=== Yatoon Salon Booking & Appointments ===
Contributors: yatoon, freemius
Tags: booking, appointments, salon, spa, beauty
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 4.7.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Salon booking for WordPress with unlimited staff, Square synchronization, online payments, reminders, and customer self-service.

== Description ==

**Run your salon's bookings, schedules, payments, and customer relationships from WordPress.**

Yatoon gives salons a polished booking experience for clients and a practical local booking toolkit for the team. Clients choose services, add-ons, professionals, dates, and times on mobile; staff manage the day from WordPress.

**[Try the live booking demo](https://yatoon.com/bookingdemo/)** - no account or installation required.

**Watch the complete mobile booking demo:**

https://youtu.be/QFeTBgVERaE

Built for nail salons, hair salons, barbershops, spas, beauty studios, and other appointment-based businesses. Yatoon has also been used for daily bookings at a real nail salon for more than a year.

**Production-proven Square workflow (Pro):** A live nail salon has used Yatoon in Square-connected mode for more than a year. Customers book on the WordPress site, appointments and changes synchronize with Square, and staff continue to take payment in Square POS when the customer arrives.

= What Free includes =

* Mobile booking for services, options, professionals, dates, times, customer details, and confirmation
* Local WordPress scheduling, staff records, customer records, notifications, and self-service
* Optional booking-form AI Style Assistant when WordPress AI Client and a provider are connected and the administrator enables it
* Booking blocks, Elementor, and shortcodes for adding booking to public pages

= What customers experience =

* A mobile booking flow for services, variations, add-ons, professionals, date, time, customer details, and confirmation
* Several services or guests in one booking journey, with separate staff choices and reference photos where enabled
* Clear service durations, prices, appointment summaries, directions, and calendar actions
* Secure self-service for viewing, rescheduling, cancelling, rebooking, and eligible service changes
* A branded service menu, discovery storefront, portfolio, favorites, quick rebooking, and lightweight installable customer app

= What your team manages =

* Services, categories, images, variations, add-ons, pricing, employee-specific durations, and staff qualifications
* Business hours, staff schedules, breaks, time off, closed dates, and local availability rules
* Appointment calendar, client records, notes, notifications, and customer self-service
* Upgrade-safe database diagnostics and privacy-safe support information; Pro adds Square operations and recovery tools

Before a booking or sensitive change is saved, Yatoon rechecks staff qualification, schedules, breaks, closed dates, existing appointments, shared resources, and relevant external availability. If a time is taken during checkout, the customer keeps their details and gets a clear recovery path.

= Add it to any WordPress page =

Use the native block, Elementor widget, or one of these shortcodes:

* `[yatoon_booking]` - complete booking form
* `[yatoon_service_menu]` - visual service menu with Book buttons
* `[yatoon_customer_portal]` - customer self-service portal
* `[yatoon_staff_portal]` - mobile staff schedule portal
* `[yatoon_discovery]` - discovery storefront and booking entry points
* `[yatoon_growth_storefront]` - packages and memberships
* `[yatoon_group_appointments]` - classes and group reservations

== Installation ==

1. Install and activate **Yatoon Salon Booking & Appointments**.
2. Complete **Yatoon Booking > Setup Wizard**.
3. Add your services, prices, durations, staff, schedules, business hours, breaks, and closed dates.
4. Connect only the payment, calendar, messaging, or platform integrations your workflow needs.
5. Add the booking block, Elementor widget, builder element, or `[yatoon_booking]` shortcode to a public page.
6. Run a test booking, payment, refund, synchronization, customer self-service, and staff workflow before launch.
7. Exclude booking and portal pages from full-page caching and delayed JavaScript optimization.

== Screenshots ==

1. Mobile booking flow: services, add-ons, staff, date, time, and a clear appointment summary.
2. Service menu with categories, images, durations, prices, and Book buttons.
3. Staff selection with Any Staff, preferred professional, and real available openings.
4. Multi-service and group booking for several services or guests in one visit.
5. Confirmation receipt with services, times, prices, directions, and calendar actions.
6. Customer self-service for reviewing, rescheduling, cancelling, and rebooking.
7. Mobile Staff Portal with a practical day schedule.
8. Admin calendar, service catalog, customer records, and appointment management.
9. Booking confirmation with services, times, prices, directions, and calendar actions.
10. Customer self-service and mobile booking screens.

== Frequently Asked Questions ==

= What does Pro add? =

Pro adds unlimited staff, two-way Square Appointments synchronization, one-way Vagaro import with booking creation, online payments and deposits, no-show tracking, SMS and calendar integrations, advanced customer self-service, growth tools, multi-location operations, and priority support.

