Privacy Policy
Last updated: August 12, 2026
This Privacy Policy describes how Calendar Scheduler ("the Service," "we," "us") collects, uses, and protects personal data. It applies to both hosts (people who create an account, connect their calendar and video-meeting apps, and share a booking page) and invitees (people who book a meeting with a host through the Service).
1. Who is responsible
The Service is currently operated by Marcelo Kaczorowsky, an individual developer based in Germany, as a personal project in active development. For any question about this Privacy Policy or your personal data, contact: marcelokaczorowsky@gmail.com.
2. What we collect
For hosts:
- Name, email address, and profile image, from signing in with Google.
- A username and the booking-page configuration you create (event types, availability, time zone).
- OAuth refresh tokens for Google Calendar and, if connected, Zoom — encrypted at rest (AES-256-GCM) and never stored in plain text.
For invitees:
- Name, email address, and (optionally) time zone, entered when booking a meeting.
- Basic marketing attribution parameters (UTM source/medium/campaign), if present in the booking-page link you arrived from.
3. Why we process this data
We process this data to operate the Service: to authenticate hosts, display real availability, create calendar events for confirmed bookings, and — where a host has enabled it — automatically generate a Google Meet or Zoom meeting link for a booking. For EU/EEA users, the legal basis is performance of a contract (providing the Service you asked to use) and, for the OAuth connections specifically, your explicit consent, which you can withdraw at any time (see Section 6).
4. Who we share it with
We do not sell personal data, and we do not share it with third parties for advertising. Data is shared only with the specific services needed to make a booking work:
- Google (Google Calendar API) — to check a host's availability and create the calendar event for a confirmed booking, and, if selected, to generate a Google Meet link.
- Zoom — only if a host has connected Zoom and selected it for an event type — to create a real Zoom meeting for a booking and retrieve its join link.
- Vercel (application hosting) and Neon (database hosting) — as infrastructure providers processing data on our behalf to run the Service.
Google and Zoom are based in the United States; data sent to them relies on those providers' own standard data-protection safeguards for international transfers.
5. How we protect it
All network traffic to and from the Service uses TLS. OAuth refresh tokens for Google and Zoom are encrypted at rest using AES-256-GCM before being stored. Credentials and encryption keys are kept as environment variables, never committed to source code, and are separated between our development and production environments.
6. Your rights, and how to exercise them
If applicable data protection law (including the GDPR) gives you rights of access, rectification, erasure, restriction, objection, or data portability, or the right to withdraw consent, you can exercise most of these directly, without waiting on us:
- Disconnect Google Calendar or Zoom at any time from your dashboard's Calendar page — this revokes our access with the provider directly, not just deletes our copy of the token.
- Delete your account at any time from your dashboard's Account page. This permanently deletes your event types, bookings, and calendar/Zoom connections, and cannot be undone.
- For anything else — including requests from invitees, who don't have an account to manage this themselves — contact us at the email above.
You also have the right to lodge a complaint with your local data protection supervisory authority.
7. Data retention
Host data is kept for as long as the account exists, and is deleted when the account is deleted. Booking records are kept for as long as the associated event type or host account exists. Deleting your account does not remove any calendar event or meeting already created on your own Google or Zoom account — those are your data, on those providers' own services, independent of us.
8. Children
The Service is not directed at children, and we do not knowingly collect personal data from children.
9. Changes to this policy
We may update this Privacy Policy as the Service changes. We'll update the date at the top of this page when we do.