Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Online booking and reservation management platform for tours, rentals and activities, with an embeddable booking widget and payments.
Checkfront is an online booking and reservation management platform used by tour, rental and activity operators to take reservations and payments. Businesses embed a booking widget or iframe on their website, and the engine handles availability, customer details and checkout. Checkfront is operated by Checkfront Bookings, Inc. in Canada, with data hosted on AWS Canada and the AWS European Sovereign Cloud.
The booking flow collects customer names, contact details, booking dates and payment information, with card data handled by Stripe. Session cookies maintain the booking basket and the logged in account, while optional Google Analytics cross domain tracking can follow a visitor from the host site into the Checkfront checkout. The embeddable widget can therefore set cookies in the context of your own domain.
Processing a booking and payment relies on the contract legal basis under Article 6(1)(b), so consent is not needed for the core reservation. However, analytics and other non essential cookies require prior consent under Article 5(3) of the ePrivacy Directive and the GDPR. Operators remain the controller for the customer data they collect and should sign a data processing agreement with Checkfront.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Canada benefits from an EU adequacy decision for commercial organisations, which lowers the transfer risk for the core hosting. Optional integrations are different: Google Analytics and Stripe may route data to the United States, so those flows need appropriate safeguards such as Standard Contractual Clauses. Analytics cookies should only load after the visitor consents through your cookie banner.
Disclose Checkfront, Stripe and any analytics in your privacy and cookie policies, and gate analytics behind consent. Sign a data processing agreement with Checkfront, keep payment handling within Stripe to stay inside PCI DSS scope, and set retention limits for completed bookings. Choose EU hosting where appropriate and document the transfer position for any United States integrations.
Websites using Checkfront must obtain user consent under GDPR regulations.
DPIA considerations
A full DPIA is usually not required for standard booking management, but a screening assessment is advisable. Consider that the booking engine processes customer contact and payment details, that the embeddable widget can set cookies on the host site, and that optional Google Analytics and Stripe integrations may transfer data to the United States. Document hosting in Canada and the EU, the role of Stripe for payments, and consent handling for analytics cookies.
Sample consent text
We use Checkfront to manage your booking and process your payment. The booking form may set cookies needed to complete your reservation, and with your consent we use analytics cookies to improve the service. You can manage your preferences at any time.
Third-party domains contacted
checkfront.comcheckfront.iojs.stripe.comapi.stripe.comgoogle-analytics.comgoogletagmanager.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| CF_SESSID | Necessary | Session | Maintains the Checkfront booking session and the contents of the reservation basket |
| checkfront_session | Necessary | Session | Keeps the authenticated account session within the Checkfront booking engine |
| _ga | Analytics | 2 years | Google Analytics cross domain cookie that distinguishes visitors across the host site and checkout |
| _gid | Analytics | 24 hours | Google Analytics cookie that distinguishes visitors over a short period |
| __stripe_mid | Necessary | 1 year | Stripe cookie used for fraud prevention during payment |
| __stripe_sid | Necessary | 30 minutes | Stripe session cookie used for fraud prevention during checkout |
Checkfront uses cookies for user preferences — inform visitors with a consent banner.
Checkfront uses necessary session cookies to maintain the booking basket and the logged in account. If you enable Google Analytics cross domain tracking it sets analytics cookies, and Stripe sets fraud prevention cookies during payment. Only the strictly necessary cookies can load without consent.
The core booking and payment rely on the contract legal basis, so they do not need consent. However, any analytics or marketing cookies the widget loads require prior consent through your cookie banner before they fire.
Processing a reservation and payment is based on contract under Article 6(1)(b) GDPR. Analytics and other non essential cookies rely on consent under Article 6(1)(a) and Article 5(3) of the ePrivacy Directive.
Core hosting is in Canada, which has an EU adequacy decision, and the EU AWS region, so the base risk is low. Optional Google Analytics and Stripe integrations may send data to the United States, which then requires Standard Contractual Clauses.
A full DPIA is usually not required for standard booking management, but a screening assessment is advisable. If you process large volumes of bookings or add extensive analytics and profiling, a DPIA may become necessary.
Disclose Checkfront, Stripe and any analytics, and gate analytics cookies behind consent. Sign a data processing agreement, keep card data within Stripe to limit PCI DSS scope, and set retention limits for completed bookings.
Alternatives include FareHarbor, Rezdy, Bokun, Peek Pro and TrekkSoft. EU or adequacy country hosting and clear consent handling for analytics should weigh in any comparison.
List the necessary booking and Stripe cookies separately from the optional Google Analytics cookies, and explain their purpose and duration. Review the entry whenever you change integrations or Checkfront updates its widget.