= Does Yatoon require Square? =

No. Yatoon Free runs in Local mode inside WordPress. Square, Vagaro, Stripe, PayPal, Twilio, Google Calendar, and Outlook Calendar are optional integrations.

= Are AI features enabled automatically? =

No. New installations keep customer-facing AI off until an administrator connects a provider and deliberately enables the booking-form Style Assistant. Connecting a provider or entering an API key does not publish an AI feature by itself. Existing sites keep their saved settings when updating.

= What does the Square integration cover? =

Yatoon Pro supports two-way Square Appointments synchronization - creating, updating, and cancelling Square bookings and receiving Square webhooks - plus Square online payment, deposit, and refund options. Point of sale is limited to recording that an appointment was paid in Square POS or Tap to Pay so it settles correctly in Yatoon's own reports and invoices; Yatoon does not replace the Square point-of-sale application.

= What exactly does the Vagaro integration do? =

It reads services, staff, and availability from Vagaro and creates new appointments in Vagaro when a customer books. It is an import plus booking creation, not two-way synchronization: Yatoon does not push Vagaro reschedules or cancellations, receive Vagaro webhooks, or run a scheduled re-pull.

= Can customers book more than one service or guest? =

Yes. Each guest can have separate services, staff assignments, timing, and reference photos while remaining part of one booking journey.

= Does Pro support deposits and online payments? =

Yes. Configure the provider and deposit rules required by your business, then test the complete payment and refund workflow in the provider's test environment before going live.

= Does the no-show rule charge the customer automatically? =

It requires a deposit; it does not take money on its own. Once a customer reaches your threshold, their next booking is treated as a deposit booking and checkout asks for the deposit amount configured under Payments, through the gateway configured there. If no deposit gateway is set up, the rule can only flag the customer.

= How does Yatoon protect against schedule conflicts? =

It checks staff qualification, working hours, breaks, closed dates, existing appointments, shared resources, and external availability where applicable. A final server-side check runs immediately before the change is saved.

= Can customers and staff manage appointments from a phone? =

Yes. Customers can use the lightweight booking app and Customer Portal, while the Staff Portal is designed for mobile daily operations.

= Does Yatoon work with page builders? =

Yes. Major booking surfaces are available through Gutenberg blocks, Elementor widgets, shortcodes, and adapters for Bricks, Beaver Builder, Divi, and Brizy.

= Is Yatoon multilingual? =

Yes. Yatoon is translation-ready and includes maintained catalogs for Simplified Chinese, Traditional Chinese, Spanish (Spain and Mexico), and Vietnamese. English is the source language, and site owners can edit their own service names, descriptions, policies, and labels.

= Where can I get help? =

Downloads, licensing, updates, and priority support are available through [Yatoon.com](https://yatoon.com/). Copy the privacy-safe technical summary from Operations when reporting an integration problem.

== External Services and Privacy ==

**Google Maps - `www.google.com/maps`.** The confirmation page displays a lazy-loaded map when a business address is configured. The preview sends the public business address and normal browser connection information to Google; it does not include customer names, email, appointment details, or manage tokens. Clicking the map opens Google Maps directions to that address. See [Google Privacy](https://policies.google.com/privacy) and [Google Terms](https://policies.google.com/terms).

Free Local mode performs booking and availability inside WordPress and does not require Square, Vagaro, Stripe, PayPal, Twilio, Google Calendar, Microsoft Outlook, or Meta WhatsApp.

Every external service Yatoon can contact is listed below with what is sent, when it is sent, and the provider's own policies. Nothing in this list is contacted unless the corresponding feature is switched on by an administrator.

**Fonts.** Yatoon does not download fonts from any remote host, and does not bundle font files either. Choosing a font family under Brand & Colors only adds that family name to the CSS font stack; otherwise the system font is used.

**Yatoon push relay (Cloudflare Worker) - `https://yatoon-api.yatoon.workers.dev`.** Optional and disabled by default. When explicitly enabled, Yatoon sends a signed, pseudonymous browser push subscription endpoint and a generic event type to this Cloudflare Worker. Customer names, contact details, services, appointment times, and notes are never sent. See [Yatoon](https://yatoon.com/) and the [Cloudflare Privacy Policy](https://www.cloudflare.com/privacypolicy/).

**Freemius - `https://api.freemius.com`.** Used for optional account connection, licensing, plugin updates, and upgrade screens. It is contacted only when an administrator opts in or uses one of those features. See [Freemius Privacy Policy](https://freemius.com/privacy/) and [Freemius Terms](https://freemius.com/terms/).

