Yatoon Salon Booking & Appointments

Description

A flexible WordPress booking system built for salons, spas, and service businesses. The free version provides a complete local booking workflow, while Pro adds Square integration and advanced operational features.

Yatoon has powered daily bookings at a real nail salon for more than a year, connecting a branded customer experience with day-to-day salon operations.

Try the live booking demo – no account or installation required.

Start booking with Free

Square is not required. Local mode runs inside WordPress and gives service businesses a practical booking system without connecting an external scheduling or payment account.

  • Mobile-first booking for services, options, staff, date, time, customer details, and confirmation
  • Services, service variations, qualified staff, business hours, staff schedules, breaks, and closed dates
  • Any Staff assignment and final server-side availability checks to help prevent schedule conflicts
  • Multiple services and guests in one booking journey, with separate staff choices and reference photos
  • Booking calendar, appointment management, client records, notes, and basic reports
  • Email confirmations and configurable booking notifications
  • Secure customer self-service for viewing, cancelling, rescheduling, rebooking, and adding appointments to a calendar
  • Staff Portal schedule view for day-to-day mobile access
  • Service menu, waitlist, form fields, brand basics, privacy tools, and a guided one-click migration from Bookly or Amelia (Pro also migrates from LatePoint)
  • SEO-ready local discovery storefront with portfolio, popular services, multi-location links, private favorites, and quick rebooking
  • Privacy-safe booking-funnel reporting and an installable lightweight customer app for home-screen access
  • Gutenberg blocks, Elementor widgets, shortcodes, responsive layouts, RTL styles, and maintained language catalogs
  • Up to two staff members in the Free plan

Grow with Pro

Upgrade when your business needs Square, payments, automation, more staff, or broader salon operations. Pro includes everything in Free, plus:

  • Unlimited staff members
  • Square Appointments and POS workflows, Square online payments, deposits, refunds, sync monitoring, and recovery tools
  • Optional Vagaro synchronization and Google Calendar two-way availability
  • Stripe and PayPal payment options, deposits, prepayment, invoices, taxes, and refund workflows
  • SMS reminders through Twilio and optional WhatsApp workflows (Pro adds full Meta WhatsApp Cloud API templates)
  • Packages, memberships, gift cards, coupons, loyalty, recurring appointments, waitlist automation, broadcasts, and review requests
  • Verified-appointment review badges and one-customer-at-a-time timed waitlist claim links
  • Advanced customer self-service, including changing services safely
  • Multi-location rules, shared resources, inventory, commissions, dynamic pricing, group classes, reports, and automations
  • Advanced brand controls, operational diagnostics, authenticated REST integrations, and priority support
  • Native Bricks, Beaver Builder, and Divi booking modules

External providers are optional and require their own accounts, credentials, supported regions, and any applicable provider fees.
Features connected to external providers also depend on those providers’ API availability, compatibility, policies, and continued service; provider outages or API changes can temporarily affect the corresponding integration without affecting Local mode.

Reliability for real salon operations

Yatoon rechecks staff qualification, working hours, breaks, closed dates, existing appointments, and relevant external availability before sensitive booking changes are saved. If confirmation fails, the booking form keeps the customer’s details and provides clear recovery actions instead of forcing the customer to start over.

Pro’s Operations health center adds recent sync activity, webhook status, stale-sync warnings, failed background jobs, retry controls, migration status, upgrade snapshots, rollback tools, performance measurements, and a privacy-safe technical summary for support.

Add Yatoon anywhere

  • [yatoon_booking] – complete booking form
  • [yatoon_discovery] – indexable salon discovery storefront, portfolio, favorites, reviews, and booking entry points
  • [yatoon_service_menu] – visual service menu with Book buttons
  • [yatoon_customer_portal] – customer self-service portal
  • [yatoon_staff_portal] – mobile staff schedule portal
  • [yatoon_growth_storefront] – Pro package and membership storefront
  • [yatoon_group_appointments] – Pro capacity-based classes and independent attendee reservations

Every major shortcode is also available as a native Gutenberg block and Elementor widget.

