Latest
issue
Uniting the world of spa & wellness
Get Spa Business and Spa Business insider digital magazines FREE
Sign up here ▸
News   Features   Products   Company profilesProfiles   Press releasesProfiles   Magazine   Handbook   Advertise    Subscribe  
Software
Building relationships

Using personal data to stay in touch with spa guests and customising experiences can increase repeat visits, but GDPR can make this challenging and operators have been fined millions for breaches. So how can software suppliers help?


Sneha Thuppul
Agilysys
Sneha Thuppul / photo: Agilysys

The Agilysys Spa solution provides valuable information to employees to enhance the guest experience and retain wallet share for future visits, whether that’s via automated, targeted campaigns or one-to-one outreach. Onsite, staff can use Agilysys’ common profile and single itinerary view to identify and cater to guests – if they’re only staying and playing golf, for example, staff can target specific offers to entice them to book a spa appointment too.

Agilysys Spa enhancements allow properties to create custom policies that enable staff to collect guest consent to retain guest information for a specified period. After the specified period, if guest consent to keep their data longer isn’t obtained, that data is rendered anonymous to comply with region-specific data protection and privacy acts, such as GDPR and CCPA.

Agilysys Spa enhancements allow properties to create custom policies for collecting and retaining guest information
Craig Griffin
Journey
Craig Griffin / Journey

With Journey, spas can easily capture customer information and send messages via the client’s preferred contact method – email, call or SMS. Marketing is restricted to clients who opt-in for such messages; this complies with GDPR requirements. Contacts can be segmented based on times of visit, treatment types and spending history. Those who’ve not explicitly opted-in to receive marketing are marked for service emails only such as booking and/or payment confirmations.

Spas must maintain customer records within Journey’s system, including removing and deleting their data and updating preferences when required. Spa clients can update their details and preferences online; updates act as an electronic signature meeting the ‘right to rectification’ requirement of GDPR.

Journey helps simplify data processes for spas. Our software is GDPR and PCI-DSS compliant, keeping customer data secure. We regularly audit customers and assess our software’s functionality, releasing updates to ensure spas meet and retain GDPR compliance.

Journey regularly releases updates to ensure spas meet and retain GDPR compliance
Devon McKercher
Spasoft
Devon McKercher / photo: SpaSoft

Due to the nature of the spa industry and the type of services offered, guests share a lot of information and operators need to be careful that all their systems and data processes – not just software – are GDPR compliant and that employees are trained on how to respond to inquiries and requests.

SpaSoft has strong reporting capabilities allowing staff to pull reports on past guests. Combined with customisable wellness intake forms and post-service surveys spas have all the data they need to recommend services that are personalised to guest preferences.

SpaSoft has developed a series of features that allow spas to comply with GDPR and enhance overall guest data security.

These include:

• Enhanced change logs that allow spas to track any guest anonymisation with change reason codes

• A report that lists the personal information that is retained for a guest. This report can also be shared with a guest for verification

• An anonymisation feature that removes all guest information retained in the system on demand – although references to some items are inserted with generic tags that allow the operational data to remain intact for reporting and historical accuracy.

SpaSoft’s enhanced change logs allow spas to track guest anonymisation
An anonymisation feature removes guest data on demand / photo: Spasoft
Sal Capizzi
Book4Time
Sal Capizzi / photo: Book4Time

It’s been proven that when a guest feels seen and heard, they’re more likely to spend more time at your spa, increasing the overall ticket amount. Book4Time offers a digital intake solution which guests fill out before they even arrive on site, allowing operators to get to know them before their treatment and potentially provide an exceptional experience. Our system also easily enables spas to create customised marketing campaigns.

Book4Time ensures that personal data stored on the system is compliant with ever-changing regulations. Enterprise and global reporting gets stripped of personal data (name, address). We also have a data processing agreement with operators and give recommendations on how to use the information once collected.

Book4Time has a data processing agreement and gives recommendations on how to use information once collected
Charity Hudnall
Vagaro
Charity Hudnall / photo: Vagaro

Vagaro’s spa software offers spas a robust suite of marketing features to effectively keep in touch with clients to help with retention, loyalty and recurring revenue.

