BookInnTime

Product

How BookInnTime keeps your account and your customers safe

Lockouts, locked-down emails, encrypted keys and a calendar that can't be double-booked — the security work you shouldn't have to think about.

28 September 20265 min read

A booking system holds names, phone numbers, email addresses and, for some businesses, payments. Most of the work that protects that is invisible when it's done well. Here's what's in place, in plain language.

Guessing passwords doesn't work

After five wrong passwords from the same connection, sign-in pauses for fifteen minutes. That applies to business, customer and admin logins alike. The pause is tied to where the attempts come from, not to the email being tried — otherwise anyone could lock you out of your own account just by typing your email address wrong five times.

Passwords themselves are never stored as you typed them. Each one is salted and run through a slow one-way hash, so even we can't read them back.

Sign-in links only ever go to your inbox

Confirm-your-email and reset-your-password links are only ever sent by email — never shown on screen, even if sending fails. A link on screen would let anyone who typed your address into the sign-up form walk straight into your account.

Account emails are also limited to three an hour for any one address, and a new sign-up can resend its confirmation once. That stops the forms being used to flood someone's inbox. And the forgot-password form gives the same answer whether or not an account exists, so it can't be used to find out who's on BookInnTime.

Keys are encrypted, card numbers never reach us

The keys that let BookInnTime send email are stored encrypted, and the admin panel can only replace them, never display them. Payment keys can't be set from the website at all. Card numbers go straight to Stripe and never touch our servers; we only ever see whether a payment succeeded.

Nobody can be double-booked

Two people tapping the same time at the same moment is handled by the database itself, which refuses to store two overlapping bookings for one business. We wrote about why that has to live in the database.

Coupons can't be used for spam

A business can email a coupon code only to customers who have booked with it before. The form can't be used to send mail on BookInnTime's name to the rest of the internet.

What we keep, and for how long

Every email the site sends is logged with who it went to, what kind it was and whether it was delivered — never the message itself — and the log is deleted after 90 days. A suspended account is signed out everywhere immediately, not at its next login. The full detail is in our privacy policy.

If you spot something

If you ever see something that looks wrong — an email you didn't expect, a page showing someone else's details — tell us straight away. Security reports jump the queue.

Take bookings through a link

Your own booking page, live in minutes.