Humble Bookings
Humble Bookings streamlines facility and booking management by centralising memberships, payments, customer data, and analytics into one platform. Organisations benefit from automated booking processes, QR code sign-in, comprehensive reporting, marketplace functionality for partners, branded customer-facing websites, and real-time insights that reduce administrative workload while improving operational efficiency and revenue growth.
Features
- Manage memberships, facilities and events
- Real-time reporting
- Works with existing hardware
- QR code based sign in system
- Branded website
- Report builder
- Supports one off events and recurring ones with complex schedules
- Ability to process payments
- Role based access control and permissions
- Accident/incident logging
Benefits
- Allow stakeholders to directly access the reports they require
- Reduce workload by giving customers autonomy
- Create reports that contain exactly the information you need
- Grow revenue and scale strategically
- Eliminate double bookings and inaccurate data
- Improve customer experience
- Make data-driven decisions
- Improve efficiency from day one, without investing in new hardware
- Be more flexible with the services you offer
- Optimise resource and capacity utilisation
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 1 7 2 1 6 0 2 2 6 6 3 2 4 5
Contact
Humble
Andy Green
Telephone: 0330 229 5066
Email: tenders@wearehumble.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Humble Bookings is only available as a hosted solution (not on-premise/self hosted).
- System requirements
-
- An active internet connection
- Users must be able to use MFA
- An up-to-date web browser that supports Javascript
User support
- Email or online ticketing support
- Yes
- Support response times
- We aim to respond to all support requests within 24 - 48 hours, but it is often within a couple of hours during office hours (9 AM to 5 PM - Monday to Friday). Outside of office hours, we still aim to respond within 24 - 48 hours. For urgent requests, we typically respond within the hour and move to telephone support.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Basic support, provided to all customers, is primarily support ticket based. We reply fastest within our office hours but support tickets are monitored outside of office hours. Tickets can be escalated by our team, at which point we may decide that it is more efficient to use a different means of communication or plan a site visit.
We can also offer Service Level Agreements (SLAs) on a bespoke basis. These can include guaranteed response times, dedicated account managers, priority support and regular meetings/visits. They are priced according to an organisation's requirements. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide comprehensive onboarding support through a structured three-stage process designed to ensure successful adoption.
Initial Consultation: We begin by understanding your organisation's objectives and current operations. This holistic approach ensures Humble Bookings integrates seamlessly with existing processes rather than disrupting them. We explore all available features and identify cost-benefit opportunities to streamline processes, increase margins, or grow revenue.
Setup and Implementation: Following consultation, we configure Humble Bookings specifically for your organisation, importing existing customer data via CSV files or directly from platforms like Eventbrite. For organisations migrating from other systems, we can develop bespoke import tools. We handle Stripe payment integration and can provision the system as quickly as the same day as your consultation. A detailed rollout plan, including training schedules, is then prepared.
Training and Support: Our training extends beyond software mechanics to focus on effective use within your specific organisational context. We train all relevant staff members and support them in guiding your customers through the adoption period.
Throughout onboarding, users receive dedicated account management, unlimited email support (escalated to calls or in-person meetings as needed), access to comprehensive support materials, and our standard response time commitments to ensure a smooth transition. - Service documentation
- No
- End-of-contract data extraction
- Any report, as well as lists of information, can be exported from the system in various formats (most commonly CSV and Excel workbooks) at any time via the interface. We can also create custom data extracts for users upon request.
- End-of-contract process
- At the end of the contract, customers retain full access to their account for 30 days to export data, which we are happy to assist with. Customer data is retained for 30 days after contract termination to allow for reactivation, after which it is securely and permanently deleted in accordance with UK GDPR requirements. Final invoices are issued and any outstanding payments settled. No charges apply for data export, but we may charge if customers require support migrating to another service.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- For the most part, it is possible to do everything that you can on a desktop on a mobile device. However, when using a mobile device, it is not as easy to use some of the more advanced features such as reporting. On the other hand, the registration interface has been optimised for mobile devices.
