Skip to main content

Help us improve the Digital Marketplace - send your feedback

SPACETOCO UK LTD

Facility Booking Management Software

SpacetoCo is a cloud-hosted SAAS platform, offering clients a flexible, scalable, and secure solution for managing bookings, events and ticketing and offering customers a marketplace of community facilities to quickly and easily hire. SpacetoCo simplifies bookings, cuts admin, and increases revenue - so clients can focus on community outcomes.

Features

  • Real-time availability and booking calendar for all spaces.
  • Mobile-responsive interface accessible on all devices and browsers
  • Self-service customer dashboard for managing bookings, payments, and documents.
  • Secure online payments with PCI-DSS compliance and debt management
  • Automated reporting with exportable CSV data for Power BI
  • Bulk booking tool for up to three years’ recurring dates
  • Intuitive dashboard with daily schedules and urgent tasks
  • Automated notifications for confirmations, payments, and documentation
  • Role-based access control and single sign-on (SSO) integration
  • Integration with Microsoft Outlook and common finance systems.

Benefits

  • Reduce administrative workload by automating bookings, payments, and debt management
  • Enable customers to self-serve bookings and payments anytime
  • Improve decision-making with instant access to real-time data
  • Eliminate manual reconciliation with automated, fully integrated financial workflows
  • Increase venue utilisation through enhanced online discoverability via digital marketplace.
  • Minimise errors and double-bookings with real-time calendar synchronisation
  • Support flexible working with secure access from any location/device.
  • Accelerate onboarding and training with intuitive, user-friendly system design
  • Enhance customer satisfaction with automated notifications and 24/7 support options
  • Strengthen compliance and security with enterprise-grade protocols and auditing

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales.uk@spacetoco.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 9 5 1 9 3 0 3 8 5 7 3 6 5 3

Contact

SPACETOCO UK LTD Jessica Davies
Telephone: 03308182437
Email: sales.uk@spacetoco.com

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
None
System requirements
  • Modern web browser with JavaScript enabled
  • Reliable internet connection for real-time access and updates.
  • Antivirus software recommended for all staff and administrator devices.
  • Mobile devices must support responsive web browsing and secure connections.

User support

Email or online ticketing support
Yes
Support response times
Email support is monitored 7 days a week, with 90% of emails answered within 24 hours.
Live Chat and the Help Centre are available within the SpacetoCo platform, with 80% of chats answered within 1 minute.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
We aim to support all modern browsers and major assistive technologies. Our supported screen readers include:
Windows desktop: Non-Visual Desktop Access (NVDA) and Job Access With Speech (JAWS).
Mac: VoiceOver.
Mobile: VoiceOver (iOS) and Talkback (Android).
Web chat accessibility testing
We conduct regular accessibility testing of our web chat using a range of assistive technologies, including screen readers (NVDA, JAWS), keyboard-only navigation, and browser-based accessibility tools.
Onsite support
Yes, at extra cost
Support levels
We provide comprehensive support at no additional cost, including Level 1 support for all users—both staff and customers. Our support covers phone, email, and live chat channels. All support queries are triaged by our Customer Success team, with critical issues escalated immediately. There are no extra charges for higher priority support or after-hours queries.
A dedicated Account Manager is assigned to each client, acting as the primary contact for escalations, technical queries, and ongoing relationship management. For complex technical matters, our development team are available to resolve issues promptly. All support, training, and account management services are included in the platform subscription, ensuring predictable costs and responsive service throughout the contract term.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We help users start using SpacetoCo through a comprehensive onboarding program. Staff receive tailored training, which can be delivered onsite or online, covering all key functions and user roles. We provide a full suite of training materials, including step-by-step guides, video tutorials, and a searchable online knowledge base with over 130 support articles available 24/7. Self-paced learning modules and workshops are available for both Administrators and end users. Ongoing support is provided via live chat, phone, and email, ensuring users can access help when needed. Our intuitive interface and in-app tooltips further reduce the need for formal training, enabling most users to get started confidently from day one.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When the contract ends, SpacetoCo provides clients with a secure, structured process for data extraction and transition. All client-owned data—including bookings, customer records, financial transactions, audit logs, and associated documents—can be exported in standard formats such as CSV or JSON. Administrators can initiate data exports directly from the admin dashboard at any time during or at the end of the contract.
Upon contract termination or expiry, a disengagement meeting is held to confirm data requirements and handover schedules. SpacetoCo securely transfers all requested data via encrypted channels or physical media, ensuring completeness and data integrity. Once the client confirms receipt, all copies are securely deleted, and a formal Data Deletion Certificate is issued. System access is disabled, and all integrations are decommissioned in a controlled process. For up to 30 days post-disengagement, SpacetoCo provides technical support to assist with transitional queries, ensuring a smooth and compliant transition.
End-of-contract process
At the end of the contract, SpacetoCo provides a structured, secure offboarding process to ensure a smooth transition for all clients. Administrators can export all client-owned data—including bookings, customer records, financial transactions, audit logs, and documents—in standard formats (CSV or JSON) directly from the admin dashboard. Upon contract expiry or termination, we schedule a disengagement meeting to confirm data requirements and handover timelines. Once data extraction is complete and confirmed by the client, we securely delete all remaining copies and provide a Data Deletion Certificate for compliance assurance. System access is disabled, and all integrations are decommissioned in a controlled manner. For up to 30 days post-disengagement, SpacetoCo offers free technical support to assist with transitional queries.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
We currently use the HTML5 standard to publish documents. All PDFs are PDF/A. Our next major release, scheduled for December 2026, will reflect our good faith implementation of the WCAG 2.2 Level AA accessibility standards.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
SpacetoCo provides a fully responsive platform, ensuring a consistent experience across desktop, tablet, and mobile devices. All core features—searching, booking, payments, document uploads, and dashboard access—are available on every device. The mobile interface is optimised for touch, with larger buttons and streamlined menus for quick, on-the-go access. Desktop users benefit from a broader layout, enabling detailed calendar views, advanced reporting, and bulk booking management. There are no functional restrictions on mobile; however, some advanced reporting and multi-calendar comparison tools are best experienced on desktop due to screen size.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
SpacetoCo offers a modern, intuitive service interface that is fully web-based and accessible via any standard browser. The interface is designed for ease of use, requiring minimal training for both staff and customers. It features clear navigation, responsive design, and context-sensitive online help, ensuring users can complete tasks efficiently on desktop or mobile devices.
Our interface is developed using a user interface (UI) framework with WCAG compliance built in.
Our next major release in December 2026, will reflect our good faith implementation of the WCAG 2.2 Level AA accessibility standards.
Accessibility standards
None or don’t know
Description of accessibility
SpacetoCo is compliant with the Web Content Accessibility Guidelines (WCAG) 2.1 Level A and is actively progressing towards WCAG 2.2 Level AA.
Accessibility testing
SpacetoCo’s interface is developed using a user interface (UI) framework with Web Content Accessibility Guidelines (WCAG) compliance built in.
Our next major release, scheduled for December 2026, will reflect our good faith implementation of the WCAG 2.2 Level AA accessibility standards. This will be comprehensively tested.
API
No
Customisation available
Yes
Description of customisation
SpacetoCo offers extensive customisation options to meet the operational needs of users. Administrators can customise:
Space details: Add or edit descriptions, images, amenities, rules, and pricing for each venue.
Booking forms: Configure up to 32 custom questions per space, set mandatory fields, and tailor information collection to specific requirements.
Booking rules: Set approval workflows, restrict booking times, apply buffer periods, and manage access for different user groups.
Reporting: Create and save custom reports, filter data by venue, date, or user group, and schedule automated report delivery.
Tags and task lists: Apply custom tags to bookings, spaces, or customers, and create task lists to prompt staff actions.
Customisation is performed through the intuitive admin dashboard, with changes applied in real time. Clients with appropriate permissions can manage these settings, ensuring flexibility and control. Custom development of new integrations and functionality is also possible via a scoped project of works with our in-house Development team.

