← Journal
Software selection

Medical Spa Booking Software Isn't Salon Booking Software With a Different Logo

Most "best medspa software" lists are salon-spa rankings with the word medspa pasted on. Here's the actual test — provider eligibility logic, deposit capture, and one client record — to run against anything on your shortlist, including us.

The Lumè team6 min read

Open one of these "best medspa booking software" roundups and look for a methodology. Most don't have one worth the name — no description of what was tested, by whom, or against what standard. What you're often looking at is a ranking of salon-spa platforms with the word "medspa" bolted onto the headline.

We think placement on those lists correlates with referral fees, not fit. Use them to build a shortlist. Then ignore the ranking and judge the software on the mechanics that actually separate a salon scheduler from a medspa CRM.

What actually makes booking software "medspa" software

Strip away the marketing and the test is narrow. Three things:

  1. Provider eligibility logic on the public booking page — the system knows which provider can perform which service before it offers the slot.
  2. Deposit capture at time of booking — not an optional toggle buried in settings, built into the flow.
  3. Booking that flows into the same client record as the rest of the visit — not a booking widget that hands off to a separate charting or payments system.

This is a general test. Apply it to whatever's on your shortlist, not just to us.

Provider eligibility: the check a salon tool has no reason to build

A salon booking page needs to know whether a chair is free at that hour. A medspa booking page needs to know something else: whether the provider on that slot is credentialed for the treatment being booked. Neurotoxin and filler aren't haircuts. Not every provider on staff is eligible for every injectable, and a public booking page that can't tell the difference will let a client book with someone who shouldn't be performing that service.

Nobody notices until the morning of the appointment, when the front desk has to call and rebook — or doesn't catch it at all. A booking page built for a medspa checks provider eligibility before it offers the slot, which is the logic our own scheduling runs on.

Deposits: the strongest anti-no-show lever, and the honest number on refusal

Every operator we talk to has the same fear before turning on deposits: clients will refuse to book, and revenue drops with them. The actual number is under 5% drop-off. And the clients who refuse skew disproportionately toward the ones most likely to no-show anyway.

A deposit at booking is, by a wide margin, the strongest anti-no-show intervention available — stronger than any reminder sequence built on top of it. Reminders help at the margin, but not equally: voicemail-only calls perform about the same as no reminder at all, while SMS moves the number.

The mechanics matter too. A deposit captured inside the appointment and posted straight to the invoice, with a card on file and a receipt trail tied to the same client, behaves differently than one collected through a third-party link that gets reconciled by hand later.

Consent belongs inside the booking flow, not after it

For an injectable-driven practice, consent is part of the clinical record, not paperwork tacked onto the end of booking. Treated as a follow-up from a separate e-signature tool, it's the thing that gets missed, or signed in a version that doesn't match what was actually administered.

Versioned consent forms with e-signature — capturing name, timestamp, device or IP, and the exact form version signed — belong auto-sent the moment the appointment is made, stored on the same chart the provider opens at the visit. Ours works this way; see consent for how it's structured.

HIPAA and a BAA should be the floor, not a paid upgrade

If compliance is a paid tier, the base product doesn't have it. HIPAA and a Business Associate Agreement should be the floor at every tier a medspa can buy — not something you get upsold into once you've outgrown the starter plan. A public booking page is already touching a client's name, contact information, and the service they're booking. That's data worth protecting on day one, at the cheapest plan.

We build to that floor: BAA included in the standard contract at every tier, database-level tenant isolation, an append-only audit log on every PHI read, encryption in transit and at rest. See hipaa for the detail.

We'd also push back on the assumption a lot of owners walk in with — that none of this applies because they don't bill insurance. That's half a story. HSA and FSA payment rails, and a growing number of state-level overlays, can pull a cash-only practice into scope without a single insurance claim. We frame our architecture as defensible and addressable. Nobody selling software honestly gets to promise more than that.

