One client profile the whole clinic works from

Visit history, notes, files, tags, and medical alerts on one record that booking, charting, and checkout all read.

Velarya is med spa client management software built around a single client record. Booking, charting, payments, memberships, and rewards all read and write the same profile, so a client’s visit history, wallet balance, points, membership status, files, and medical alerts are one thing rather than five systems that agree with each other on a good day. Clinical information is separated from operational information deliberately: allergies, medications, and conditions are stored encrypted and gated by role, while notes, tags, and visit history support the front desk without exposing anything clinical to people who do not need it.

What sits on a client profile

Most clinics do not have a client management problem. They have a client record scattered across a booking system, a card reader, a loyalty app, and a filing cabinet, and the cost only becomes visible when somebody has to answer a question that spans two of them.

On the profile

Written by

Visit history and upcoming appointments

The calendar, online booking, and the front desk

Purchases, refunds, and wallet balance

Checkout

Membership status and remaining benefits

The membership the client is on

Points balance and reward activity

Every sale, challenge, referral, and check-in

Notes, files, and consent documents

Staff, and forms the client submitted

Clinical profile and medical alerts

Providers with clinical permission

Contact details and notification preferences

The client, in your app

Because these are one record rather than seven, a question like whether a member has an unused benefit and a documented allergy has one answer, available at the moment somebody is standing at the desk asking it.

Two kinds of alert, on purpose

Velarya keeps scheduling alerts and clinical alerts separate, and this is a deliberate design decision rather than an accident of history.

A scheduling alert is the thing the front desk needs when handling a booking. A clinical medical alert is a different object: it is graded by severity, it records which user created it, it is removed by a soft delete that records who removed it, and it lives alongside a structured clinical profile carrying allergies, medications, medical conditions, and pregnancy or breastfeeding status.

Collapsing the two is the common shortcut, and it fails in both directions. Either front desk staff end up reading clinical detail they have no business seeing, or a genuine contraindication gets buried in a general notes field where the injector never looks. Keeping them apart is what lets the right warning reach the right person.

Notes that attach to what they are about

A note in Velarya records who wrote it and when. It can be attached to the specific transaction it concerns rather than floating loose on the profile, which is the difference between a history and a pile.

Notes can also mention another team member, so the person who needs to act is pulled in rather than relied upon to notice, and a note can carry file attachments. The practical result is that the answer to why a client was given a courtesy credit last March is on the transaction, written by a named person, instead of being a thing somebody half remembers.

Files, and where they came from

Every file on a client record carries a label, a category, and a source, so a document the client submitted through an intake form is distinguishable from something a staff member uploaded on their behalf. That provenance is not bureaucratic detail. When someone asks whether a client actually signed a consent or whether a staff member added it afterwards, the record answers.

Deletion is soft and records who performed it, so a removed file leaves a trace rather than a gap. Forms, charts, and photos are covered in more depth alongside the clinical tooling, and the intake side connects to the same profile the booking engine reads.

Tags that stay consistent

Tags in Velarya are defined for the business rather than typed freehand on each client, which sounds like a small thing and is the reason segmentation still works after two years. Free-text tagging reliably produces the same idea spelled four ways, and a segment built on it silently misses a quarter of the people it should include.

Because tags sit on the same profile as visit history and membership status, they are usable for the thing clinics actually want them for: finding people who have drifted, grouping clients who need particular handling, or isolating a cohort worth contacting about something specific.

What the profile notices on its own

Some of the most useful information on a client record is not typed by anyone. A rolling six-month no-show count accrues automatically, so a pattern is visible on the profile rather than being a feeling the front desk has about a particular client. Check-ins record actual arrivals. Membership state resolves from the plan the client is on rather than from a field somebody has to remember to update.

That last one matters more than it looks: a status that is derived cannot go stale, whereas a status that is typed always eventually disagrees with reality. It also means retention work can rely on the record instead of a spreadsheet exported last month.

Who can see what

Information

How it is protected

Clinical profile and medical alerts

Encrypted rather than stored as plain text, and gated by role

Client records generally

Role-based access that can be scoped per location

Views and changes

Audit-logged, so access is reconstructable

Wallet and points adjustments

Separate permission, with every adjustment recorded

Velarya is built for HIPAA-covered practices, and the separation between operational and clinical information is the practical expression of that rather than a badge. A receptionist can do their whole job without clinical access, and a group can scope access per site so a staff member at one location is not browsing another location’s clients. The wider model is on the multi-location page.

Leaving, archiving, and deleting

Clients leave, and what happens to their record afterwards is a question most software answers badly. Archiving keeps the record and its history intact while taking the client out of day-to-day lists, which is what you want for someone who simply stopped coming.

A permanent delete is a separate and deliberate action, and it also purges the clinical records attached to that client rather than leaving them orphaned in the database with nothing pointing at them. That distinction matters for a practice holding PHI: the difference between tidying a list and actually removing someone’s medical information should never be a single ambiguous button.

Why this belongs in one system

A dedicated CRM will beat any clinic platform on marketing automation and pipeline reporting, and if that is your bottleneck it is the right tool. What a CRM cannot do is know that the person at your register is a member with one facial left, a documented allergy, and a no-show last month, because it has never seen the calendar, the chart, or the till. That combination is what the front desk actually needs, and it only exists when the record is shared. Plan differences are on the pricing page, and memberships write to this same profile.

Frequently asked questions

What is med spa client management software?

It is the system of record for everyone your clinic treats: who they are, what they have had done, what they were charged, what they are allergic to, and what they are owed. In Velarya that record is shared with booking, charting, and payments rather than being a separate CRM that has to be kept in step.

Can I see a client’s full visit history?

Yes. Every appointment, purchase, note, and file sits on one timeline, alongside membership status, points balance, and wallet balance. Because checkout writes to the same record, the history includes what was actually bought rather than only what was booked, which is usually where the two diverge.

How does Velarya handle medical alerts and allergies?

With two separate systems on purpose. A scheduling alert flags something the front desk needs to see when handling the booking. Clinical medical alerts are graded by severity, created by a named user, and sit alongside a structured clinical profile holding allergies, medications, conditions, and pregnancy or breastfeeding status.

Can staff leave notes on a client profile?

Yes, and a note can be attached to the specific transaction it relates to rather than floating on the profile. Notes record who wrote them, can mention another team member so the right person is pulled in, and can carry file attachments. That makes a note a piece of history rather than a sticky label.

Where do intake forms and photos end up?

On the client record. Files carry a label, a category, and a source, so a document a client submitted through a form is distinguishable from something a staff member uploaded. Deletion is soft and records who did it, which matters when someone asks months later what happened to a consent form.

Can I tag or segment clients?

Yes. Tags are defined for the business rather than typed freehand per client, so the same idea does not end up spelled four ways across your database. Tags sit on the profile next to visit history, which is what makes them usable for finding clients who have drifted or who belong to a group you want to treat differently.

What happens to a client’s data if I delete them?

Archiving keeps the record and its history while removing the client from day-to-day lists. A permanent delete is a separate, deliberate action that also purges the clinical records attached to that client, so nothing clinical is left orphaned in the database once the person it belongs to is gone.

Who can see a client’s clinical information?

Only staff whose role grants it, and access can be scoped per location. Clinical fields such as allergies, medications, and conditions are stored encrypted rather than as plain text, and views and changes to client records are audit-logged. Velarya is built for HIPAA-covered practices, and that separation is the reason.

Ready to see it on your own med spa?

We’d love to give you a personalized tour and answer all your questions.