Your diary and your guest list are your business’s property, and you should be able to find out exactly how they are held. Last updated 11 August 2026.
Everything runs in the United Kingdom. The application is hosted on Vercel in their London region, and the database is Neon’s managed Postgres in eu-west-2, which is also London. Your bookings and your guest list do not leave the UK in the ordinary course of running the service.
Traffic between a guest’s browser and ClickBook is over HTTPS, and the connection between the application and the database requires TLS.
Every venue is a separate tenant. Your diary, your tables and your guests are scoped to your venue, and one venue’s staff cannot see another’s.
Within your venue, each member of staff has their own account and a role. A bartender does not need the settings or the reports, and does not get them.
We can reach your data. ClickBook has support accounts that can open a venue’s portal, because that is how a problem gets fixed at half past seven on a Saturday when the alternative is asking you to describe it down the phone. We say so here rather than implying otherwise. It is a small number of named people, not a department, and if you would rather we asked before looking, tell us and we will.
Passwords are stored as bcrypt hashes and never in a form anyone here can read — not us, not our database, not a support ticket. If you forget one it gets reset, never retrieved, because retrieving it is not possible.
A session is a signed token in a cookie your browser will only send back to us, only over HTTPS in production, and never to another site. Sessions last thirty days, and signing out ends one immediately.
We never hold them. Where a venue takes a deposit or a card hold, the card goes straight to Stripe and the money goes to the venue’s own Stripe account. Card numbers do not pass through ClickBook, are not stored by ClickBook, and are not something we could hand over if we were asked.
Five suppliers, each doing one job, all named here and in our privacy policy:
There is no advertising network, no data broker and no third party we sell anything to, because we do not sell anything. That is not a policy position we could quietly change: it is what the list above consists of.
For your guests’ data, the venue is the controller and ClickBook is the processor. The guest booked with you. We hold their booking so that you can run it, on your instructions, and for no purpose of our own.
For your own account — your staff logins, your billing, your emails to us — ClickBook is the controller.
If you need a data processing agreement for your records, ask and we will send one.
Your guest list exports from the portal whenever you want it, as does your reporting. You do not have to ask us and there is no retrieval fee, because the point of ClickBook is that the list is yours rather than rented back to you.
You can delete a guest at any time, and we delete on request. If you stop using ClickBook, tell us and your venue’s data is removed — you are not required to keep paying to keep hold of it.
We are not certified to ISO 27001, SOC 2 or Cyber Essentials, and nothing here should be read as saying otherwise. We have not commissioned a penetration test. We publish no uptime figure because we have not been running long enough for one to mean anything.
Everything above is something we do and can show you. When one of the things in this paragraph becomes true, it will move up the page.
If you think you have found a security issue, email hello@clickbook.co.uk with enough detail to reproduce it. We will confirm we have received it, we will not take any action against you for reporting it in good faith, and we will tell you when it is fixed.
Contact: hello@clickbook.co.uk · Cornwall, United Kingdom