Legal

How your data is kept safe

A committee is answerable to its members for the list it holds. This is what we do so you can answer that question properly.

Last reviewed 15 August 2026

Written for the person on a committee who has to sign off on using this. If something here is not enough for your organisation, write to us and ask.

01

We never see a card number

Card details are entered directly into Stripe’s own payment form, which runs inside the page but sends nothing to us. No card number, expiry or security code ever reaches our servers or our database. Stripe is certified to PCI DSS Level 1, the standard the banks are held to.

Money is paid into your own connected Stripe account rather than ours, so we never hold your funds at any point.

02

Encrypted in transit and at rest

Every page and every email link is served over HTTPS. Records are encrypted at rest in the database, and backups are encrypted too.

03

One organisation cannot see another

Separation is enforced in the database itself with row-level security, not only in the application. A query that asks for another workspace’s bookings returns nothing, whichever way it is asked.

04

Roles decide what each person opens

People you invite are owners, admins or members. A member on the door can scan tickets and search the roster.

To be straight with you about a current limit: an invited member can also reach the rest of the portal. There is no door-only login that sees the roster and nothing else. If that matters for your event, invite the people you would trust with the whole account, and remove them afterwards.

05

Nothing is lost quietly

Refunds, deletions and changes of role are recorded with a name and a time. Every email the platform sends on your behalf is written to a log you can read in the portal, including the ones that failed and why.

06

Who we rely on

  • Stripe, for payments and payouts.
  • Supabase, for the database, authentication and file storage.
  • Vercel, for hosting and delivery.
  • Resend, for email delivery.

Each is a established provider with its own security programme, and each only receives what it needs to do its part.

07

Access on our side

Access to production is limited to the people who maintain the platform, and is used for support and for fixing faults. We do not browse organiser data, we do not market to your attendees, and we do not sell anything to anybody.

08

Getting your data out, or deleted

Contacts and bookings export to CSV from the portal at any time, without asking us. Deleting removes the record from your workspace. Booking and payment records are kept for as long as financial-record rules require, and are then deleted.

09

Reporting a vulnerability

If you find a security problem, email salam@barakahbookings.comwith enough detail to reproduce it. We will acknowledge it, keep you updated while we fix it, and credit you if you would like that. Please do not test against real organisers’ data or run anything that would degrade the service for a live event.

Start when you are ready

Hold the list properly from the first booking.

Free to start. Export it or delete it whenever you like, and it leaves with you.

Create your first program
Create your first program, free