{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "acuity-scheduling",
    "name": "Acuity Scheduling API",
    "vendor": "Squarespace",
    "vendorUrl": "https://acuityscheduling.com",
    "kind": "http-api",
    "category": "scheduling",
    "summary": "Acuity Scheduling is Squarespace's appointment booking product. Its REST API reads availability, creates, reschedules and cancels appointments, manages clients and blocked time, and sends webhooks, with Basic authentication or OAuth2.",
    "url": "https://www.anchorterminal.com/tools/acuity-scheduling",
    "markdownUrl": "https://www.anchorterminal.com/tools/acuity-scheduling.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/acuity-scheduling.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/acuity-scheduling.json",
    "repo": "https://github.com/AcuityScheduling/acuity-js",
    "license": "Proprietary service under Squarespace's Developer Terms. The Node.js and PHP SDKs are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://acuityscheduling.com/api/v1",
    "packages": [
      {
        "registry": "npm",
        "name": "acuityscheduling"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. One account uses HTTP Basic authentication with the numeric User ID as username and the account API key as password, found under Integrations in the Acuity settings. Apps that connect other people's accounts register an OAuth2 client at https://acuityscheduling.com/oauth2/register and use the authorisation code grant, which has one scope, `api-v1`, and returns a Bearer token. `POST /oauth2/disconnect` disables a token. No app review step, token expiry or refresh token is described in the OAuth guide. Requests must come from a server, as cross-origin requests are refused.",
    "pricing": "paid",
    "pricingNotes": "The pricing page lists \"Custom API and CSS\" on the Premium plan only, at $61 a month or $49 a month billed yearly. Starter is $20 ($16 yearly) and Standard $34 ($27 yearly), in USD before tax. Each plan has a 7-day trial with no card needed. We did not establish whether the trial includes API access. No free tier or sandbox was found, and API calls carry no separate charge. An Enterprise plan with additional APIs is sold through sales (https://acuityscheduling.com/pricing).",
    "priceSummary": "$61 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs or on the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 9182,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developers.acuityscheduling.com",
    "llmsTxt": "https://developers.acuityscheduling.com/llms.txt",
    "capabilities": [
      "calendar.read",
      "calendar.availability",
      "calendar.booking",
      "calendar.webhooks"
    ],
    "tags": [
      "hosted",
      "paid",
      "trial",
      "rest",
      "oauth",
      "basic-auth",
      "webhooks",
      "llms-txt",
      "closed-source",
      "status-page",
      "hipaa",
      "nodejs",
      "php"
    ],
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 42.4,
      "grade": "E",
      "agentReady": false,
      "rank": 678,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 8,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 44,
        "maintenance": 15,
        "payments": 30,
        "reliability": 58,
        "schema": 56,
        "security": 27,
        "transparency": 54
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 58,
          "points": 11.6,
          "reason": "Graded as a hosted API. Statuspage site at status.acuityscheduling.com with incident history, though one component stands for the whole product (20). In the 90 days to 8 October 2026 the feed shows a critical disruption of 2 hours 5 minutes on 19 July and one of 18 minutes on 12 August, both marked as possibly affecting all users and services, plus a four-day iOS app fault and three minor integration incidents. Read as one major outage (10). 10 requests a second and 20 concurrent connections per IP (15). The 429 body is documented, with no `Retry-After`, backoff advice or idempotency key for booking writes (3). No SLA found, and the Developer Terms disclaim uninterrupted service (0). The v1 API is generally available (10). Total 58."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 56,
          "points": 9.1,
          "reason": "Each reference page carries an OpenAPI 3.1 fragment for its own operation, generated by the docs platform from hand-written pages. No single downloadable specification was found (15). `llms.txt` is published and every page has a Markdown copy, but the index lists only five of 36 reference pages (8). Pages explain client and admin booking modes and when availability is validated, without when-not-to-use guidance (10). Parameters are typed with required fields, but there are no enums and `datetime` is any string PHP's strtotime accepts (8). Request examples, an error table and per-endpoint error codes (12). The path is versioned as v1, with no changelog found (3). Total 56."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 44,
          "points": 7.15,
          "reason": "`max` caps list size and `excludeForms` trims intake forms from appointments. No field selection (10). Filters by date, calendar, type and client, but no cursor or offset is documented, so long lists need date windows (10). Errors carry a status, a named code and a message, and a 404 suggests the nearest path (16). No idempotency key or safe-retry guidance for `POST /appointments` (0). Booking needs five fields and picks a calendar when none is given. SDKs exist for Node.js and PHP, both last released in 2019 (8). Total 44."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 27,
          "points": 4.72,
