Client management for a small business: client cards and privacy
What belongs on a client card, what to write in the notes, how the history brings clients back, and what privacy law (Israel's Amendment 13, the GDPR) requires.
In short
- A good client card answers three questions in a second: who this is, what happened last time, and what to remember next time. A name and a phone number, the appointment history, short notes, consents, and a debt if there is one.
- A client list is a database under privacy law. Israel's Amendment 13, in force since August 2025, widened the duties of every business and the powers of enforcement: a defined purpose, security, access by need, answering requests to see and to delete. The GDPR asks the same in Europe.
- The best note is the short one: "prefers quiet", "allergic to colour 7", "always 10 minutes late". The worst note is an opinion about the client, because the client may ask to read it.
What a client card should answer
A good client card answers three questions in one second, when the client is at the door: who this is, what happened last time, and what to remember this time. Everything else is an extra. A small business does not need an insurance company's CRM; it needs to remember, by name, the client who came three weeks ago and was not happy with the shade.
That memory is the difference between a business clients come back to and one they replace. And in a business with several team members it is the difference between a consistent service and a service that depends on who is working today.
What is on the card
| Field | What goes in it | What does not |
|---|---|---|
| Details | Name, phone, preferred language, how they found you | Address and ID number, unless needed for an invoice |
| Appointment history | Builds itself: when, which service, with whom, how much they paid, came or not | Nothing manual |
| Notes | Facts that affect the service: preferences, sensitivities, what was done | Opinions, personal descriptions, gossip |
| Consents | Appointment messages, promotions, forms signed, with a date | "They probably agree" |
| Money | An open debt, a punch card, a credit | A card number. Never |
| Cancellations | No-shows and late cancellations, with a date | Judgement |
A good note is short, factual, and useful next time: "prefers quiet during the treatment", "allergic to colour 7", "always 10 minutes late, book last before the break". A bad note is an opinion. The difference matters for more than politeness: under privacy law the client may ask to see the information held about them, and "annoying client" on the card is a conversation you do not want to have.
How the history turns into a client who returns
The appointment history is a list that builds itself. Using it is what makes the difference:
- The client who did not come back. Someone who was a regular and vanished two months ago is one message: "we miss you — the open times are here". The system knows who that is; you do not, among three hundred clients.
- An offer on time. Someone who comes every three weeks and has not booked the next one gets a reminder in the third week, not after six months. Standing appointments save even that.
- The cancellers. Two late cancellations on the card are a conversation, before the third. We wrote about it.
- A punch card running out. A client on their last punch gets an offer to renew before the appointment, not after.
- The team. A new team member opens the card and knows what the client likes, without her having to tell it again.
Amendment 13: what changed and what applies to you
A client list with names and phone numbers is a database under privacy law, even when it is small. In Israel, Amendment 13 to the Privacy Protection Law, in force since August 2025, is the biggest change to the law since it was passed, and it touches every business; the GDPR asks much the same of a business in Europe:
Checklist
The details, the thresholds and the exceptions are updated and published on the Privacy Protection Authority's site. For a business that takes clients from Europe or operates there, the GDPR applies as well, and it is similar in spirit.
Messages to clients: service versus advertising
There is a difference between a message about the client's appointment and a message about a promotion. The first is a service on an existing transaction; the second is advertising, and anti-spam laws allow it only to someone who consented in advance and explicitly, in writing, with a way to opt out. In Israel a breach means compensation per message, with no proof of damage needed (Kol Zchut)); the US and the EU have their own versions.
So the client card keeps two separate consents: appointment messages (which comes with the booking) and advertising (which needs a separate tick). And it keeps when and how each was given. A client who asked to be taken off the promotions keeps getting reminders about their appointments, which is exactly what they want.
How it looks in Torly
In Torly the client card builds itself from the first appointment: a name, a phone number and a language; the appointment history with who treated, what was paid and what was cancelled; internal notes only the team sees; the consents the client gave on the booking site and in forms, with a date; an open debt, a credit and punch cards; and the forms they signed, version by version. A client can be blocked from booking on the booking site, and one who cancels again and again can be marked. Access is by account: a team member sees what was set for them. And what is not kept: clients' card numbers are never on the card. Deletion at a client's request is done from the card itself, and what must be kept (accounting documents) stays.
Questions and answers
Does a small business have to register a database?
In Israel, Amendment 13 changed the registration rules: the duty to register was narrowed to large or especially sensitive databases, and in its place duties that apply to everyone were widened: a purpose, security, and in some cases a privacy officer. Check the Privacy Protection Authority's site for what applies to the size and kind of your database, and do not assume small means exempt.
What may I write in the notes about a client?
Facts that affect the service: preferences, sensitivities, what was done last time, consents. Not opinions, not personal descriptions, not information unrelated to the service. A rule of thumb: write as if the client will read it tomorrow, because under the law they may ask to.
A client asked me to delete them. What do I do?
Delete what there is no duty to keep, and tell them it was done. What you must keep (invoices and receipts under tax law, for example) stays, and the client gets an explanation. Record the request and the answer.
May I send clients messages about promotions?
Only with explicit prior consent, in writing, under anti-spam law. Consent to receive appointment reminders is not consent to promotions. Keep the consent (when, how, for what) and honour an opt-out in one tap.
Who on the team should see the client card?
Whoever treats the client, and only what they need. Whoever manages appointments does not need to see a health declaration; whoever treats does not need to see the debt. A system with permissions does this effortlessly; a shared spreadsheet does not.
What is the difference between the appointment history and the client card?
The appointment history is a list: when, what, with whom, how much. The client card is the context: who the client is, what they prefer, what they agreed to, what they owe, and what to remember. The history builds itself from the appointments; you build the card with one note after every visit.
Sources
Updated · By Moti Hanukah
Builds Torly, an appointment scheduling system for small businesses, and works every day with owners who want a full calendar and fewer phone calls. Writes here about what we learn along the way.
