Privacy Policy
Last updated April 28, 2026
This Privacy Notice for BTWN Calendars (“we,” “us,” or “our”) describes how and why we access, collect, store, use, and share (“process”) your personal information when you use our services (“Services”), including when you:
- Visit our website at https://btwncalendars.com, or any website of ours that links to this Privacy Notice.
- Use BTWN Calendars to help groups automatically find common meeting times by integrating with online calendars.
- Engage with us in other related ways, including support inquiries.
Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. Questions or concerns? Email support@btwncalendars.com.
Summary of Key Points
- What personal information do we process? Name, email address, profile identifier, profile photo URL, and OAuth authentication tokens. If you sign up with email + password, the password is stored only by Firebase Authentication in hashed form and is never accessible to us.
- Do we process sensitive personal information? No.
- Do we collect information from third parties? When you sign in or connect a calendar through Google or Microsoft, we receive your name, email, profile identifier, and calendar busy/free or event metadata within the scopes you authorize.
- How do we process your information? To authenticate you, compute team availability, communicate with you, and maintain security. We do not sell or share your data for advertising.
- How do we keep your information safe? We use organizational and technical measures, but no system is 100% secure.
- What are your rights? Depending on your location, you may have rights to access, correct, delete, or export your data, and to revoke OAuth permissions at any time.
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide when you register on the Services, sign in with a third-party provider, or contact us. The personal information we collect includes:
- Name
- Email address
- Profile identifier from Google or Microsoft (when used to sign in)
- Profile photo URL (when provided by your sign-in provider)
- OAuth access and refresh tokens for calendar integrations
- Calendar busy/free times and event metadata within the scopes you authorize
If you create an account with email and password, the password is handled exclusively by Firebase Authentication and stored in hashed form. We never see, log, or store your raw password.
Sensitive Information
We do not process sensitive personal information.
Google API Services
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide and administer the Services, authenticate you, compute team availability, communicate with you, and maintain security.
- To create and authenticate your account.
- To compute and display shared availability for the teams you participate in.
- To create calendar events on your behalf when you authorize event creation.
- To respond to inquiries and provide support.
- To prevent fraud, abuse, and security incidents.
- To comply with applicable law.
We do not use your information for advertising and do not use it to train AI/ML models.
3. WHAT LEGAL BASES DO WE RELY ON?
In Short: We only process your personal information when we have a valid legal reason to do so under applicable law.
If you are located in the EU or UK, we may rely on the following legal bases under GDPR and UK GDPR:
- Consent— you have given us permission to process your information for a specific purpose, which you can withdraw at any time.
- Performance of a Contract— processing is necessary to deliver the Services to you.
- Legal Obligations— processing is required to comply with law, regulation, or legal process.
- Vital Interests— processing is necessary to protect the vital interests of you or another person.
If you are located in Canada, we rely on your express or implied consent, which you may withdraw at any time, except in the limited cases where applicable law permits processing without consent.
7. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as your account is active, or as required by law.
- Account data and team membership— retained while your account is active.
- OAuth tokens— deleted when you disconnect the integration or delete your account.
- Calendar busy/free data— processed in memory to compute availability and not retained beyond what is needed to display the resulting busy blocks.
- Account deletion— associated personal data is removed immediately, except where retention is required by law.
8. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through organizational and technical security measures.
We rely on Firebase Authentication for password handling, store data in Cloud Firestore with access rules, transmit data over TLS, and restrict administrative access to authorized personnel. However, no electronic transmission or storage technology can be guaranteed to be 100% secure, so we cannot promise that unauthorized third parties will not be able to defeat our security measures. You should access the Services only within a secure environment.
9. DATA BREACH NOTIFICATION
In Short: If we discover a personal data breach affecting you, we will notify you without undue delay.
In the event of a confirmed personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users by email at the address associated with their account and, where required by applicable law (including GDPR Article 33 and relevant US state laws), notify the appropriate supervisory authority. Notifications will describe, to the extent known, the nature of the breach, the categories of data involved, the likely consequences, and the measures we have taken or propose to take in response.