- Service interface
- No
- User support accessibility
- EN 301 549
- API
- No
- Customisation available
- Yes
- Description of customisation
- Users with administrator access to the service can customise the colours used and upload their own logos via the Settings. These customisations affect emails sent, as well as the interface that students and parents/guardians use to book onto activities, monitor their attendance and make payments.
Scaling
- Independence of resources
- Humble Bookings operates on a multi-tenant architecture with strict data isolation between organisations. Each tenant's data is logically separated at the database level, preventing any cross-contamination. Our AWS infrastructure automatically scales resources based on demand, ensuring consistent performance across all customers. We implement rate limiting, asynchronous message processing for resource-intensive operations, and caching to prevent any single tenant from monopolising system resources. Performance is continuously monitored, and we maintain capacity headroom to handle usage spikes without impacting other users' experience.
Analytics
- Service usage metrics
- Yes
- Metrics types
- User activity (such as login date/time), usage per school and subject area, number of reports generated, logs on when attendance data is uploaded and the discrepancy between when data is uploaded vs when an activity actually took place, revenue collected. Many of these metrics can also be compared to previous periods.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Never
- Protecting data at rest
-
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users export data through the same web interface they use on a day to day basis.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLSX
- JSON
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Humble Bookings is hosted on AWS infrastructure with auto-scaling capabilities to ensure high availability. While our standard service does not include a formal SLA, we maintain platform availability through redundant systems, automated monitoring, and proactive maintenance scheduling.
For customers requiring guaranteed uptime commitments, we offer bespoke Service Level Agreements providing up to 99% availability guarantees. These custom SLAs include:
Availability Commitment: Up to 99% monthly uptime (excluding scheduled maintenance windows notified 7 days in advance)
Service Credits: If guaranteed availability is not met, customers receive percentage-based refunds of their monthly SLA fee, calculated proportionally to the shortfall in uptime
Monitoring & Reporting: Automated uptime tracking with monthly availability reports provided to SLA customers
Exclusions: Downtime caused by Force Majeure events, customer-initiated actions, or emergency security patches are excluded from SLA calculations.
Customers interested in formal availability commitments should contact us to discuss bespoke SLA requirements tailored to their specific needs and risk profile. - Approach to resilience
-
Humble Bookings is built on AWS infrastructure designed for high availability and resilience:
Infrastructure Redundancy: We use auto-scaling across multiple availability zones, ensuring service continuity if individual servers or zones experience issues. Load balancers automatically distribute traffic and route around failed instances.
Database Resilience: Databases are automatically backed-up daily with point-in-time recovery capability. Database instances can be configured with Multi-AZ deployment for automatic failover, maintaining data availability during infrastructure failures.
Scalability: Auto-scaling groups automatically adjust capacity based on demand, preventing performance degradation during traffic spikes while maintaining cost efficiency during low-usage periods.
Monitoring & Response: Automated monitoring with CloudWatch alerts enables rapid detection and response to system issues. Performance metrics, error rates, and availability are continuously tracked.
Disaster Recovery: Automated daily backups retained for 30 days enable rapid recovery from data corruption or system failures. Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets can be defined in bespoke SLAs.
Security Updates: Critical security patches are applied promptly, with routine updates scheduled during low-usage periods with advance customer notification.
Detailed resilience documentation including architectural diagrams and incident response procedures is available on request. - Outage reporting
- Customers will be alerted to any outages, and updates related to them, via emails sent to all administrators within their account. Over time, we will also be introducing a public dashboard that serves as a log for any incidents.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
We strictly control access through role-based access control (RBAC) and multi-factor authentication (MFA) and continually review the roles that each member of staff has.
Version control systems (BitBucket) require two-factor authentication and access is granted only to development team members. Deployment pipeline access is controlled through AWS IAM roles with granular permissions.
