Trust

Security at BookMyVenue.

Last updated: September 5, 2026

BookMyVenue is a product operated by Xpykerz. Protecting venue, customer, and business information is a shared responsibility.

How we protect the service

BookMyVenue applies authenticated access, tenant and permission boundaries, short-lived sessions, encrypted transport in production, protected mobile credential storage, privacy-minimal notifications, restricted local caching, and audit-oriented operational controls. Access is limited according to each organization's configured roles.

Your responsibilities

Use a strong, unique password, keep devices and recovery channels secure, grant staff only the access they require, sign out of shared devices, and promptly remove access for people who no longer need it.

Report a vulnerability

If you believe you found a security issue in BookMyVenue, email hello@xpykerz.com. Include the affected URL or feature, clear reproduction steps, potential impact, and a safe way to contact you. Do not include credentials, customer records, or other unnecessary sensitive data.

Responsible testing

Use only accounts and data you own or are explicitly authorized to test. Do not disrupt availability, access another organization's data, run denial-of-service activity, use social engineering, or publicly disclose an unresolved issue. A report does not create a promise of payment or a public bug-bounty program.

Response

Xpykerz will review good-faith reports, validate the affected product surface, coordinate follow-up when contact details are provided, and prioritize remediation according to risk.