Legal
Privacy Policy
Effective July 23, 2026 · Last updated July 23, 2026
1. Scope and who we are
This Privacy Policy explains how Calenyo collects, uses, discloses, and protects personal information when you visit our websites, create an account, publish a booking page, schedule or manage an appointment, connect an integration, contact us, or otherwise use our scheduling software, applications, APIs, emails, and related services (collectively, the “Service”).
Calenyo is operated by Calenyo, with a mailing address at --. “Calenyo,” “we,” “us,” and “our” refer to that entity. This Policy should be read with our Terms and Conditions.
This Policy does not govern third-party websites or services that have their own privacy practices. If an organizer uses Calenyo to offer services, the organizer may provide an additional privacy notice governing how that organizer uses invitee information.
2. Our privacy roles
For account, website, billing, security, support, product analytics, and direct relationship information, Calenyo generally determines why and how the information is processed and acts as a controller or “business” under applicable privacy law.
When an organizer configures booking questions and uses Calenyo to collect or manage invitee information, the organizer generally determines the purpose of that processing. In that context, the organizer may be the controller or business and Calenyo may act as its processor or service provider. We may still process limited information independently to secure, maintain, and comply with law for the Service.
3. Information we collect
Depending on how you use the Service, we may collect:
- Account and profile information: name, email address, password hash, Google sign-in identifier, profile image, phone number, username, time zone, date and time preferences, plan, and account settings.
- Scheduling and invitee information: event titles and descriptions, availability, duration, location, booking-page settings, form questions and responses, appointment times, invitee contact details, notes, reminders, cancellation or rescheduling information, and related communications.
- Contacts and content: contacts, notes, files, profile images, templates, prompts, feedback, and other information submitted to the Service.
- Payment information: plan, subscription, transaction status, billing identifiers, and limited payment metadata. Payment-card information is collected and processed by our payment provider; Calenyo does not receive full card numbers.
- Communications: support requests, contact messages, email delivery history, and records of communications with us.
- Device, usage, and diagnostic information: IP address, browser and device type, operating system, language, approximate location inferred from IP, pages and features used, referral and campaign information, timestamps, cookie or local-storage identifiers, logs, errors, performance data, and security events.
- Information from integrations: information returned by services that you deliberately connect, such as Google sign-in, Google Calendar, and payment services.
We collect information directly from users and invitees, automatically from devices and browsers, from organizers who invite or book someone, and from third parties that a user chooses to connect. Please do not submit highly sensitive information—such as passwords, payment-card numbers, government identifiers, detailed medical records, or information about children—unless Calenyo expressly supports and requests it.
4. Google account and Google Calendar data
Google sign-in provides identity information, such as a verified email address and basic profile details, so that you can create or access a Calenyo account. Connecting Google Calendar is a separate, optional authorization.
When you connect Google Calendar, Calenyo requests permission to read calendar availability and events needed to prevent scheduling conflicts and to create, update, or delete Calenyo booking events in a calendar you control. Calenyo may process event identifiers, titles, start and end times, all-day status, free/busy ranges, calendar identifiers, OAuth scopes, token expiry information, and connection status. Calendar data is retrieved as needed to provide the integration. We store encrypted OAuth access and refresh tokens and identifiers needed to keep Calenyo bookings synchronized.
Calenyo uses Google user data only to provide or improve the user-facing Google sign-in and Calendar integration, to maintain security, to provide user-authorized support, and to comply with law. We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or permit humans to read it except with the user’s affirmative permission for support, when necessary for security, when required by law, or when it has been aggregated so that it does not identify an individual.
Calenyo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect Google Calendar from the Calendar page. Disconnecting removes the stored Calendar connection from Calenyo and stops future API access through that connection. You can also revoke Calenyo directly from your Google Account permissions. Account deletion removes the stored Google OAuth credentials associated with the Calenyo account.
5. How we use information
We use personal information to:
- create, authenticate, administer, and secure accounts;
- publish booking pages, calculate availability, process appointments, maintain contacts, synchronize calendars, and send confirmations, reminders, and service messages;
- process subscriptions and provide billing and account support;
- provide optional AI-assisted event setup and suggestions when a user asks for those features; user-supplied prompts and relevant event details may be sent to our AI provider to generate the requested output;
- respond to requests, investigate problems, prevent fraud or abuse, enforce our Terms, and protect users and the Service;
- measure usage, diagnose errors, monitor performance, understand acquisition, and improve the Service;
- comply with legal obligations and establish, exercise, or defend legal claims; and
- send product or promotional communications where permitted, with an unsubscribe option when required.
Our websites and applications may use cookies, local storage, Google Tag Manager, internal analytics, error monitoring, and session-replay or diagnostic tools such as Sentry and OpenReplay when configured. These tools may collect page interactions, device and network information, errors, and diagnostic context. Session replay is used to diagnose failures and improve usability, not to serve targeted advertising. Browser settings may allow you to limit cookies or local storage, but essential authentication and security features may then stop working.
