=== Yatoon Salon Booking & Appointments ===
Contributors: yatoon, freemius
Tags: booking, appointments, salon, spa, beauty
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 4.7.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Salon booking for WordPress: services, staff schedules, appointments, and customer self-service. Free local mode with optional Pro integrations.

== Description ==

**Put your salon's booking desk on your own WordPress website.**

Yatoon lets clients choose a service, add-ons, preferred professional, date, and time in a clean mobile booking flow. Your team manages availability, appointments, customers, and follow-up from WordPress.

**[Try the live booking demo](https://yatoon.com/bookingdemo/)** - no account or installation required.

**Watch the complete mobile booking demo:**

https://youtu.be/RCE9AIg9Yig

Yatoon is built for nail salons, hair salons, barbershops, spas, beauty studios, and other appointment-based businesses. It has also been used for daily bookings at a real nail salon for more than a year.

= Start free - no Square account required =

Free Local mode runs inside WordPress. You can launch a useful booking workflow without connecting a payment provider, marketplace, or external scheduling account.

* Mobile-first booking for services, variations, add-ons, staff, date, time, customer details, and confirmation
* Service catalog with pricing, durations, categories, images, qualified staff, and custom fields
* Business hours, staff schedules, breaks, time off, closed dates, and conflict-aware availability
* Any Staff assignment or a customer's preferred professional, with a final server-side availability check
* Multiple services and guests in one booking journey, including reference photos where enabled
* Appointment calendar, client records, notes, reports, email confirmations, and configurable notifications
* Customer self-service for viewing, rescheduling, cancelling, rebooking, and adding appointments to a calendar
* Mobile Staff Portal for the day's schedule
* Visual service menu, waitlist, brand basics, privacy tools, and guided migration from Bookly or Amelia
* Discovery storefront, portfolio, favorites, quick rebooking, booking-funnel reporting, and a lightweight installable customer app
* Gutenberg blocks, Elementor widgets, shortcodes, responsive layouts, RTL styles, and translation-ready catalogs
* Free plan supports up to two staff members

The AI Chat Concierge is a Pro feature and is not included in the Free plugin. Free includes the standard booking form and customer self-service; upgrade to Pro for the floating AI chat experience.

= Upgrade when your salon is ready =

Pro includes everything in Free, then adds the tools growing teams usually need:

* Unlimited staff and broader salon operations
* Two-way Square Appointments sync, Square online payments, deposits, refunds, webhooks, monitoring, and recovery tools
* Stripe and PayPal payments, prepayment, invoices, taxes, refunds, and cards on file where configured
* Vagaro service/staff/availability import with new booking creation
* Google Calendar and Microsoft Outlook workflows, plus Twilio SMS and Meta WhatsApp messaging
* Packages, memberships, gift cards, coupons, loyalty, recurring appointments, waitlist automation, broadcasts, and review requests
* Group classes, multi-location rules, shared resources, inventory, commissions, dynamic pricing, reports, and automations
* No-show tracking, advanced customer self-service, brand controls, operations diagnostics, REST endpoints, and priority support

Third-party integrations are optional and require their own accounts, credentials, supported regions, and provider terms. Local mode continues to work inside WordPress when an external provider is unavailable.

= Designed for real salon workflows =

Yatoon understands that a salon appointment is more than a time slot. Services can have variations, add-ons, different durations by professional, and qualification rules. Customers can book several services or guests in one journey, while staff see a practical daily schedule.

Before a booking or sensitive change is saved, Yatoon rechecks staff qualification, schedules, breaks, closed dates, existing appointments, shared resources, and relevant external availability. If a time is taken during checkout, the customer keeps their details and gets a clear recovery path.

= Add it to any WordPress page =

Use the native block, Elementor widget, or one of these shortcodes:

* `[yatoon_booking]` - complete booking form
* `[yatoon_service_menu]` - visual service menu with Book buttons
* `[yatoon_customer_portal]` - customer self-service portal
* `[yatoon_staff_portal]` - mobile staff schedule portal
* `[yatoon_discovery]` - discovery storefront and booking entry points
* `[yatoon_growth_storefront]` - Pro packages and memberships
* `[yatoon_group_appointments]` - Pro classes and group reservations

== Installation ==

1. Install and activate **Yatoon Salon Booking & Appointments**.
2. Complete **Yatoon Booking > Setup Wizard**.
3. Add your services, prices, durations, staff, schedules, business hours, breaks, and closed dates.
4. Add the booking block, Elementor widget, or `[yatoon_booking]` shortcode to a public page.
5. Run a test booking before launch. Connect only the payment, calendar, messaging, or platform integrations your workflow needs.
6. Exclude booking and portal pages from full-page caching and delayed JavaScript optimization.

