Security basics

What Booked does under the hood to keep your data safe.

Booked is built on a small set of well-run services and a strict set of rules about how data moves between them.

The short version

Why passwordless is a security decision, not a convenience one

The most common way a small business loses an account is a password reused somewhere that was breached. There is no password on a Booked account to reuse, so there is nothing for a credential-stuffing list to try. Sign-in is a code sent to an address or number you control, and it expires.

The practical consequence: whoever controls the shop's email or phone controls the shop. Securing that mailbox is the single highest-value thing an owner can do.

What a customer never has

No account, no password, no login. A booking is reached through a link plus the contact details on the booking, so there is no customer credential to steal in the first place.

What we cannot protect you from

A device left unlocked, a staff member who should have been removed and was not, or a phone number ported away by someone impersonating you at your carrier. Remove staff the day they leave, and treat carrier account security as part of your own.

Sub-processors

The full list — payments, database, hosting, email, SMS — is on the Privacy page. Changes get 30 days' notice before they go live.

More in Evaluating Booked