Customer support channels (email helpdesk) authenticate users through verified email addresses and account details verification. Sensitive account modifications require additional validation steps.
All administrative access is logged and monitored via AWS CloudTrail, creating comprehensive audit trails for security review and compliance purposes. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials & Cyber Essentials Plus
- Information security policies and processes
-
Humble maintains comprehensive information security policies with clear accountability and oversight structures. Our security framework includes:
Data Protection: Full UK GDPR compliance with documented privacy policies, data processing agreements, and regular reviews of data handling practices.
Access Controls: Role-based access within the application, multi-factor authentication for administrative access, password hashing using bcrypt, and principle of least privilege across all systems.
Infrastructure Security: AWS-managed infrastructure with encryption at rest (RDS) and in transit (TLS 1.2+), automated security patching, isolated multi-tenant architecture, and continuous monitoring.
Development Practices: Secure coding standards, regular dependency updates, input validation and sanitization, and thorough testing before deployment.
Incident Response: Documented procedures for security incidents including customer notification protocols and breach reporting to ICO where required.
Compliance: Cyber Essentials Plus certified, with regular security reviews and annual policy updates. Our AWS infrastructure benefits from their compliance certifications (SOC 2, ISO 27001).
All security policies are documented, regularly reviewed, and enforced throughout the development and operational lifecycle. Reporting structures ensure accountability and rapid response to security concerns, with developers reporting currently to company directors. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All code and infrastructure components are version-controlled in Git (BitBucket) using GitFlow branching strategy, maintaining complete change history and traceability throughout the component lifecycle.
Changes follow a structured workflow: development occurs in feature branches, undergoes peer review via pull requests, and requires director/manager approval before merging to production branches. AWS CodePipeline automates deployment from approved branches, ensuring consistency and traceability.
Security impact assessment is integrated into the review process, evaluating changes for potential vulnerabilities, data exposure risks, authentication/authorisation impacts, and dependency updates. Critical security changes receive enhanced scrutiny before deployment. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Potential threats are continuously assessed through automated dependency scanning, infrastructure security bulletins, framework advisories, and vulnerability alerts. Sentry provides real-time error tracking to detect application anomalies indicating potential security issues.
Critical security patches are deployed within 24-48 hours following expedited testing. Routine updates are applied during scheduled maintenance windows. Cloud-managed services receive automatic security patches.
Threat intelligence sources include AWS Security Hub, framework-specific resources, OWASP, and NCSC alerts. CloudWatch and Sentry monitoring detect suspicious activity or exploitation attempts in real-time. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Potential compromises are identified through monitoring AWS logs for suspicious activity patterns and Sentry for application errors and anomalies. Automated alerts also flag authentication failures, unusual access patterns, or resource consumption spikes.
Upon detecting potential compromises, we investigate immediately, assessing severity and scope. Critical incidents trigger immediate containment actions including isolating affected systems, revoking compromised credentials, and blocking malicious traffic. Affected customers are notified within 72 hours.
Response times: Critical security incidents receive immediate attention (within 1 hour), high-priority issues within 4 hours, and standard incidents within 24 hours. All incidents are documented with root cause analysis and remediation steps - Incident management type
- Supplier-defined controls
- Incident management approach
- In order to report an incident, we ask users to email as much detail as possible to an email address provided to them during the onboarding process. All incidents will first be reviewed by management, who will decide the best course of action and who should be responsible for resolving the issue. We do not currently have pre-defined processes as this ensures incidents are reviewed on a case by case basis. Once an incident is resolved, a manager will email a report to affected users outlining the incident and the steps taken.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We offer an unlimited free trial for 30 days - no payment required. During the trial, there is unrestricted access to the service and all features.
- Link to free trial
- https://bookings.wearehumble.co.uk/signup
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Fbe92e99-66ea-4fcb-9c8e-80c026be5ed6
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 8d157d52-25a4-43bd-8f9b-f6174b8c3fc2
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Content of the outreach activity is designed to suit the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-