How to set up BookingAddOn and start accepting appointments.
Add two lines of code to your site: one script tag and one button element. It works with WordPress, Wix, Squarespace, or any website that supports HTML.
Yes. BookingAddOn embeds on any platform via a lightweight script. No plugins, no iframes, no migration required.
Clients visit your booking page, pick an available time slot, enter their details, pay online if required, and receive an instant confirmation via email and SMS.
BookingAddOn is built for appointment-based wellness and therapeutic services including physical therapy, massage therapy, counseling, psychoanalysis, acupuncture, and coaching.
Yes. You can import existing client data via CSV or start fresh. Our onboarding takes under 5 minutes.
Reminders, payments, and what's included in each plan.
BookingAddOn uses Stripe to accept all major credit and debit cards. You can also sell session packages so clients can prepay for multiple visits.
Email and SMS reminders are sent automatically at 72 hours and 24 hours before each appointment. The 72-hour reminder includes one-click reschedule options.
Custom branding starts at the Practice tier.
Find the right plan for your practice.
The Practice plan is designed for teams of 2–5 people, supporting up to 5 staff calendars and 750 bookings per month.
Yes, we offer a Lifetime plan for a $250 one-time payment. It includes all Clinic features, including two-way SMS and intake forms.
Yes. Every plan includes a 14-day free trial with full access to all features. No credit card required to start.
How BookingAddOn works with Google Calendar, Apple iCalendar, and Outlook.
We provide a reliable real-time one-way push for business owners. Using a secure OAuth connection, BookingAddOn automatically pushes every new appointment, update, or cancellation directly to your Google Calendar in real time. This ensures you can view your entire professional schedule from any device using the Google Calendar app.
Yes. We offer universal compatibility for your clients. Immediately after booking, they can add the appointment to their preferred platform: Google Calendar (one-click automated sync), Apple iCalendar (instant download of a standard .ics file), or Microsoft Outlook (a prefilled event link for quick saving).
Real-time one-way push is the preferred choice for many professionals because it protects your privacy and keeps your business data clean. It ensures that your client bookings are pushed to your calendar, but prevents your personal Google Calendar events (like private family dinners or medical appointments) from being imported into your BookingAddOn database as "business leads."
Yes. Even with one-way push, BookingAddOn is designed to respect your availability. You can set your specific working hours and block out time directly within the app to ensure that you are never double-booked.
How we protect your data and your clients' information.
Client contact information is encrypted at rest using AES-256, the same encryption standard used by banks and government agencies. All connections use HTTPS with TLS encryption and HSTS preload, so data is protected both in storage and in transit.
Passwords are hashed with bcrypt and never stored in plain text. Sessions use httpOnly secure cookies that cannot be accessed by JavaScript, and we support two-factor authentication for admin accounts. Sessions can be revoked instantly if needed.
All payments are processed by Stripe, a PCI Level 1 certified payment processor. Credit card numbers never touch our servers—they go directly to Stripe's secure infrastructure.
We use database-backed, multi-tier rate limiting to block brute force and spam attempts. All database queries are fully parameterized to prevent SQL injection, and strict Content Security Policy headers protect against cross-site scripting.
BookingAddOn is not currently HIPAA certified. Most of our target customers—coaches, massage therapists, acupuncturists, and similar wellness practitioners—are not classified as HIPAA-covered entities. That said, we take security seriously and implement encryption, secure authentication, and access controls that go beyond what most booking platforms offer.