LemonBooking
LemonBooking is a booking and invoicing system designed for councils and council-supported community venues. It helps councils manage multiple bookable assets (e.g., halls, meeting rooms, sports facilities, outdoor spaces and library rooms) with online availability, booking requests/approvals, and fast invoice generation — reducing admin time for staff and volunteers.
Features
- Online real-time availability calendar
- Online booking
- Fast invoice generation
- Online payments via card and Direct Debit integrations
- Deposit rules, discounts, and automatic price calculations
- Track payments, part-payments, refunds, and outstanding balances
- Customer accounts with booking history and recurring hire settings
- Custom booking forms, terms, and automated email templates
- Staff roles, permissions, and audit logs
- Reports for income, utilisation, arrears, and exports
Benefits
- Reduce admin time for staff and volunteers
- Faster invoicing means improved cashflow and fewer late payments
- Avoid double bookings
- Improve customer experience with self-service bookings and payments
- Standardise processes across multiple venues and bookable assets
- Increase revenue with better utilisation and upsell extras
- Reduce errors with automated pricing, deposits, and invoices
- Clear oversight of arrears and payments for bookkeeping
- Easy handover with centralised records and repeatable workflows
- Better compliance with clear audit trails and consistent documentation
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 4 7 4 7 4 4 3 0 6 5 0 5 3 9
Contact
LemonBooking
Paul Grosvenor
Telephone: +4553665767
Email: paul@tectonic-software.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Asset life-cycle management
Financial
- Financial and Accounting Applications
- Accounts Payable Applications
- Accounts Receivable Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Requires an internet connection and a browser (Chrome, Edge, Safari, Firefox or Opera) which has been updated in the past 12 months.
- System requirements
-
- Internet connection
- Chrome, Edge, Safari, Firefox or Opera
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 2 working days. Monday - Friday, 9am to 4pm.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- Documentation and email support is available with all plans. Screensharing support is also available with the Gold plan. If you run multiple LemonBooking systems (e.g. multiple venues) you will also be assigned an account manager.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- LemonBooking staff do all the initial setup, branding and configuration - except for data entry.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- All data can be exported to XLSX or SQL
- End-of-contract process
- There are no cancellation or termination fees.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No significant differences
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- LemonBooking has two main interfaces. The customer-facing frontend shows real-time availability for rooms and facilities, lets users submit booking enquiries or requests, and supports online payments where enabled. Customers can receive automated confirmations, view booking details, and manage their information through a simple web experience embedded in the venue’s website. The staff backend provides an admin dashboard to approve bookings, manage calendars, customers and pricing, generate invoices, track payments and arrears, and run reports. Role-based access controls support different staff responsibilities across one or multiple venues.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We use the WAVE Evaluation Tool to check the frontend (customer-facing interface) is WCAG 2.2 AA compliant. The backend (staff-only) is not WCAG compliant.
- API
- Yes
- What users can and can't do using the API
- LemonBooking provides a read-only REST API over HTTPS returning JSON, authenticated using an API key bearer token. It supports listing and retrieving details for locations (venues), facilities (spaces), opening hours, customers, bookings, time slots, booking sessions, calendar restrictions, invoices, payments, and events/ticketing. Results are paginated (up to 50 items per response) and key endpoints support filters such as bookings by customer and date range, and time slots/sessions by booking, facility, or date range.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Customisation is possible for organisations that purchase 5 or more systems
Scaling
- Independence of resources
- We prevent “noisy neighbour” impact through isolation, scaling and safeguards. Each organisation’s data and access are logically separated. LemonBooking runs on serverless infrastructure that automatically scales compute capacity as demand rises, so one customer’s peak usage increases capacity rather than consuming a fixed shared pool. We continuously monitor database and application performance and scale capacity when needed. Rate limiting and abuse controls prevent any single tenant from overwhelming shared services. Heavy tasks (emails, exports, integrations) run via queues/background processing to keep the user interface responsive for everyone.