== Screenshots ==

1. Mobile booking flow: services, add-ons, staff, date, time, and a clear appointment summary.
2. Service menu with categories, images, durations, prices, and Book buttons.
3. Staff selection with Any Staff, preferred professional, and real available openings.
4. Multi-service and group booking for several services or guests in one visit.
5. Confirmation receipt with services, times, prices, directions, and calendar actions.
6. Customer self-service for reviewing, rescheduling, cancelling, and rebooking.
7. Mobile Staff Portal with a practical day schedule.
8. Admin calendar, service catalog, customer records, and appointment management.
9. Pro payments, Square connection, and operational status screens.
10. Pro brand controls, packages, memberships, and growth tools.

== Frequently Asked Questions ==

= What can I do with the free version? =

Free Local mode includes the complete core booking workflow, service catalog, staff schedules, appointment management, customer self-service, email notifications, Staff Portal, service menu, waitlist, migration tools, blocks, Elementor support, and more. The Free plan supports up to two staff members.

= Does Yatoon require Square or another external service? =

No. Yatoon can run in Local mode inside WordPress. Square, Vagaro, Stripe, PayPal, Twilio, Google Calendar, and Outlook Calendar are optional integrations.

= Who is Yatoon for? =

Yatoon is built for nail salons, hair salons, barbershops, spas, beauty studios, and other service businesses that need services, staff qualifications, schedules, add-ons, repeat bookings, and customer self-service.

= What makes Yatoon different from a generic appointment plugin? =

Yatoon focuses on salon workflows: service variations, multi-service visits, reference photos, qualified technicians, Any Staff assignment, customer self-service, and practical staff and client tools. Pro extends those workflows with Square and other advanced operations.

= What does Pro add? =

Pro adds unlimited staff, two-way Square Appointments synchronization, one-way Vagaro import with booking creation, online payments and deposits, no-show tracking with automatic deposits, SMS and calendar integrations, advanced customer self-service, growth tools, multi-location operations, and priority support. Features that use third-party providers require separately configured provider accounts.

= What does the Square integration cover? =

Square is optional. Yatoon Pro supports two-way Square Appointments synchronization - creating, updating and cancelling Square bookings and receiving Square webhooks - plus Square online payment, deposit, and refund options. Point of sale is limited to recording that an appointment was paid in Square POS or Tap to Pay so it settles correctly in Yatoon's own reports and invoices; Yatoon has no cart, retail checkout, cash drawer, or Terminal API and does not replace the Square point-of-sale application.

= What exactly does the Vagaro integration do? =

It reads services, staff, and availability from Vagaro and creates new appointments in Vagaro when a customer books. It is an import plus booking creation, not two-way synchronization: Yatoon does not push Vagaro reschedules or cancellations, receive Vagaro webhooks, or run a scheduled re-pull.

= Can customers book more than one service or guest? =

Yes. Each guest can have separate services, staff assignments, timing, and reference photos while remaining part of one booking journey.

= Does the no-show rule charge the customer automatically? =

It requires a deposit; it does not take money on its own. Once a customer reaches your threshold, their next booking is treated as a deposit booking and checkout asks for the deposit amount configured under Payments, through the gateway configured there. If no deposit gateway is set up, the rule can only flag the customer.

= How does Yatoon protect against schedule conflicts? =

It checks staff qualification, working hours, breaks, closed dates, existing appointments, shared resources, and external availability where applicable. A final server-side check runs immediately before the change is saved.

= Can customers and staff manage appointments from a phone? =

Yes. Customers can install the lightweight booking app from a supported browser for fast access to booking, discovery, and My Appointments. The Customer Portal provides secure self-service, and the Staff Portal is designed for mobile daily operations.

= Does it support deposits and online payments? =

Yes, in Pro with a configured payment provider. Configure only the provider and deposit rules required by your business, then test the full payment and refund workflow in the provider's test environment before going live.

= Does Yatoon work with page builders? =

Yes. Major booking surfaces are available through Gutenberg blocks, Elementor widgets, shortcodes, and Pro adapters for Bricks, Beaver Builder, Divi, and Brizy.

