1. Introduction
CalStack ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, and protect your information when you use our website and services located at calstack.io (the "Service").
CalStack is a SaaS platform that helps businesses connect their calendars with their websites to enable seamless booking and scheduling functionality. This policy complies with the General Data Protection Regulation (GDPR), Google API Services User Data Policy, and other applicable data protection laws.
2. Data Controller
Contact Email: mail@calstack.io
3. Information We Collect
3.1 Personal Information
When you use our Service, we may collect the following personal information:
- Contact Information: Name, email address, phone number
- Company Information: Company name, business details
- Quote Requests: Information you provide when requesting quotes through our funnels
- Account Information: Registration details, login credentials
3.2 Google Calendar Data
When you connect your Google Calendar to CalStack, we request the calendar.calendarlist.readonly, calendar.freebusy, and calendar.events.owned scopes. With them we access the following data:
- Calendar Availability: Free/busy information (via
calendar.freebusy) to display available time slots and prevent double-booking. We read it from Google each time someone opens your booking funnel or books a call, and we do not store it - Your Calendar List: The names and timezones of your calendars (via
calendar.calendarlist.readonly), so you can pick which calendar CalStack uses - Booking Events: We create, update, and cancel calendar events on calendars you own (via
calendar.events.owned) when calls are booked, rescheduled, or cancelled through your funnel, and save each event's ID, Google Meet link, and Google Calendar link with the booking - Changes to Booking Events: For the events CalStack created, we read their time, status, and guest responses, so your bookings stay in sync when you change them in Google Calendar
We only access the minimum data necessary to provide the calendar integration functionality. We do not read or store the titles, descriptions, or guests of any calendar event that CalStack did not create.
3.3 Google Meet Add-on Sign-In Data
CalStack offers an add-on for Google Meet that shows meeting hosts prep notes and context for the call in a side panel. When you sign in to the add-on with your Google account, we access:
- Basic Profile Information: Your name, email address, and email verification status, via the
openid, email, and profile scopes
We use this information solely to sign you in and match you against a CalStack organization and the booking associated with the active Google Meet call, so we can show that booking's talking points and context to signed-in hosts and teammates. To keep you signed in, we store your email address and a Google refresh token. If you generate talking points for a call that has no CalStack booking, we save your name and email address with them. We do not access your Google Calendar, Gmail, Drive, or any other Google data through the Meet add-on. See Section 4.7 for how this data is stored, retained, and deleted.
3.4 Gmail Data
When the owner of an organization connects a Gmail account so a booking funnel can send emails, we request the gmail.send scope, plus openid and email to show which account is connected. With it we:
- Send emails: the emails you set up in the booking funnel builder, from your address, to the recipients you choose, when a call is booked, rescheduled, or cancelled
- Read your email address: to show which account is connected
We cannot read, change, or delete any email in your mailbox, and we do not access your contacts.
3.5 Google Chat Data
When the owner of an organization connects a Google Workspace account for Google Chat, we request the chat.spaces.readonly and chat.messages.create scopes, plus openid and email. With them we:
- List your spaces: the names of the Chat spaces you are a member of, so you can pick where messages go
- Post messages: the messages you set up in the booking funnel builder, as you, in the spaces you picked, when a call is booked, rescheduled, or cancelled
We cannot read the messages in your spaces or direct messages. We store only the names of the spaces you picked.
3.6 Google Sheets and Google Drive Data
When the owner of an organization connects a Google account for Google Sheets, we request the drive.file scope, plus openid and email. With it we:
- Create spreadsheets: a new spreadsheet in your Google Drive when you ask for one in the booking funnel builder
- Add rows: one row with the booking details you chose, when a call is booked, rescheduled, or cancelled, and the column names in the first row when you ask for it
- List and open those spreadsheets: their names and tabs, so you can pick where rows go
The drive.file scope only reaches files CalStack created. We cannot see, open, or change any other file in your Google Drive, and we do not read the rows already in a spreadsheet.
3.7 Slack Data
When the owner of an organization connects a Slack workspace, CalStack is added to that workspace as an app. We request the chat:write, chat:write.public, channels:read, and groups:read scopes. With them we:
- List your channels: the names of the workspace's public channels, and of the private channels CalStack has been invited to, so you can pick where messages go
- Post messages: the messages you set up in the booking funnel builder, as the CalStack app, in the channels you picked, when a call is booked, rescheduled, or cancelled
We cannot read the messages in your channels or direct messages. We store the workspace's name and ID, the access token Slack gives the app, and the names of the channels you picked. When the owner disconnects Slack, we delete the token and remove the app from the workspace, unless another CalStack organization still uses it there.
