Your clients stay yours
Your customer list is separated from every other business at the database level, and you can export it whenever you want.
You are about to put your calendar, your client list and possibly your card payments into someone else's software. This page explains exactly what we do with all of it — and is deliberately limited to things we can actually stand behind today.
Your customer list is separated from every other business at the database level, and you can export it whenever you want.
Card payments run through Stripe into your own Stripe account. We never hold your money and never see card numbers.
Every page and API call is served over HTTPS, and the database is encrypted on disk.
No lock-in. Export your bookings and customers, then ask us to delete the account and we will.
Booknexo runs many businesses on one system. Every table that holds your data carries your shop's identifier, and the database itself enforces that a query can only ever return rows belonging to the shop making it. That rule lives in Postgres, not in application code, so a mistake in a page or an API route cannot leak another shop's bookings or customers.
Appearing in the public Explore directory is opt-in, and off unless you turn it on.
Owners and staff sign in with an email address and password. Your clients never need a password at all — they get a one-time link by email to view and manage their own bookings.
Owners, staff and customers each land in a different part of the product and can only reach what their role allows. Dashboard pages are login-gated and excluded from search engines.
Sign-in, registration and password-reset attempts are rate limited. Error messages are deliberately vague about whether an email address exists, so the login form cannot be used to find out who has an account.
When you switch on online payments, card details are handled entirely by Stripe. They never reach Booknexo's servers and we never store a card number.
Payouts go to your own Stripe account, connected to you rather than to us. We are not in the middle of your money. Messages coming back from Stripe are signature-verified, so a forged payment confirmation cannot be accepted.
Every page and API request is served over HTTPS, so traffic between your device and Booknexo is encrypted in transit. The database is encrypted at rest on disk by our hosting provider.
Credentials you connect — your email or messaging provider's API keys — are stored server-side and are never sent to the browser.
We use a small number of other companies to run Booknexo. These are the only ones that can hold your data:
Your bookings, your customer list and your revenue figures belong to your business. You can export bookings, customers and revenue to CSV from the Reports screen at any time, without asking us.
We do not sell your data, and we do not market to your clients.
There is no minimum term and no exit fee. Export anything you want to keep first, then email hello@booknexo.com and we will delete your shop and the data attached to it.
If you think you have found a vulnerability, email hello@booknexo.com with enough detail to reproduce it. We would much rather hear from you than not, and we will not pursue anyone who reports something in good faith and gives us a reasonable chance to fix it first.
No. Every record carries your shop's identifier, and the database itself refuses to return rows belonging to a different shop. That rule is enforced in Postgres rather than in application code, so a bug in a page or an API route cannot expose another shop's data.
No. If you turn on online payments, card details go straight to Stripe and never reach our servers. Payouts land in your own Stripe account, not ours.
Yes. You can export bookings, customers and revenue to CSV from the Reports screen whenever you want, without asking us. There is no minimum term and no exit fee.
Email hello@booknexo.com with enough detail to reproduce the problem. Please give us a reasonable chance to fix it before disclosing it publicly. We will not pursue anyone who reports something in good faith.
If you need detail we haven't published — because your industry or your clients require it — email hello@booknexo.com and ask. We would rather answer a hard question directly than put a vague claim on this page.