          "reason": "Basic authentication with one account API key, or OAuth2 with the single scope `api-v1`. Tokens can be disabled at `/oauth2/disconnect`. No scoped keys, expiry or rotation documented. Credentials travel in headers only (15). No read-only credential. Client-mode validation is the default and `admin=true` is opt-in (3). Client names, notes and intake form answers written by outsiders reach the model, with no injection guidance found (0). No API audit log found (0). Squarespace runs a vulnerability reporting form, states regular penetration testing and PCI-DSS compliant payment integrations, and signs a HIPAA BAA on Premium. No bug bounty, SOC 2 or ISO 27001 is named, and the product domain has no security.txt (9). Total 27."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Plan prices are public, $20, $34 and $61 a month, with nothing per call (10). A 7-day trial needs no card. Whether the trial includes API access was not established (20). A person signs up in a browser and copies the key or approves OAuth (0). Total 30."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 15,
          "points": 1.31,
          "reason": "No changelog or release notes found. The docs' own page dates show the OAuth guide edited on 1 October 2026 and the webhooks guide on 25 June 2026, which we count as the latest dated change (10). No three dated entries in 90 days (0). A developer email address and a support form, with no public issue tracker for the API (5). The Node.js and PHP SDKs were last tagged in July 2019 (0). No current package to assess (0). Total 15."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 54,
          "points": 4.72,
          "note": "editorial 34, provenance 74",
          "reason": "Closed service under Squarespace's Developer Terms of 16 December 2025, with MIT SDKs (15). The privacy policy of 15 July 2026 names acuityscheduling.com and states no retention periods. The DPA of the same date promises deletion within 90 days of cancellation on written request (15). No deprecation policy, and the Developer Terms allow changes to developer tools without notice (0). Sub-processors are disclosed only on request by email, and data may move to any country where Squarespace or its sub-processors operate, the US in particular (4). Total 34."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`max` caps list size and `excludeForms` trims intake forms from appointments. No field selection (10). Filters by date, calendar, type and client, but no cursor or offset is documented, so long lists need date windows (10). Errors carry a status, a named code and a message, and a 404 suggests the nearest path (16). No idempotency key or safe-retry guidance for `POST /appointments` (0). Booking needs five fields and picks a calendar when none is given. SDKs exist for Node.js and PHP, both last released in 2019 (8). Total 44.",
          "maintenance": "No changelog or release notes found. The docs' own page dates show the OAuth guide edited on 1 October 2026 and the webhooks guide on 25 June 2026, which we count as the latest dated change (10). No three dated entries in 90 days (0). A developer email address and a support form, with no public issue tracker for the API (5). The Node.js and PHP SDKs were last tagged in July 2019 (0). No current package to assess (0). Total 15.",
          "payments": "No x402, MPP or L402 (0). Plan prices are public, $20, $34 and $61 a month, with nothing per call (10). A 7-day trial needs no card. Whether the trial includes API access was not established (20). A person signs up in a browser and copies the key or approves OAuth (0). Total 30.",
          "reliability": "Graded as a hosted API. Statuspage site at status.acuityscheduling.com with incident history, though one component stands for the whole product (20). In the 90 days to 8 October 2026 the feed shows a critical disruption of 2 hours 5 minutes on 19 July and one of 18 minutes on 12 August, both marked as possibly affecting all users and services, plus a four-day iOS app fault and three minor integration incidents. Read as one major outage (10). 10 requests a second and 20 concurrent connections per IP (15). The 429 body is documented, with no `Retry-After`, backoff advice or idempotency key for booking writes (3). No SLA found, and the Developer Terms disclaim uninterrupted service (0). The v1 API is generally available (10). Total 58.",
          "schema": "Each reference page carries an OpenAPI 3.1 fragment for its own operation, generated by the docs platform from hand-written pages. No single downloadable specification was found (15). `llms.txt` is published and every page has a Markdown copy, but the index lists only five of 36 reference pages (8). Pages explain client and admin booking modes and when availability is validated, without when-not-to-use guidance (10). Parameters are typed with required fields, but there are no enums and `datetime` is any string PHP's strtotime accepts (8). Request examples, an error table and per-endpoint error codes (12). The path is versioned as v1, with no changelog found (3). Total 56.",
          "security": "Basic authentication with one account API key, or OAuth2 with the single scope `api-v1`. Tokens can be disabled at `/oauth2/disconnect`. No scoped keys, expiry or rotation documented. Credentials travel in headers only (15). No read-only credential. Client-mode validation is the default and `admin=true` is opt-in (3). Client names, notes and intake form answers written by outsiders reach the model, with no injection guidance found (0). No API audit log found (0). Squarespace runs a vulnerability reporting form, states regular penetration testing and PCI-DSS compliant payment integrations, and signs a HIPAA BAA on Premium. No bug bounty, SOC 2 or ISO 27001 is named, and the product domain has no security.txt (9). Total 27.",
          "transparency": "Closed service under Squarespace's Developer Terms of 16 December 2025, with MIT SDKs (15). The privacy policy of 15 July 2026 names acuityscheduling.com and states no retention periods. The DPA of the same date promises deletion within 90 days of cancellation on written request (15). No deprecation policy, and the Developer Terms allow changes to developer tools without notice (0). Sub-processors are disclosed only on request by email, and data may move to any country where Squarespace or its sub-processors operate, the US in particular (4). Total 34."
