Retention

Building a Simple Client Database

A guide working with a client on the water, photographed by 24/7 Sportfishing in FL24/7 Sportfishing, FL
24/7 Sportfishing at work.
Short answerAccess limited to what somebody needs is the element nobody applies. A sub-guide who needs Thursday's boat list does not need the master file.
Key takeaways
  • 16 CFR 314.1(b) applies the security rule to financial institutions within the Commission's jurisdiction, which a guiding business is not.
  • The rule's stated purpose names three kinds of safeguard, administrative, technical and physical, and three properties, security, confidentiality and integrity.
  • 16 CFR 314.4(c)(1) requires access limited to what a user needs, which for a guide means sharing a day's list rather than the master file.
  • 16 CFR 314.4(c)(2) requires knowing what data you hold and where, which most operations cannot answer because it lives in five places.
  • Keep the trip record and the marketing list as separate files, so the list can be pruned without destroying evidence.
  • Test the backup once by opening the copy and checking the last client you added is in it.

A guiding operation is not a financial institution, so the federal information security rule does not reach it. What that rule requires is nevertheless the clearest published account of what looking after a customer list actually involves, and most of it costs nothing.

Which is the useful way to approach a client database. The question is not what software to buy, it is what the list has to be able to do and what has to be true about it. The rule answers the second question in eight or nine elements, and the ones that matter to a one-person operation are access control, knowing what data you hold and where, and disposing of it when it stops being needed. Below the scope and the elements are read from the regulation as a model rather than a requirement, then the database itself. None of the rule applies to you. This is not legal advice. Related pieces sit at the running the business hub.

What a guide's client list actually has to do
JobField it needs
Decide whether to send a rebooking messageDate of last trip
Send it at a sensible hourState or time zone
Offer a specific date rather than a calendarWeeks previously fished
Honour a request to stopContact preference

Does the security rule apply to a guide?

No, and the scope provision says why.

Section 314.1(b) of Title 16 applies the part to the handling of customer information by financial institutions over which the Commission has rulemaking authority, and defines a financial institution as an entity whose business is engaging in an activity that is financial in nature or incidental to such activities, as described in the referenced banking legislation.

A guiding business does none of that, so the part does not reach it.

Paragraph (a) states the purpose, which is to set standards for developing, implementing and maintaining reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of customer information.

That sentence is the model worth borrowing, because it names the three kinds of safeguard and the three properties they protect, which is a better framework than any software feature list.

Part 314 is carried on the eCFR.

What the records themselves have to establish is covered in the bookkeeping piece.

The working end of a guided day, photographed by Corpus Christi Port Aransas Saltwater Fly Fishing Charter in TXCorpus Christi Port Aransas Saltwater Fly Fishing Charter, TX
On the water with Corpus Christi Port Aransas Saltwater Fly Fishing Charter.

What does the rule ask of access?

Two things, and the second is the one guides ignore.

Section 314.4(c)(1) requires the implementation and periodic review of access controls, including technical and as appropriate physical controls, to authenticate and permit access only to authorised users, and to limit authorised users' access only to the information they need to perform their duties.

The first limb is a password, which every operation has in some form.

The second is the interesting one: access limited to what somebody needs. A sub-guide who needs to know who is on Thursday's boat does not need the whole client list with telephone numbers and medical notes.

Which for a spreadsheet means two files rather than one, or a shared view rather than the master.

That distinction costs nothing and is almost never made.

What the arrangement with that person should cover is in the first sub-guide piece.

A list is worth more than the software that holds it. Ninety clients a season, with a thirty per cent rebooking rate, is 27 trips a year that arrive because somebody was on a list. At $650 that is $17,550 of revenue attributable to a spreadsheet. Against a paid channel at, say, $120 a booked trip, replacing those 27 bookings would cost $3,240 a year, every year. Which values the list at several thousand dollars annually and makes losing it the most expensive single accident available to a one-person operation. A backup costs nothing.

