Skip to main content
SunnyDays

Access & account · Security

How does magic-link sign-in work, and is it secure?

You book as a guest — no account, no password. To see or manage a booking later you enter your email and we send a single-use link.

The security properties, stated plainly:

  • Signed and scoped — the token is signed server-side and bound to that email address and that set of bookings. It cannot be edited to reach anyone else's trip.
  • Short-lived — valid 15 minutes.
  • Single use — it burns the first time it's opened. A forwarded email is a dead link.
  • Bound session — opening it grants a 30-minute session tied to that browser.
  • Re-challenged for destructive actions — cancelling or amending requires a fresh link, so an old email in someone else's inbox can't cancel your holiday.
  • No enumeration — we return the same "check your email" message whether or not the address has bookings, so nobody can use the form to test who's a customer.

Compared with a password, there is no credential to reuse, phish, breach or forget. The trade-off is that access depends on your email account — so secure that with two-factor authentication.

More on access & account

All 21 help articles

Still stuck? Talk to a person

Email help@sunnydays.thedigitalcarpenter.com — replies within one business day, most inside four hours.

Travelling in the next 48 hours, or travelling now: the urgent line +1 (555) 018-7742 is staffed 24/7 and answered in under three minutes, or we call you back.

Full contact detail, including postal address, is on the contact page. Please never send card numbers by email — we will never ask for one, and we do not need it to find your booking.

Help centre last reviewed 3 August 2026. Our terms of service and privacy policy are the governing documents; where this page summarises them, they win.