        },
        "sources": [
          {
            "what": "API quick start and authentication",
            "url": "https://developers.acuityscheduling.com/reference/quick-start.md",
            "seen": "2026-10-08"
          },
          {
            "what": "docs index for agents",
            "url": "https://developers.acuityscheduling.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth2 guide",
            "url": "https://developers.acuityscheduling.com/docs/oauth2.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API errors and rate limit",
            "url": "https://developers.acuityscheduling.com/reference/api-errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "create appointment reference",
            "url": "https://developers.acuityscheduling.com/reference/post-appointments.md",
            "seen": "2026-10-08"
          },
          {
            "what": "list appointments reference",
            "url": "https://developers.acuityscheduling.com/reference/get-appointments.md",
            "seen": "2026-10-08"
          },
          {
            "what": "availability times reference",
            "url": "https://developers.acuityscheduling.com/reference/get-availability-times.md",
            "seen": "2026-10-08"
          },
          {
            "what": "cancel appointment reference",
            "url": "https://developers.acuityscheduling.com/reference/put-appointments-id-cancel.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks guide",
            "url": "https://developers.acuityscheduling.com/docs/webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "dynamic webhooks",
            "url": "https://developers.acuityscheduling.com/page/webhooks-webhooks-webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "SDK list",
            "url": "https://developers.acuityscheduling.com/docs/sdks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "legal links for developers",
            "url": "https://developers.acuityscheduling.com/reference/legal.md",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://acuityscheduling.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "status incident feed",
            "url": "https://status.acuityscheduling.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status components",
            "url": "https://status.acuityscheduling.com/api/v2/components.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Developer Terms",
            "url": "https://www.squarespace.com/developer-terms",
            "seen": "2026-10-08"
          },
          {
            "what": "Terms of Service",
            "url": "https://www.squarespace.com/terms-of-service",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.squarespace.com/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "data processing addendum",
            "url": "https://www.squarespace.com/dpa",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.squarespace.com/security",
            "seen": "2026-10-08"
          },
          {
            "what": "security measures",
            "url": "https://www.squarespace.com/measures",
            "seen": "2026-10-08"
          },
          {
            "what": "vulnerability reporting",
            "url": "https://www.squarespace.com/vulnerability-reporting",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt on the product domain (404)",
            "url": "https://acuityscheduling.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "live `/meta` response",
            "url": "https://acuityscheduling.com/api/v1/meta",
            "seen": "2026-10-08"
          },
          {
            "what": "Node.js SDK repository",
            "url": "https://github.com/AcuityScheduling/acuity-js",
            "seen": "2026-10-08"
          },
          {
            "what": "PHP SDK repository",
            "url": "https://github.com/AcuityScheduling/acuity-php",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry entry",
            "url": "https://registry.npmjs.org/acuityscheduling",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.verisign.com/com/v1/domain/acuityscheduling.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "Whether the 7-day trial includes API access, given the pricing page lists the API on Premium only",
          "Whether the account API key can be rotated, and whether OAuth access tokens expire. The OAuth guide shows no expiry or refresh token",
          "Whether `GET /appointments` has any paging beyond `max` and the date filters",
          "Whether Squarespace holds SOC 2 or ISO 27001 reports covering Acuity. None is named on the security or measures pages",
