Privacy policy
Last updated: August 16, 2026
CallSlot is a meeting scheduling service. You publish a booking page, people pick a time, and you manage those bookings. This policy explains what personal data we handle to make that work, why we handle it, who we share it with, and how you can get it deleted.
This policy covers the CallSlot service at app.callslot.app. The data controller is CallSlot. You can reach us at [email protected].
Data we collect
We collect only what the service needs to function.
- Account data. Your name, your email address, and your account preferences (language, time zone, time format, week start). If you sign in with Google or Microsoft, we receive your name, email address and profile picture from that provider instead of a password.
- Scheduling data. The booking pages and events you create: titles, descriptions, locations, available times, and settings.
- Participant data. The names, email addresses and booking details of the people who book time with you. Guests may enter this themselves, or you may enter it for them when you invite them. If you enter another person's details, you are responsible for having a lawful basis to do so.
- Calendar data — only if you connect a calendar. See the Google user data section below.
- Billing data. If you buy a paid plan, we store your plan, its status and its renewal dates. We do not store your card number.
- Technical data. Cookies that keep you signed in and keep your preferences, plus server logs (IP address, browser user agent, requested URL, timestamp) used for security, rate limiting, abuse prevention and debugging.
We do not sell personal data, and we do not use your data to train machine learning models.
Why we use it
- To provide the service: create booking pages and events, collect availability, and send the emails that scheduling requires (verification codes, booking confirmations, reminders, and cancellations).
- To keep accounts secure and to prevent spam and abuse, including rate limiting.
- To take payment and manage subscriptions, if you are on a paid plan.
- To meet legal obligations and to establish, exercise or defend legal claims.
Where the GDPR applies, our legal bases are performance of a contract (providing the service you signed up for), legitimate interests (security, abuse prevention, service improvement), consent (where you connect a calendar, and for any optional cookies), and legal obligation (tax and accounting records).
Google user data and Limited Use
Connecting a Google Calendar is optional. CallSlot works without it. If you choose to connect one, you grant access through Google's own consent screen, and we request only these scopes:
- https://www.googleapis.com/auth/calendar.readonly — to read the events on the calendars you select, so CallSlot can show you which candidate times conflict with something you already have booked.
- https://www.googleapis.com/auth/calendar.events — to create an event when a meeting time is confirmed, and to update or remove that event if the meeting changes or is cancelled.
- userinfo.email and userinfo.profile — to know which Google account the connection belongs to, so we can label it in your settings.
We use this access only for the scheduling features you asked for. We do not read your calendar for any other purpose, we do not show your event details to other participants (only your busy or free status for the candidate times), and we do not use calendar content for advertising.
CallSlot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not transfer Google user data to third parties except as necessary to provide or improve the features you use, to comply with applicable law, or as part of a merger or acquisition; we do not use Google user data for advertising; we do not allow humans to read Google user data unless we have your explicit consent for a specific support request, it is necessary for security purposes or to comply with applicable law, or the data is aggregated and anonymised.
You can disconnect a calendar at any time from your CallSlot settings, or revoke access from your Google account permissions page. When you disconnect, we delete the stored access and refresh tokens and the cached availability derived from that calendar.
Who we share data with
We use a small number of service providers to run CallSlot. Each one receives only the data it needs, and each is bound by a contract to protect it.
- Vultr — hosting. The CallSlot application runs on a single virtual private server operated by CallSlot at a Vultr data centre in the United States.
- Supabase — the managed PostgreSQL database that stores your account and scheduling data.
- Resend — outbound email delivery. Resend is the SMTP provider that carries the emails CallSlot sends, so it processes the recipient address and the content of those emails.
- Stripe — payments, for paid plans. Card numbers are entered directly into Stripe and never reach CallSlot servers. We receive and store only a customer identifier, the subscription status, and card metadata such as the brand, the expiry month and year and the last four digits, so that we can show you which card is on file.
We may also disclose data where the law requires it, or to protect the rights, safety and property of CallSlot, our users or the public. If CallSlot is ever involved in a merger, acquisition or sale of assets, personal data may be transferred, and we will give notice before it becomes subject to a different privacy policy.
Analytics and tracking
We currently run no third-party analytics and no advertising trackers on CallSlot. In future we may use privacy-respecting product analytics to understand which features are used and where people get stuck. If we do, we will update this policy before turning it on, and we will not use it to build advertising profiles or to sell data.
International transfers
CallSlot is hosted in the United States. If you use the service from the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to and processed in the United States. Where required, these transfers rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism agreed with the relevant provider.
How long we keep data
We keep your account data and scheduling data for as long as your account is open. A booking page you delete is hidden immediately and then permanently removed from our database 7 days later.
When you delete your account, deletion is scheduled rather than instant: the account is disabled straight away and enters a 7-day grace period, during which you can cancel the deletion if you change your mind. After the grace period ends, your account, your booking pages and events, your guest records and your calendar tokens are permanently erased, and any active subscription is cancelled. Backups age out on their own cycle and are overwritten within 30 days. We may keep invoices and payment records for as long as tax and accounting law requires, and a minimal record of the deletion itself so that we can prove it happened.
Your rights
Depending on where you live, you may have the right to access a copy of your data, to correct it, to delete it, to restrict or object to processing, to portability, and to withdraw consent at any time. Most of this you can do yourself from your account settings — you can edit your profile, disconnect calendars, delete booking pages and events, and delete your account.
For anything else, email [email protected] and we will respond within 30 days. If you are in the EEA or the UK and you believe we have handled your data badly, you also have the right to complain to your local data protection authority.
Security
Traffic to CallSlot is encrypted with TLS, and data is encrypted at rest by our hosting and database providers. Access to production systems is limited to the people who operate the service. Calendar access and refresh tokens are encrypted before they are written to the database. No system is perfectly secure, so if a breach affects your personal data we will notify you and the relevant authority as the law requires.
Children
CallSlot is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as the service changes. When we do, we update the "last updated" date at the top. If a change materially affects how we handle your personal data, we will tell you by email or with a notice in the app before it takes effect.
Contact
Questions about this policy, or about your data, go to [email protected]. Our terms of service are available at /terms.