"Zenoti vs. Mindbody" is a search someone runs assuming there's one universal winner at the end of it. There isn't. These two platforms serve different markets, and neither one may be sized for yours.
Buying up or down a size is the most common and most expensive mistake in choosing a CRM. It doesn't announce itself right away. It shows up later, as a workaround the front desk has quietly built, or a consent form that turns out not to hold up the way you assumed it would.
So before the feature grid, the actual question: what size operation do you run, and how injectable-heavy is it? Answer that first. The platform comparison sorts itself out after.
Mindbody: Salon-Spa-First
Mindbody was built for the broad wellness and salon market — yoga studios, hair salons, day spas, gyms. That's a real and large market, and it's a different market than an injectable-driven medspa holding PHI on every client.
A medspa doing neurotoxin and filler needs a versioned consent form and a place to record a lot number, attached to the right client and the right visit, permanently. That's not a knock on Mindbody's engineering. It's a statement about who the product was built to serve. Practices ask us, often, when they've outgrown a salon tool like Mindbody, Vagaro, or Boulevard. Usually the answer is: right around the point where treatment notes and consent stop fitting in a generic field.
Zenoti: Built for Chains
Zenoti sits at the other end of the category. It's built for enterprise-scale, multi-location chains and franchises. That's a legitimate market, and the market framing bears it out: medspa CRMs on the high end run to $600+ a month once you're paying for multi-location plans with AI and marketing bundled in. That's chain-scale pricing for chain-scale infrastructure.
Where We Stand
We'll say the same thing about ourselves that we just said about Zenoti's actual customer: Lumè is not the right call for a large enterprise chain. That's Zenoti's lane, not ours. If you're running a ten-location franchise with a corporate ops layer, we'd rather tell you that on page one than have you find it out during onboarding.
The Operator Neither Platform Was Built For
Between salon-spa-first and enterprise-chain sits an operator neither platform was actually designed around: injectable-driven, holding PHI, needing a BAA and versioned e-signed consent, without carrying hospital-grade weight built for a system it will never use.
This is the solo nurse injector running one room. It's the single-location medspa that's outgrown a booking app and started keeping treatment notes in a spreadsheet because the software has no real place for dosages. It's the practice adding a second and third provider, where "who's eligible to book this service" stops being obvious. It's the small multi-location group — two, three, maybe four locations — that is not shopping for what a ten-location chain needs, and shouldn't be quoted like one.
Location count alone misses the variable that actually matters: clinical intensity. A five-location day spa doing facials and a two-location medspa doing neurotoxin and filler at every visit look identical on a "how many locations" filter. They are not the same buyer.
Compare Total Cost, Not the Sticker
The cheapest headline plan is often not the cheapest system. The number on a pricing page rarely includes everything you end up paying for once the front desk needs training or messaging turns out to be a separate line item.
Look at how the pieces get priced elsewhere in this category. Podium, sold as a standalone add-on for messaging and reviews, runs approximately $400–$600 a month by itself, on top of whatever core scheduling system you're already paying for. Base platform, then a stack of modules priced separately, each with its own contract.
We built Lumè's Pro tier the other way. The AI SMS agent is included at $249 a month, alongside the full medspa CRM: scheduling, charting, consent, payments, memberships, marketing. Not metered separately. Not a premium add-on stacked on top. When you're comparing total cost, ask what the advertised number actually includes, and price out what it takes to reach parity everywhere else.
What Actually Belongs on One Record
Here's what we think should live on a single client record for this operator, concretely.
Scheduling that runs on provider-column calendars with drag-to-reschedule and buffer time, plus a public booking page that captures a deposit and respects who's actually eligible to perform the service booked.
Client charts carrying treatment history, provider notes, dosages and lot numbers, and before/after photos. Not a generic notes box.
E-signed consent that's versioned, auto-sent on booking, and stored on the chart, so you can show which exact form version a client signed and when.
Integrated payments — card, cash, check — posted straight to the invoice, with cards on file, deposits taken at booking, and a receipt and refund trail tied to that same client.
Memberships and packages with recurring billing, banked or rollover credits, member pricing, and package balances that draw down automatically.
Retention automations — rebooking prompts, treatment-cycle reminders, membership renewals, lapsed-client win-backs — firing directly off that record instead of a separate marketing tool that doesn't know the client's actual history.
That's clinical depth sized for aesthetics, not a certified EHR. A handful of practices that write prescriptions and operate as full medical clinics genuinely need a certified EHR alongside a system like this. Most injectable-driven medspas don't. They need the chart, the consent, and the audit trail, without carrying software built for a hospital they aren't.
HIPAA as a Floor, Not an Upsell
If compliance is a paid tier, the base product doesn't have it. HIPAA and a BAA should be the floor at every tier of a medspa CRM, not an enterprise upgrade you chase once you're big enough to ask for it.
Concretely, that means a Business Associate Agreement included in the standard contract at every tier, not quoted separately, not gated behind a higher plan. It means tenant data isolated at the database level, an append-only audit log on every PHI read, and encryption in transit and at rest. We frame this as defensible, not as an absolute guarantee. No vendor should hand you a promise that compliance risk disappears the moment you sign. What we can stand behind is the architecture, and the fact that it's the same architecture whether you're on the smallest plan or the largest.
Who This Guidance Is Actually For
This is written for the solo injector or single-location spa outgrowing a salon tool like Mindbody, Vagaro, or Boulevard, and for the small multi-location group that hasn't reached chain scale — the gap that sits between Mindbody and Zenoti, unaddressed by either one.
If that's not you, if you're running a ten-location franchise with a corporate ops team, this piece isn't sized for you either. Go look at Zenoti.
If it is you, the practical question isn't which platform wins a feature grid. It's what the software actually looks like for an operation your size, holding the PHI you hold, at the clinical intensity you actually run. Start there, and the rest of the comparison gets a lot shorter.