3.8 Technical Information
- Device Information: Device type, operating system, browser type
- IP Address: Your internet protocol address
- Usage Data: How you interact with our Service
3.9 Cookies and Tracking Technologies
We and our third-party service providers use cookies and similar tracking technologies to:
- Maintain user sessions and authentication
- Remember your preferences and settings
- Analyze website usage and performance
- Enable integrations with third-party services
- Improve our Service functionality
Types of cookies we use:
- Essential Cookies: Required for basic website functionality and security
- Functional Cookies: Remember your preferences and enable features
- Analytics Cookies: Help us understand how you use our Service (Contentsquare, which includes Hotjar)
- Advertising Cookies: A Google Ads tag on our website measures the results of our own ad campaigns. It never receives Google user data from your connected Google accounts
- Third-Party Cookies: Set by our integrated services (HubSpot, Google, Clerk, Zapier) and by Crisp, the support chat in your dashboard
When you first visit our website, a first-party cookie records the page you landed on, the website or link that sent you, and any campaign parameters in that link. If you create an account, we save this with your account, along with your approximate location (country, region and city, derived from your IP address by our hosting provider). We do not store your IP address for this.
You can control cookies through your browser settings. However, disabling certain cookies may affect the functionality of our Service. Essential cookies cannot be disabled as they are necessary for the Service to function properly.
4. Google API Services User Data Policy
CalStack's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.1 What Google User Data We Access
Depending on which Google integrations you connect, we access:
- Google Calendar: calendar availability (free/busy status), your list of calendars with their timezones, and permission to create, read, update, and delete the calendar events CalStack makes for bookings
- Gmail: permission to send email from your address (no access to your mailbox)
- Google Chat: the names of the spaces you are in, and permission to post messages in them
- Google Sheets and Drive: permission to create spreadsheets and add rows to the spreadsheets CalStack created (no access to your other files)
- Gmail, Google Chat, and Google Sheets: the email address of the connected account
- Google Meet add-on: your name, email address, and email verification status from your Google profile
4.2 How We Use Google User Data
We use Google user data exclusively to:
- Display your available time slots on your booking funnel
- Create calendar events when clients book appointments through your funnel
- Prevent double-booking by checking availability
- Keep your bookings in sync when you move or cancel a booking event, or its guests respond, in Google Calendar
- Send the emails, post the Chat messages, and add the spreadsheet rows you set up, when a call is booked, rescheduled, or cancelled
- Show which Google account each integration uses
- Sign you in to the Google Meet add-on and show you the prep notes of the booking tied to your call
Each of these happens only because you set it up, and only with the account you connected for it. We do not use Google user data for any other purpose.
4.3 Limited Use Disclosure
CalStack's use of Google user data is limited to providing and improving the Google integration features of our Service described in this policy. We strictly adhere to the following:
- No Sale of Data: We do not sell Google user data to third parties.
- No Advertising: We do not use Google user data for advertising purposes, including retargeting, personalized advertising, or interest-based advertising.
- No Data Brokers: We do not provide Google user data to data brokers or information resellers.
- No Credit Assessment: We do not use Google user data for determining creditworthiness or lending purposes.
- No AI/ML Training: We do not use Google user data, including data from Google Workspace APIs, to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
- No AI Providers: Our AI features (talking points and call summaries) use OpenAI, and work only from booking details collected by your funnel and the notes or prompts you write. We do not send Google user data to OpenAI or to any other AI provider.
- No Databases or Profiles: We do not compile Google user data into databases or profiles for any purpose other than providing the features described in this policy.
- User-Facing Features Only: We use Google user data only to provide or improve the user-facing features described in this policy, which are visible in the CalStack interface.
- Limited Transfers: We transfer Google user data to others only as needed to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after notice to you.
- No Human Access: No person at CalStack reads your Google user data unless you give us affirmative agreement to view specific data (for example, in a support request), it is necessary for security purposes such as investigating abuse, it is required by law, or the data is aggregated and anonymized for internal operations.
4.4 Google Data Sharing
We do not sell Google user data, and we share, transfer, or disclose it only in these cases:
- Google: we send data back to Google to carry out what you set up, such as creating a calendar event, sending an email, posting a Chat message, or adding a spreadsheet row.
- The people and services you choose: the guests of your booking events, the recipients of the emails you set up, and the members of the Chat spaces you pick receive what you told CalStack to send them. If you set up an automation to Zapier, n8n, or your own webhook, the booking details it sends include the Google Meet link and Google Calendar link of the booking event.
