue get their own access: Invite users and assign permissions.
Warning: Sunworker doesn't ask for your password. Never give it out – not even when you write to Sunworker.
Protection in messages
Sunworker hides phone numbers, email addresses, postal addresses, links, messenger names and social media references in messages before they are delivered – in both directions. This also protects against fraud and harassment. Messages are also checked automatically for fraud, insults and threats; a conspicuous message is flagged and looked at by a person.
If you are asked to continue working together outside Sunworker or to pay outside the platform, that breaks the rules. More under Contact and payment outside the platform; how to report it is explained under Reporting violations – and what happens next.
If you've forgotten your password
- Open Forgotten password. You'll also find the link on the sign-in page.
- Enter the email address you registered with and submit the form.
- Open the email from Sunworker and follow the link in it.
- Set a new password of at least 10 characters. Then sign in as usual.
Didn't get an email? For security reasons the page always gives the same response, even without an account. So check:
- Look in your spam folder and check whether you used the address you registered with.
- If you have only ever signed in with Google or Apple, your account may not have a password. In that case, sign in again with the same provider.
- You can request a new email no more than 5 times per hour per address. After that, wait a while.
All the details are in the Help Centre: Reset your password.
If you suspect someone else has access
- Reset your password and choose a new one that you don't use anywhere else.
- Sign out on your other devices – you may still be signed in there after the reset.
- Tell Sunworker without delay by email to kontakt@sunworker.eu. Never include your password.
Frequently asked questions
Does Sunworker store my fingerprint or my face?
No. With a passkey, your device confirms it's you. Sunworker only stores a public key and an identifier; biometric data never leaves your device.
Why do I see “Too many requests”?
After 10 failed attempts within 15 minutes, Sunworker temporarily blocks further sign-in attempts for that email address. Wait a moment and then try again.
I sign in with Google or Apple. Do I have a password?
Possibly not. In that case, always sign in with the same provider.
Can I also set up a venue with my professional account?
No. A professional account has exactly one role. It cannot become a venue or a private individual.
Was this article helpful?
This page explains; it is not legal or tax advice. Our Terms are what counts.