10. DO WE COLLECT INFORMATION FROM MINORS?
In Short: The Services are not directed to children under 13.
The Services are not directed to children under 13 years of age, and we do not knowingly solicit data from or market to children under 13. We do not actively verify the age of users. If you are a parent or guardian and believe your child has provided personal information to us, please contact support@btwncalendars.com and we will take reasonable steps to delete such information.
11. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal information.
In some regions (such as the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws, including:
- The right to request access to and obtain a copy of your personal information.
- The right to request correction or erasure.
- The right to restrict the processing of your personal information.
- Where applicable, the right to data portability.
- The right not to be subject to solely automated decision-making.
To exercise these rights, email support@btwncalendars.com. You may also revoke OAuth access to your Google or Microsoft account at any time using the links in Section 6, and you can review, update, or delete most of your account data directly from your account settings.
If you are located in the EEA or UK and believe we are unlawfully processing your personal information, you also have the right to lodge a complaint with your local data protection authority. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
12. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers include a Do-Not-Track (“DNT”) feature. Because no uniform standard for recognizing and implementing DNT signals has been finalized, we do not currently respond to DNT browser signals. If a standard is adopted that we are required to follow, we will update this notice accordingly.
13. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: Residents of certain US states have additional rights regarding their personal information.
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to, correct, delete, or obtain a copy of the personal information we maintain about you, and to withdraw consent to processing.
Categories of Personal Information We Collect
- Identifiers— name, email address, profile identifier from sign-in provider. YES
- California Customer Records (name only) — YES
- Internet activity— limited diagnostic data collected by Firebase Performance Monitoring for reliability purposes only. YES
- Protected classification characteristics, commercial information, biometric information, geolocation data, professional/employment information, education information, sensitive personal information, and inferences — NO
Sale & Sharing
We have not sold personal information and have not shared personal information for targeted advertising in the preceding twelve (12) months, and we do not currently do so.
Your Rights
- Right to know whether we are processing your personal data.
- Right to access your personal data.
- Right to correct inaccuracies.
- Right to request deletion.
- Right to obtain a copy of your data.
- Right to non-discrimination for exercising your rights.
How to Exercise Your Rights
Email support@btwncalendars.com. We may need to verify your identity before fulfilling a request. Authorized agents must provide written, signed permission from you.
Appeals
If we decline to act on your request, you may appeal by emailing support@btwncalendars.com. If your appeal is denied, you may submit a complaint to your state attorney general.
14. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
The updated version will be indicated by an updated “Last updated” date at the top of this Privacy Notice. If we make material changes, we may notify you by prominently posting a notice or by emailing the address on your account.
15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, contact us at:
BTWN CalendarsUnited States
support@btwncalendars.com
16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
You may review or change account information from your account settings page. To delete your account and associated personal data, use the delete account option in your settings or email support@btwncalendars.com. Deletion is immediate, except where retention is required by law.
17. SERVICE INTEGRATIONS & DATA HANDLING
Google API Services — Limited Use
BTWN Calendars’ use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the minimum Google Calendar scopes needed to read busy/free times and write events you authorize. Calendar event metadata is used solely to compute availability for your teams; it is not sold, used for advertising, used to train AI/ML models, or shared with third parties beyond what you direct.
Microsoft Graph / Outlook Calendar
When you connect a Microsoft account, we request the minimum Microsoft Graph scopes needed to read busy/free times and write events you authorize. Tokens and event metadata are handled under the same Limited Use principles described above and are governed by the Microsoft Privacy Statement on Microsoft’s side.
Sub-processors
- Firebase (Google LLC)— authentication, Cloud Firestore database, storage, hosting, and Performance Monitoring.
- Vercel Inc.— web hosting and serverless function execution.
- Google LLC— Google Calendar API integration (only when you connect a Google account).
- Microsoft Corporation— Microsoft Graph / Outlook Calendar integration (only when you connect a Microsoft account).
Account Deletion & Data Removal
You can disconnect a calendar integration at any time from the account settings page, which revokes our access tokens. To delete your account and all associated personal data, use the delete account option in your user settings. Deletion is immediate.