Legal
Privacy Policy
Last updated: March 2026
This policy explains what personal data ScheduleMeeting handles, why, and what you can ask us to do with it. It is written to be read rather than to be survived. ScheduleMeeting is the operator of this service and the data controller for account data; where we process booking data on behalf of a customer organisation, that organisation is the controller and we are its processor.
Contact for any privacy question or request: [email protected].
1. Who is covered by this policy
Two different groups of people appear in ScheduleMeeting, and they are treated differently:
- Customers. Companies that hold an account, and the individual team members within them who sign in and host meetings.
- Invitees. People who open a customer's public booking page and book a meeting. We process their data on behalf of the customer whose page they used.
2. What we collect
Account data (customers)
- Your name and email address.
- A hashed password. We never store your password in a readable form and cannot recover it.
- Your organisation's name and its members.
- Your timezone and working hours, which are needed to compute availability.
- Meeting types you create, including titles, descriptions, durations and locations.
Booking data (invitees)
- The name and email address entered on the booking form.
- The timezone used when booking, so times can be shown correctly.
- Any notes voluntarily written into the booking form.
- The meeting time, and if the meeting is cancelled, the reason if one is given.
We ask invitees for the minimum a meeting needs. We do not require a phone number, a company size, a job title or anything else that only serves marketing.
Calendar data
If a team member connects Google Calendar, we read the busy periods on that calendar so we can remove them from the times offered on their booking page, and we write confirmed bookings back to it. We use this data for scheduling only. We do not mine calendar contents, build profiles from it, or share it.
Payment data
Payments are processed by Stripe. Card numbers are entered on Stripe's own hosted checkout and never reach our servers. We store the subscription identifiers Stripe gives us so we know which plan an organisation is on.
Technical data
Our servers keep standard request logs (IP address, timestamp, requested URL, user agent) for security and diagnosis, including detecting abuse of the public booking endpoints. We use a session cookie to keep signed-in users signed in and a CSRF token cookie to protect form submissions. We do not run advertising trackers.
3. Why we process it, and on what legal basis
- To provide the service — performance of a contract. Creating accounts, computing availability, taking bookings, sending confirmations and reminders.
- To take payment — performance of a contract, and a legal obligation for the resulting financial records.
- To keep the service secure — our legitimate interest in preventing abuse, spam bookings and unauthorised access.
- To respond to your messages — our legitimate interest in supporting our customers.
We do not sell personal data. We do not share it with advertising networks. We do not use booking or calendar data to train models.
4. Who we share data with
We use a small set of sub-processors, each for one clear purpose:
- Our hosting and database provider — runs the application and stores its data.
- Stripe — payment processing and subscription billing.
- Google — only for accounts that connect Google Calendar, and only for that calendar's data.
- Our email delivery provider — sends verification codes, booking confirmations, reminders and cancellation notices.
We may also disclose data where the law requires it, or where it is necessary to establish or defend a legal claim. If our business is ever transferred, data may transfer with it and this policy would continue to apply to it.
5. International transfers
Our providers may process data outside your country, including in the United States. Where personal data of people in the European Economic Area or the United Kingdom is transferred, it is covered by the standard contractual clauses or another approved transfer mechanism in our agreements with those providers.
6. How long we keep data
- Account data — for as long as the account exists. Deleting your organisation deletes its account data.
- Booking data — kept as a record of meetings for the customer organisation. Cancelled bookings are retained so both sides have a history of what happened.
- Billing records — kept for the period required by tax and accounting law, typically several years, even after an account closes.
- Request logs — kept for a short period for security and diagnosis, then discarded.
Ending a subscription does not delete your data. It drops the organisation back to demo limits so nothing is lost if you return.
7. Your rights
Depending on where you live, you may have the right to:
- Ask what personal data we hold about you and get a copy of it.
- Have inaccurate data corrected.
- Have your data deleted, where we are not required to keep it.
- Object to or restrict processing based on our legitimate interests.
- Receive your data in a portable format.
- Complain to your data protection authority.
Write to [email protected] and we will respond within one month. If you are an invitee asking about a meeting you booked with one of our customers, that customer controls the record; tell us who they are and we will pass the request on and help them action it.
8. Security
Traffic is served over HTTPS. Passwords are stored hashed. Data is scoped so members of one organisation cannot read another organisation's bookings, meeting types or members. Booking management links use unguessable identifiers, which is what authorises an invitee to change their own meeting and nothing else. Public endpoints that write data are rate limited, and booking forms carry a hidden field that automated submissions fill in and humans do not.
No system is perfectly secure and we do not claim otherwise. We do not advertise a certification we have not been audited for. If you discover a vulnerability, please report it to [email protected] before disclosing it publicly.
9. Children
ScheduleMeeting is a business product sold to companies. It is not directed at children and we do not knowingly collect data from anyone under 16. If you believe we have, contact us and we will delete it.
10. Cookies
We use only the cookies the service needs to function: a session cookie that keeps you signed in, and a CSRF token cookie that protects form submissions against cross-site forgery. Public booking pages do not require you to be signed in and set no advertising or analytics cookies.
11. Changes to this policy
If we change this policy we will update the date at the top. Where a change materially affects how we handle personal data, we will notify account holders by email before it takes effect.
12. Contact
Questions, requests and complaints: [email protected]. ScheduleMeeting is the operator of this service and is responsible for it.