Skip to main content

Help us improve the Digital Marketplace - send your feedback

LemonBooking

LemonBooking

LemonBooking is a booking and invoicing system designed for councils and council-supported community venues. It helps councils manage multiple bookable assets (e.g., halls, meeting rooms, sports facilities, outdoor spaces and library rooms) with online availability, booking requests/approvals, and fast invoice generation — reducing admin time for staff and volunteers.

Features

  • Online real-time availability calendar
  • Online booking
  • Fast invoice generation
  • Online payments via card and Direct Debit integrations
  • Deposit rules, discounts, and automatic price calculations
  • Track payments, part-payments, refunds, and outstanding balances
  • Customer accounts with booking history and recurring hire settings
  • Custom booking forms, terms, and automated email templates
  • Staff roles, permissions, and audit logs
  • Reports for income, utilisation, arrears, and exports

Benefits

  • Reduce admin time for staff and volunteers
  • Faster invoicing means improved cashflow and fewer late payments
  • Avoid double bookings
  • Improve customer experience with self-service bookings and payments
  • Standardise processes across multiple venues and bookable assets
  • Increase revenue with better utilisation and upsell extras
  • Reduce errors with automated pricing, deposits, and invoices
  • Clear oversight of arrears and payments for bookkeeping
  • Easy handover with centralised records and repeatable workflows
  • Better compliance with clear audit trails and consistent documentation

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at paul@tectonic-software.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 4 7 4 7 4 4 3 0 6 5 0 5 3 9

Contact

LemonBooking Paul Grosvenor
Telephone: +4553665767
Email: paul@tectonic-software.com

About your service

Service categories

Applications

Enterprise resource management

  • Asset life-cycle management

Financial

  • Financial and Accounting Applications
  • Accounts Payable Applications
  • Accounts Receivable Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Requires an internet connection and a browser (Chrome, Edge, Safari, Firefox or Opera) which has been updated in the past 12 months.
System requirements
  • Internet connection
  • Chrome, Edge, Safari, Firefox or Opera

User support

Email or online ticketing support
Yes
Support response times
Within 2 working days. Monday - Friday, 9am to 4pm.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
No
Support levels
Documentation and email support is available with all plans. Screensharing support is also available with the Gold plan. If you run multiple LemonBooking systems (e.g. multiple venues) you will also be assigned an account manager.
Support available to third parties
No

Onboarding and offboarding

Getting started
LemonBooking staff do all the initial setup, branding and configuration - except for data entry.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
All data can be exported to XLSX or SQL
End-of-contract process
There are no cancellation or termination fees.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
No significant differences
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
LemonBooking has two main interfaces. The customer-facing frontend shows real-time availability for rooms and facilities, lets users submit booking enquiries or requests, and supports online payments where enabled. Customers can receive automated confirmations, view booking details, and manage their information through a simple web experience embedded in the venue’s website. The staff backend provides an admin dashboard to approve bookings, manage calendars, customers and pricing, generate invoices, track payments and arrears, and run reports. Role-based access controls support different staff responsibilities across one or multiple venues.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We use the WAVE Evaluation Tool to check the frontend (customer-facing interface) is WCAG 2.2 AA compliant. The backend (staff-only) is not WCAG compliant.
API
Yes
What users can and can't do using the API
LemonBooking provides a read-only REST API over HTTPS returning JSON, authenticated using an API key bearer token. It supports listing and retrieving details for locations (venues), facilities (spaces), opening hours, customers, bookings, time slots, booking sessions, calendar restrictions, invoices, payments, and events/ticketing. Results are paginated (up to 50 items per response) and key endpoints support filters such as bookings by customer and date range, and time slots/sessions by booking, facility, or date range.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Customisation is possible for organisations that purchase 5 or more systems

Scaling

Independence of resources
We prevent “noisy neighbour” impact through isolation, scaling and safeguards. Each organisation’s data and access are logically separated. LemonBooking runs on serverless infrastructure that automatically scales compute capacity as demand rises, so one customer’s peak usage increases capacity rather than consuming a fixed shared pool. We continuously monitor database and application performance and scale capacity when needed. Rate limiting and abuse controls prevent any single tenant from overwhelming shared services. Heavy tasks (emails, exports, integrations) run via queues/background processing to keep the user interface responsive for everyone.