Analytics
- Service usage metrics
- Yes
- Metrics types
- LemonBooking can produce stats on booking volume and utilisation (by venue, room/facility, day/time, date range), income and invoicing (invoices raised, totals, VAT/tax breakdowns, paid vs unpaid, arrears, overdue amounts), and payments (amounts received, part-payments, refunds, payment methods). It can also report on customer activity (new customers, repeat hirers), cancellations/changes, and performance over time to help track demand, occupancy, and cashflow.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- All data can be exported to XLSX or SQL
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLSX
- SQL
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XLSX
- SQL
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Amazon Web Services (AWS) guarantees a minimum uptime of 99.95%.
- Approach to resilience
- Available on request
- Outage reporting
- Uptime statistics for the LemonBooking application, website and API are tracked and published here: https://status.lemonbooking.com
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted to authorised staff on a least-privilege, need-to-know basis, with role-based permissions and regular access reviews. Administrative access is protected using strong, unique passwords and multi-factor authentication where available. Support requests are handled only via approved channels, with verification checks before discussing account-specific information or making changes. Access attempts and relevant activity are logged and can be investigated as part of our incident response process.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials for LemonBooking + ISO/IEC 27001 for AWS
- Information security policies and processes
- Tectonic Software’s Information Security Policy commits to protecting the confidentiality, integrity, and availability of information assets. Data is classified (public, internal, confidential) to apply appropriate safeguards. Access is granted on a need-to-know basis, reviewed regularly, and access attempts are logged. Staff use strong, unique passwords and MFA where possible. Sensitive data is encrypted in transit. Company devices must be secured, with remote wipe enabled for mobiles. Systems are patched regularly. A documented incident response process and staff security training are in place. Physical server security is handled by AWS. Vendors are assessed, backups are performed and tested, and UK DPA 2018 compliance is maintained.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Tectonic Software’s Change Management Policy ensures changes are introduced in a controlled, low-risk way. Any proposed change is raised as a GitHub issue with a clear description, purpose, benefits, and risks. Issues are reviewed in team meetings, tagged and prioritised, then either scheduled into a development cycle, placed in the backlog, or rejected. Once approved, changes are implemented by the development team and deployed. If problems occur, a predefined rollback procedure is used to restore the previous state and minimise downtime. All changes are documented for audit and improvement, staff are trained, and the policy is reviewed annually.
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- We manage vulnerabilities through regular patching and controlled remediation. Systems, applications and dependencies are kept up to date, with security updates applied promptly to address known issues. Potential vulnerabilities are triaged, prioritised and tracked as GitHub issues, reviewed in team meetings, then scheduled or fast-tracked depending on risk. Changes follow our change management process, with testing, documented outcomes, and a defined rollback procedure to minimise disruption. Incidents are handled via a documented response process and staff security awareness training.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use protective monitoring to detect unauthorised access and abnormal activity. Access is restricted on a need-to-know basis, reviewed regularly, and relevant access attempts are logged for investigation. We monitor system health and availability using cloud/provider monitoring and application logs, and investigate alerts or anomalies promptly. Backups are performed and tested to support recovery and to identify unexpected data loss events. Suspected security events are handled through our documented incident response process, with actions tracked and lessons fed back into operational controls.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Tectonic Software’s security incident response sets out an emergency plan and incident-specific playbooks. Once an incident is identified, the team is alerted immediately, system availability and performance are checked (BetterStack) and errors reviewed (Bugsnag), then findings are shared internally. Suppliers are contacted where relevant, and customers are notified with an initial update, follow-up updates (including recovery estimates), and a post-incident review to improve controls. Response plans cover software failures (rollback), AWS outages (use AWS Health Dashboard and, if prolonged, prepare failover to Google Cloud), supplier issues, integration failures, regulatory changes, and DDoS/phishing/hacking.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- 30-day free trial with full access to all features and modules
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7c0e4e41-d5a9-4dbc-96e7-7799bcc7dfc1
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-