FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Other
  4. Acuity Scheduling
A

Acuity Scheduling

Preferences

Related services

AccuWeather

AccuWeather is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AccuWeather supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AccuWeather ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

Affirm

Affirm is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Affirm is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Affirm offers reliable solutions that scale with organizational needs and evolving web standards.

Other

Algolia

Algolia is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Algolia is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Algolia offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

AppDynamics

AppDynamics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. AppDynamics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, AppDynamics empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

Apple App Store

Apple App Store is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, Apple App Store delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Other
A

Apple iCloud Mail

Apple iCloud Mail is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Apple iCloud Mail supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Apple iCloud Mail ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Acuity Scheduling do?

Acuity Scheduling, now branded Squarespace Scheduling, is an appointment booking platform widely used by coaches, therapists, salons, photographers, consultants and small healthcare practices. It offers a calendar centric booking experience with intake forms, reminders, recurring appointments and integrations with Stripe, Square, Zoom, Google Meet and most calendar systems. The Acuity widget loads on the customer site and transmits booking data to Squarespace, Inc. servers in the United States.

What is Acuity Scheduling

Acuity Scheduling, now formally Squarespace Scheduling since the 2019 acquisition by Squarespace, is an online appointment booking platform aimed at independent professionals and small businesses. Coaches, therapists, hairdressers, photographers, consultants and small healthcare practices use it to publish a public booking page, manage availability, send automated reminders and reduce no shows. Customers can book single or recurring appointments, complete intake forms, pay through Stripe or Square at booking, and join video meetings via Zoom or Google Meet.

What data and cookies Acuity collects

At booking time, Acuity collects name, email, phone, address, optional date of birth, intake form responses (which may include health information for medical practices), payment data forwarded to Stripe or Square and IP address. The embedded widget sets cookies on acuityscheduling.com such as _acuityscheduling_session, acuity-csrf-token and several Squarespace tracking cookies (ss_cookieAllowed, RecentRedirect). Webhook integrations expose data to Mailchimp, ConvertKit, ActiveCampaign or Zapier depending on the practitioner''s configuration.

GDPR and ePrivacy implications

The embedded widget loads automatically on the host page and sets cookies before any booking starts, which triggers Article 5(3) ePrivacy. The processing of appointment data after the user actively books rests on contract performance under Article 6(1)(b) GDPR. Intake forms collecting health information bring Article 9 special category data into play, requiring an explicit consent or a healthcare professional secrecy basis. The US transfer must be referenced with the DPF or SCC mechanism.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Is consent required

For the embedded widget, yes: gate the script behind a consent banner under the Functional or Marketing category. If you only link to a hosted booking page on acuityscheduling.com, the consent shift moves to that destination and the user is then on Acuity''s privacy notice. Inside the booking flow itself, once the user has actively chosen to book, processing can run under contract, but intake forms with health data still need their own explicit consent.

Data transfers to the United States

Acuity Scheduling stores all appointment, customer and payment data on Squarespace, Inc. infrastructure in the United States. Squarespace is self certified under the EU US Data Privacy Framework. EU SCCs are included in the Squarespace DPA. For healthcare professionals, the US storage of Article 9 data requires a documented Transfer Impact Assessment and is in tension with several national health data laws (notably the Health Data Hub doctrine in France and the BfArM Hosting requirements in Germany).

Practical compliance steps

Gate the widget behind your consent manager, sign the Squarespace DPA, configure intake forms to avoid collecting sensitive data unless strictly necessary, and obtain explicit consent for any health information. Document Squarespace, Inc. as a recipient in the privacy policy with the DPF and SCC mechanism. For practices subject to French Health Data Hosting (HDS) certification or German healthcare hosting requirements, consider an EU based alternative.

GDPR consent category

Preferences

Websites using Acuity Scheduling must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy) for the embedded scheduling widget that loads scripts before any booking is initiated; contract (Art. 6(1)(b)) for processing the appointment data after the user actively books; legal obligation (Art. 6(1)(c)) for invoicing related retention
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, TTDSG, LIL, PSD2 for any payments processed through Stripe or Square within Acuity

DPIA considerations

A DPIA can be required when Acuity is used by healthcare professionals collecting health data, by therapists handling sensitive disclosures, or at large scale across multiple practices. Document the categories of data collected through intake forms, the US transfer mechanism, the integrations with payment and video providers, and the retention.

