Bookteq Booking Software
Bookteq streamlines venue management by automating bookings, reducing workload, and increasing utilisation. The online system attracts customers, secures payments online, and minimises errors. By simplifying operations and improving visibility, Bookteq enables councils, schools, and community venues to generate more revenue while delivering a smoother experience for both staff and hirers.
Features
- self-service bookings
- document capture
- online payments
- payment plans
- invoicing
- in-depth reporting/analytics
- multi-venue management
- calendar management
- multiple user access levels
- customer portal
Benefits
- time saving
- increased revenue
- increase utlisation
- improved customer experience
- reduced admin
- increased visibility
- marketing presence
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 0 6 8 0 7 8 4 3 9 7 3 4 9 0
Contact
MY LOCAL PITCH LTD
Luke Joseph
Telephone: 0203 637 4328
Email: sales@playfinder.com
About your service
- Service categories
-
Applications
Customer relationship management
- Digital commerce
- Customer service
- Contact centre
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Yes, our service has the following constraints:
Maintenance: We notify of scheduled maintenance but reserve the right to suspend access without notice for emergency fixes. Routine releases occur during business hours.
API Limits: Requests are capped at 5,000 per hour to ensure stability.
Customisation: Clients cannot copy, modify, or create derivative works from the software.
Support: Limited to Business Hours (Mon-Fri, 09:00–18:00).
Data Restoration: While system-wide recovery is standard, customer-specific rollbacks (e.g. accidental user deletion) require allocated development time. - System requirements
-
- Internet access
- Web browser
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support Channels: Support is provided via direct email, knowledge base for both admin staff and their hirers, in-product messaging, and telephone.
Support Hours: Monday–Friday 09:00 – 18:00 (UK time).
Response Time: We aim to respond to all inbound enquiries and tickets with a time to first response of less than 1 Business Day. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Our in-product messaging and web chat functionality is tested as part of our broader platform accessibility testing. We utilise automated scanning tools within our test environment to verify compliance with WCAG 2.1 Level AA guidelines. This ensures that the chat interface maintains compatible contrast ratios, proper aria-labels, and keyboard navigability suitable for assistive technologies.
While we rely primarily on automated scanning to ensure continuous compliance across our release cycles, we adhere to the principles of best practice for accessibility to ensure our service remains usable for all users. - Onsite support
- No
- Support levels
-
Support Levels Provided
We provide Standard Support via telephone, email, and in-product messaging. Support operates during Business Hours (Monday to Friday, 09:00 – 18:00). We also offer Managed Services, an optional tier where Playfinder performs active administration of bookings and enquiry handling on the Client's behalf.
Cost of Support Levels
Standard Support: Included in the annual Subscription Fee at no additional cost.
Managed Services: An optional add-on priced based on the specific scope required.
Integration Support: One-on-one developer time is available if required.
Technical Account Manager & Cloud Support Engineer Yes, we provide:
Account Manager: A dedicated Account Manager handles the Client’s account. Ensures that the client is getting value from the software and using it in an efficient way for their specific use case. The Account Manager also heads up the Support and Onboarding Teams.
Developer Support: We provide access to technical staff for integrations, including one-on-one time.
Support Team: Our helpdesk handles faults adhering to strict SLA severity levels (Critical to Low) with defined response/fix times. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Onboarding Process
We follow a structured onboarding timeline managed by a dedicated Account Manager. The process typically includes:
- Configuration: We collect "Venue Information Forms" to configure spaces, facilities, pricing schemes, and repeat booking settings.
- Setup: We create the Bookteq account and Playfinder marketplace listings.
- Testing: We support client testing, including data checks, connecting payment accounts (Stripe/GoCardless), and familiarisation with the system.
- Go-Live: We host a pre-launch call to verify settings and assist with embedding calendar widgets onto the client’s website.
- Training: We arrange dedicated training sessions for staff which can be delivered in-person (at additional cost) or via Teams. These sessions are recorded and shared afterwards for internal reference.
- Documentation and Support: Clients have access to a support library and knowledge base. We also assist with customer communication assets, such as a customer portal guide, to help explain the new booking journey to end-users. Ongoing support is provided via telephone, email, and in-product messaging. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
Users can extract their data at any time directly through the Bookteq system.
Format: All data (e.g., customers, bookings) is downloadable via CSV format.
Cost: There are no charges incurred for accessing, sharing, or downloading system data at the request of the Client.
Timing: Clients must extract their data prior to the termination date. On or before the termination date, we execute a process to complete the deletion of all accounts, reports, and data related to the client. - End-of-contract process
-
End-of-Contract Process
At the end of the contract, the Client is responsible for extracting their data prior to the termination date. All data (e.g., customers, bookings) is downloadable via CSV format directly through the Bookteq system.
On or before the termination date, we execute a standard process to complete the deletion of all accounts, reports, and databases related to the Client. If the Client does not already control their Stripe payment account, we can transfer control of the internal Stripe account to the Client upon termination. Upon termination, the Client must immediately cease using Playfinder’s Intellectual Property.
Price and Additional Costs
Included in the Price: Standard offboarding is included in the contract price. There are no charges incurred for accessing, sharing, or downloading system data at the request of the Client. The deletion of accounts/data and the transfer of Stripe account control (where required) are also performed at no additional cost.
