Acuity EU Client Data Checks
What EU appointment-based businesses should verify in Acuity: vendor terms, exports, intake forms, SMS consent, payment providers, transfers.

What EU appointment-based businesses should verify in Acuity: vendor terms, exports, intake forms, SMS consent, payment providers, transfers. It covers start with the role split, what acuity says about GDPR tools, review the data you actually collect, and intake forms are the highest-risk area.
Acuity and EU Client Data: What Appointment-Based Businesses Should Verify
Acuity is not only a booking page. For many appointment-based businesses, it holds client records, appointment history, intake answers, notes, payments, packages, subscriptions, SMS opt-ins, and reports.
For EU businesses, that means the buying question is broader than "does Acuity have GDPR tools?" The better question is: can you configure, document, export, and govern the client data you collect through Acuity?
This guide explains what to verify before using Acuity for EU client data, before expanding how much data you collect, or before moving from Acuity into a CRM such as Tregovia.
Start With The Role Split
Start by separating what the business controls from what the platform processes under its own published terms. For most service businesses, that split is practical before it is legal: you choose the client questions, appointment labels, retention rules, staff access, reminder content, and exports.
For an appointment-based business, the practical split is:
- You decide what client data you collect.
- You decide why you collect it.
- You decide how long to keep it.
- You decide which staff can access it.
- The platform processes data to provide the service, subject to its terms.
That is why vendor terms do not replace your own privacy notice, lawful basis, staff process, or retention policy.
What Acuity Says About GDPR Tools
Squarespace's GDPR help page says Acuity has tools that can help with GDPR, including:
- Displaying terms and conditions in scheduling instructions
- Including consent requests on intake forms
- Requiring agreement to terms before package or subscription purchases
- Deleting client information in the client list, including inactive clients and bulk deletion
- Exporting client data for portability requests
It also says being GDPR-ready is ultimately up to the business and depends on how the account is configured and what client data is collected.
That is the right framing for buyers: useful tools, but not automatic compliance.
Review The Data You Actually Collect
Open a real Acuity account or export and list every data category.
Common categories:
- Client name, email, and phone
- Appointment type
- Appointment date, time, and location/calendar
- Intake answers
- Uploaded files
- Private client notes
- Payment status and amount paid
- Packages, gift certificates, and subscriptions
- SMS opt-in behavior
- Cancellation, no-show, and reschedule history
- Staff or admin notes
Some appointment types can reveal more than you expect. A therapy, massage, medical, legal, coaching, or financial appointment title may reveal sensitive context even before form answers are considered.
Intake Forms Are The Highest-Risk Area
Acuity intake forms can collect custom information during scheduling, and form answers can appear in appointment details. Acuity's help center says selected intake form answers can also be included in appointment exports.
That is useful operationally, but it means every form question deserves review.
Ask:
- Do we need this question?
- Is it mandatory for every appointment type?
- Does it reveal health, financial, legal, or other sensitive information?
- Who can see the answer?
- Does it appear in emails or exports?
- How long do we keep it?
- Can the client update it?
- What happens if the form is deleted later?
Do not use one giant form for every service. Collect the minimum useful data for each appointment type.
For businesses where intake is central, compare with the GDPR-aware massage booking software guide, even if your vertical is different. The same principle applies: appointment context can become sensitive data.
SMS Consent And Reminder Content
Acuity's SMS help says clients must opt in for text reminders, clients can opt out, replies receive an automated response, and each appointment can send one text reminder. It also tells businesses to provide notice and obtain legally required consent before enabling text notifications.
For EU buyers, this creates two checks:
- Is the opt-in process appropriate for your country and message type?
- Does the reminder content avoid sensitive details?
Safe reminder:
Reminder: your appointment with {{business_name}} is on {{date}} at {{time}}.
Risky reminder:
Reminder for your debt consultation / injury treatment / legal dispute call tomorrow.
