Log in Register ⚡ Features 🔍 How it works 💰 Pricing 🎬 Video ❓ FAQ 📲 Mobile App 🔒 Security 📖 Documentation ⬇️ Download
🔒 Security & Privacy

Your space, your security

At BookingFish, security is not an option — it's the architecture. Your space is private, your data is encrypted, and your emails to clients are digitally signed.

HTTPS All connections encrypted
DKIM Digitally signed emails
🇨🇦 Data hosted in Canada
0 BookingFish access to your bank
🏗️ Architecture

Security at the heart of the system

Every layer of BookingFish was designed with security as the absolute priority.

End-to-end encryption

All communications between your browser and our servers are encrypted via HTTPS/TLS. Impossible to intercept.

  • Active SSL certificate on all pages
  • TLS 1.2 protocol minimum
  • Forced HTTP → HTTPS redirect

Secured database

All your reservation data, member information and client data are stored encrypted with restricted access.

  • Hashed passwords (bcrypt)
  • Payment data never stored
  • Access restricted by user role

Member isolation

Each member only has access to their own data. Your reservations, clients and information are completely isolated from other members.

  • No data sharing between members
  • Secure sessions with unique token
  • Revocable guide access tokens

Payments via Stripe Express

BookingFish uses only the Stripe gateway to transfer your clients' payments directly to you. BookingFish has no access to your bank account.

  • Card numbers never transmitted to BookingFish
  • PCI DSS compliance via Stripe
  • Direct transfers to your bank account

Secure authentication

Access to your member area is protected by robust authentication. Each session is verified and unauthorized access is blocked.

  • Session verification on every request
  • Automatic expiration of inactive sessions
  • Protection against brute force attacks

Continuous updates

The BookingFish platform is actively maintained. Vulnerabilities are fixed quickly and dependencies are kept up to date.

  • Security patches applied quickly
  • Continuous technology monitoring
  • Validation tests after each update
📧 Signed emails

Your emails digitally signed with SMTP-DKIM

Every email sent to your clients — confirmation, cancellation, reminder — carries a cryptographic signature that proves its authenticity.

How does DKIM work?

DKIM (DomainKeys Identified Mail) is an email authentication protocol. When an email is sent to your clients, it is signed with a cryptographic private key associated with the bookingfish.ca domain.

The recipient's mail server verifies this signature by consulting the public DNS of bookingfish.ca. If the signature is valid, the email is delivered normally. Otherwise, it is flagged as suspicious or rejected.

  • Cryptographic signature on every email
  • Impossible to forge a BookingFish email
  • Your clients receive emails in main inbox
  • Protects against phishing and spoofing

What this means for you

Without DKIM, booking confirmation emails can end up in spam. With our integrated SMTP-DKIM system, your clients receive emails directly in their main inbox.

  • Booking confirmation delivered to main inbox
  • Cancellation email always received by client
  • Fishing trip reminder clearly visible
  • No configuration required on your part
  • System entirely managed by BookingFish
Key advantage: Your client who books a fishing trip will receive their confirmation immediately, in their main inbox — not in junk. That's the difference DKIM makes.
🔐 Private space

Your individual private space — not a marketplace

BookingFish is not a marketplace where clients browse multiple guides. It's your own private booking space.

BookingFish
Your private space
Direct link → your clients only → your bookings
vs
Marketplace (FishingBooker, etc.)
Shared public space
Your competitors shown next to you → your clients see other guides

Your booking system, entirely yours

With BookingFish, you get a unique booking link that belongs to you. When a client clicks your link, they land directly on your form — not on a page where your competitors are listed right next to you.

  • Exclusive direct link: Your booking URL leads only to your calendar
  • No visible competition: Your clients don't see other guides on your page
  • Your clients belong to you: BookingFish does not reuse your client data for other members
  • Integration on your site: Embed your calendar on your own WordPress site
  • Data isolated in DB: Your reservations and client data are isolated from other accounts
  • No ranking algorithm: You are not rated or ranked against other guides
📊 Comparison

BookingFish vs other booking platforms

Understand the fundamental differences between BookingFish and other solutions available for fishing guides.