- Your team and your call: members of your CalStack organization can see the bookings it owns. Talking points generated in the Meet add-on for a call with no CalStack booking can be seen by other people in that call who sign in to the add-on; your name and email address are not shown to them.
- Our hosting providers: the companies that host our servers and database store and process data on our behalf, only to run the Service.
- Legal reasons: when required by law, or to protect the safety and security of our users and the Service.
- Business transfers: as part of a merger, acquisition, or sale of assets, after notice to you.
We do not transfer or disclose Google user data for any other purpose. We never share it with advertisers, data brokers, information resellers, or AI providers.
4.5 Google Data Security
We protect Google user data using:
- Encryption in Transit: All data transmitted between CalStack and Google services uses HTTPS/TLS encryption
- OAuth 2.0 Authentication: Secure token-based authentication without storing your Google password
- Minimal Data Access: We only request access to the minimum scopes each feature needs, and only when you connect that feature
- Server-Side Token Storage: OAuth tokens are stored only in our server-side database, with access limited to the parts of our Service that need them, and are never sent to your browser
- Account Isolation: Google data connected to an organization is only available to that organization, and only its owner can connect or disconnect Gmail, Google Chat, and Google Sheets
- Restricted Staff Access: No one at CalStack reads Google user data except in the cases listed in Section 4.3
4.6 Google Data Retention and Deletion
Retention: We keep Google user data only as long as the feature you set up needs it:
- OAuth tokens and connected email addresses: kept while the integration is connected, and deleted when you disconnect it.
- Calendar availability: read from Google when it is needed and never stored.
- Booking event details: the ID, Google Meet link, Google Calendar link, time, status, and guest responses of the events CalStack created are kept with the booking for as long as your account is active, and deleted when you ask us to delete them or close your account.
- Chat spaces and spreadsheets you picked: their names and IDs are kept in your automation settings until you change or delete the automation.
- Delivery logs: for each email sent, Chat message posted, or spreadsheet row added, we keep a log (the recipients, spaces, or spreadsheet, and what was sent) for 30 days so you can see what happened, then delete it.
- Google Meet add-on: see Section 4.7.
Deletion: You can revoke CalStack's access to any of your Google integrations at any time by:
- Disconnecting the integration from your CalStack dashboard
- Removing access from your Google Account permissions
- Contacting us at mail@calstack.io to delete any Google user data we hold about you, which we do within 30 days
When you disconnect an integration in CalStack, we delete its stored Google OAuth tokens and stop accessing your Google data through it. Removing CalStack from your Google Account permissions ends access for every integration at once.
4.7 Google Meet Add-on
The CalStack add-on for Google Meet (see Section 3.3) requests the openid, email, and profile scopes to identify the signed-in host so we can show them the right booking's prep notes. How we handle this data:
- Verified server-side: your Google sign-in is verified on our servers on every request and never trusted from the browser alone.
- Sign-in session: so you do not have to sign in again, we store your email address and a Google refresh token on our servers, and a session ID and your Google sign-in credential in your browser's local storage. When you sign out, we revoke the refresh token with Google and delete the session. If you remove CalStack from your Google Account instead, we delete the session the next time the add-on tries to use it.
- Talking points without a booking: if you generate talking points for a call that has no CalStack booking, we save your name and email address with them, along with your browser type and country, to record who created them. We keep them until you ask us to delete them at mail@calstack.io.
- Never sold, shared with advertisers, sent to AI providers, or used to train AI/ML models, consistent with Section 4.3.
- Used only to sign you in, look up the booking tied to the active Google Meet call, confirm you belong to the organization that owns it, and record who created talking points — not for any other purpose.
You can end this access at any time by using "Sign out" inside the add-on (which revokes the Google session and clears the cached credential from your browser) or by removing CalStack from your Google Account permissions.
5. How We Use Your Information
We process your personal data for the following purposes:
- To provide and maintain our Service
- To process and respond to quote requests
- To create and manage user accounts
- To facilitate integrations with third-party services (HubSpot, Google Calendar, Gmail, Google Chat, Google Sheets, Slack, Zapier)
- To generate talking points and call summaries with OpenAI from booking details and your notes (never from Google user data)
- To provide customer support
- To improve our Service and user experience
- To comply with legal obligations
6. Marketing Communications
Important Clarification:
- We only send marketing communications to users who have signed up for a CalStack account and have opted in to receive such communications.
- We do not use data collected through our users' funnels (end-user data) for our own marketing purposes.
- We do not send marketing materials to contacts collected through our customers' booking funnels.
- Google user data is never used for marketing or advertising purposes.
7. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: To provide our Service and fulfill our obligations
- Legitimate Interest: To improve our Service and provide customer support
- Consent: Where you have given explicit consent for specific processing
- Legal Obligation: To comply with applicable laws and regulations
8. Data Sharing and Third Parties
We may share your information with the following third parties:
8.1 Service Integrations
We share data with the following third-party services, which may also use their own cookies and tracking technologies:
- HubSpot: For CRM and contact management (when you enable this integration). HubSpot uses cookies for analytics and marketing purposes.
- Google Calendar: For scheduling and calendar integration (when you enable this integration). See Section 4 for detailed information on Google data handling.
- Gmail, Google Chat, and Google Sheets: To send the emails, post the messages, and add the spreadsheet rows you set up (when you enable these integrations). See Section 4 for detailed information on Google data handling.
- Slack: To post the messages you set up in the channels you pick (when you enable this integration). See Section 3.7.
- Zapier: For workflow automation (when you enable this integration). Zapier uses cookies for authentication and service delivery.
- Clerk: For authentication and user management. Clerk uses cookies for session management and security.
- OpenAI: To generate talking points and call summaries from booking details and your notes. We do not send Google user data to OpenAI.
- Contentsquare (Hotjar): For website and product analytics.
- Crisp: For the support chat in your dashboard.
These third parties have their own privacy policies and cookie policies. We recommend reviewing their policies to understand how they handle your data:
8.2 Other Disclosures
We do not sell, trade, or rent your personal information to third parties. We may disclose your information only when required by law or to protect our rights and safety.
9. User Responsibility for Collected Data
CalStack provides tools for our users (business owners) to collect booking information through funnels embedded on their websites.
Important:
- Data Controller: Our users (business owners) are the data controllers for any personal data they collect through their CalStack funnels.
- User Responsibility: Each user is responsible for how they use, store, and manage the data collected through their funnels, including compliance with applicable data protection laws.
- No Control: CalStack does not control how our users choose to use the data collected through their funnels.
- Data Processor: CalStack acts as a data processor on behalf of our users, processing data only as necessary to provide our Service.
10. Data Storage and International Transfers
Your personal data is stored and processed in the United States. We ensure appropriate safeguards are in place for international data transfers in compliance with GDPR requirements.
We work with service providers that have implemented adequate safeguards, including Standard Contractual Clauses (SCCs) where applicable.
11. Data Retention and Deletion
We retain your personal data for as long as necessary to provide our Service and fulfill the purposes outlined in this Privacy Policy.
- Account Data: Retained for the duration of your account and deleted upon account termination (subject to legal retention requirements).
- Funnel Data: The admin user is responsible for managing data retention within their account. Data can be deleted through the dashboard or upon request.
- Google Data: Access tokens for each Google integration are deleted when you disconnect it. Calendar availability is never stored. Delivery logs for emails, Chat messages, and spreadsheet rows are deleted after 30 days. See Sections 4.6 and 4.7.
Requesting Deletion: You may request deletion of your data at any time by contacting us at mail@calstack.io. We will process your request within 30 days.
When the data retention period expires or upon your request, we will securely delete or anonymize your personal data.
12. Cookie Consent and Management
By continuing to use our Service, you consent to our use of cookies as described in this policy. You have the following options to manage cookies:
- Browser Settings: Most browsers allow you to control cookies through their settings preferences
- Opt-out Tools: Some third parties provide opt-out mechanisms for their tracking technologies
- Do Not Track: We honor browser "Do Not Track" signals where technically feasible
Please note that disabling cookies may limit your ability to use certain features of our Service.
13. Your Rights Under GDPR
If you are located in the European Union, you have the following rights:
- Right of Access: Request access to your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Request transfer of your data
- Right to Object: Object to processing of your data
- Right to Withdraw Consent: Withdraw consent where applicable
To exercise any of these rights, please contact us at mail@calstack.io. We will respond to your request within 30 days.
14. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security measures include:
- Encryption: All data transmitted to and from our Service is encrypted using TLS/SSL protocols
- Secure Authentication: We use OAuth 2.0 for third-party integrations and secure session management
- Access Controls: Strict access controls ensure only authorized personnel can access sensitive data
- Regular Security Reviews: We regularly review and update our security practices
- Secure Infrastructure: Our Service is hosted on secure, industry-standard infrastructure
However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
15. Children's Privacy
Our Service is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us immediately.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top of this policy. For significant changes, we will notify registered users via email. Before we use Google user data in a new way, or for a purpose not described in this policy, we will update this policy, notify you, and ask for your consent. We encourage you to review this Privacy Policy periodically.
17. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
Contact Email: mail@calstack.io
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.