Scaling

Independence of resources
SpacetoCo guarantees that users are not affected by the demand other users place on the service through a robust, cloud-based architecture hosted on Amazon Web Services (AWS). The platform employs auto-scaling server clusters and advanced load balancing to dynamically allocate resources based on real-time demand. This ensures consistent performance, reliability, and responsiveness, even during peak usage periods or high-volume booking events. Automated health checks and real-time monitoring proactively detect and resolve any performance bottlenecks. All user actions (including searching, booking, and data retrieval) are processed without delay, maintaining a seamless experience for every user regardless of system load.

Analytics

Service usage metrics
Yes
Metrics types
Administrators can access real-time dashboards and export reports detailing booking volumes, venue utilisation rates, revenue by space or period, average attendance, customer demographics, and payment status. Metrics can be filtered by venue, date range, booking type, or user group, supporting operational analysis and strategic planning. All data is available in CSV or JSON format for further analysis or integration with business intelligence tools such as Power BI.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Administrators can export all client-owned data—including bookings, customer records, financial transactions, audit logs, and documents—in standard formats (CSV or JSON) directly from the admin dashboard. Users simply select the required data and download it for further analysis or archiving. This process is intuitive and does not require technical expertise. Upon contract expiry or termination, we schedule a disengagement meeting to confirm data requirements and handover timelines. Once data extraction is complete and confirmed by the client, we securely delete all remaining copies and provide a Data Deletion Certificate for compliance assurance.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
Other
Other data import formats
Not applicable