AI-assisted outputs may be inaccurate and are provided as suggestions. Calenyo does not use AI features to make decisions that produce legal or similarly significant effects about individuals.
6. Legal bases for processing
Where a law such as the GDPR or UK GDPR requires a legal basis, we rely on one or more of the following:
- Contract: processing necessary to provide the Service requested by an account holder or to take steps at their request.
- Legitimate interests: securing, supporting, measuring, and improving the Service; preventing abuse; communicating with users; and operating our business, balanced against the rights of affected individuals.
- Consent: where you choose an optional integration or feature, or where applicable law requires consent. You may withdraw consent without affecting earlier lawful processing.
- Legal obligation and claims: complying with law and protecting legal rights.
When Calenyo acts as a processor or service provider for an organizer, the organizer is responsible for identifying its legal basis and giving required notices to invitees.
7. How we disclose information
We disclose personal information only as reasonably necessary for the purposes described above:
- Organizers and invitees: appointment and contact details are shared with the people involved in scheduling and managing the appointment.
- Service providers: hosting and database providers, object storage, email delivery, Google services, Stripe, OpenAI, analytics, error monitoring, session replay, security, and customer-support vendors that process information for us under appropriate terms.
- Professional advisers and authorities: where reasonably necessary for legal, accounting, audit, security, or compliance purposes, or in response to valid legal process.
- Business transfers: in connection with a proposed or completed financing, merger, acquisition, reorganization, or sale of assets, subject to applicable law and the Google API Services User Data Policy where Google user data is involved.
- With direction or consent: when a user asks us to connect, export, publish, or otherwise share information.
Calenyo does not sell Google user data. Calenyo does not sell personal information or share it for cross-context behavioral advertising as those terms are defined by applicable US state privacy laws.
8. Retention and deletion
We retain information for the shortest period reasonably necessary to provide the Service, maintain security and continuity, resolve disputes, enforce agreements, and meet legal, tax, accounting, and compliance obligations. Retention depends on the type of information, the account’s status, user instructions, the sensitivity of the information, and applicable law.
- Account, event, appointment, contact, and related operational information is generally kept while the account is active and until deleted through available controls or account deletion.
- Google OAuth credentials are kept while the Calendar connection remains active and are removed from Calenyo when the integration is disconnected or the account is deleted.
- Security, diagnostic, email-delivery, and transaction records may be retained for a limited period after account deletion where needed for security, fraud prevention, legal compliance, or dispute resolution.
- Payment providers may retain transaction information under their own legal obligations. Residual copies may remain temporarily in protected backups until the applicable backup cycle completes.
Account holders can permanently delete their account and associated Calenyo-owned data from account settings. Invitees who want information deleted should contact the organizer first; they may also contact Calenyo if they need assistance identifying the relevant organizer or exercising a right that applies to Calenyo.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, authentication, transport security, encrypted storage of Google OAuth tokens, scoped authorization, logging, and procedures for responding to suspected incidents. Access by personnel and service providers is limited according to role and need.
No internet service is completely secure. You are responsible for protecting credentials, API keys, management links, and devices and for promptly notifying us through support if you suspect unauthorized access.
10. Your choices and privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to request access, confirmation, correction, deletion, restriction, objection, portability, or a copy of personal information; withdraw consent; opt out of certain communications; and appeal a denied privacy request. You may also have the right to complain to a local data-protection authority. We do not discriminate against people for exercising applicable privacy rights.
You can update profile information, disconnect Google Calendar, revoke Google access, unsubscribe from eligible emails, and delete your Calenyo account through available product controls. You may also submit a request through our contact page. We may need to verify identity and authority before completing a request. Authorized agents may submit requests where permitted by law, subject to verification.
If an organizer controls invitee information, we may direct the request to that organizer or assist it in responding. We may deny or limit requests where permitted by law, including when necessary to protect another person, preserve security, or comply with a legal obligation.
11. International data transfers
Calenyo and its service providers may process information in Türkiye, the United States, and other countries where we or they operate. Those countries may have different data-protection rules. Where required, we use recognized transfer mechanisms and supplementary safeguards designed to provide appropriate protection.
12. Children
The Service is not directed to children under 18 or the age of legal majority where they live. We do not knowingly collect personal information directly from children for their own Calenyo accounts. If you believe a child has provided information contrary to this Policy, contact us so we can investigate and take appropriate action.
13. Changes and contact
We may update this Policy to reflect changes to the Service, law, or our practices. We will post the updated version and change the “Last updated” date. If a change materially affects privacy rights, we will provide additional notice where reasonably practicable or required by law.
Questions, privacy requests, and complaints can be sent through Calenyo support. Please include enough information for us to understand and verify the request. You may also write to Calenyo, --.