= Is Yatoon multilingual? =

Yes. Yatoon is translation-ready and includes maintained catalogs for Simplified Chinese, Traditional Chinese, Spanish (Spain and Mexico), and Vietnamese. English is the source language, and site owners can edit their own service names, descriptions, policies, and labels.

= Where can I get help? =

Downloads, licensing, updates, and priority support are available through [Yatoon.com](https://yatoon.com/). Copy the privacy-safe technical summary from Operations when reporting an integration problem.

== External Services and Privacy ==

**Google Maps - `www.google.com/maps`.** The confirmation page displays a lazy-loaded map when a business address is configured. The preview sends the public business address and normal browser connection information to Google; it does not include customer names, email, appointment details, or manage tokens. Clicking the map opens Google Maps directions to that address. See [Google Privacy](https://policies.google.com/privacy) and [Google Terms](https://policies.google.com/terms).

Free Local mode performs booking and availability inside WordPress and does not require Square, Vagaro, Stripe, PayPal, Twilio, Google Calendar, Microsoft Outlook, or Meta WhatsApp.

Every external service Yatoon can contact is listed below with what is sent, when it is sent, and the provider's own policies. Nothing in this list is contacted unless the corresponding feature is switched on by an administrator.

**Fonts.** Yatoon does not download fonts from any remote host, and does not bundle font files either. Choosing a font family under Brand & Colors only adds that family name to the CSS font stack; otherwise the system font is used.

**Yatoon push relay (Cloudflare Worker) - `https://yatoon-api.yatoon.workers.dev`.** Optional and disabled by default. When explicitly enabled, Yatoon sends a signed, pseudonymous browser push subscription endpoint and a generic event type to this Cloudflare Worker. Customer names, contact details, services, appointment times, and notes are never sent. See [Yatoon](https://yatoon.com/) and the [Cloudflare Privacy Policy](https://www.cloudflare.com/privacypolicy/).

**Freemius - `https://api.freemius.com`.** Used for optional account connection, licensing, plugin updates, and upgrade screens. It is contacted only when an administrator opts in or uses one of those features. See [Freemius Privacy Policy](https://freemius.com/privacy/) and [Freemius Terms](https://freemius.com/terms/).

**Provider integrations.** Each service below is contacted only when an administrator has configured its credentials and switched the corresponding feature on, and only while performing the action that needs it. Provider credentials are stored encrypted in WordPress; Yatoon diagnostics must not include them.

* Square - `connect.squareup.com`, `web.squarecdn.com` (booking synchronization, payments, refunds, webhooks). [Privacy](https://squareup.com/us/en/legal/general/privacy) - [Terms](https://squareup.com/us/en/legal/general/ua)
* Vagaro - `api.vagaro.com` (service, staff, and availability import; booking creation). [Privacy](https://www.vagaro.com/privacy) - [Terms](https://www.vagaro.com/terms)
* Stripe - `api.stripe.com`, `js.stripe.com` (deposits, prepayment, refunds, cards on file). [Privacy](https://stripe.com/privacy) - [Terms](https://stripe.com/legal/ssa)
* PayPal - `api-m.paypal.com`, `www.paypal.com` (deposits and prepayment). [Privacy](https://www.paypal.com/us/legalhub/privacy-full) - [Terms](https://www.paypal.com/us/legalhub/useragreement-full)
* Twilio - `api.twilio.com`, `lookups.twilio.com` (SMS reminders and phone lookup). [Privacy](https://www.twilio.com/en-us/legal/privacy) - [Terms](https://www.twilio.com/en-us/legal/tos)
* Google - `oauth2.googleapis.com`, `www.googleapis.com`, `accounts.google.com` (Calendar sync and customer/staff sign-in). [Privacy](https://policies.google.com/privacy) - [Terms](https://policies.google.com/terms)
* Google Gemini - `generativelanguage.googleapis.com` (optional AI assistant). [Privacy](https://policies.google.com/privacy) - [Terms](https://ai.google.dev/gemini-api/terms)
* OpenAI - `api.openai.com` (optional AI assistant). [Privacy](https://openai.com/policies/privacy-policy/) - [Terms](https://openai.com/policies/business-terms/)
* Anthropic - `api.anthropic.com` (optional AI assistant). [Privacy](https://www.anthropic.com/legal/privacy) - [Terms](https://www.anthropic.com/legal/commercial-terms)
* Microsoft - `graph.microsoft.com`, `login.microsoftonline.com` (Outlook Calendar). [Privacy](https://privacy.microsoft.com/privacystatement) - [Terms](https://www.microsoft.com/servicesagreement)
* Meta - `graph.facebook.com`, `www.facebook.com` (WhatsApp Cloud API messaging and Facebook sign-in). [Privacy](https://www.facebook.com/privacy/policy/) - [Terms](https://www.whatsapp.com/legal/business-terms)
* Apple - `appleid.apple.com` (Sign in with Apple). [Privacy](https://www.apple.com/legal/privacy/) - [Terms](https://developer.apple.com/terms/)
* Cloudflare Turnstile - `challenges.cloudflare.com` (optional booking-form bot check). [Privacy](https://www.cloudflare.com/privacypolicy/) - [Terms](https://www.cloudflare.com/website-terms/)
* Zoom - `api.zoom.us`, `zoom.us` (optional virtual appointments). [Privacy](https://www.zoom.com/en/trust/privacy/) - [Terms](https://www.zoom.com/en/trust/terms/)