Feature BookingFish 🎣 FishingBooker Roverd FareHarbor Checkfront
Private member space Partial
Public marketplace (competitors visible) No No
Commission per booking 0% (with annual plan) ~20–25% Variable ~6% Monthly subscription
Free without bookings Free sign-up
SMTP-DKIM signed emails Not documented Not documented Not documented Not documented
Direct payments (Stripe Express) Platform holds the funds Variable Variable Variable
Data hosted in Canada ✗ (USA) ✗ (USA)
Mobile calendar sync (ICS) Limited Limited Limited
Integrated gift certificates Limited
Free WordPress plugin Paid
Specialized fishing / Quebec / Canada International
Note: Information about other platforms is based on their public policies available at the time of writing. Terms may vary.
⚖️ Compliance

Compliance and Canadian regulation

BookingFish is developed and operated in Canada, in compliance with Canadian personal data protection laws.

LPRPDE / PIPEDA

Personal Information Protection and Electronic Documents Act — full compliance.

PCI DSS

Compliance with Payment Card Industry data security standards via Stripe.

Canadian hosting

Your data is hosted on servers in Canada, under Canadian jurisdiction.

CASL / LCAP

Canadian Anti-Spam Legislation: no commercial emails sent without explicit consent.

🔒

Your data belongs to you. Period.

BookingFish does not sell, rent or share your data or your clients' data with third parties for commercial purposes. Your information is used only to operate your booking system.

  • No targeted advertising with your data
  • No sale of client lists
  • Deletion on request available
  • Right of access to your data guaranteed
❓ FAQ

Frequently asked questions about security

Everything you wanted to know about BookingFish security.

Does BookingFish have access to my bank account?

No, never. BookingFish uses the Stripe Express payment gateway to transfer your clients' payments directly to your Stripe account, which is connected to your bank account. BookingFish has no access to your banking information — only Stripe handles the transfers.

Where is my data stored?

All BookingFish data is hosted on servers located in Canada, under Canadian jurisdiction. We do not transfer your personal data to servers outside Canada, except for Stripe for payment processing (which complies with international security standards).

Can another guide see my reservations or client information?

Absolutely not. Each member account is completely isolated. Your reservations, client data, and booking information are only accessible to you. No other member can see your data, and BookingFish staff only access account data to provide technical support.

Are my clients' emails going to end up in spam?

With our integrated SMTP-DKIM system, emails sent to your clients (confirmation, cancellation, reminder) are digitally signed and identified as coming from bookingfish.ca. This greatly reduces the risk of landing in spam. Your clients receive their booking confirmation directly in their main inbox.

What happens to my clients' data when they make a reservation?

Client data (name, email, phone, reservation details) is stored encrypted in our database and is accessible only to you — the member concerned. BookingFish does not share, sell or use this information for any purpose other than managing your reservations. Data is retained for 7 years to meet Canadian tax obligations.

Are my payments secure?

Yes. All payments are processed by Stripe, which is PCI DSS Level 1 certified — the highest security standard in the payment industry. Card numbers are never transmitted to BookingFish's servers. Stripe handles the entire payment process and the money is transferred directly to your bank account.

What is the difference between BookingFish and FishingBooker?

FishingBooker is a public marketplace where clients search among multiple fishing guides — your competitors are visible right next to you. BookingFish is your own private booking space: you share your direct link with your clients, and they land exclusively on your calendar. No competition, no ranking algorithm, your clients belong to you.

Can I request deletion of my data?

Yes, you can request deletion of your account and associated data at any time by contacting support@bookingfish.ca. Reservation data is retained for 7 years for Canadian tax obligations, then permanently deleted.

Another security question?

support@bookingfish.ca