In addition, Vagaro’s Forms feature allows service providers to create client SOAP notes – to further customise treatment plans and product suggestions – as well as intake questionnaires and surveys for feedback.

This amounts to a lot of personal information and spa owners are ultimately responsible for keeping records of their clients safe and secure. Any data breach can compromise the trust between a business and its customers and has the potential to invite huge fines and litigations.

Regularly updating staff training on best practices for data protection is essential for maintaining GDPR compliance. Software systems can help too – Vagaro encrypts all customer data and stores it securely. In addition, spas can limit which employees have access to view, add, edit or delete SOAP notes.

As per GDPR guidelines, customers can request businesses to delete all their data. If spa owners are manually managing their customer data, this could pose a major issue. It’s beneficial in this instance to use spa software such as Vagaro, which provides a process for customer data deletion and helps businesses to be GDPR compliant at all times.

Vagaro encrypts all customer data and stores it securely

Read more from this issue of Spa Business magazine

View contents of Spa Business 2024 issue 1
FEATURED SUPPLIERS

Longevity in spas: a strategic choice, not a default setting
Longevity has become one of the most debated concepts in contemporary wellness. [more...]

Introducing Glass Act by Templespa
Introducing Glass Act, your new go-to eye serum for brighter, smoother, beautifully awakened eyes. [more...]
+ More featured suppliers  
COMPANY PROFILES
Life Fitness/Hammer Strength

Life Fitness / Hammer Strength works with some of the world’s most recognised hospitality brands, su [more...]
Charme D'Orient

Charme d’Orient is a cosmetics and wellness brand deeply inspired by the ancestral beauty and wellne [more...]
+ More profiles  
CATALOGUE GALLERY
 

+ More catalogues  

DIRECTORY
+ More directory  
DIARY

 

21-23 Jun 2026

Spa Life International (UK)

Midlands (Venue TBA), Liphook, United Kingdom
22-22 Jun 2026

World Bathing Day

Worldwide,
+ More diary  
 
ABOUT LEISURE MEDIA
LEISURE MEDIA MAGAZINES
LEISURE MEDIA HANDBOOKS
LEISURE MEDIA WEBSITES
LEISURE MEDIA PRODUCT SEARCH
 
SPA BUSINESS
SPA OPPORTUNITIES
SPA BUSINESS HANDBOOK
PRINT SUBSCRIPTIONS
FREE DIGITAL SUBSCRIPTIONS
ADVERTISE . CONTACT US

Leisure Media
Tel: +44 (0)1462 431385

©Cybertrek 2026
Uniting the world of spa & wellness
Get Spa Business and Spa Business insider digital magazines FREE
Sign up here ▸
News   Products   Magazine   Subscribe
Software
Building relationships

Using personal data to stay in touch with spa guests and customising experiences can increase repeat visits, but GDPR can make this challenging and operators have been fined millions for breaches. So how can software suppliers help?


Sneha Thuppul
Agilysys
Sneha Thuppul / photo: Agilysys

The Agilysys Spa solution provides valuable information to employees to enhance the guest experience and retain wallet share for future visits, whether that’s via automated, targeted campaigns or one-to-one outreach. Onsite, staff can use Agilysys’ common profile and single itinerary view to identify and cater to guests – if they’re only staying and playing golf, for example, staff can target specific offers to entice them to book a spa appointment too.

Agilysys Spa enhancements allow properties to create custom policies that enable staff to collect guest consent to retain guest information for a specified period. After the specified period, if guest consent to keep their data longer isn’t obtained, that data is rendered anonymous to comply with region-specific data protection and privacy acts, such as GDPR and CCPA.

Agilysys Spa enhancements allow properties to create custom policies for collecting and retaining guest information
Craig Griffin
Journey
Craig Griffin / Journey

With Journey, spas can easily capture customer information and send messages via the client’s preferred contact method – email, call or SMS. Marketing is restricted to clients who opt-in for such messages; this complies with GDPR requirements. Contacts can be segmented based on times of visit, treatment types and spending history. Those who’ve not explicitly opted-in to receive marketing are marked for service emails only such as booking and/or payment confirmations.

