Calendary Privacy Policy
Effective date: July 12, 2026
This Privacy Policy explains how Calendary, operated by Grimado Global Group LLC(“Calendary,” “we,” “us,” or “our”), collects, uses, and shares information when you use our scheduling and booking service, including the web app at thecalendary.com and, once released, the Calendary mobile apps (together, the “Service”).
1. Who this applies to
- Hosts: people who create a Calendary account to set their availability, create event types, and share a booking link.
- Invitees: people who book a meeting through a host’s public booking page. Invitees do not need an account.
2. Information we collect
2.1 Account information (hosts)
- Email address and password (if you sign up with email/password), or name and email address provided by Google, Microsoft, or Apple if you use “Continue with Google,” “Sign in with Microsoft,” or “Sign in with Apple.”
- Username you claim (forms your public booking link, e.g. thecalendary.com/yourname).
- Timezone, detected automatically from your device.
- Subscription/plan status (Free or Pro).
2.2 Scheduling data
- Event types you create (title, description, duration, location type, price if applicable, color, active/inactive status).
- Availability schedules (days and time ranges you’re bookable).
- Bookings made through your link: the invitee’s name and email, meeting time, and any notes provided at booking.
2.3 Invitee information
When someone books a meeting with a host, we collect the name, email address, and any information they enter on the booking form, in order to create and confirm the booking.
2.4 Payment information (Pro subscriptions and paid bookings)
- Subscription billing is handled by Stripe on the web; purchases made in the mobile apps, once released, will be handled by RevenueCat and the app stores (Apple App Store / Google Play). We do not receive or store your full payment card details. These processors pass us only subscription status (active/inactive, plan).
- Paid bookings (when a host charges for a meeting) are processed by Stripe Checkout. We do not store invitee card numbers; Stripe handles the transaction and confirms payment status to us via webhook.
2.5 Third-party calendar and communication data
If you connect these services, we access only what’s needed to provide the feature, and only for your account:
- Google Calendar (OAuth): to create, update, and delete calendar events and Google Meet links tied to your bookings.
- Microsoft Outlook Calendar (OAuth): to check your busy times and to create, update, and delete calendar events tied to your bookings.
- Apple Calendar (CalDAV): same purpose as Google Calendar, via your CalDAV credentials, if you choose to connect it.
- Zoom (OAuth): to create a meeting link for a booking that uses Zoom as its location. If you connect your own Zoom account, the meeting is created on your account and we store only the OAuth tokens needed to do that; you can disconnect at any time from Settings.
- Slack: if you set up a webhook, booking created/cancelled/rescheduled notifications are posted to a Slack channel you choose.
2.6 Automatically collected / analytics data
We use Firebase Analytics to understand product usage, for example, onboarding step completion, paywall views, and booking-page views. These events are tied to your app usage, not sold to third parties. Firebase Analytics may also collect device information (such as device model, operating system version, and app-instance identifiers) as part of producing these usage statistics.
Hosts on our Insights plan additionally see the approximate time and location (city, region, and country) of visits to their own booking pages, so they can understand where interest in their link is coming from. We derive this location from network-level geolocation provided by our hosting infrastructure at the moment of the request; we do not collect, process, or store IP addresses, precise (GPS) location, or device identifiers, and this record is only ever created for a visit where the visitor accepted analytics cookies (see Section 3). These records are kept for 90 days, are visible only to the host whose link was visited, and are never shared with anyone else.
2.7 Emails
Booking confirmations, cancellations, and reschedule notices are sent via email (including a calendar .ics attachment) to hosts and invitees.
3. Cookies and similar technologies
We keep this simple: no third-party cookies, no advertising cookies, no cross-site tracking. Two categories only:
- Strictly necessary (always on): sign-in and session storage used by Firebase Authentication, security protections, your saved cookie choice, and short-lived per-tab storage that stops a page refresh from being counted as a second visit. The Service cannot function without these.
- Analytics (only with your consent): a single first-party cookie named cal_vid containing a random identifier (no name, no email, no cross-site tracking). It lets the host whose booking page you visited see accurate visit counts and whether visits led to a booking. It expires after 12 months. If you decline, pages you visit are still counted anonymously in aggregate, with no cookie set and no identifier stored.
When you first visit, a banner asks for your choice; you can pick “Necessary only” to decline everything optional. You can change your mind at any time via the “Cookie preferences” link in the site footer, or right here: .
4. How we use information
We use the information above to:
- Operate the Service: create your account, publish your booking page, process bookings, and sync your calendar.
- Send transactional emails (confirmations, cancellations, reschedules).
- Process subscription payments and paid bookings.
- Maintain security (e.g., Firestore access rules that restrict data to its owner).
- Understand and improve the product (aggregated analytics).
- Communicate with you about your account or the Service.
We do not sell your personal information.
5. How information is stored and shared
- Data is stored in Google Firebase(Firestore database and Authentication). Firestore security rules restrict scheduling data (event types, schedules, bookings) so only the owning host’s account can read/write it, aside from what’s necessarily public (a host’s public booking page).
- We share data with the third-party service providers listed in Section 2 (Google, Microsoft, Apple/CalDAV server if connected, Zoom, Slack, Stripe, RevenueCat) only to the extent needed to provide the feature you’ve enabled.
- We may disclose information if required by law, or to protect the rights, property, or safety of Calendary, our users, or others.
- We do not share your information with advertisers or data brokers.
6. Data retention
We retain account and scheduling data for as long as your account is active. If you delete your account (or ask us to), we delete your profile, event types, schedules, and future bookings within a reasonable time, except where we’re required to retain records (e.g., payment records) for legal or accounting purposes.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at cx@thecalendary.com. You can also:
- Disconnect Google Calendar, Microsoft Outlook Calendar, Apple Calendar, Zoom, or Slack at any time from Settings.
- Delete your account and associated data at any time from Settings → Danger zone in the app, or by emailing cx@thecalendary.com from your account email; we complete deletion requests within 30 days.
- Cancel your subscription at any time through your account settings (or, for future in-app purchases, the App Store or Google Play). This stops future billing but doesn’t automatically delete your data (see above for deletion).
8. Children’s privacy
Calendary is not directed to children under 13 (or the minimum age required by your local law), and we do not knowingly collect personal information from children.
9. International data
Our infrastructure (Firebase/Google Cloud, Stripe, RevenueCat) may process and store data in countries other than where you live.
10. Changes to this policy
We may update this Privacy Policy from time to time. We’ll update the effective date above when we do, and, for material changes, provide additional notice (e.g., email or in-app notice).
11. Contact us
Questions about this Privacy Policy or your data: cx@thecalendary.com.