Privacy
Privacy Policy
This policy explains how Slotkit processes data when you use its scheduling service, including when a Host chooses to connect Google Calendar. Last updated August 22, 2026.
What Slotkit processes
Slotkit processes account identity and contact information, workspace configuration, Host availability, and Booking information such as a Guest’s name, email address, selected time, and Booking status. It also processes technical and security information needed to operate the service, such as session, request, and audit records.
Google Calendar data
Google Calendar access is optional and is connected by a Host or an authorized workspace administrator. When connected, Slotkit processes the Google account identifier and email, the list of calendars available to that account, selected Calendar identifiers, names, and access roles, and encrypted OAuth credentials.
Slotkit uses this data only to provide the Calendar features the Host has configured:
- show calendars that can be selected for conflict checks or as a destination Calendar;
- query free/busy time for the Calendars selected for conflict checks, so unavailable time is not offered as a Slot;
- create, read when needed for recovery, update, and delete Slotkit-managed Booking events in the selected destination Calendar; and
- request a Google Meet conference only when the selected Event Type requires one.
Slotkit does not copy external Calendar events into its own Booking records, synchronize external Calendar edits back into Slotkit, use Google Calendar data for advertising, or sell Google user data.
How we use and share data
We use data to authenticate Users, operate workspaces and Booking pages, prevent double-booking, deliver Calendar events and transactional messages, secure the service, investigate reliability or security issues, and comply with applicable legal obligations. We share data only with service providers required to operate the service, such as Google when you use its Calendar integration, and only for the purpose of providing the selected service. We do not sell personal data.
Slotkit’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Storage, security, and retention
Google OAuth credentials are encrypted at rest and are never returned in ordinary API responses. Logs and error payloads are designed to exclude credentials and one-time security values. Booking Guest personal data and Booking Metadata are retained for 24 months after a Booking ends or is cancelled, then anonymized while preserving non-identifying scheduling history. Data required to finish unresolved Calendar cleanup may be retained until that work is terminal.
Short-lived login, verification, reset, and Hosted Session credentials are removed within 24 hours after expiry or consumption. Calendar reconciliation records and Webhook delivery records are retained for 30 days. Security audit records are retained for 12 months. Protected backups may retain data for up to 35 days before expiry.
Your choices
An authorized User can disconnect a Host’s Google Calendar connection in Slotkit. Disconnecting removes the locally stored access and refresh credentials and asks Google to revoke the credential where possible. Workspace Owners can request Tenant deletion; User account closure invalidates credentials and Sessions and anonymizes User identity information within 30 days, subject to the retention rules above.
Contact
For privacy questions or requests, contact [email protected]. Do not send passwords, OTPs, API Keys, Webhook secrets, or provider tokens by email.