Security
Last updated: 27 June 2026
Guestwork is being built for venues that trust it with booking, table, staff, and guest information. Security is treated as part of the product, not an afterthought.
1. Security principles
- Limit access to data to people and systems that need it.
- Use secure authentication and access controls for product areas.
- Protect data in transit with HTTPS where services are exposed online.
- Keep systems, dependencies, and hosting environments maintained.
- Monitor for errors, abuse, and unusual behaviour where practical.
2. Access control
Venue accounts should be limited to authorised staff. Customers are responsible for managing who has access to their venue data and for removing staff access when it is no longer needed.
3. Data handling
Guestwork aims to collect and process only the data needed to operate booking, table, floorplan, guest record, support, and account functions. Personal data should not be entered into free-text notes unless it is necessary for the venue's service and lawful for the venue to store.
4. Backups and resilience
Production systems should use appropriate backup and recovery practices. Specific backup frequency, retention, and recovery commitments may depend on the customer agreement or hosting arrangement in place.
5. Responsible disclosure
If you believe you have found a security issue affecting Guestwork, please email hello@guestwork.co.uk with enough detail for us to investigate. Please do not access, modify, delete, or disclose data that does not belong to you.
6. No absolute guarantee
No online service can guarantee perfect security. Guestwork will continue to improve its security practices as the product develops.
Book a demo