Split systems create a second record you keep in sync by hand

If booking lives in one tool and charting, consent, and payments live in another, the client's history is split across two logins. The split shows up at checkout, at rebooking, at the moment a provider needs to see what was charted last visit before administering this one.

We think about this as seven jobs, one record — booking, charting, consent, payments, memberships, marketing, and retention all reading and writing the same client file. Integrated payments captured inside the appointment and posted straight to the invoice. Membership and package balances that draw down automatically instead of living in a spreadsheet next to the booking tool. A chart carrying treatment history, dosages, lot numbers, and before/after photos, visible to the provider the moment booking becomes a visit. It's a fair test to run against any vendor on your list, not just us.

The most expensive mistake: buying the wrong size

Buying up or down a size is the most common and most expensive mistake in choosing a CRM, and it runs both directions. A solo nurse injector doesn't need multi-location provider-column calendars or a pricing tier built for five locations of overhead. A growing multi-location group will outgrow a single-calendar booking tool fast, and migrating client records mid-growth costs far more than paying for headroom up front.

Compare total cost, not the sticker. The cheapest headline plan is often not the cheapest system once you add the modules the entry tier didn't include.

And we'll say plainly what we're not: Lumè isn't built for large enterprise chains. That's Zenoti's lane, not ours. If you're a solo injector, a growing single location, or a small multi-location group, size the tool to that — not to where you hope to be in five years.

What to actually check before you buy

Apply the three-part test — provider eligibility, deposit capture, one client record — to any platform on your shortlist. If a vendor can't clearly answer whether the booking page checks eligibility before offering a slot, that's your answer.

If AI SMS booking is on your list, ask the specific version of the question, not the marketing version. Does the agent read live availability, staff schedules, provider eligibility, and account or package balances through structured, audited tool calls — or is it guessing off a cached schedule? Is the system prompt PHI-free, with a pre-send scan for SSN, date of birth, and payment card numbers that blocks the send and escalates instead of transmitting it? Can staff pause a single conversation from the inbox without shutting off the whole system, and is there a daily send cap? Does it escalate to a human the moment something clinical or payment-related comes up?

Ours does all of that. It's included in the Pro tier at $249/month alongside the rest of the CRM — see pricing for how the tiers break down. Whatever you buy, that's the bar to hold it to.

Frequently asked questions

What's the real difference between salon booking software and medspa booking software?
Salon booking only needs to know if a chair is free at a given hour. Medspa booking needs provider eligibility logic — confirming the specific provider on that slot is credentialed for the treatment being booked, since not every staff member can perform every injectable. Most 'best medspa software' lists rank generic salon-spa platforms that never built this check.
Will requiring a deposit at booking cost me clients?
The actual drop-off from requiring deposits is under 5%, and the clients who refuse skew toward the ones most likely to no-show anyway. Deposits captured at booking are the strongest anti-no-show lever available, stronger than any reminder sequence layered on top.
Do reminder texts and calls actually reduce no-shows?
They help, but not equally — voicemail-only reminder calls perform about the same as sending no reminder at all, while SMS reminders meaningfully move the number. Deposits remain the stronger intervention; reminders work best as a layer on top of a deposit, not a replacement for one.
Do cash-only medspas still need to worry about HIPAA?
Yes. HSA and FSA payment rails, along with a growing number of state-level privacy overlays, can pull a cash-only practice into compliance scope without a single insurance claim ever being filed. HIPAA and a signed BAA should be included at every pricing tier, not sold as an upgrade once you've outgrown a starter plan.
How do I know if I'm buying the wrong size CRM for my medspa?
Buying the wrong size runs both directions: a solo injector paying for multi-location provider-column calendars, or a growing multi-location group stuck on a single-calendar tool it will outgrow fast. Compare total cost across the modules you'll actually need, not the headline sticker price, since migrating client records mid-growth costs far more than paying for headroom up front.
Get a demo

See exactly how Lumè fits your medspa.

A focused 30-minute walkthrough of the platform, tailored to how your spa runs. The first call is the demo.