Before any customer text can reach an AI provider, Yatoon requires explicit one-time consent and screens the message for sensitive data. The AI assistant is off unless an administrator supplies a provider API key.

Site owners are responsible for obtaining required consent, publishing an accurate privacy notice, configuring retention, and complying with the rules of their region and chosen providers.


== Changelog ==

= 4.7.2 =
* Hardened AI input handling, added multilingual sensitive-data screening, and made the site-wide provider hourly cap configurable with a safer default.
* Improved payment and refund webhook reliability, including duplicate, pending, failed and out-of-order events.
* Prevented stale optimized assets on customer booking pages and added a fresh 4.7.2 asset build identifier.
* Made waitlist notification retries safe and booking-funnel/email reporting more accurate.
* Condensed recommended openings into three compact shortcuts while keeping the full time list.
* Added the AI chat concierge (Pro). One floating button in the corner that tucks into a small circle a few seconds after load. The customer says what they want in their own words; it works out the service and options, offers the real open times, collects name, phone and email, then shows a summary card - nothing is booked until they tap Confirm, and the booking runs through the existing endpoint, so conflict checks and the confirmation email/SMS behave exactly as they do from the booking form. It can only name services, staff and prices that exist in your database. Returning customers can move or cancel after a one-time code, a full day offers the waitlist, and leaving a message for a human is built in. When it is on it takes over the Text Us corner so there is only one button; your Text Us setting is left untouched. The switches are on the AI Assistant page, with the other AI settings.
* Admin search now takes keywords from the feature that owns them. A new `yatoon_admin_search_index` filter lets a class register its own search terms next to the code they describe, so a switch ships with the words merchants would type to find it instead of being added to a hand-maintained list later - or forgotten. The chat concierge registers its own, in English and Chinese.
* Chat concierge: the assistant now picks its suggested services from what the customer actually described instead of always the first few in the list, always gives a real reply instead of a generic line, and no longer shows a service picker under a plain question about hours, address or policies.
* Chat concierge: fixed the assistant announcing that the day ended at lunchtime. The list of open times was cut to the first 12 slots before it reached the model and the first 18 on screen, so a late afternoon or evening opening was invisible. The whole day is sent now, the buttons group into morning/afternoon/evening when there are many, and a customer can ask to change the time, day, professional, add-ons or service and actually be taken back to that step.
* Chat concierge: fixed "Message the salon" sitting on "Sending..." forever. The email is now handed off after the reply is sent, so a slow mail host no longer holds the chat window, and a failed insert no longer lets a visitor trigger a full database schema rebuild.
* Chat concierge: fixed voice input working only once per visit. Speaking a reply aloud and listening share one audio channel on iPhones, so the microphone came up dead on the second tap and the button stayed stuck. Reading is now stopped before listening starts, and the button always releases itself even when the browser never reports that it finished.
* Chat concierge: opening hours answers now account for a midday closing break, keyword guesses no longer overrule the model on words like "facebook", and asking a question mid-booking no longer wipes the booking off the screen.
* Chat concierge: the website knowledge index now respects membership and translation plugins rather than reading published posts directly, page-builder content is rendered inside a guard so a faulty plugin cannot take the chat down, and a customer never sees a raw browser error message.
* Chat concierge: voice input and read-aloud are now hidden unless switched on, and ship off. Safari returns no words and no error on a second dictation, and a microphone button that opens the microphone and does nothing is worse than no button. The handling that recovers from it stays in place, so the switch on the AI Assistant page turns the feature back on the day browsers can be relied on.
* Chat concierge: worked around an Apple WebKit bug where the microphone opens for a second dictation - the phone even shows the recording indicator - but no words are ever delivered and no error is raised. Reading replies aloud is now switched off the first time the microphone is used, because audio playback is what breaks it; a short pause is left between recordings; a live "Listening" line shows what the microphone is doing; and if nothing comes through the assistant says so and points to typing instead of sitting there silently.
