Organization and role boundaries
Authenticated access is checked against organization membership and role permissions. Staff can access only the organizations and locations they are authorized to use, and public customers do not receive operator-dashboard access.
Private customer access
Appointment management, queue tickets, intake requests, and similar customer actions use scoped, expiring access links. Public responses are designed not to reveal another customer's personal information. Private links should not be posted publicly or shared with unrelated people.
Operational integrity
Capacity is rechecked when bookings and changes are confirmed. Important booking, queue, status, estimate, and message actions are designed to be safe to retry, while audited state changes help authorized teams understand what happened.
Intake and documents
Secure intake uses access controls, configured encryption for documents and secrets, malware-scanning support, and retention controls. Organizations remain responsible for requesting only information they need and configuring an appropriate retention period.
Payment boundaries
Subscription purchases and customer appointment payments use supported third-party providers. AppointLane is designed not to store full payment-card details processed by those providers. Appointment revenue remains with the organization's configured provider; AppointLane does not hold those customer funds.
Monitoring and responsible reporting
Rate limits, request controls, security logging, and safe error categories support abuse prevention and investigation. If you believe you have found a vulnerability, email [email protected] with enough detail to investigate safely, and do not publicly disclose sensitive details before there has been a reasonable opportunity to respond.
For data categories, providers, retention, analytics choices, and individual rights, read the Privacy Notice. For other questions, use the contact page.