TreyzaHelp Center
Account & Security

Sign-in History

It lists the most recent sign-in attempts on your account with device, location, method and outcome. If a device you have never used signs in…

Where to find: Merchant panel → ProfileSecurity tab → Sign-in history card Who it's for: Anyone who wants to track the sign-in attempts on their account — both the successful ones and the failed ones In short: It lists the most recent sign-in attempts on your account with device, location, method and outcome. If a device you have never used signs in successfully, you get an email.


What is it for?

The Active sessions card shows you who is inside right now. Sign-in history shows you who tried to get in — whether they succeeded or not.

That difference matters:

  • If someone tried your password and failed, there is no session at all — nothing shows up in the active sessions list. But sign-in history records it as "Failed · Wrong password".
  • Consecutive failed attempts are the earliest sign that someone is trying to reach your account.
  • Someone who knew your password but got stuck at two-factor verification appears here as "Failed · Wrong verification code". If you see that row, your password is in someone else's hands — change it immediately.

Where do I find it?

  1. In the merchant panel, go to Profile from your profile menu at the top right.
  2. Switch to the Security tab.
  3. In the right column, below the Active sessions card, you will see the Sign-in history card.

What do you see in the list?

Every row is one sign-in attempt:

InformationDescription
Outcome badgeSuccessful or Failed.
Device / browserE.g. "Chrome 141 · Windows". If it cannot be detected it says Unknown device.
New device badgeThis sign-in came from a device that had not been used before.
DescriptionThe sign-in method if successful, the reason if failed.
Location / IPApproximate location and masked IP.
TimeSuch as "3 hours ago". Hover over it to see the exact date.

The card shows the last 20 records at a time. Use the Show more button below it to go further back.


What do the sign-in methods mean?

LabelMeaning
Signed in with passwordSigned in with email + password only.
Signed in with email codeAfter the password, the 6-digit code sent to your email was entered.
Signed in with two-factor codeAfter the password, the code from your authenticator app was entered.
Signed in with passkeySigned in with the device lock, without typing a password.
Signed in from a trusted deviceSigned in from a device you previously marked "remember for 30 days"; no code was requested again.

What do the failure reasons mean?

LabelMeaning
Wrong passwordThe email was correct, the password was not.
Wrong verification codeThe password was correct but the second-step code was wrong.
Too many attemptsToo many wrong codes in a row temporarily used up the attempt allowance.
Account disabledThe sign-in was rejected because the account is closed.
Account suspendedThe sign-in was rejected because the business account you belong to is suspended.

New device sign-in alert

When a device that has never been used before signs in to your account successfully, you receive a warning email. It contains the device, approximate location, masked IP and the date. A panel notification is created at the same time.

No spam: You will not get repeated alerts for the same device. Once a device is recognised, later sign-ins from it are recorded silently.

The alert cannot be turned off. This email exists for account security and cannot be disabled from notification preferences.

If you received an alert and the sign-in was not you, do the following in order:

  1. Change your password (Profile → Security → Password),
  2. Sign out all other sessions (see Active Sessions and "Sign Out Everywhere"),
  3. Turn on two-factor authentication (see Two-Factor Authentication).

Privacy: what data, for how long?

Sign-in history contains personal data, so we keep this transparent.

What is stored?Why?
IP addressSo you can tell where the sign-in came from.
Browser / operating system / device typeSo you can recognise the device.
Approximate location (country/city)Estimated from the IP.
Method, outcome and timeSo you can judge the attempt.
  • These records are kept for account security only; they are not used for marketing or profiling.
  • Records are kept for 180 days, then deleted automatically. The note under the card states the current period.
  • The IP address is shown masked — the last part is hidden (e.g. 88.230.10.•••). The raw IP is never shown in the interface.
  • The raw browser identifier (user-agent) is not shown to you; only the simplified "Chrome 141 · Windows" summary is.
  • This list belongs to your own account only. You cannot see another user's sign-in history, and nobody can see yours.

Frequently asked questions

Do attempts made with an email address I don't recognise show up here? No. The list only shows attempts made against your account. Attempts with an email address that does not exist are not tied to any account and are not recorded at all.

There are fewer records than I expected. Two reasons: records are deleted after 180 days; and identical attempts repeated within a very short interval are collapsed into a single row (so the list is not flooded with hundreds of rows during an attack).

My own sign-in is shown as a "new device". Clearing browser data, using a different browser or moving to a new computer all count as a new device. This is normal.

I signed in from the same device but the location says another city. Location is estimated from the IP address. A VPN, a mobile carrier network or a corporate connection can place you in another city. Do not treat location alone as proof.

Can I delete a record from the sign-in history? No. The records exist for security and cannot be deleted by hand; they are removed automatically when they expire.

Does changing my password reset the history? No. Changing the password closes open sessions, but the sign-in history stays as it is.

I saw a failed attempt — is my account locked? No. The system slows down repeated attempts but does not lock the account automatically. If you are suspicious, change your password and turn on two-factor authentication.

Was this page helpful?

On this page