What did Kintsu need from its booking software?
The big picture. When your schedule, prices, and patient records sit inside one vendor's software, your website is either connected to it or it is decoration.
The alternatives: the vendor's stock widget on an off-brand page, or staff keying everything by hand. Nobody could say what Zenoti lets an outside system do, so we found out first.
What lands in Zenoti, and how
What we built runs one way: a booking made on Kintsu's page goes into Zenoti and nowhere else.
Six pieces, one place the records live
Everything talks to your booking software, and nothing changes it without you
Four of the six are working today. Two are on the way, and both of those are named.
Online booking page
LivePatients book themselves in, straight into your booking software.
Live since July 12, 2026. Nothing is stored, and no patient details show up in web addresses.
Lead inbox
LiveEvery enquiry from your website lands in your booking software as a guest.
Duplicates are skipped, and your front desk is told straight away.
A private assistant that reads your bookings
LiveIt answers questions about your own data and can only read, never write.
It runs on one machine and is never open to the internet.
Read-only staff dashboard
LiveYour team sees what it needs and cannot change anything.
It never touches anything that carries patient details.
Change tools that ask you first
ComingThey show you exactly what would change, and apply nothing until you say yes.
Built and ready. Nothing has been applied for real yet.
Appointment numbers on the dashboard
ComingThe card is built and sitting there, waiting on your booking software vendor to open up appointment data.
It stays visible and tells you plainly that the data is not there yet.
Your booking software
The one place your records live
One thing is not in this picture. We built a version of the assistant that could be reached over the internet, then set it aside the same day and kept everything on one machine.
One system of record, no double entry, and no change you did not see coming.
- Booking on their own page. Patients pick a service, a provider, and a time without leaving Kintsu's site. Bookings go straight into Zenoti. The site stores nothing.
- A settled answer on what Zenoti allows. Four reviewers checked three independent sources on June 13, 2026 and found only staff records can be changed from outside. Services, products, packages, and rooms are read-only. Zenoti confirmed it in writing on June 30, 2026.
- A helper that can look but never change anything. It answers questions about Kintsu's own booking data for reports. An outside marketing helper sees no patient information.
- Updates you approve first. Two tools show what a price or staff change would do, then write only after a person says go. An outside review on June 15, 2026 caught three faults. No price or staff update had gone live as of June 19, 2026.
How do you launch online booking that passes a HIPAA review?
What we did. We got a clear answer on what the law required, then kept every safeguard we had built anyway. Hosting moved twice before landing on Kintsu's own server on July 12, 2026, once the owner confirmed Kintsu does not bill insurance electronically.
On July 3, 2026, three reviewers checked the design, the prototype, and the hosting plan separately.
Booking launched without promotion on purpose: hidden from search, out of the menu, no trackers. Patient lookup stays silent, so nobody can test whether a person is a patient. What those reviewers found runs to 24 items, each with what it was and what happened to it.
July 3, 2026
Twenty-four privacy problems, dealt with before a patient saw the page
Three reviewers read the booking design, the prototype and the hosting plan at the same time, each without the others.
24 problems found, none of them by a patient. Three of them are below.
A calendar invitation carrying the treatment and the provider
Read by a reviewer who had the booking design and nothing else.
Anyone who saw that invitation would have learned what a patient was booked for and with whom. Both names came out of the link before booking opened.
An analytics call reporting the whole web address a visitor left on
Read by the reviewer holding the prototype.
It now reports the site name and the page, and nothing after them, so nothing a visitor typed or picked travels out with it.
A guest lookup that could carry patient details in the request
Read by the reviewer holding the plan for moving the data.
This one was a risk rather than a live leak, so it was recorded in writing and designed around rather than left unsaid.
The embarrassing privacy problem gets found by your own people, before it is found by a patient.
Why nothing writes to Zenoti by itself
Nothing writes to Zenoti without a person confirming it. We could have let the assistant edit records directly. We did not, because a change nobody has read cannot be checked, and a retry can double-book.
The same rule killed a feature in a day. We told Kintsu and did not bill for it. The whole episode comes down to what we asked, what we found, and what it cost.
July 17, 2026
Stopped on purpose, before anyone wrote a line of code
Redeem a Groupon voucher straight into the booking software
- What we asked
- Whether Groupon would let Kintsu redeem a voucher into Zenoti automatically, instead of the front desk doing it by hand.
- What we found
- That access is issued to the big point-of-sale vendors, not to individual practices. There was no version of this that Kintsu could have.
- What happens instead
- Staff keep redeeming in the Groupon merchant app, exactly as before. The answer is written down, so nobody has to ask it twice.
An hour of asking is cheaper than a month of building the wrong thing, and we did not bill for the hour.
What went wrong
Some of what Zenoti allows is only discoverable by testing, so we tested it and wrote the answer down.
One dashboard card is still blocked. Kintsu's key is refused on the permission it needs, open with Zenoti since July 26, 2026. We left the card visible showing the error.
A patient reported a failed booking on August 15, 2026. The real bad day turned out to be August 18: 213 visits and zero bookings against about 10 expected.
Kintsu's side was stable, and the request log from the reported day had been erased by an unrelated update. We asked Zenoti for its records rather than make a claim we could not prove.
Results
- Online booking live on Kintsu's site since July 12, 2026.
- 24 privacy problems found and dealt with before launch.
- The connection was verified against Kintsu's real catalog of 67 services on June 24, 2026.
Not yet measured. Booking volume, revenue, and conversion rate are not ours to claim yet. The number that will judge this work is the Zenoti booking count since July 12, 2026. The full Kintsu write-up lists everything else we publish.


