Yatoon Salon Booking Pro – Square & Vagaro Sync
A flexible WordPress booking system built for salons, spas, and service businesses. The free version provides a complete local booking workflow, while Pro adds Square integration and advanced operational features. Yatoon has powered daily bookings at a real nail salon for more than a year, connecting a branded customer experience with day-to-day salon operations. Try the live booking demo – no account or installation required. Start booking with Free Square is not required. Local mode runs inside WordPress and gives service businesses a practical booking system without connecting an external scheduling or payment account. Mobile-first booking for services, options, staff, date, time, customer details, and confirmation Services, service variations, qualified staff, business hours, staff schedules, breaks, and closed dates Any Staff assignment and final server-side availability checks to help prevent schedule conflicts Multiple services and guests in one booking journey, with separate staff choices and reference photos Booking calendar, appointment management, client records, notes, and basic reports Email confirmations and configurable booking notifications Secure customer self-service for viewing, cancelling, rescheduling, rebooking, and adding appointments to a calendar Staff Portal schedule view for day-to-day mobile access Service menu, waitlist, form fields, brand basics, privacy tools, and a guided one-click migration from Bookly or Amelia SEO-ready local discovery storefront with portfolio, popular services, multi-location links, private favorites, and quick rebooking Privacy-safe booking-funnel reporting and an installable lightweight customer app for home-screen access Gutenberg blocks, Elementor widgets, shortcodes, responsive layouts, RTL styles, and maintained language catalogs Up to two staff members in the Free plan Grow with Pro Upgrade when your business needs Square, payments, automation, more staff, or broader salon operations. Pro includes everything in Free, plus: Unlimited staff members Two-way Square Appointments synchronization (create, update, cancel, plus incoming Square webhooks), Square online payments, deposits, refunds, sync monitoring, and recovery tools Square POS payment status: an appointment can be marked as paid in Square POS or Tap to Pay so it settles in reports and invoices. Yatoon has no cart, retail checkout, cash drawer, or Terminal API of its own and does not replace the Square POS application Vagaro one-way import plus booking creation: services, staff and availability are read from Vagaro and new appointments are pushed to it. Yatoon does not send Vagaro reschedules or cancellations, there is no Vagaro webhook and no scheduled re-pull, so a change made in either system must be repeated in the other Google Calendar and Microsoft Outlook Calendar workflows Stripe and PayPal payment options, deposits, prepayment, invoices, taxes, and refund workflows SMS reminders through Twilio, plus full Meta WhatsApp Cloud API templates for reminders, confirmations, and updates — WhatsApp is the default messaging channel for most customers outside the US, so this alone can raise show-up rates in Southeast Asia, Latin America, and the Middle East Packages, memberships, gift cards, coupons, loyalty, recurring appointments, waitlist automation, broadcasts, and review requests Verified-appointment review badges and one-customer-at-a-time timed waitlist claim links Advanced customer self-service, including changing services safely Multi-location rules, shared resources, inventory, commissions, server-authoritative dynamic pricing, group classes, reports, and automations Advanced brand controls, operational diagnostics, and priority support Authenticated REST endpoints under yatoon/v1 for bookings (list, create, read, update, cancel), order refunds, and directory data (services, staff, locations, customers). Every route is capability-checked. There is no availability endpoint and no published API reference yet; the routes are intended for your own server-side automation, not as a documented public API Automatic no-show tracking: count how many times a customer has been marked No Show inside a window you choose (3 in 12 months by default) and either require a deposit on their next booking or simply flag them for staff. Flagged customers are listed on the No-show Tracking screen and any of them can be permanently exempted with one click. Requiring a deposit uses the deposit amount and gateway already configured under Payments, so a site with no deposit gateway configured can flag customers but cannot charge them; the screen says so Migration center also imports from LatePoint, on top of the Bookly and Amelia migration already in Free — switching from another WordPress booking plugin keeps your services, staff, and client list Bricks, Beaver Builder, Divi and Brizy elements that place any Yatoon surface (booking form, service menu, catalog, gallery, reviews, customer portal, staff portal, manage booking) into those builders. These adapters wrap the matching shortcode rather than reimplementing the UI, and they are included in the free plugin as well as Pro External providers are optional and require their own accounts, credentials, supported regions, and any applicable provider fees. Features connected to external providers also depend on those providers’ API availability, compatibility, policies, and continued service; provider outages or API changes can temporarily affect the corresponding integration without affecting Local mode. Reliability for real salon operations Yatoon rechecks staff qualification, working hours, breaks, closed dates, existing appointments, and relevant external availability before sensitive booking changes are saved. If confirmation fails, the booking form keeps the