This Privacy Policy explains how calendar.app (“we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use our website, applications, APIs, embeds, and related services (the “Service”), including at getcalendar.app and deployments such as meetroom.brandstory.ai.
By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service. Our Terms and Conditions also apply.
1. Who this Policy covers
- Account users — workspace owners, admins, members, and platform admins who sign in
- Guests / invitees — people who book meetings without creating an account
- Website visitors — people who browse our marketing site
- API / Partner consumers — applications and developers that connect via API keys, webhooks, embeds, or Partner API
2. Self-hosted vs hosted
Self-hosted deployments: When you run calendar.app on your own infrastructure, you (the organization operating that instance) are typically the controller of Customer Data stored in your database. This Policy describes practices for our hosted/operated Service and marketing properties. Your own privacy notice may apply to guests on your booking pages.
Hosted Service: When we operate the Service for you, we process personal data to provide scheduling, integrations, and related features as described below.
3. Information we collect
3.1 You provide
- Account details (name, email, password or sign-in via Google, timezone, avatar)
- Organization and team information
- Scheduler settings, availability rules, custom booking questions and answers
- Booking details (guest name, email, timezone, meeting time, location/video link, notes)
- Support and contact messages
- Payment-related information for paid events (processed by Stripe or similar; we typically do not store full card numbers)
3.2 From integrations you connect
- Calendar free/busy and event data needed to schedule and sync (for example Google Calendar, Outlook)
- Conferencing metadata (for example Zoom, Google Meet, Microsoft Teams)
- CRM fields and records you map and sync (for example HubSpot, Salesforce, Zoho, Pipedrive, monday.com, Freshsales)
- OAuth connection identifiers; provider OAuth tokens are handled via our integration layer (Nango) rather than stored as raw provider tokens in our app database where that architecture applies
3.3 AI Notetaker (optional)
- Meeting links, transcripts, summaries, action items, and related session metadata
- Audio or transcript content captured via optional bot join, Chrome extension, or paste import
- Processing may use third-party AI or speech providers you or we configure (for example Anthropic, Whisper-compatible services, Recall.ai)
3.4 Automatically collected
- Log and device data (IP address, browser type, pages viewed, timestamps)
- Session information (login sessions may include IP and user agent for security)
- API and webhook delivery metadata (for reliability and audit)
- Cookies or similar technologies on marketing or product surfaces where used
4. How we use information
- Provide, operate, and secure the Service (accounts, bookings, holds, availability, emails)
- Sync calendars, create events, and provision conference links
- Sync CRM records according to your mappings
- Deliver embeds, APIs, webhooks, and Partner API access you authorize
- Generate Notetaker outputs when enabled
- Process paid-event payments through payment providers
- Send transactional messages (for example booking confirmations) when email is configured
- Monitor abuse, debug issues, and maintain audit logs
- Improve the product and communicate Service-related updates
- Comply with law and enforce our Terms
5. Legal bases (where applicable)
Depending on your location, we may process personal data based on: contract performance; legitimate interests (securing and improving the Service); consent (where required, for example certain cookies or recording); and legal obligations.
6. How we share information
We may share personal information with:
- Service providers — hosting, email (SMTP), payments (Stripe), OAuth/integration proxy (Nango), AI/notetaker providers, analytics or error monitoring if enabled
- Integration providers you connect — calendars, video, CRM, and similar tools you authorize
- Partner applications — when an organization connects a partner app with scoped access to bookings, event types, or Notetaker data
- Workspace members — hosts and admins who can see bookings and related data for their organization
- Professional advisors and authorities — when required by law or to protect rights and safety
- Business transfers — in connection with a merger, acquisition, or asset sale
We do not sell personal information as that term is commonly understood for advertising data brokers.
7. Booking guests
When someone books via your public page or embed, their details and form answers are stored for that booking and may be sent to calendars, email, CRM, webhooks, or partners you configure. Hosts are responsible for providing any required notices to guests and for collecting recording/transcription consent when using Notetaker features.
8. Cookies and similar technologies
We may use essential cookies for authentication and security, and optionally analytics or preference cookies on marketing pages. You can control cookies through your browser settings. Disabling essential cookies may break sign-in or core features.
9. Data retention
We retain personal data for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Booking, audit, webhook delivery, and Notetaker records may be retained according to your workspace settings and our operational needs. Self-hosted operators control retention on their systems.
10. Security
We use administrative, technical, and organizational measures appropriate to the Service, including multi-tenant isolation by organization, scoped API and partner tokens, webhook signature verification where implemented, and session management. No method of transmission or storage is 100% secure. You are responsible for protecting passwords, API keys, and Partner secrets, and for securing self-hosted deployments.
11. International transfers
If you access the Service from outside the country where data is processed or stored, your information may be transferred across borders. Where required, we use appropriate safeguards for such transfers.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal data; object to or restrict certain processing; withdraw consent; and lodge a complaint with a supervisory authority. Account users can often update profile information in-product. For guest data, contact the organization that owns the booking page, or contact us if we operate the relevant instance.
To exercise rights related to our hosted Service, email privacy@getcalendar.app.
13. Children’s privacy
The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided data, contact us and we will take appropriate steps.
14. Third-party sites and services
The Service links to and integrates with third parties. Their privacy practices are governed by their own policies. Review those policies before connecting accounts or sharing data.
15. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date will change when we post revisions. Continued use after an update means you accept the revised Policy where permitted by law.
16. Contact
Privacy questions: privacy@getcalendar.app
Legal: legal@getcalendar.app
Web: getcalendar.app
Related: Home · Terms and Conditions · Privacy Policy