External Services and Privacy

Free Local mode performs booking and availability inside WordPress and does not require Square, Vagaro, Stripe, PayPal, Twilio, Google Calendar, Microsoft Outlook, or Meta WhatsApp.

The plugin bundles Freemius for optional account connection, licensing, updates, and upgrade screens. Freemius is contacted when an administrator chooses to opt in, connect an account, manage a license, or use related services, and may receive the site, administrator, plugin, WordPress, PHP, and license information required to provide them. See Freemius Privacy Policy and Terms.

Pro integrations contact only the providers an administrator configures and enables. Depending on the workflow, the minimum required booking, customer, staff, catalog, calendar, message, payment, refund, location, and provider-reference data is sent to that provider. Provider credentials are stored encrypted in WordPress; Yatoon diagnostics must not include them.

Site owners are responsible for obtaining required consent, publishing an accurate privacy notice, configuring retention, and complying with the rules of their region and chosen providers.

Screenshots

Installation

  1. Install and activate Yatoon Salon Booking.
  2. Complete Yatoon Booking > Setup Wizard.
  3. Configure services, variations, staff qualifications, schedules, business hours, breaks, and closed dates.
  4. Stay in Local mode with Free, or connect the integrations your Pro workflow requires.
  5. Add the Yatoon Booking block, Elementor widget, or [yatoon_booking] shortcode to a public page.
  6. Exclude booking and portal pages from full-page caching and delayed JavaScript optimization.
  7. Complete a test booking and confirmation before launch. If configured, also test payment, refunds, synchronization, customer self-service, and staff workflows.

FAQ

Does the Free version require Square or another external service?

No. Free can run in Local mode inside WordPress. Square, Vagaro, Stripe, PayPal, Twilio, and Google Calendar are optional Pro integrations.

What makes Yatoon different from a generic appointment plugin?

Yatoon focuses on salon workflows: service variations, multi-service visits, reference photos, qualified technicians, Any Staff assignment, customer self-service, and practical staff and client tools. Pro extends those workflows with Square and other advanced operations.

What does Pro add?

Pro adds unlimited staff, Square and Vagaro synchronization, online payments and deposits, SMS and calendar integrations, advanced customer self-service, growth tools, multi-location operations, and priority support. Features that use third-party providers require separately configured provider accounts.

What does the Square integration cover?

Square is optional and available in Pro. Yatoon Pro supports Square Appointments and POS workflows plus Square online payment, deposit, and refund options. Exact behavior depends on correct Square location, service, variation, team-member, and permission mappings.

How does Yatoon protect against schedule conflicts?

It checks staff qualification, working hours, breaks, closed dates, existing appointments, shared resources, and external availability where applicable. A final server-side check runs immediately before the change is saved.

Can one booking contain several services or guests?

Yes. Each guest can have separate services, staff assignments, timing, and reference photos while remaining part of one booking journey.

Can customers and staff manage appointments from a phone?

Yes. Customers can install the lightweight booking app from a supported browser for fast access to booking, discovery, and My Appointments. The Customer Portal provides secure self-service, and the installable Staff Portal is designed for mobile daily operations.

Does it support deposits and online payments?

Online payments and deposits are available in Pro. Configure only the provider and deposit rules required by your business, then test the full payment and refund workflow in the provider’s test environment before going live.

Is Yatoon multilingual?

Yes. Yatoon is translation-ready and includes maintained catalogs for Simplified Chinese, Traditional Chinese, Spanish (Spain and Mexico), and Vietnamese. English is the source language. Community translations distributed by WordPress.org continue to work, and untranslated strings safely fall back to English. Business-owned service names, descriptions, policies, and custom labels remain editable by the site owner.

Where can I get help?

Downloads, licensing, updates, and priority support are available through Yatoon.com. Copy the privacy-safe technical summary from Operations when reporting an integration problem.

Reviews

Read all 1 review

Contributors & Developers

“Yatoon Salon Booking & Appointments” is open source software. The following people have contributed to this plugin.

Contributors

“Yatoon Salon Booking & Appointments” has been translated into 2 locales. Thank you to the translators for their contributions.