Keep reminders neutral unless you have a clear reason and documented permission.
Payment Providers And Third Parties
Acuity can connect with Stripe, Square, or PayPal for payments. Acuity's payment help says payment fees and provider terms are separate. That means your data review should include the payment provider, not only Acuity/Squarespace.
Review:
- Which payment provider you use
- Where payment-provider terms apply
- Whether appointment type, amount, or client data is sent to the payment provider
- Refund process
- Data export/report needs for bookkeeping
- Whether payment links or invoices expose unnecessary detail
For cost-side evaluation, use the Acuity total cost guide.
Export, Delete, And Retention
Acuity can export appointment and client data. Its client list help says deleting a client permanently deletes their appointments from the client list and cannot be undone; it also notes that some deleted clients may remain if they have active packages, gift certificates, or subscriptions until those are deleted.
This is why retention policy needs to be written before cleanup.
Define:
- Which records are kept for accounting
- Which records are kept for service history
- Which records are deleted after inactivity
- Who can approve deletion
- What is exported before deletion
- Where exports are stored
- When exports are deleted locally
Deletion is not only a button. It is a business record decision.
Compare The Data Workflow Before Migrating
If the Acuity review exposes fragmented records, unclear exports, overgrown forms, or staff workarounds, compare the data workflow before switching tools. The migration question is not only "can we import clients?" It is whether the next system gives staff a clearer operating record.
For Tregovia, review these practical points with real examples:
- Where client profile data appears
- Where appointment notes and form answers appear
- Which staff roles can see sensitive context
- How exports are handled during migration
- How billing records connect to service history
- What should be archived instead of imported
- Which reminders might expose appointment context
Tregovia's fit here is not a blanket GDPR guarantee. It is a CRM workflow to evaluate around client records, appointments, billing, forms, reports, exports, and staff access. The business still needs vendor-term review, lawful basis, privacy notices, retention rules, and staff training.
Use moving from Acuity to a CRM if the data review turns into a migration, and use Tregovia pricing only after you know which workflow pieces are actually needed.
EU Client-Data Questions
Is Acuity GDPR-ready?
That is the wrong binary question. Squarespace provides GDPR-related tools and vendor terms, but your compliance depends on your configuration, data collection, notices, lawful basis, retention, and staff behavior.
Should intake answers be exported before leaving Acuity?
Yes, if you need them for continuity, records, or portability. Acuity appointment exports can include selected intake form answers, so test the export before migration pressure.
Are appointment titles personal data?
They can be. If the title reveals a service connected to health, legal, financial, or other sensitive context, treat it carefully in reminders, exports, calendars, and reports.
Does switching to Tregovia remove Acuity data obligations?
No. You still need to handle exported files, archived records, deletion decisions, and any data that remains in Acuity during or after the transition.
Verification Checklist
Before expanding Acuity usage or migrating away from it, verify:
- What client and appointment data is collected
- Which intake questions are still necessary
- Whether reminder content reveals sensitive context
- Which payment, SMS, and third-party providers are involved
- How exports and deletion behave in practice
- Which records must be retained for accounting or service continuity
- How staff access should work after migration
Tregovia can be evaluated for CRM-connected client-data workflows, not as a substitute for legal and operational review.
Related articles
Commercial
Move from Acuity to CRM Checklist
A practical Acuity-to-CRM migration checklist covering clients, appointments, intake forms, calendars, services, booking links, payments, and cutover.
Commercial
Acuity Total Cost: 12-Month Model
Acuity total cost guide for appointment-based businesses: plan prices, calendars, SMS reminders, payments, packages, migration, and CRM comparison.
Commercial
GlossGenius EU Client Data Checks
What EU-based independent stylists should verify before using GlossGenius or moving client data: availability, privacy terms, exports, vendors.
Review client-data workflows in Tregovia
Review how client records, appointments, forms, billing context, reports, exports, and staff access fit together before migrating.