**Provider integrations.** Each service below is contacted only when an administrator has configured its credentials and switched the corresponding feature on, and only while performing the action that needs it. Provider credentials are stored encrypted in WordPress; Yatoon diagnostics must not include them.

* Square - `connect.squareup.com`, `web.squarecdn.com` (booking synchronization, payments, refunds, webhooks). [Privacy](https://squareup.com/us/en/legal/general/privacy) - [Terms](https://squareup.com/us/en/legal/general/ua)
* Vagaro - `api.vagaro.com` (service, staff, and availability import; booking creation). [Privacy](https://www.vagaro.com/privacy) - [Terms](https://www.vagaro.com/terms)
* Stripe - `api.stripe.com`, `js.stripe.com` (deposits, prepayment, refunds, cards on file). [Privacy](https://stripe.com/privacy) - [Terms](https://stripe.com/legal/ssa)
* PayPal - `api-m.paypal.com`, `www.paypal.com` (deposits and prepayment). [Privacy](https://www.paypal.com/us/legalhub/privacy-full) - [Terms](https://www.paypal.com/us/legalhub/useragreement-full)
* Twilio - `api.twilio.com`, `lookups.twilio.com` (SMS reminders and phone lookup). [Privacy](https://www.twilio.com/en-us/legal/privacy) - [Terms](https://www.twilio.com/en-us/legal/tos)
* Google - `oauth2.googleapis.com`, `www.googleapis.com`, `accounts.google.com` (Calendar sync and customer/staff sign-in). [Privacy](https://policies.google.com/privacy) - [Terms](https://policies.google.com/terms)
* Google Gemini - `generativelanguage.googleapis.com` (optional AI assistant). [Privacy](https://policies.google.com/privacy) - [Terms](https://ai.google.dev/gemini-api/terms)
* OpenAI - `api.openai.com` (optional AI assistant). [Privacy](https://openai.com/policies/privacy-policy/) - [Terms](https://openai.com/policies/business-terms/)
* Anthropic - `api.anthropic.com` (optional AI assistant). [Privacy](https://www.anthropic.com/legal/privacy) - [Terms](https://www.anthropic.com/legal/commercial-terms)
* Microsoft - `graph.microsoft.com`, `login.microsoftonline.com` (Outlook Calendar). [Privacy](https://privacy.microsoft.com/privacystatement) - [Terms](https://www.microsoft.com/servicesagreement)
* Meta - `graph.facebook.com`, `www.facebook.com` (WhatsApp Cloud API messaging and Facebook sign-in). [Privacy](https://www.facebook.com/privacy/policy/) - [Terms](https://www.whatsapp.com/legal/business-terms)
* Apple - `appleid.apple.com` (Sign in with Apple). [Privacy](https://www.apple.com/legal/privacy/) - [Terms](https://developer.apple.com/terms/)
* Cloudflare Turnstile - `challenges.cloudflare.com` (optional booking-form bot check). [Privacy](https://www.cloudflare.com/privacypolicy/) - [Terms](https://www.cloudflare.com/website-terms/)
* Zoom - `api.zoom.us`, `zoom.us` (optional virtual appointments). [Privacy](https://www.zoom.com/en/trust/privacy/) - [Terms](https://www.zoom.com/en/trust/terms/)

Before any customer text can reach an AI provider, an administrator must enable the relevant AI feature, and Yatoon requires explicit one-time customer consent and screens the message for sensitive data. Customer-facing AI is off by default on new installations; connecting a provider alone does not publish it.

Site owners are responsible for obtaining required consent, publishing an accurate privacy notice, configuring retention, and complying with the rules of their region and chosen providers.

== Changelog ==

= 4.7.2 =
* Made customer-facing AI opt-in for new installations while preserving upgraded-site settings, and consolidated all AI choices on one page.
* Clarified synchronization status, recovery links, Free/Pro feature boundaries, and production Square workflow documentation.
* Improved booking, availability, payment, refund, notification, and cache reliability.
* Added a customer-facing AI chat concierge that uses real services and openings and never books without confirmation.
* Refined the mobile booking experience, accessibility, translations, and frontend performance.
* Improved Free/Pro compatibility and release package validation.

= 4.7.1 =
* Added employee-specific service durations and stronger availability checks.
* Improved booking summaries, database upgrades, frontend caching, and diagnostics.

= 4.7.0 =
* Added booking horizon, client time zones, signed webhooks, and automation foundations.
* Improved booking reliability, integrations, responsive layouts, validation, permissions, and rate limiting.

Older release notes are preserved in the project release archive.
