Security & compliance

Built quietly,
protected loudly.

EU data residency, GDPR by default, Stripe payments, encryption everywhere. Hosts run real businesses on BookBed — we treat it that way.

Data residency

Hosted in the EU.

Our primary database lives in the Frankfurt region, behind a Supabase Postgres deployment with row-level security enabled by default. Backups stay inside the EU.

Compliance

GDPR by default.

Every reservation, message, and payout is exportable as CSV or via the API at any time. Cancel and your data stays accessible for 90 days, then gets permanently deleted on a verifiable schedule.

Payments

Stripe handles every cent.

Card data never touches BookBed servers. Stripe is PCI-DSS Level 1 — the highest tier. Your payouts and refund flow run through Stripe Connect with bank-level reconciliation.

Encryption

TLS in transit, AES at rest.

Every request to bookbed.io uses HTTPS with HSTS. Sensitive fields (tokens, keys, guest PII) are encrypted at rest. Production secrets live in a managed vault, not in source control.

Access

Least-privilege by design.

Role-based permissions inside the app. Engineering access to production is logged, time-bound, and requires a second-factor approval. We rotate credentials on departures, not annually.

Resilience

Channel sync that survives outages.

If Airbnb or Booking.com lags, our two-way iCal sync surfaces the gap on your dashboard before a guest sees it. Conflict prevention layered on top eliminates double-bookings even when a feed goes silent.

Policies

The legal stuff, written in plain English.

Three documents cover the BookBed promise — read them or send them to your lawyer. We make changes infrequently, and we version every revision.

Need a security questionnaire, DPA, or sub-processor list? Email dusko@book-bed.com.