Spas must maintain customer records within Journey’s system, including removing and deleting their data and updating preferences when required. Spa clients can update their details and preferences online; updates act as an electronic signature meeting the ‘right to rectification’ requirement of GDPR.

Journey helps simplify data processes for spas. Our software is GDPR and PCI-DSS compliant, keeping customer data secure. We regularly audit customers and assess our software’s functionality, releasing updates to ensure spas meet and retain GDPR compliance.

Journey regularly releases updates to ensure spas meet and retain GDPR compliance
Devon McKercher
Spasoft
Devon McKercher / photo: SpaSoft

Due to the nature of the spa industry and the type of services offered, guests share a lot of information and operators need to be careful that all their systems and data processes – not just software – are GDPR compliant and that employees are trained on how to respond to inquiries and requests.

SpaSoft has strong reporting capabilities allowing staff to pull reports on past guests. Combined with customisable wellness intake forms and post-service surveys spas have all the data they need to recommend services that are personalised to guest preferences.

SpaSoft has developed a series of features that allow spas to comply with GDPR and enhance overall guest data security.

These include:

• Enhanced change logs that allow spas to track any guest anonymisation with change reason codes

• A report that lists the personal information that is retained for a guest. This report can also be shared with a guest for verification

• An anonymisation feature that removes all guest information retained in the system on demand – although references to some items are inserted with generic tags that allow the operational data to remain intact for reporting and historical accuracy.

SpaSoft’s enhanced change logs allow spas to track guest anonymisation
An anonymisation feature removes guest data on demand / photo: Spasoft
Sal Capizzi
Book4Time
Sal Capizzi / photo: Book4Time

It’s been proven that when a guest feels seen and heard, they’re more likely to spend more time at your spa, increasing the overall ticket amount. Book4Time offers a digital intake solution which guests fill out before they even arrive on site, allowing operators to get to know them before their treatment and potentially provide an exceptional experience. Our system also easily enables spas to create customised marketing campaigns.

Book4Time ensures that personal data stored on the system is compliant with ever-changing regulations. Enterprise and global reporting gets stripped of personal data (name, address). We also have a data processing agreement with operators and give recommendations on how to use the information once collected.

Book4Time has a data processing agreement and gives recommendations on how to use information once collected
Charity Hudnall
Vagaro
Charity Hudnall / photo: Vagaro

Vagaro’s spa software offers spas a robust suite of marketing features to effectively keep in touch with clients to help with retention, loyalty and recurring revenue.

In addition, Vagaro’s Forms feature allows service providers to create client SOAP notes – to further customise treatment plans and product suggestions – as well as intake questionnaires and surveys for feedback.

This amounts to a lot of personal information and spa owners are ultimately responsible for keeping records of their clients safe and secure. Any data breach can compromise the trust between a business and its customers and has the potential to invite huge fines and litigations.

Regularly updating staff training on best practices for data protection is essential for maintaining GDPR compliance. Software systems can help too – Vagaro encrypts all customer data and stores it securely. In addition, spas can limit which employees have access to view, add, edit or delete SOAP notes.

As per GDPR guidelines, customers can request businesses to delete all their data. If spa owners are manually managing their customer data, this could pose a major issue. It’s beneficial in this instance to use spa software such as Vagaro, which provides a process for customer data deletion and helps businesses to be GDPR compliant at all times.