9The columns a guide's client list actually needs: name, telephone, email, state, last trip date, water and week, party size and composition, amount paid, and contact preference.Source: Operational judgment, not a sourced figure
The working end of a guided day, photographed by Flatsmonster Inshore Fishing in FLFlatsmonster Inshore, FL
Another frame from Flatsmonster Inshore Fishing.

What does it say about knowing your own data?

Identify and manage it, in proportion to its importance.

Section 314.4(c)(2) requires you to identify and manage the data, personnel, devices, systems and facilities that enable you to achieve business purposes, in accordance with their relative importance to business objectives and your risk strategy.

Stripped of the framing, that is an inventory question: what do you hold, where is it, and which of it matters.

Most guiding operations cannot answer it, because client information lives in a spreadsheet, a booking tool, an email inbox, a phone's contacts and a pile of paper forms simultaneously.

Which means an accident in any one of five places is an accident, and none of them is backed up together.

Writing the inventory down is twenty minutes and it is the step that makes every other decision possible.

What the paper side of it looks like is covered in the intake form piece.

The rule described does not bind you. It applies to financial institutions within the Commission's jurisdiction and is quoted as a model of what safeguarding a customer list involves. State data breach and privacy statutes were not read for this page and several impose duties on small businesses. Take advice if you hold anything sensitive, and confirm any obligation with your own state before relying on this.

What about encryption?

Required there, sensible here, and mostly already done for you.

Section 314.4(c)(3) requires customer information to be protected by encryption both in transit over external networks and at rest, with a provision allowing effective alternative compensating controls where encryption is determined to be infeasible.

For a guiding operation the practical position is that a mainstream cloud spreadsheet or booking tool already encrypts in both states, and a spreadsheet on a laptop desktop does not.

Which is an argument for keeping the master list in a hosted service rather than on a device, and it is also the cheaper option.

Where paper forms exist, the equivalent control is physical: a locked drawer rather than the back of the truck.

None of that is difficult and all of it is the sort of thing nobody does until something goes wrong.

Why the paper record still matters is covered in the digital waiver piece.

What should the database actually contain?

Nine fields, and not one more than you use.

Name, telephone number and email address, which is the contactable minimum.

The state they live in, because message timing and licence questions both depend on it.

The date of their most recent trip, which is the field every follow-up decision runs off.

The water and the week they fished, so a rebooking message can offer a date rather than a calendar.

How many people they brought and who they were, since a group organiser is a different sort of client from a solo angler.

What they paid, because it distinguishes a full-day client from somebody who has only ever taken half days.

And a contact preference field recording anything they have asked for, which overrides everything else.

Nine columns, and every one of them gets used.

Why those fields drive the sequence is covered in the rebooking pack piece.

What should it not contain?

Anything you would not want to lose.

Card numbers, which the payment provider holds properly and which have no business in a spreadsheet.

Full dates of birth, unless a licence question genuinely requires one, since that is identity data rather than contact data.

Clinical detail from an intake form, which belongs with the trip record rather than in the marketing list.

Private notes you would not want read aloud, because a shared spreadsheet is eventually shared with the wrong person.

Every field you add is a field you have to protect and eventually dispose of, which is the argument for the shortest useful list.

What the intake form should hold instead is covered in the intake form piece.

What does the list let you actually do?

Four things, and each one needs a specific field.

Decide whether somebody is worth messaging, which runs off the date of their last trip and nothing else.

Send at a sensible hour, which needs the state they live in, because a message sent at six your time can arrive at nine theirs.

Offer a specific date rather than the whole calendar, which needs the week they fished last time recorded rather than remembered.

And honour a request to be left alone, which needs a field that overrides everything else and which most spreadsheets do not have.

Any list that cannot do those four is not a database, it is a pile of addresses.

What those messages should say is covered in the text scripts piece.

Should past clients be segmented?

Into three groups, and no more.

People who fished within the last season, who get the full sequence and the priority offer.

