Privacy Policy

Last updated 26 July 2026

Who we are

BookToMeetis a scheduling service. Account holders (“hosts”) publish booking pages, and their invitees (“guests”) choose a time. This policy explains what we collect, why, and what we never do.

What we collect

From hosts, when they create an account:

  • Name, email address, password (stored only as a salted hash)
  • Profile details they choose to publish: username, bio, picture, timezone
  • Their availability, meeting types and booking settings
  • Billing details if they subscribe — card data is handled by our payment processor and never stored on our servers

From guests, when they book:

  • Name, email address and timezone
  • Answers to any questions the host added to that meeting type
  • The meeting time selected

We also record basic technical information needed to run the service securely, such as request logs and rate-limiting counters.

Google user data — access, use and sharing

Connecting Google Calendar is optional and always initiated by the host. If they connect it, they grant BookToMeetaccess to their Google account through Google’s own consent screen. We request only:

  • calendar.events — to create, update and delete the calendar event for a booking, and to generate its Google Meet link
  • calendar.readonly — to read busy times so a booked slot never conflicts with an existing commitment

BookToMeet’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, that means we:

  • use Google calendar data only to provide scheduling features the host asked for
  • never use it for advertising or ad targeting
  • never sell it, and never transfer it except as needed to provide the service, comply with law, or in a merger with equivalent protections
  • neverallow humans to read it, except with the host’s explicit permission for support, for security or abuse investigation, or where legally required
  • read only free/busy information for conflict checking — we do not mine the content of unrelated calendar events

A host can disconnect Google at any time from their BookToMeet settings, or revoke access directly at myaccount.google.com/permissions. On disconnection we delete the stored access and refresh tokens.

Zoom data

Connecting Zoom is likewise optional and host-initiated. With their permission we create scheduled meetings on their Zoom account so a booking has a join link, and we delete that meeting if the booking is cancelled. We store the resulting meeting id and join URL, plus the account email so the host can see which account is connected. We do not access recordings, chat, or other Zoom content. Access can be revoked in BookToMeetor in the host’s Zoom account settings.

How we use information

  • To show available times and create, reschedule and cancel bookings
  • To send transactional email: confirmations, calendar invites, reminders, and reschedule or cancellation notices
  • To operate, secure and support the service, including preventing abuse
  • To bill subscriptions

We do not sell personal information, and we do not use guest or calendar data for advertising.

Programmatic access

A host may issue API keys so their own systems — or an AI assistant they configure — can look up availability and book on their behalf. Those keys are scoped, revocable, and limited to that host’s account. They never grant access to the host’s Google or Zoom credentials: a request asks BookToMeet to schedule, and BookToMeetuses the host’s own connection internally.

Sharing and processors

We share data only with providers needed to deliver the service: hosting and database infrastructure, the email provider used to send booking mail, the payment processor for subscriptions, and — at the host’s direction — Google and Zoom. We disclose information if required by law.

Retention

Booking records are kept while the host’s account is active, since they are that host’s business records. OAuth tokens are deleted on disconnection. If a host deletes their account we remove their data, including bookings and connections, except where we must retain records for legal or accounting reasons.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal information, and to object to certain processing. Guests should contact the host they booked with, since that host controls the booking; we will assist them. For anything else, contact us at [email protected].

Security

Traffic is encrypted in transit. Passwords are stored as salted hashes, never in plain text. OAuth tokens and API keys are stored server-side; API keys are kept only as a hash and shown once at creation. Access to production systems is restricted.

Changes

If we make a material change we will update the date above and, where appropriate, notify account holders by email.

Contact

Questions about this policy or your data: [email protected].

Privacy Policy — BookToMeet | BookToMeet