Translate “Yatoon Salon Booking & Appointments” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

4.6.1

  • New: client Look History. The client profile now has a place to log what color, style, or product a visit used, with an optional photo, tied to that client and (when logged from a booking) that appointment automatically.
  • New: keep a card on file. Customers can save a card when they book, after agreeing to your cancellation policy — the exact wording they agreed to is stored with the card, with the date. Cards are held by Stripe; nothing in your database can be used to reconstruct a card number.
  • New: charge for missed appointments and late cancellations, as a fixed amount or a percentage of the booking. Manual by default, with an option to charge automatically.
  • New: move in from Fresha, Booksy, Vagaro or any system that exports a CSV. Customers, appointment history, remaining package visits and gift card balances all come across, with a preview before anything is written and every import reversible.
  • Staff Portal sign-in — PIN, Google, and email/text-message codes — is now set up directly from the employee editor instead of a separate Identity screen, and setting a PIN no longer reloads the page.
  • Fixed a site activated through WP-CLI or another headless/staging tool never getting past the licensing library’s one-time connect-or-skip prompt: 10 admin pages returned a bare “Sorry, you are not allowed to access this page” until that prompt was seen in a browser.
  • Fixed the Settings page itself being able to disappear from the admin menu on some installs, from the plugin registering its other pages before its own Settings page instead of first.
  • Fixed a JavaScript error on every Settings tab except General, and on five locked feature-preview pages, from a script reading a Deposit/Prepay control that only exists on the General tab.
  • Fixed the setup wizard creating a duplicate “My Appointments” customer page and silently switching every customer-facing link to it, instead of reusing the page the plugin already creates automatically on activation.
  • Fixed the Clients screen showing “No clients yet” directly under a heading that said how many customers you have — three of the five sort columns used SQL the database rejects.
  • Fixed the month view of the booking date picker, which threw a JavaScript error and never rendered.
  • Fixed five Settings sub-pages (SMS, Google Calendar, Deposit & Prepay, No-show Tracking, Waitlist) rendering their controls without the script driving them.
  • Fixed a fatal error on every fresh install from the salon-operations dashboard loading on a profile switch it did not belong to.
  • Fixed double-booking on customer self-service: rescheduling and changing services now take the same per-day lock new bookings already used.
  • Added rate limiting to the booking endpoint, per visitor and per contact detail.
  • Fixed appointment times shown in Zoom invitations, confirmation emails, admin notifications and waitlist notices, which were shifted by the site’s UTC offset.
  • API credentials are no longer silently stored in plain text when a server cannot encrypt; saving now fails with a clear notice instead.
  • Reference-photo uploads now verify the chosen service actually accepts them, instead of only checking the site-wide switch.
  • Push notifications no longer send customer names, services or appointment times to an external relay.
  • Escaped staff names in the booking form, added accessible names to form controls, translated 60+ booking-flow strings, raised touch targets to 44×44, and fixed a text colour below the accessibility contrast floor.
  • Availability lookups now cache within a request: a multi-location, multi-service search dropped from hundreds of database queries to a handful.
  • Free and Pro no longer drift on cancelled-appointment workload counting, webhook health checks, or the Reviews builder widget.