          "The Squarespace DPA does not name Acuity Scheduling. It covers the Services, which the Terms of Service define to include acuityscheduling.com",
          "unchecked: help.acuityscheduling.com answered 403, so the help centre's articles on API credentials and plans were not read",
          "unchecked: Squarespace's Acceptable Use Policy, which the Terms of Service incorporate",
          "unchecked: the Enterprise API documented at enterprise-scheduling.readme.io, which is sold through sales and is not graded here",
          "unchecked: GitHub issue activity for the two SDK repositories, and star counts"
        ]
      },
      "negative": 0,
      "verdict": "The API covers the full booking cycle, with availability checks, named error codes and signed webhooks retried for 24 hours. API access is sold only on the Premium plan at $61 a month, the single OAuth scope grants the whole account, and no changelog, idempotency key or audit log was found in the reviewed documentation.",
      "bestFor": "A business that already takes bookings in Acuity and wants an agent to check slots, book, move and cancel appointments for clients, including classes, packages and intake forms.",
      "strengths": [
        "Availability by date and time, booking, rescheduling and cancelling are separate documented endpoints under `/api/v1`",
        "Errors return a status code, a named `error` code and a message, and a 404 suggests the nearest valid path",
        "Webhooks are signed with HMAC-SHA256 in `x-acuity-signature` and retried nine times over 24 hours",
        "Every docs page has a Markdown copy with an OpenAPI 3.1 fragment, and `llms.txt` is published",
        "Rate limit stated as 10 requests a second and 20 concurrent connections per IP"
      ],
      "weaknesses": [
        "The pricing page lists custom API access on Premium only, $61 a month or $49 billed yearly",
        "OAuth2 has one scope, `api-v1`, and Basic authentication uses one account API key, so no read-only credential exists",
        "No changelog or deprecation policy was found, and the Developer Terms allow changes without notice",
        "The Node.js and PHP SDKs were last released in July 2019",
        "The status page records two critical service disruptions in the last 90 days, on 19 July and 12 August 2026"
      ],
      "agentNotes": [
        "Call `/availability/dates` then `/availability/times` with `appointmentTypeID` before `POST /appointments`, which validates the slot as a client would",
        "Avoid `admin=true` unless the owner asks for it, because it skips availability and form validation",
        "Pass `noEmail=true` when a booking or cancellation must not send the client an email or SMS",
        "Check `GET /appointments` filtered by `email` and date before retrying a booking, since no idempotency key is documented",
        "Stay under 10 requests a second and 20 concurrent connections per IP, and back off on 429, which carries no documented `Retry-After`"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "E",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 42.4
        }
      ],
      "editorialScores": {
        "ergonomics": 44,
        "maintenance": 15,
        "payments": 30,
        "reliability": 58,
        "schema": 56,
        "security": 27,
        "transparency": 34
      },
      "provenanceScore": 74
    },
    "connect": {
      "install": "npm install --save acuityscheduling",
      "http": "curl -u ACUITY_USER_ID:ACUITY_API_KEY \"https://acuityscheduling.com/api/v1/appointments\""
    },
    "letme": {
      "capability": "https://letme.dev/calendar.read",
      "tool": "https://letme.dev/acuity-scheduling"
    },
    "notable": [
      "`POST /appointments` validates availability and intake forms as a client booking would. `admin=true` turns that validation off and requires a `calendarID` (https://developers.acuityscheduling.com/reference/post-appointments.md)",
      "The API is limited to 10 requests a second and 20 concurrent connections from an IP, and answers 429 with `too_many_requests` (https://developers.acuityscheduling.com/reference/api-errors.md)",
      "Webhooks cover `appointment.scheduled`, `appointment.rescheduled`, `appointment.canceled`, `appointment.changed` and `order.completed`, with at most 25 subscriptions an account created through `POST /webhooks` (https://developers.acuityscheduling.com/page/webhooks-webhooks-webhooks.md)",
      "Webhook bodies carry only the action and IDs, signed with HMAC-SHA256 using the API key, and are retried nine times over 24 hours on a 500 or a connection error (https://developers.acuityscheduling.com/docs/webhooks.md)",