Sample consent text

We use Acuity Scheduling (Squarespace Scheduling) to manage appointments. Loading the booking widget sends your IP and booking details to Squarespace, Inc. in the United States. Do you accept?

Technical details

Tracking methodEmbeddable scheduling widget (acuityscheduling.com iframe) or full redirect to a hosted booking page; client side script embed.js for inline integration; REST API for server side appointment management; webhooks for integrations with CRM and calendar providers
Server locationUnited States (Squarespace, Inc., New York City; Acuity Scheduling was acquired by Squarespace in 2019 and is now Squarespace Scheduling) on AWS US infrastructure
Data transferred outside the EUAcuity Scheduling is operated by Squarespace, Inc. in the United States. All appointments, customer contact details, payment metadata and intake form responses are stored on US infrastructure. Squarespace is self certified under the EU US Data Privacy Framework and signs SCCs through the Squarespace Data Processing Addendum.

Third-party domains contacted

acuityscheduling.comapp.squarespacescheduling.comcdn.acuityscheduling.comsquarespace.comjs.stripe.comsquarecdn.com

Cookies placed

NameTypeDurationPurpose
_acuityscheduling_sessionthird partySessionMaintains the booking session between the embedded widget and the Acuity backend during a reservation.
acuity-csrf-tokenthird partySessionCross site request forgery protection token used by Acuity during the booking flow.
ss_cookieAllowedthird party1 yearSquarespace cookie that remembers the user's cookie banner choice on the Squarespace platform.
RecentRedirectthird partySessionSquarespace cookie used to track the previous URL when redirecting between Squarespace properties.
crumbthird partySessionSquarespace CSRF protection cookie set on the booking page.
__stripe_mid / __stripe_sidthird partySession to 1 yearStripe payment cookies set when paying through Acuity, used for fraud prevention by Stripe.

Acuity Scheduling uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Acuity Scheduling set?

The widget sets _acuityscheduling_session for the booking session, acuity-csrf-token for CSRF protection and a few Squarespace cookies (ss_cookieAllowed, RecentRedirect). If payment is configured, Stripe or Square cookies are also set during checkout.

Do I need consent for the Acuity widget?

For the embedded widget yes, because it sets cookies and loads scripts before any booking. Once the user actively books, the strictly necessary cookies (session, CSRF) can run under contract performance, but the initial load still needs consent.

What is the legal basis for Acuity Scheduling?

Contract performance (Art. 6(1)(b) GDPR) for the booking and any service delivered after, legal obligation (Art. 6(1)(c)) for invoicing retention, consent (Art. 6(1)(a)) for the widget loading on the host page and for intake forms collecting Article 9 health data.

Are personal data transferred to the United States?

Yes. Squarespace, Inc. operates Acuity from US infrastructure. The EU US Data Privacy Framework certification and EU SCCs in the Squarespace DPA cover the transfer. Health data raises an additional layer requiring a Transfer Impact Assessment.

Do I need a DPIA for Acuity Scheduling?

For independent coaches or beauty salons, generally no. For healthcare professionals collecting health data, therapists or multi practitioner platforms, a DPIA is recommended to cover the Article 9 processing, the US transfer and the integrations with Stripe, Square, Zoom or Google Meet.

How do I deploy Acuity compliantly?

Gate the widget behind a CMP, sign the Squarespace DPA, configure intake forms to ask only what is necessary, anchor health data on explicit consent, list Squarespace, Inc. as a recipient with the DPF or SCC mechanism, and consider an EU alternative for HDS or BfArM regulated practices.

What are the alternatives to Acuity Scheduling?

EU based alternatives: Doctolib (FR, healthcare), Maiia (FR), Planity (FR, salons), Treatwell (UK/EU, salons), Calendly (US, but ISO 27001 with EU region), TIMIFY (DE), SimplyBook.me (UK/Cyprus). Open source: Cal.com (self hostable).

How should I describe Acuity in the cookie policy?

Add an entry under Functional or Marketing: provider Squarespace, Inc. (USA), domains acuityscheduling.com, app.squarespacescheduling.com, cookies (_acuityscheduling_session, acuity-csrf-token, ss_cookieAllowed), purpose appointment booking, transfer mechanism EU US Data Privacy Framework and SCCs, retention according to your appointment retention policy.