1. Information we handle

Applications built by our customers may collect additional information under their own privacy policies. Avoid placing unnecessary sensitive personal information in calendar content.

2. Why we use information

We use information to provide accounts and workspaces, authenticate users, deliver calendar and sync features, send requested service messages, answer support requests, prevent abuse, troubleshoot failures, and meet legal obligations. We do not sell personal information or use calendar content for targeted advertising.

Where the GDPR or UK GDPR applies, our legal bases include performing a contract, legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations. Google authorization permits access to your Google data; you can withdraw that access at any time.

3. Google Calendar data and Limited Use

Connecting Google Calendar is optional. After you authorize access, we access your calendar list, calendar names, identifiers, display colors, access roles, account email associated with the connection, and event data from calendars selected for synchronization. Supported event data can include titles, descriptions, locations, start and end times, time zones, recurrence, and provider identifiers. We store synchronized data and authorization tokens to keep your connected calendar features working.

The current integration requests Google's Calendar permission (https://www.googleapis.com/auth/calendar). This permission can allow viewing, editing, sharing, and deleting calendars you can access. Our integration uses it to list calendars and synchronize events, including creating, updating, or deleting events when requested through the connected application and permitted by your calendar access role.

We use Google data only to provide or improve the calendar features you use and for permitted security or legal purposes. We do not sell Google data, use it for advertising, transfer it to data brokers, use it for credit decisions, or use it to train general-purpose AI or machine learning models.

Schedule-X Cloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. These restrictions also apply to data derived from Google data.

Human access to Google data is restricted to situations allowed by that policy, such as your affirmative agreement to inspect specific data for support, necessary security investigations, legal obligations, or permitted aggregated internal operations. Service providers receive access only as needed for permitted purposes and subject to these restrictions.

You can disconnect through an application using our integration or ask your workspace administrator for help. You can also revoke authorization in your Google Account connections. Disconnecting stops future sync; it does not automatically delete calendar data already imported into Schedule-X Cloud or events already written to Google. To request deletion of stored connection data, tokens, or imported calendar data, contact us or the application or workspace that manages your account.

4. Sharing and service providers

Calendar and workspace data is available to the application and authorized workspace members according to configured access permissions. We use service providers to operate the service, including Hetzner for infrastructure and backups and Resend for transactional email. Email providers receive the recipient and message data needed to send account messages; we do not send calendar content to them for marketing.

We may disclose information where legally required or necessary to protect the service and users. For Google data, any transfer must also satisfy Google's Limited Use rules; transfers in a business transaction require prior user consent where those rules require it. We do not sell or share personal information for cross-context behavioral advertising.

5. Storage, retention, and security

Our production infrastructure is hosted with Hetzner in Finland. Other service providers may process information in other countries. Where required, international transfers must use an applicable legal mechanism, such as an adequacy decision or approved contractual safeguards.

We retain account and calendar data while needed to provide the service, and retain logs, security records, and backups for operational, legal, or security needs. Data awaiting deletion may remain in restricted backups until those backups expire. Contact us for information about retention or to request deletion; we may retain limited records when required by law or to establish or defend legal claims.

We use HTTPS, access controls, password hashing, and application-level encryption for Google authorization tokens. No service can guarantee absolute security. Keep credentials private and report suspected unauthorized access promptly.

6. Cookies and local storage

The console uses necessary session cookies for authentication. Applications using our SDK may use browser storage for session restoration or calendar preferences under their own policies. These public pages do not set advertising cookies or include advertising trackers.

7. Your privacy rights

Depending on your location and circumstances, you may have rights to access, correct, delete, or obtain a copy of your information, restrict processing, object to processing, or withdraw consent. EEA and UK residents may complain to their local data protection authority. Withdrawing consent does not affect the lawfulness of earlier processing.

Residents of California and other US states may have rights to know the categories and specific pieces of information collected, request access, correction, or deletion, and appeal a denied request where applicable. The categories described above include identifiers, internet or network activity, and information you provide in calendar content or communications. We do not sell personal information or share it for cross-context behavioral advertising, so there is no sale or advertising-sharing opt-out to exercise. We will not unlawfully discriminate against you for exercising your rights.

Send requests to tom@schedule-x.dev. We may need to verify your identity or an authorized agent's authority. Where we process calendar data on behalf of an application or workspace, we may direct your request to that customer and assist them in responding.

8. Our role and customer responsibilities

For console accounts, website operation, and our direct business communications, we determine how information is processed. For calendar data hosted on behalf of a customer's application or workspace, that customer generally determines the purposes of processing and we act on their instructions. Customers are responsible for their own notices, lawful instructions, permissions, and any required data processing agreement with us.

9. Children

Schedule-X Cloud is a developer service and is not directed to children under 16. If you believe a child has provided personal information without appropriate authorization, contact us.

10. Changes and contact

We will update this page when practices change and give additional notice where required. If we introduce a new use of Google data, we will update our disclosures and obtain renewed consent before that use where required. Questions and requests: tom@schedule-x.dev.