* Chat concierge: a customer who is already signed in is no longer asked for a one-time code to see their own appointments, and their name, phone and email are filled in for them at the last step. Identity is resolved over AJAX rather than written into the page, so a full-page cache can never serve one visitor these details on another visitor's screen.
* Fixed the cart drawer inheriting the theme's button skin: Close is the flow's own small pill on the right of the sheet again, not a wide coloured block at the left. The drawer sits outside the booking container, so it also now takes the flow's type face instead of the theme's heading font, and its Edit / Remove / Change labels keep their own casing. The row eyebrows stay uppercase.
* Restored the mobile cart bar's own layout: Back, a centred cart block with the icon beside the two text lines, and the action button. Neutralising a theme's button skin in 4721 removed the padding that had been holding the bar together without supplying the flow's own grid, because that grid lives in a stylesheet the browser was still serving from cache. Both now ship together, and Back / the action button keep the theme's casing.
* Removed the drop shadow from the category chips.
* Centred the category row again, without the shrink-to-fit sizing that caused the two-chip bug: the row stays full width and the chips are centred inside it, so the same categories fit as before.
* Fixed the mobile category bar settling on two categories with unused space beside them. The row was sized with width:max-content so a short bar could be centred, and the fitting script measured that same row - so moving one category into "More" narrowed the row, which moved the next one out too. The row is full width again and the script measures the column, so a 430px phone now shows every category that genuinely fits.
* Stopped themes that skin the bare button element (Astra and most page builders set background, radius, padding and uppercase text on it) from repainting the mobile cart bar. The service count and "Tap cart" label are plain text on the bar again instead of a large coloured pill.
* Gave the step 2 service artwork one wide 3:2 frame on phones, flush with the panel, instead of inheriting the upload's own proportions. Portrait artwork no longer fills most of the screen. Per-service crop position and zoom still control the visible area.
* Shipped the two changed frontend assets under new file names and added a one-time cache purge after an update, so sites whose optimiser strips ?ver= from asset URLs (LiteSpeed Cache "Remove Query Strings") receive the new CSS and JS instead of the previously cached copies.
* Prevented accidental cart opening while keeping compact Back / Continue buttons and a borderless cart label. Improved appointment summary alignment and keyboard-friendly cart closing.
* Fixed named professionals such as Tiffany and Dany being mistaken for the Any professional option.
* Made the mobile calendar summary expandable while preserving service and guest editing.
* Fixed international phone entry when optional widgets are unavailable, aligned client/server validation, and preserved country codes in blacklist matching.
* Redesigned mobile service details with larger, fully filled artwork and an expandable description; removed conflicting image sizing and redundant default headings.
* Added accessible loading placeholders for options, professionals, and available times, respecting reduced-motion preferences.
* Fixed availability errors and incomplete responses leaving customers without a useful retry action. Retry preserves the selected date.
* Clarified unavailable-time messages, corrected escaped service names, and added translations for the new interface text.
* Added live text-contrast guidance to brand button previews while preserving saved colors.
* Hardened Free/Pro payment availability and missing payment-class handling, including gift cards.
* Refreshed production JavaScript, CSS, RTL styles, and release packaging checks.

= 4.7.1 =
* Added employee-specific service and add-on durations with availability, conflict checks, and clear Staff editing controls.
* Improved appointment summaries so price and duration update immediately when a variation or add-on changes.
* Fixed named-staff availability, database migration repair, cached frontend assets, and Square time filtering.
* Added System Diagnostics with schema checks, repair tools, Site Health entries, and a copyable support report.

= 4.7.0 =
* Added booking-horizon controls, stored client time zones, accessible booking-flow focus handling, signed webhooks, and Pro automation triggers.
* Improved booking reliability, availability checks, payments, Square/Vagaro handling, responsive layouts, and staff mobile sessions.
* Added category management, service artwork improvements, and stronger validation, permissions, and rate limiting.

Older release notes are preserved in the project release archive.