4.6.0

  • Added a polished local discovery storefront, favorites sync, quick rebooking, verified review trust signals, privacy-safe booking-funnel analytics, timed waitlist claim links, and an installable customer PWA.
  • Balanced the mobile whitespace above the Your appointments card and shortened guest sign-in guidance across the booking flow.
  • Added a fast, free-tier-friendly frontend AI mode with conditional availability checks, shorter prompts, bounded retries, provider-aware failover, answer caching, and clickable local-menu fallback instead of a dead-end busy message.
  • Added configurable frontend AI performance and cache controls plus a clearer progress state for slower provider responses.
  • Fixed multi-service owner and customer emails so every selected variation and add-on is listed with its segment duration.
  • Added salon address, phone, website, manage/reschedule/cancel, and calendar links to customer confirmations, including sites with older saved email templates.
  • Clarified optional guest checkout and removed repeated sign-in prompts from intermediate booking steps.
  • Corrected confirmation and admin email duration for combined services and add-ons.
  • Fixed multi-service Square time checks so selected add-ons and total duration match final confirmation.
  • Added better Step 5 spacing and sticky-header-safe mobile progress scrolling.
  • Restored desktop hover opening for the booking sign-in menu and stopped failed AI provider calls from consuming the customer’s longer usage allowance.
  • Added automatic model/provider failover for temporary AI overloads and rate limits, without exposing raw technical provider errors to customers.
  • Replaced the browser-native booking sign-in control with a stable button menu, removing the duplicate triangle and unreliable open/close behavior seen in Chrome.
  • Restored the booking sign-in menu as a tidy desktop overlay that no longer expands the whole appointment banner.
  • Styled Google, Facebook, and email as consistent full-width boxed sign-in actions.
  • Keeps current Gemini, OpenAI, and Claude choices while restoring the complete original working model set, compatibility-first defaults, and provider-agnostic runtime fallback.
  • Increased wide-screen booking typography so the expanded layout remains readable and visually balanced.
  • Added a wider, balanced booking layout for large desktop screens while preserving responsive laptop and mobile behavior.
  • Removed the booking page’s wide-then-shrink first-paint jump and fixed delayed AI Feature Switch checkmarks.
  • Made hidden optional modules searchable with direct enable-feature guidance.
  • Added secure booking-homepage customer sign-out, responsive Growth Modules forms, and clearer AI settings discovery.
  • Refined the customer sign-in banner with a branded Google button, clear appointment-management copy, and a login-aware My Appointments action.
  • Fixed Rank Math breadcrumb JSON-LD items that omitted the Google-required name field.
  • Added Google and email-code customer sign-in, with SMS-code capability available when the Pro Twilio integration is configured.
  • Added customer self-service service changes with fresh staff/time availability checks for eligible unpaid single-service appointments.
  • Hardened local reschedule availability across breaks, resources, time off, and external calendars.
  • Added native Brizy elements for booking, customer and staff portals, service menus, catalogs, galleries, reviews, and booking management.
  • Fixed the enabled Already booked banner being suppressed by legacy option types or temporarily unavailable destination URLs.
  • Prevented partial General settings actions from silently clearing unrelated checkboxes.
  • Fixed delayed checkbox checkmarks across all Settings controls in Chromium and Edge.
  • Fixed false no-availability results when a primary variation was also submitted as an add-on after staff selection.
  • Added Google sign-in and My Appointments to the optional booking-form portal banner, automatic customer-portal page setup, and clearer OAuth readiness guidance.
  • Added shared Google OpenID Connect identity for customers and explicitly authorized employees.
  • Added customer Google sign-in and verified profile prefill in both Local and Square booking modes.
  • Added employee Google, email-code, SMS-code, and six-digit PIN sign-in with one hardened session model.
  • Added persistent identity links, one-time OAuth handoffs, collision-safe customer matching, and Square Customer resolution.
  • Added an Identity & Sign-in admin screen with per-employee authorization controls and audit-ready bindings.
  • Simplified the booking-page sign-in dropdown wording (“Continue with email” / “Continue with text message”) and made both labels editable under Settings.
  • Fixed the “Already booked with us?” banner heading not upgrading to the shorter default when the saved text used different capitalization.
  • Moved the direct-access guard in class-yatoon-core.php to the top of the file (it previously sat after an unguarded top-level function).
  • Fixed appointment reminders being marked as sent even when delivery failed, whenever the (Pro-only) SMS reminder toggle was left checked.
  • Added revenue trend, revenue-by-service, and revenue-by-staff charts to the Reports page.
  • Added an AI reschedule assistant: customers can describe a new time in their own words in “My Appointments”; AI only reads real open slots and never invents availability, and the customer still confirms before anything changes.
  • Gave WhatsApp reminders and the Bookly/Amelia/LatePoint migration center their own readme callouts instead of leaving them buried in a shared bullet point.
  • Rebuilt the Reports page charts on a locally-vendored Chart.js (no CDN): a combined revenue/bookings trend chart plus real bar charts for revenue by service and by staff, replacing the earlier plain CSS bars.
  • Broadened the AI assistant in “My Appointments” beyond reschedule-only: it now also recognizes cancellation requests (“please cancel it”) from the same chat box, still only proposing an action after checking real data, and still requiring the customer to confirm before anything changes.