People who fished within the last two or three seasons, who get the annual announcement and one direct ask.

People beyond that, who get one honest question about whether they want to stay in contact and then whatever they answer.

Three groups can be maintained with a single column and read at a glance, and any finer segmentation for a list of a hundred and forty people is theatre.

What matters is that the groups drive different treatment rather than existing as labels.

How the lapsed group should be handled is covered in the win-back piece.

Spreadsheet or software?

Spreadsheet, until the calendar forces the change.

Nine columns and a hundred rows is a spreadsheet problem, and a hosted spreadsheet gives you access control, encryption at rest and in transit, version history and a backup without configuring anything.

What it does not give you is an automated prompt, which is the one thing a rebooking sequence genuinely needs.

Which is why the honest threshold is not list size but whether you are missing follow-ups, since that is the failure a tool actually fixes.

An operation of one boat with ninety clients and a working habit does not need software; one running three boats and forgetting people does.

Paying for a tool to solve a discipline problem is the most common wasted expense in this trade.

What the tool comparison should weigh is covered in the tooling piece.

How does the trip record relate to the list?

Two documents, and confusing them is the usual mistake.

The trip record is what happened: the date, the party, the conditions, what was paid, the forms signed and anything that went wrong.

The client list is who to contact and when, and it holds a small subset of the trip record plus a contact preference.

Keeping them separate means the marketing list can be pruned freely while the trip records stay for as long as their own retention periods require.

Merging them produces a list nobody will prune, because deleting a row would destroy evidence, and so the list grows until it is useless.

Two files, one derived from the other, is the whole of the architecture.

How the priority offer should be run off it is covered in the priority booking piece.

What about disposal?

A stated period, and it is the step nobody plans.

The security rule addresses disposal of customer information as one of its elements, on the principle that information kept beyond its usefulness is a risk carried for nothing.

Which is the opposite instinct from the one a marketing list produces, where addresses accumulate for a decade.

The workable position separates two things: the trip record, which has retention periods driven by tax and wage rules and should be kept, and the marketing list, which serves no purpose once somebody has not engaged for years.

Removing a lapsed contact from the marketing list is not deleting the trip record, and confusing the two is why nobody prunes.

State one period for the marketing list, in years, and apply it every winter.

What the trip record retention actually requires is covered in the fall wrap-up piece.

How should it be backed up?

Automatically, in two places, and tested once.

A hosted spreadsheet is already replicated, which covers hardware failure and not deletion, and deletion is the more likely accident.

Which means a periodic export to a second location, ideally on a schedule you do not have to remember, plus a copy that lives somewhere the working file cannot reach.

Testing it once matters more than the arrangement, because an untested backup is a belief rather than a backup.

The test is thirty seconds: open the copy and check the last client you added is in it.

Given the list is worth several thousand dollars a year in bookings, this is the highest return per minute available anywhere in the operation.

Why the list's value should be quantified is covered in the numbers piece.

Where do client databases go wrong?

Five ways, and the first is fragmentation.

Client information living in five places at once, so no single record is complete and no backup covers everything.

Collecting fields nobody uses, which lowers completion on the form and increases what has to be protected.

Giving a sub-guide the master file rather than the day's list, when access limited to what somebody needs is the whole point.

Holding card details or clinical notes in a marketing spreadsheet, which is a risk carried for no benefit.

And never pruning, so a list of two hundred addresses contains eighty people who have not fished in six years and one who asked to be removed.

How the pruning should happen before a send is covered in the season announcement piece.

What the retention side involves is covered in the new year checklist.

When should the record be written?

On the day, before you drive home.

A record written at the takeout is accurate and a record written in February is a reconstruction, and the difference shows up in every message you send afterwards.

Which is a five minute habit: date, party, water, what they paid, one line about how the day went and one about anything they said they wanted next time.

That last field is the one that makes a rebooking message land, because a client who mentioned wanting to try a different stretch remembers saying it.

