BookMyVenue is a product operated by Xpykerz. Protecting venue, customer, and business information is a shared responsibility.
How we protect the service
BookMyVenue applies authenticated access, tenant and permission boundaries, short-lived sessions, encrypted transport in production, protected mobile credential storage, privacy-minimal notifications, restricted local caching, and audit-oriented operational controls. Access is limited according to each organization's configured roles.
Your responsibilities
Use a strong, unique password, keep devices and recovery channels secure, grant staff only the access they require, sign out of shared devices, and promptly remove access for people who no longer need it.
Report a vulnerability
If you believe you found a security issue in BookMyVenue, email hello@xpykerz.com. Include the affected URL or feature, clear reproduction steps, potential impact, and a safe way to contact you. Do not include credentials, customer records, or other unnecessary sensitive data.
Responsible testing
Use only accounts and data you own or are explicitly authorized to test. Do not disrupt availability, access another organization's data, run denial-of-service activity, use social engineering, or publicly disclose an unresolved issue. A report does not create a promise of payment or a public bug-bounty program.
Response
Xpykerz will review good-faith reports, validate the affected product surface, coordinate follow-up when contact details are provided, and prioritize remediation according to risk.