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We guarantee a minimum system availability of 99.99% per annum, excluding scheduled maintenance windows. This high level of availability is achieved through our cloud-based architecture, with auto-scaling, redundancy, and real-time monitoring.
All planned maintenance is communicated at least two weeks in advance and scheduled outside of peak hours to minimise disruption.
Critical incidents are responded to within four (4) hours, with resolution targeted within two (2) hours.
24/7 real-time monitoring and automated alerts ensure immediate triage and escalation of any availability issues.
As our platform operates on a commission-based model with fees linked to successful booking revenue, in the unlikely event of downtime, clients are not charged for periods where bookings cannot be processed. Therefore, refunds are not applicable under this model.
Approach to resilience
Our service is designed for resilience, ensuring continuous availability and robust protection of Council data. The platform is hosted on Amazon Web Services (AWS) in the UK, leveraging a stateless, cloud-native architecture. All critical components are deployed across multiple AWS Availability Zones, providing automatic failover and redundancy. If one datacentre or zone experiences an outage, services seamlessly fail over to another zone with minimal disruption.
We perform automated daily backups of all critical system and customer data, supporting point-in-time recovery to the exact second. Recovery Point Objective (RPO) is 24 hours, and Recovery Time Objective (RTO) is 4 hours. The platform is monitored 24/7 using AWS GuardDuty, automated health checks, and anomaly detection systems, with real-time alerts escalated to our engineering team for immediate response.
Our Disaster Recovery and Business Continuity Plans are reviewed and tested at least annually, in line with ISO 22301 guidelines. AWS datacentres comply with ISO/IEC 27001, CSA CCM v4.0, and SSAE-18 / ISAE 3402, and are protected by multiple layers of physical security, including biometric access controls and strict authorisation.
Outage reporting
We provide a transparent, multi-channel approach to outage reporting, ensuring clients receive timely and accessible information during any service interruption. This includes a public live status page and email alerts for scheduled maintenance and any rare significant outages.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
We restrict access to management interfaces and support channels using role-based access control, enforced via Enterprise Single Sign-On (SSO), and Multi-Factor Authentication (MFA) for all administrators. All actions are logged and monitored for compliance.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We follow a comprehensive suite of information security policies and processes aligned with ISO/IEC 27001. Our policies are reviewed annually and updated as required to reflect changes in legislation, standards, and best practice.
Key Policies:
- Information Security Management System (ISMS)
- Access Control Policy
- Audit Logging and Monitoring Policy
- Vulnerability Management Policy
- Incident Response Policy
- Data Protection and Privacy Policy
- Physical Security Policy
- Business Continuity and Disaster Recovery Policy
- Acceptable Use Policy
Our Chief Information Security Officer (CISO) leads the information security program and reports directly to senior management. The CISO is supported by the IT Manager and Executive Team.
All staff receive regular security awareness training and must adhere to documented security policies. Policy compliance is monitored through internal audits, automated controls, and regular management reviews. Any non-compliance or breaches result in immediate investigation and, where necessary, removal of access rights or further disciplinary action.
This governance structure ensures our information security policies are consistently applied, risks are proactively managed, and data remains protected in line with government and industry standards.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our configuration and change management processes comply with ISO/IEC 27001 and CSA CCM v4.0. All service components are tracked using version control and asset registers from development to decommissioning, with full audit logs for traceability. Change requests are documented, categorised, and assessed for operational and security impact by technical leads and the Chief Information Security Officer (CISO). Major changes require a security risk assessment. Approved changes are tested in separate environments before deployment, and only authorised personnel can implement changes to production. This disciplined approach ensures all changes are controlled and data remains protected.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our vulnerability management process aligns with ISO/IEC 27001 and industry best practice. We assess potential threats using automated vulnerability scanning, penetration testing, and continuous monitoring of threat intelligence feeds (including AWS GuardDuty, vendor advisories, and government alerts). Vulnerabilities are prioritised using the Common Vulnerability Scoring System (CVSS v3.0). Critical and high-risk patches are deployed within 24 hours; all other security patches are applied as part of our daily automated update cycle. Information about potential threats is sourced from security advisories, vendor notifications, industry forums, and government agencies. This ensures rapid response and ongoing protection.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We use automated tools (including AWS GuardDuty and anomaly detection) to monitor for suspicious activity such as unusual logins or privilege escalation. All access to sensitive data is logged with timestamps and user IDs. If a potential compromise is detected, our engineering team is alerted immediately, isolate affected systems and investigate. We respond to critical incidents within 24 hours, with all actions documented under our ISO/IEC 27001-aligned policies. This ensures rapid detection, containment, and remediation, maintaining data integrity
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We maintain a structured incident management process with pre-defined procedures for common events, including system outages, security breaches, and data loss. Users report incidents via phone, email, or live chat, with all tickets logged and tracked in our support system.
Incidents are prioritised as follows:
- Critical (system-wide outage/security breach)
- High (payment or booking errors)
- Medium (workflow bugs)
- Low (minor issues).
Clients receive immediate notification for any incident impacting their data, including a summary of the issue, impact, and remediation steps.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
INTERCERT
ISO/IEC 27001 accreditation date
Wednesday 27 August 2025
What the ISO/IEC 27001 doesn’t cover
The scope of the Information Security Management System is limited to information security relating to the design, development, and operation of all applications, data, and infrastructure utilized by SpacetoCo in the successful delivery of its services to customers and stakeholders.
The Information Security Management System (ISMS) encompasses the following departments:
Information Technology, Software Development, Information Security, Customer Success, Marketing, Human Resources, Finance, Risk and Compliance Management.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
8955ee78-31e5-401d-8ba9-38e4df13cf9e
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
Data Protection Registration Certificate

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales.uk@spacetoco.com. Tell them what format you need. It will help if you say what assistive technology you use.