4.5.6

  • Closed a concurrent Square webhook duplicate-processing window with atomic event claims and safe retry release.
  • Stopped the booking service worker from persisting HTML, API responses, WordPress nonces, or personalized pages.
  • Added post-migration table verification so failed optional-module migrations retry instead of being marked complete.
  • Added direct-access guards to remaining core integration classes and expanded executable release contracts.

4.5.5

  • Expanded the release preflight to inventory AJAX registrations package-wide and reject public actions without authenticated twins or nonce/auth/rate-limit primitives.
  • Unified booking-day concurrency locks across customer booking, REST updates, and Staff Portal writes to prevent overlapping appointments under parallel requests.
  • Made OTP and Staff Portal PIN abuse counters atomic and made add-on/main-option controls expose their correct checkbox/radio semantics.
  • Recheck growth, automation, and loyalty database postconditions before recording a migration as complete.
  • Documented that automatic pre-upgrade snapshots run before migrations from every older recorded schema version, not only from 4.5.4.
  • Prevented duplicate appointments when customers retry after a timeout or interrupted connection by persisting a privacy-safe attempt reference.
  • Made local multi-service bookings transactional: every service is saved together or none are saved.
  • Added clear recovery guidance when WordPress cannot confirm a booking outcome.
  • Removed a schema-inspection query from normal booking requests and added a verified lookup index for duplicate-safe retries.
  • Preserved booking availability when restricted database hosts cannot install the new retry index, with diagnostics instead of a blocked checkout.

4.5.4

  • Restored the merchant-facing Square note for single-service Any Staff bookings while retaining the concrete team member chosen from live availability.
  • Rebuilt saved appointment cards after a checkout-page refresh and prevented completed-step navigation from opening a misleading empty appointment.
  • Prevented mixed-language AM/PM markers inside a single appointment time range when the visitor and site use different locales.
  • Fixed MySQL 8 upgrade snapshots and restores for booking tables that contain generated conflict-guard columns.
  • Made the Commerce order-number migration compatible with legacy non-unique indexes while retaining a separate uniqueness guarantee when data permits.
  • Distinguished historical timing rows from detailed diagnostic samples, added an image-upload threshold, and kept small samples in a neutral collecting state.
  • Preserved the exact Square team member that made an Any Staff slot available and revalidated the same assignment at confirmation.
  • Added actionable booking-failure recovery with retry, choose-another-time, and choose-staff actions while keeping customer form data intact.
  • Added privacy-safe booking reference numbers for support correlation and clearer availability, network, payment, and conflict failure categories.
  • Expanded Square staging acceptance coverage, immutable-build release checks, support diagnostics, and activation/shortcode troubleshooting.
  • Added slow-request percentages and tail-latency guidance to Performance & Reliability without adding work to the public booking path.
  • Added P50/P95/P99 timing, database-query and provider-time attribution, payload classification, and privacy-safe bottleneck reporting for real booking traffic.
  • Polished the five-minute setup path with progress, starter content, launch readiness, and a required test-booking milestone.
  • Improved mobile-keyboard behavior, long-label wrapping, focus visibility, reduced-motion support, touch targets, and recovery-panel focus handling.
  • Expanded Chrome, WebKit, Pixel, and iPhone automation plus failure-recovery, performance, acceptance, case-study, and video documentation.

4.5.3

  • Added tested runtime profiles for Square single-store, Square multi-store, Local lean, and the complete platform.
  • New installations default to a lean profile; upgrades preserve every existing module choice until an administrator deliberately changes profiles.
  • Disabled modules and unconfigured payment/integration providers now skip their PHP boot, hooks, routes, cron jobs, menus, and search entries.
  • Prevented Stripe.js from loading alongside active Square Online Payments and added release contracts for Square-only operation.
  • Replaced broad machine-generated locale bundling with a smaller maintained language set; Spanish and Vietnamese received terminology, brand, booking-context, placeholder, and catalog compilation review.