      "`llms.txt` lists five of the 36 reference pages. The other pages answer with Markdown when `.md` is added to the URL (https://developers.acuityscheduling.com/llms.txt)",
      "The status feed shows critical service disruptions on 19 July 2026 (2 hours 5 minutes) and 12 August 2026 (18 minutes), each marked as possibly affecting all users and services (https://status.acuityscheduling.com/history)",
      "The Node.js SDK `acuityscheduling` 0.1.9 was published on 15 July 2019 and still drew 9,182 npm downloads in the week to 4 October 2026 (https://registry.npmjs.org/acuityscheduling)"
    ],
    "area": "everyday",
    "details": [
      {
        "label": "Surface graded",
        "value": "The public REST API at https://acuityscheduling.com/api/v1. No official MCP server for the product was found in the developer docs"
      },
      {
        "label": "Endpoints",
        "value": "36 reference pages covering appointments (list, get, create, update, cancel, reschedule, payments), appointment types and add-ons, availability (dates, times, classes, check-times), blocks, calendars, clients, forms, labels, certificates, orders, products, `/me` and `/meta`, plus `/webhooks`"
      },
      {
        "label": "Credentials",
        "value": "HTTP Basic with User ID and one account API key, or OAuth2 authorisation code grant with the single scope `api-v1` and a Bearer token"
      },
      {
        "label": "Plan needed",
        "value": "Premium, $61 a month or $49 a month billed yearly, per the pricing page. 7-day trial without a card"
      },
      {
        "label": "Rate limits",
        "value": "10 requests a second and 20 concurrent connections per IP. 429 with a JSON body, no `Retry-After` documented"
      },
      {
        "label": "Listing controls",
        "value": "`GET /appointments` takes `max` (default 100), `minDate`, `maxDate`, `calendarID`, `appointmentTypeID`, client name, email and phone filters, `excludeForms` and `direction`. No cursor or offset is documented"
      },
      {
        "label": "Errors",
        "value": "JSON with `status_code`, `error` and `message`. Booking has named codes such as `required_email`, `invalid_timezone` and `invalid_appointment_type`"
      },
      {
        "label": "Dates and time zones",
        "value": "`datetime` is parsed by PHP's strtotime in the business or calendar time zone. Time zones are IANA identifiers"
      },
      {
        "label": "Webhooks",
        "value": "Five events, form-encoded POST with IDs only, `x-acuity-signature` HMAC-SHA256, nine retries over 24 hours, disabled after five days of failures, 25 subscriptions an account. `/meta` lists the sending IP ranges"
      },
      {
        "label": "SDKs",
        "value": "Node.js `acuityscheduling` 0.1.9 on npm and PHP `acuityscheduling/acuityscheduling` on Packagist, both MIT, last tagged July 2019"
      },
      {
        "label": "Status",
        "value": "status.acuityscheduling.com on Statuspage, one component for the whole product, with an incident history back past October 2025"
      },
      {
        "label": "Compliance",
        "value": "HIPAA business associate agreement on Premium. Squarespace's measures page states regular penetration testing. No SOC 2 or ISO 27001 report is named"
      }
    ],
    "unitPrices": [
      {
        "item": "Premium (the plan with API access)",
        "unit": "month",
        "usd": 61,
        "note": "Monthly billing. $49 a month billed yearly"
      }
    ],
    "provenance": {
      "legalEntity": "Squarespace, Inc.",
      "domain": "acuityscheduling.com",
      "domainRegistered": "2007-01-15",
      "endpointOnVendorDomain": true,
      "terms": "https://www.squarespace.com/developer-terms",
      "privacy": "https://www.squarespace.com/privacy",
      "statusPage": "https://status.acuityscheduling.com",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The developer docs' legal page links two documents, Squarespace's Developer Terms (last updated 16 December 2025) and Squarespace's privacy policy (effective 15 July 2026). Both name acuityscheduling.com.",
        "The contracting entity is Squarespace, Inc., 225 Varick Street, New York, for US users and Squarespace Ireland Limited, Dublin, for others.",
        "acuityscheduling.com/.well-known/security.txt returns 404. www.squarespace.com publishes one that expires on 1 January 2028 and points to its vulnerability reporting page.",
        "The API answers at https://acuityscheduling.com/api/v1 and OAuth at https://acuityscheduling.com/oauth2.",
        "RDAP gives a registration date of 2007-01-15 and MarkMonitor Inc. as registrar.",
        "No changelog was found. developers.acuityscheduling.com/changelog.md returns the docs' not-found page."