customer’s details and provides clear recovery actions instead of forcing the customer to start over. Pro’s Operations health center adds recent sync activity, webhook status, stale-sync warnings, failed background jobs, retry controls, migration status, upgrade snapshots, rollback tools, performance measurements, and a privacy-safe technical summary for support. Add Yatoon anywhere [yatoon_booking] – complete booking form [yatoon_discovery] – indexable salon discovery storefront, portfolio, favorites, reviews, and booking entry points [yatoon_service_menu] – visual service menu with Book buttons [yatoon_customer_portal] – customer self-service portal [yatoon_staff_portal] – mobile staff schedule portal [yatoon_growth_storefront] – Pro package and membership storefront [yatoon_group_appointments] – Pro capacity-based classes and independent attendee reservations Every major shortcode is also available as a native Gutenberg block and Elementor widget. External Services and Privacy Google Maps – www.google.com/maps. The confirmation page displays a lazy-loaded map when a business address is configured. The preview sends the public business address and normal browser connection information to Google; it does not include customer names, email, appointment details or manage tokens. The iframe suppresses the page referrer. Clicking the map opens Google Maps directions to that address. If a consent manager or network blocks the preview, the visible address and directions link remain available. See Google Privacy and Google Terms. Free Local mode performs booking and availability inside WordPress and does not require Square, Vagaro, Stripe, PayPal, Twilio, Google Calendar, Microsoft Outlook, or Meta WhatsApp. Every external service Yatoon can contact is listed below with what is sent, when it is sent, and the provider’s own policies. Nothing in this list is contacted unless the corresponding feature is switched on by an administrator. Fonts. Yatoon does not download fonts from any remote host, and does not bundle font files either. Choosing a font family under Brand & Colors only adds that family name to the CSS font stack; it changes the booking page only if the active theme or another plugin already serves that font locally. Otherwise the system font is used. Releases before 4.6.2 loaded these families from Google Fonts; that request was removed and was not replaced with self-hosted copies, so a site that depended on it now falls back to the system font. Yatoon push relay (Cloudflare Worker) – https://yatoon-api.yatoon.workers.dev. Optional and disabled by default; it additionally requires the site owner to configure a private worker secret before it will send anything. When explicitly enabled, Yatoon sends a signed, pseudonymous browser push subscription endpoint and a generic event type to this Cloudflare Worker, which relays the notification to the merchant’s own browser or device. It is contacted only when a merchant-facing push notification is actually sent. Customer names, contact details, services, appointment times, and notes are never sent. The endpoint is operated by Yatoon on Cloudflare Workers. See Yatoon and the Cloudflare Privacy Policy. Freemius – https://api.freemius.com. Used for optional account connection, licensing, plugin updates, and the upgrade/checkout screens. Contacted when an administrator opts in, connects an account, manages a license, or checks for an update, and it may receive the site URL, administrator name and email, plugin, WordPress, PHP, and license information required to provide those services. See Freemius Privacy Policy and Freemius Terms. Provider integrations. Each of the services below is contacted only when an administrator has configured its credentials and switched the corresponding feature on, and only while performing the action that needs it. Depending on the workflow, the minimum required booking, customer, staff, catalog, calendar, message, payment, refund, location, and provider-reference data is sent to that provider. Provider credentials are stored encrypted in WordPress; Yatoon diagnostics must not include them. Square – connect.squareup.com, web.squarecdn.com (booking synchronization, payments, refunds, webhooks). Privacy – Terms Vagaro – api.vagaro.com (service, staff and availability import; booking creation). Privacy – Terms Stripe – api.stripe.com, js.stripe.com (deposits, prepayment, refunds, cards on file). Privacy – Terms PayPal – api-m.paypal.com, www.paypal.com (deposits and prepayment). Privacy – Terms Twilio – api.twilio.com, lookups.twilio.com (SMS reminders and phone lookup). Privacy – Terms Google – oauth2.googleapis.com, www.googleapis.com, accounts.google.com (Calendar sync and customer/staff sign-in). Privacy – Terms Google Gemini – generativelanguage.googleapis.com (optional AI assistant). Privacy – Terms OpenAI – api.openai.com (optional AI assistant). Privacy – Terms Anthropic – api.anthropic.com (optional AI assistant). Privacy – Terms Microsoft – graph.microsoft.com, login.microsoftonline.com (Outlook Calendar). Privacy – Terms Meta – graph.facebook.com, www.facebook.com (WhatsApp Cloud API messaging and Facebook sign-in). Privacy – Terms Apple – appleid.apple.com (Sign in with Apple). Privacy – Terms Cloudflare Turnstile – challenges.cloudflare.com (optional booking-form bot check). Privacy – Terms Zoom – api.zoom.us, zoom.us (optional virtual appointments). Privacy – Terms Before any customer text can reach an AI provider, Yatoon requires an explicit one-time consent from that customer and screens the message for sensitive data. The AI assistant is off unless an administrator supplies a provider API key. Site owners are responsible for obtaining required consent, publishing an accurate privacy notice, configuring retention, and complying with the rules of their region and chosen providers.