4.5.2

  • Corrected WordPress dbDelta schema syntax, rebuilt audited production assets, strengthened multi-service pricing, and completed 24-locale release validation.
  • Improved checkout total alignment in desktop sidebars, mobile drawers, and RTL layouts.

4.5.1

  • Replaced per-request schema DDL with a locked, versioned migration manifest that writes its completion marker only after verification.
  • Added privacy-safe diagnostic redaction for credentials, email addresses, phone numbers, and sensitive query parameters.
  • Corrected Free/Pro licensing metadata, release titles, version constants, locale counts, and translation-coverage claims.
  • Added deterministic release checks for PHP, JavaScript, JSON, gettext catalogs, package tiers, and archive contents.
  • Expanded bundled locale catalogs with explicit coverage reporting and safe English fallback.

4.5.0

  • Added public throttling and generic failure responses for gift-card/coupon validation, plus a 60-request-per-minute availability budget.
  • Added explicit local and UTC creation timestamps for appointments so optional Pro background jobs never depend on the MySQL server timezone.
  • Added safe cleanup of optional WooCommerce background jobs when switching from Pro to Free.
  • Pro adds optional WooCommerce checkout, signed webhooks for Zapier/Make/n8n, Zoom meetings and Google Meet.
  • Added an Integrations settings entry with a clear Pro upgrade gate; integrations remain off by default.
  • Includes all search, staff assignment, payment, WhatsApp and reliability improvements prepared for the previous release candidate.

4.4.5

  • Expanded topbar search into a complete catalog of Yatoon pages, hidden tools, settings tabs, settings sections, runtime menus, and English/Chinese aliases with relevance ranking.
  • Added editable Staff Priority to employee profiles; smaller numbers appear first and new employees default to the end of the list.
  • Pro adds PayPal Checkout and restores Stripe deposit checkout; payment gateways remain a Pro feature.
  • Pro adds Meta WhatsApp Cloud API transactional notifications through approved templates.
  • Removed an unreferenced JavaScript build artifact and added release/package validation guidance.
  • Added a visible single-writer database deployment warning to Platform settings.
  • Expanded the admin topbar search with feature keywords and English/Chinese aliases while keeping Pro-only results hidden.
  • Added direct topbar search results for Complete Backup & Restore, including backup, restore, migration, snapshot, 备份, and 恢复 keywords.
  • Hardened admin diagnostics: raw booking and Square inspection endpoints now require WP_DEBUG or YATOON_ENABLE_ADMIN_DIAGNOSTICS, reject invalid dates/service IDs, and HTML-escape database/API output.
  • Enlarged the Add guests and services remove control to a clear 42px circular target and added direct Remove beside Edit on Step 4; confirmation now refreshes the group review only after the service is actually deleted.
  • Added an accessible one-click Remove action beside Edit in the appointment summary; it clears the selected service and dependent options, staff and time without leaving stale totals.
  • Expanded the Customer Account Center with editable profile preferences, balance payment links, signed invoice downloads, package and membership history, and atomic loyalty reward redemption.
  • Added a recommended admin settings view that keeps common store controls visible while placing developer credentials and synchronization internals behind an accessible Advanced toggle.
  • Rebuilt the Step 4 appointment summary as calm, responsive person/service cards with readable staff selection and accessible edit, remove and reorder controls.
  • Removed technical timing offsets and competing green treatments from the customer flow; booking typography is now isolated from theme heading styles.
  • Upgraded Customer Wallet from a placeholder to verified account data for gift cards, packages, memberships, loyalty points, balance due and payment history.
  • Extended Brand & Colors live preview to include page, card, border and primary-action styling before saving.
  • Added a real-salon case study, public trust checklist, three short video storyboards, desktop/mobile regression matrix and automated release-contract checks.
  • Preserved the group-booking return flow introduced in 4.4.4 and retained all established booking, staff and admin workflows.

For the complete version history, see changelog.txt included with the plugin.