Vagaro encrypts all customer data and stores it securely

Read more from this issue of Spa Business magazine

View contents of Spa Business 2024 issue 1
LATEST NEWS
The Good Spa Guide sets up event for modified Good Spa Guide Awards
The UK spa review and discovery platform for consumers, the Good Spa Guide, has announced it will host the Good Spa Guide Awards 2026 during an event on 16 November at Sopwell House Hotel in St Albans, UK.
McKinsey: 84 per cent of consumers say wellness is a top priority
Eighty-four per cent of consumers now say wellness is a top priority in their lives, with this percentage increasing year on year, according to a preview presentation of McKinsey’s Future of Wellness 2026 research report.
Protests continue in Albania against US$1.6 billion luxury resort backed by Jared Kushner and Ivanka Trump
Mass protests have been taking place since Monday 1 June in Albania over the development of a luxury resort by Donald Trump’s daughter Ivanka Trump and her husband Jared Kushner.
Barons Eden rebrands to Hiddenwell ahead of spa hotel portfolio expansion
Barons Eden, the UK parent company that operates luxury destination properties in England, has rebranded to become Hiddenwell.
Belgin Aksoy marks 15 years of Global Wellness Day
Global Wellness Day (GWD) marked its 15th anniversary on Saturday 13 June 2026, with the theme: #JoyMagenta – a celebration of the healing qualities of simple gestures and activities that spark joy.
HUM2N launches longevity clinic at Six Senses London
Global luxury hospitality brand, Six Senses, has partnered with longevity healthcare provider, HUM2N, to launch a clinic at Six Senses London, at The Whiteley.
Mayrlife opens first hotel day clinic in partnership with Rosewood Vienna
As part of its first hotel partnership, Mayrlife – the medical health resort company known for its site in Altaussee, Austria – has launched a day clinic at the Rosewood Vienna.
KX Chelsea invests £15 million to upgrade its wellness offering
Premium London health club, KX Chelsea, will imminently unveil its most significant redevelopment since its launch in 2002 to create an integrated wellness model combining training, recovery and relaxation.
Rosewood Le Guanahani St Barth offers ocean-themed yoga for Global Wellness Day
Rosewood Le Guanahani St Barth, on the northeast coast of Saint Barthélemy in the French West Indies, is offering a programme of ocean-inspired yoga classes between 8-14 June to celebrate Global Wellness Day (GWD).
Butterfly sanctuary to host hot yoga during retreat at Jersey Zoo for Hotel de France
Hotel de France, located on the British Isle of Jersey, has created a wellness retreat package that includes a hot yoga session that will take place in Jersey Zoo’s butterfly sanctuary.
Hoshino Resorts combats summer heat with medically-supervised cool bathing programme for KAI onsen
Hoshino Resorts has developed a “Cool-down onsen soak” programme at properties with Japanese onsen facilities – those within the company’s KAI brand.
Rainforest immersion and mindfulness are on offer at The Ritz-Carlton, Langkawi, for Global Wellness Day
The Ritz-Carlton, Langkawi, in Malaysia, has revealed a schedule for Global Wellness Day (GWD) that includes guided rainforest walks, mindful movement and guided coastal meditation experiences.
+ More news   
 
FEATURED SUPPLIERS

Longevity in spas: a strategic choice, not a default setting
Longevity has become one of the most debated concepts in contemporary wellness. [more...]

Introducing Glass Act by Templespa
Introducing Glass Act, your new go-to eye serum for brighter, smoother, beautifully awakened eyes. [more...]
+ More featured suppliers  
COMPANY PROFILES
Life Fitness/Hammer Strength

Life Fitness / Hammer Strength works with some of the world’s most recognised hospitality brands, su [more...]
+ More profiles  
CATALOGUE GALLERY
+ More catalogues  

DIRECTORY
+ More directory  
DIARY

 

21-23 Jun 2026

Spa Life International (UK)

Midlands (Venue TBA), Liphook, United Kingdom
22-22 Jun 2026

World Bathing Day

Worldwide,
+ More diary  
 


ADVERTISE . CONTACT US

Leisure Media
Tel: +44 (0)1462 431385

©Cybertrek 2026

ABOUT LEISURE MEDIA
LEISURE MEDIA MAGAZINES
LEISURE MEDIA HANDBOOKS
LEISURE MEDIA WEBSITES
LEISURE MEDIA PRODUCT SEARCH
PRINT SUBSCRIPTIONS
FREE DIGITAL SUBSCRIPTIONS