Additional Costs: There are no additional costs for the standard end-of-contract data extraction and account closure process. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Fully mobile optimised. Full functionality of system available in a device-friendly layout and scale.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Optimised for user-friendliness, intuitiveness and accessibility. The lay out allows for simple and logical journey to complete tasks in the system.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Our in-product messaging and web chat functionality is tested as part of our broader platform accessibility testing. We utilise automated scanning tools within our test environment to verify compliance with WCAG 2.1 Level AA guidelines. This ensures that the chat interface maintains compatible contrast ratios, proper aria-labels, and keyboard navigability suitable for assistive technologies.
While we rely primarily on automated scanning to ensure continuous compliance across our release cycles, we adhere to the principles of best practice for accessibility to ensure our service remains usable for all users. - API
- Yes
- What users can and can't do using the API
- Users can perform any action through the API.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise set up - facilities, pricing and booking rules.
White labeling and developer services are available at cost to the client. These Customisations would be carried out by in-house developers and can include feature development, intergrations or system theme/branding match.
Scaling
- Independence of resources
- Load testing done frequently to ensure we can handle spikes in usage. We also DDOS protection to ensures users are not affected by other usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Customer Service
Ticket volumes (created, closed, velocity) and ticket types
Average time to first contact and close
Average call answer rate and Average first-contact resolution
Customer Satisfaction (CSAT, being changed to NPS)
Bookings Performance
Percentage of bookings and payments made online/offline
Number and value of bookings by source
Count and value of unpaid bookings (‘Aged Receivables’ / ‘Debts’)
Software Performance
Uptime percentage
Average response times from the API
Defects and Bugs, and what % of these meet agreed SLAs
Number of logged errors or failures
Number of releases and changes applied to the production systems - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Customers can pull all data out of the Bookteq system via CSV. Available for both Booking and Customer data. Other CSV reports available for invoice/finance data.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.99% Uptime
- Approach to resilience
- Available on request
- Outage reporting
- We notify via email and banners in system (where available)
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Single Sign-On (SSO)
- Access restrictions in management interfaces and support channels
-
We restrict management access using Role Based Access Control (RBAC), ensuring users cannot create accounts with higher permissions than their own. Authentication is secured via OAuth2 or passwords, with support for Multi-Factor Authentication (MFA).
Internal administration uses a separate interface without customer data access, and infrastructure is isolated within a VPN.
Support channel access follows a strict "least privilege" policy. Only required personnel have specific department-level access, which is revoked immediately upon offboarding. User identities are confirmed before access is granted. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Less than 1 month
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Less than 1 month
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Our security governance is driven by our GRC strategy, led by the CEO and overseen at board level. We leverage Vanta to automate policy management, risk assessments, and compliance monitoring, ensuring alignment UK government standards. Policies are regularly reviewed, and all staff complete annual security training. Our incident response process is documented and tested. Supplier security is assessed during procurement. Vanta’s platform enables continuous improvement and real-time visibility, supporting our commitment to robust data protection and meeting Crown Commercial Service requirements.
- Information security policies and processes
-
We implement a layered approach to information security, guided by a formal policy framework covering areas such as asset management, user access, encryption, vulnerability management, and business continuity. Our policies are designed to address both technical and organisational risks, and are accessible to all staff via our internal portal.
The Head of Development is responsible for day-to-day security operations, with regular updates provided to the CEO and Board. We ensure policy adherence through a combination of technical controls (e.g., enforced multi-factor authentication, automated device monitoring), regular compliance checks, and clear disciplinary procedures for non-compliance.
Processes include quarterly access reviews, prompt incident reporting, and periodic risk assessments. Employees are required to complete security training and policy attestations annually. We also conduct simulated phishing exercises and review lessons learned from security events to strengthen our defences.
Policy effectiveness is measured through internal audits and feedback mechanisms, with results reported to senior leadership. This ensures that our security practices remain current, effective, and responsive to emerging threats, supporting our commitment to safeguarding customer and business data. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management is governed by our Operations Security Policy and related procedures. Our approach ensures that all changes to production systems, software, and infrastructure are controlled, documented, and reviewed to maintain security and operational integrity.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We obtain information about technical vulnerabilities from multiple sources, including automated vulnerability scans, vendor alerts, and threat intelligence feeds. Application code is scanned for vulnerabilities prior to deployment. Vulnerabilities are remediated according to their severity. Critical/High: within 30 days, Medium: within 60 days, Low: within 90 days
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use runtime security tools, dependency scanning in CI/CD pipelines, and cloud-based alerting to detect vulnerabilities and threats in real time. Logs are configured to prevent tampering and are regularly reviewed.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
If a vulnerability is exploited, our incident response process includes investigation, containment, eradication, recovery, and post-incident review. Lessons learned are used to improve our vulnerability management and detection capabilities.
Users submit incidents via our chat/email/telephone. This is managed by our internal ticketing system. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- PCI Security Standards Council, LLC.
- PCI DSS accreditation date
- Thursday 4 September 2025
- What the PCI DSS doesn’t cover
- Our PCI DSS SAQ-A certification covers our specific merchant environment for E-Commerce transactions. It does not cover the electronic storage, processing, or transmission of cardholder data, as these functions are fully outsourced to our validated Third-Party Service Provider (Stripe). Additionally, this certification does not cover Card-Present (face-to-face) or Mail Order/Telephone Order (MOTO) channels, as these are not applicable to our deployment.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- F370edbf-fdad-4aeb-afea-708d7f79231c
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
-