Analytics

Service usage metrics
Yes
Metrics types
LemonBooking can produce stats on booking volume and utilisation (by venue, room/facility, day/time, date range), income and invoicing (invoices raised, totals, VAT/tax breakdowns, paid vs unpaid, arrears, overdue amounts), and payments (amounts received, part-payments, refunds, payment methods). It can also report on customer activity (new customers, repeat hirers), cancellations/changes, and performance over time to help track demand, occupancy, and cashflow.
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
All data can be exported to XLSX or SQL
Data export formats
  • CSV
  • Other
Other data export formats
  • XLSX
  • SQL
Data import formats
  • CSV
  • Other
Other data import formats
  • XLSX
  • SQL

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Amazon Web Services (AWS) guarantees a minimum uptime of 99.95%.
Approach to resilience
Available on request
Outage reporting
Uptime statistics for the LemonBooking application, website and API are tracked and published here: https://status.lemonbooking.com

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted to authorised staff on a least-privilege, need-to-know basis, with role-based permissions and regular access reviews. Administrative access is protected using strong, unique passwords and multi-factor authentication where available. Support requests are handled only via approved channels, with verification checks before discussing account-specific information or making changes. Access attempts and relevant activity are logged and can be investigated as part of our incident response process.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials for LemonBooking + ISO/IEC 27001 for AWS
Information security policies and processes
Tectonic Software’s Information Security Policy commits to protecting the confidentiality, integrity, and availability of information assets. Data is classified (public, internal, confidential) to apply appropriate safeguards. Access is granted on a need-to-know basis, reviewed regularly, and access attempts are logged. Staff use strong, unique passwords and MFA where possible. Sensitive data is encrypted in transit. Company devices must be secured, with remote wipe enabled for mobiles. Systems are patched regularly. A documented incident response process and staff security training are in place. Physical server security is handled by AWS. Vendors are assessed, backups are performed and tested, and UK DPA 2018 compliance is maintained.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Tectonic Software’s Change Management Policy ensures changes are introduced in a controlled, low-risk way. Any proposed change is raised as a GitHub issue with a clear description, purpose, benefits, and risks. Issues are reviewed in team meetings, tagged and prioritised, then either scheduled into a development cycle, placed in the backlog, or rejected. Once approved, changes are implemented by the development team and deployed. If problems occur, a predefined rollback procedure is used to restore the previous state and minimise downtime. All changes are documented for audit and improvement, staff are trained, and the policy is reviewed annually.
Vulnerability management type
Undisclosed
Vulnerability management approach
We manage vulnerabilities through regular patching and controlled remediation. Systems, applications and dependencies are kept up to date, with security updates applied promptly to address known issues. Potential vulnerabilities are triaged, prioritised and tracked as GitHub issues, reviewed in team meetings, then scheduled or fast-tracked depending on risk. Changes follow our change management process, with testing, documented outcomes, and a defined rollback procedure to minimise disruption. Incidents are handled via a documented response process and staff security awareness training.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use protective monitoring to detect unauthorised access and abnormal activity. Access is restricted on a need-to-know basis, reviewed regularly, and relevant access attempts are logged for investigation. We monitor system health and availability using cloud/provider monitoring and application logs, and investigate alerts or anomalies promptly. Backups are performed and tested to support recovery and to identify unexpected data loss events. Suspected security events are handled through our documented incident response process, with actions tracked and lessons fed back into operational controls.
Incident management type
Supplier-defined controls
Incident management approach
Tectonic Software’s security incident response sets out an emergency plan and incident-specific playbooks. Once an incident is identified, the team is alerted immediately, system availability and performance are checked (BetterStack) and errors reviewed (Bugsnag), then findings are shared internally. Suppliers are contacted where relevant, and customers are notified with an initial update, follow-up updates (including recovery estimates), and a post-incident review to improve controls. Response plans cover software failures (rollback), AWS outages (use AWS Health Dashboard and, if prolonged, prepare failover to Google Cloud), supplier issues, integration failures, regulatory changes, and DDoS/phishing/hacking.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
30-day free trial with full access to all features and modules

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
7c0e4e41-d5a9-4dbc-96e7-7799bcc7dfc1
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Plans for positive actions with community groups.
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Introducing transparency to pay and reward processes
    • Working conditions which promote an inclusive working environment and promote retention and progression
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at paul@tectonic-software.com. Tell them what format you need. It will help if you say what assistive technology you use.