      ],
      "score": 74,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Squarespace, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "acuityscheduling.com, registered 2007-01-15 (19 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "acuityscheduling.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.acuityscheduling.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.squarespace.com/developer-terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-12-16",
          "words": 13293,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: December 16, 2025",
              "says": "Last updated 2025-12-16"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "…Tools (including non-contractual disputes and matters) shall be governed in all respects by the laws of the State of New York, without regard to its conflict of law provisions, except that the Federal Arbitration Act (“FAA”) shall prevail to the extent that there exists any conflict between the FAA and the laws of the…",
              "says": "The law of the State of New York"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…fullest extent permitted by law, notwithstanding anything to the contrary in the Developer Agreement, in no event shall the aggregate liability of Squarespace for all claims arising out of or related to our Developer Tools, our Developer Programs and the Developer Agreement exceed the greater of ten thousand US dollar…",
              "says": "Capped at the greater of ten thousand US dollars and the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "(c) we may terminate, suspend, restrict or disable your access to or use of parts or all of our Developer Tools, your Developer Accounts or your participation in one or more Developer Programs;"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We may modify these Developer Terms (and other parts of the Developer Agreement including the Developer Policy) from time to time, and we will post the most current version on our site.",
              "says": "Changes are posted, with no other notice named"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not agree to all the terms in the Developer Agreement, you may not use or access our Developer Tools."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Unless expressly authorized in writing in advance by Squarespace, substantially replicate or otherwise compete with any products or services offered by Squarespace or a Squarespace affiliate.",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Squarespace may update and/or discontinue our Developer Tools from time to time, or may discontinue support for previous versions of our Developer Tools at our sole discretion and without notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "your participation in an applicable Developer Program and your license to and ability to use and access applicable Developer Tools may be temporarily or permanently revoked, with or without notice."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "Please note that Section 16 (Dispute Resolution) contains an arbitration clause and class action waiver."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Squarespace may use and publicise the marks of a developer who uses the Product Integrations Tools, for any Squarespace business purpose.",
              "quote": "(f) use and publicize the following for any Squarespace business purpose, including providing customer support to Shared Customers: (i) you or your organization’s Marks;"
            },
            {
              "date": "2026-10-08",
              "text": "The arbitration agreement can be declined by email within 30 days of first agreeing to the Developer Agreement.",
              "quote": "You can decline (also referred to as ‘opt out’) this Arbitration Agreement by emailing us at arbitration-opt-out@squarespace.com within thirty (30) days of the date that you first agree to this Developer Agreement (the “Initial Opt-Out Period”)"
            },
            {
              "date": "2026-10-08",
              "text": "A claim not subject to arbitration must be started within one year of when the party first knew or should have known of its cause.",
              "quote": "Any claim not subject to arbitration must be commenced within one (1) year after the date the party asserting the claim first knows or reasonably should know of the act, omission or default giving rise to the claim."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.squarespace.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 13275,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We explain below how we collect and use Squarespace Controlled Information and your rights."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain your information for as long as your account is active or for as long as needed to provide you with the Services.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "For Customer Controlled Information, Squarespace acts as a data processor, service provider or similar term under applicable law."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Please see the opt-out method described above in subsection (c) (“Do not sell or share my personal information”) of this Appendix I of this Privacy Policy.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You can find out about your rights and choices in Section 6 below."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "You may also contact us by email at privacy@squarespace.com to submit a request.",
              "says": "privacy@squarespace.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "in the US from, as applicable, the EEA, Switzerland and the UK pursuant to the Data Privacy Frameworks.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "disclose information about you to a third party ad serving platform to target our ads to Customers who created accounts but have not yet signed up for paid Services."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The policy does not cover the content and end user data a customer puts into the service, which the Data Processing Addendum covers.",
              "quote": "This Privacy Policy does not apply to Customer Controlled Information as described above."
            },
            {
              "date": "2026-10-08",
              "text": "Squarespace may use de-identified information and disclose it to others for any purpose, without limitation.",
              "quote": "Our use and disclosure of de-identified information is not subject to any restrictions under this Privacy Policy, and we may use and disclose it to others for any purpose, without limitation."
            },
            {
              "date": "2026-10-08",
              "text": "Squarespace may not immediately delete a customer's information when a trial expires or all paid services are cancelled.",
              "quote": "As Customers may have a seasonal site or come back to us after an account becomes inactive, if you’re a Customer, we may not immediately delete your information when your trial expires or you cancel all your paid Services."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/acuity-scheduling.json",
    "live": {
      "slug": "acuity-scheduling",
      "probe": {
        "target": "https://acuityscheduling.com/api/v1",
        "method": "get",
        "lastAt": "2026-10-08T21:12:02.913876422Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 444,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 478,
        "p95ms24h": 504,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.acuityscheduling.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T21:05:50.494732133Z"
      },
      "updatedAt": "2026-10-08T21:12:02.913876422Z"
    }
  }
}
