Security
Security is a pillar, not a footnote.
Small businesses get targeted precisely because they're small. Here's what we do about it, in plain English.
Two-factor authentication
Every dashboard account can turn on an authenticator app with backup codes. Business owners can make it mandatory for their whole team. Platform staff use it without exception.
Payments by Stripe
Card details never touch our servers. Stripe handles checkout, 3D Secure and PCI compliance. Payouts go directly to each business's own Stripe account; we never hold funds.
Encryption
All traffic is encrypted in transit (TLS). The database is encrypted at rest. Authenticator secrets are additionally encrypted with a key held outside the database. Passwords are hashed with Argon2.
Data residency and ownership
Customer data belongs to the business that took the booking. We process it to deliver the booking and never sell it or use it for advertising. Hosting is on Vercel and Neon with EU/UK regions where available. Our privacy policy lists everyone who sees it and how long we keep it.
Your data, on demand
Anyone can download everything we hold about them, or ask for it to be deleted, from their account. Deletion removes names, contact details, booking answers and notes, and we tell every business involved. Amounts and dates stay for the six years of accounts businesses must keep, with nothing that identifies the person.
Access is recorded
Opening, downloading or erasing a customer's details is logged, and owners can see it. Support access from our side is marked as such, so a business always knows when we've been in.
Least privilege
Staff, manager and owner roles limit what each person can see. Staff linked to a resource see only their own schedule. Every action is checked server-side.
Responsible disclosure
Found something? Email security@yorkshirebookings.com. We'll acknowledge within two working days and keep you posted. We don't pursue good-faith researchers.