Last reviewed 15 August 2026
Written for the person on a committee who has to sign off on using this. If something here is not enough for your organisation, write to us and ask.
01
Card details are entered directly into Stripe’s own payment form, which runs inside the page but sends nothing to us. No card number, expiry or security code ever reaches our servers or our database. Stripe is certified to PCI DSS Level 1, the standard the banks are held to.
Money is paid into your own connected Stripe account rather than ours, so we never hold your funds at any point.
02
Every page and every email link is served over HTTPS. Records are encrypted at rest in the database, and backups are encrypted too.
03
Separation is enforced in the database itself with row-level security, not only in the application. A query that asks for another workspace’s bookings returns nothing, whichever way it is asked.
04
People you invite are owners, admins or members. A member on the door can scan tickets and search the roster.
To be straight with you about a current limit: an invited member can also reach the rest of the portal. There is no door-only login that sees the roster and nothing else. If that matters for your event, invite the people you would trust with the whole account, and remove them afterwards.
05
Refunds, deletions and changes of role are recorded with a name and a time. Every email the platform sends on your behalf is written to a log you can read in the portal, including the ones that failed and why.
06
Each is a established provider with its own security programme, and each only receives what it needs to do its part.
07
Access to production is limited to the people who maintain the platform, and is used for support and for fixing faults. We do not browse organiser data, we do not market to your attendees, and we do not sell anything to anybody.
08
Contacts and bookings export to CSV from the portal at any time, without asking us. Deleting removes the record from your workspace. Booking and payment records are kept for as long as financial-record rules require, and are then deleted.
09
If you find a security problem, email salam@barakahbookings.comwith enough detail to reproduce it. We will acknowledge it, keep you updated while we fix it, and credit you if you would like that. Please do not test against real organisers’ data or run anything that would degrade the service for a live event.