Security basics
What Booked does under the hood to keep your data safe.
Booked is built on a small set of well-run services and a strict set of rules about how data moves between them.
The short version
- Passwordless login by email or phone (one-time codes). No stored passwords to leak.
- Row-level security on every table in the database — a staff member from one shop cannot query another shop's rows, even if they compromise a client.
- Card details never touch Booked. All card entry happens inside Stripe's iframes; Booked stores only a Stripe reference and non-sensitive display fields (brand, last four, expiry).
- PII is compartmentalized. Customer contact details live in the shop-scoped tables, not in shared marketing indexes.
- IP addresses are anonymized at write for analytics use.
- HTTPS everywhere. HSTS enabled, TLS 1.2+ only, modern cipher suites.
Why passwordless is a security decision, not a convenience one
The most common way a small business loses an account is a password reused somewhere that was breached. There is no password on a Booked account to reuse, so there is nothing for a credential-stuffing list to try. Sign-in is a code sent to an address or number you control, and it expires.
The practical consequence: whoever controls the shop's email or phone controls the shop. Securing that mailbox is the single highest-value thing an owner can do.
What a customer never has
No account, no password, no login. A booking is reached through a link plus the contact details on the booking, so there is no customer credential to steal in the first place.
What we cannot protect you from
A device left unlocked, a staff member who should have been removed and was not, or a phone number ported away by someone impersonating you at your carrier. Remove staff the day they leave, and treat carrier account security as part of your own.
Sub-processors
The full list — payments, database, hosting, email, SMS — is on the Privacy page. Changes get 30 days' notice before they go live.