Writing it in the truck is easier than writing it at home, and writing it at home is easier than not writing it at all.

An operation that does this for one season has a materially better list than one that has been going for ten without it.

Why the day's record matters elsewhere too is covered in the no-shows piece.

What should happen when somebody asks to be removed?

Remove them from everything, the same day.

A request to stop hearing from you applies to every channel and every list you keep, not only to the one the request arrived through.

Which is where a fragmented setup fails, because somebody unsubscribing from a mailing tool remains on a spreadsheet nobody reconciled.

The contact preference column exists precisely for this, and it has to be checked before every send rather than trusted to the tool.

Doing it the same day costs seconds and doing it late costs the relationship entirely, since a second message after a request reads as contempt.

It also keeps the list to people who want to hear from you, which improves everything you send to everybody else.

Why the same discipline applies to email is covered in the winter email piece.

What is the working setup?

One hosted sheet, nine columns, a second copy, a winter prune.

Keep one master list in a hosted spreadsheet, not on a laptop, so access control and encryption come free.

Use nine columns and no more: name, telephone, email, state, last trip date, water and week, party size and composition, amount paid, and contact preference.

Share a day's list rather than the master with anybody who works for you, which satisfies the access principle without any software.

Export a copy on a schedule to somewhere the working file cannot reach, and open it once to confirm it is real.

Then prune the marketing list every winter against a stated period, keeping the trip records separately and for as long as their own rules require.

The rule's statutory basis is at 15 U.S.C. 6801, with a parallel text on govinfo.

How the list turns into bookings is covered in the rebooking piece.

How this was checked. The purpose of the part, being to set standards for developing, implementing and maintaining reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of customer information, and its scope, applying to the handling of customer information by financial institutions over which the Federal Trade Commission has rulemaking authority under the referenced provision of the Gramm-Leach-Bliley Act, with a financial institution defined as an entity whose business is engaging in an activity that is financial in nature or incidental to such activities as described in the referenced provision of the Bank Holding Company Act, come from 16 CFR 314.1. A guiding business does not fall within that definition, and the part therefore imposes no obligation on one; it is quoted throughout as a model of what safeguarding a customer list involves. The requirement to designate a qualified individual responsible for overseeing, implementing and enforcing the information security program, together with the conditions applying where that requirement is met through a service provider or affiliate, comes from 16 CFR 314.4(a). The requirement to base the program on a written risk assessment identifying reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information and assessing the sufficiency of existing safeguards, together with the stated contents of that assessment and the obligation to perform periodic further assessments, comes from paragraph (b). The requirements to implement and periodically review access controls, including technical and as appropriate physical controls, to authenticate and permit access only to authorised users and to limit their access to the information needed to perform their duties; to identify and manage the data, personnel, devices, systems and facilities that enable business purposes in accordance with their relative importance; and to protect customer information by encryption in transit over external networks and at rest, with effective alternative compensating controls permitted where encryption is determined to be infeasible and reviewed and approved by the qualified individual, all come from paragraph (c). Part 314 was read on the Electronic Code of Federal Regulations on 26 July 2026. No state data breach or privacy statute was read, and several impose duties on small businesses that this page does not address. The statutory basis for the part is cited at 15 U.S.C. 6801 without further reliance on its text, and all arithmetic uses stated illustrative figures.

If your booking calendar has more open weeks than you’d like, I’ll build you a free preview of your booking site before you pay a cent.

Get a free website preview

Why the security rule does not apply, what it says worth borrowing, and the nine columns that get used

Does the federal security rule apply to a guide?

No. 16 CFR 314.1(b) applies the part to the handling of customer information by financial institutions over which the Commission has rulemaking authority, defining a financial institution as an entity whose business is engaging in an activity financial in nature or incidental to such activities. A guiding business does none of that. The rule is worth reading as a model of what safeguarding a list involves.

What is worth borrowing from it?

The purpose statement names three kinds of safeguard, administrative, technical and physical, protecting three properties, security, confidentiality and integrity. That is a better framework than any software feature list, and the elements that matter to a one-person operation are access control, knowing what data you hold and where, and disposing of it when it stops being needed.

What does the access requirement mean in practice?

16 CFR 314.4(c)(1) requires access controls that authenticate authorised users and limit their access to the information they need. For a guide that means two files rather than one: a day's boat list for anybody working with you, and the master list with telephone numbers and notes for you alone. It costs nothing and is almost never done.

What should the list contain?

Nine columns: name, telephone, email, the state they live in, the date of their most recent trip, the water and week they fished, party size and who was in it, what they paid, and a contact preference recording anything they have asked for. Every one of those gets used by a follow-up decision, and anything beyond them is a field you must protect for no benefit.

What should it not contain?

Card numbers, which the payment provider holds properly. Full dates of birth, unless a licence question requires one. Clinical detail from an intake form, which belongs with the trip record. And private notes you would not want read aloud, because a shared spreadsheet is eventually shared with the wrong person.

Spreadsheet or software?

A hosted spreadsheet, until you are actually missing follow-ups. Nine columns and a hundred rows is a spreadsheet problem, and a hosted one gives you access control, encryption at rest and in transit, version history and a backup without configuring anything. What it does not give you is an automated prompt, which is the one thing a tool genuinely fixes.

How should the trip record relate to the list?

As two files, one derived from the other. The trip record is what happened and has retention periods driven by tax and wage rules. The list is who to contact and when. Keeping them separate means the marketing list can be pruned freely; merging them produces a list nobody prunes, because deleting a row would destroy evidence.

Sources & methods

  1. 16 CFR part 314 on the Electronic Code of Federal Regulations, read for section 314.1, being the purpose of setting standards for developing, implementing and maintaining reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of customer information, and the scope applying the part to financial institutions over which the Federal Trade Commission has rulemaking authority under the referenced provision of the Gramm-Leach-Bliley Act, with a financial institution defined by reference to activities financial in nature or incidental to such activities under the referenced provision of the Bank Holding Company Act; and for section 314.4, being the requirement to designate a qualified individual with the conditions applying where a service provider or affiliate is used, the requirement to base the program on a written risk assessment with its stated contents and periodic repetition, and the safeguards requirements covering access controls that authenticate authorised users and limit access to what they need, the identification and management of data, personnel, devices, systems and facilities in accordance with their relative importance, and the protection of customer information by encryption in transit and at rest with compensating controls permitted where encryption is infeasible.
  2. 15 U.S.C. 6801 at the Office of the Law Revision Counsel, cited as the statutory basis for the part described, without further reliance on its text. A guiding business is not a financial institution and the part imposes no obligation on one.
  3. The Title 15 volume published on govinfo, used as an independent copy of the statutory provision cited above. No state data breach or privacy statute was read for this page, and several impose duties on small businesses that it does not address.

Every figure here is traced to a named public source and checked against it. Licensing, tax, and fee rules change. Verify your state’s current rules with the agency directly before you count on any number here.

Evan Knox
Written by

Evan Knox

I build booking websites and run the ads and search for owner-run fishing guides, one operation per stretch of water. My first guide client, Bowman Fly Fishing, grew its revenue 4x in a year from that work. Field Notes is where I put the straight numbers on the business of guiding.

More field notes

A list is only worth what you send it.

I'm Evan. The database matters once there are clients in it. I build guides the booking site and run the ads that put them there. Free preview before you pay a cent.

Get a free preview of your new website.

Tell us your water and where you're at today. We'll build a finished preview of your site, free, before any money changes hands. If your water's already taken, we'll tell you straight.

Fastest: text (470) 777-9686

Free either way. One operation per stretch of water, so if yours is taken we'll tell you straight.

Got it.

We'll check your water and email you the preview. In season, same day.

Text us Free Website Preview