1. Who We Are & How to Contact Us
CalFlow ("CalFlow", "we", "us") operates the scheduling platform available at calflow.dev. We act as the data controller for host account data and, in most cases, as a data processor for attendee data that we store on a host's behalf. For any privacy question or request — whether you are a host or an attendee — contact us at support@calflow.dev.
2. Data We Collect
Account data (hosts): name, email address, username, password (stored only as a salted hash), timezone, availability schedule, profile details, and connected calendar or payment account identifiers.
Booking data (attendees):attendee name, email address, notes and answers provided when booking, uploaded attachments, meeting date and time, and the attendee's timezone. We store this on behalf of the host you booked with.
Payment data: payments are processed by Stripe. We never receive or store card numbers or bank credentials. We store transaction metadata only (amounts, currency, payment status, and Stripe identifiers) to reconcile bookings and payouts.
Usage and log data: IP addresses, browser/device information, and request logs, used for security, debugging, and abuse prevention.
3. Why We Process Data (Lawful Bases)
We process personal data on the following legal bases: performance of a contract — providing scheduling, booking confirmations, reminders, payments, and payouts; legitimate interests — securing the platform, preventing fraud and abuse, and maintaining service reliability; and consent — where required, such as optional integrations you explicitly connect (e.g., Google Calendar). We do not sell personal data and do not use it for third-party advertising.
4. Processors & Sub-Processors
We share data with the following service providers, only to the extent needed to run CalFlow:
| Provider | Purpose |
|---|---|
| Stripe | Payment processing and payouts (Stripe Connect) |
| Resend | Transactional email (confirmations, reminders, receipts) |
| MongoDB Atlas | Primary database hosting |
| Google Cloud Run | Application hosting and infrastructure |
| Cloudflare R2 | File and attachment storage |
| OAuth sign-in and calendar sync, where you connect them |
5. Data Retention
Account data is retained until you delete your account. Booking data (including attendee details) is retained while the host's account exists, so hosts keep their scheduling history. Financial and transaction records are kept for as long as tax, accounting, and anti-fraud laws require, even after account deletion. Log data is retained for a limited period for security purposes.
6. Your Rights
Depending on where you live (including under the GDPR and CCPA/CPRA), you have the right to access, rectify, erase, and receive a portable copy of your personal data, and to object to or restrict certain processing. You will not be discriminated against for exercising these rights.
Hosts: you can export your data in-app (Dashboard → Profile → Export my data) and delete your account from the same page.
Attendees: because we hold your data on behalf of the host you booked with, please contact that host first, or email support@calflow.dev — we will assist with any access, correction, or deletion request within 30 days.
7. International Transfers
CalFlow runs on infrastructure located in the United States and the European Union. Where personal data of EU/EEA, UK, or Swiss residents is transferred outside those regions, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and UK/Swiss equivalents) entered into with our sub-processors.
8. Cookies
We use essential cookies only: secure session cookies set by NextAuth to keep you signed in and to protect against cross-site request forgery. We do not use advertising cookies, cross-site trackers, or third-party analytics scripts, so no cookie consent banner is required for our essential cookies.
9. Security
We protect personal data with encryption in transit (HTTPS/TLS everywhere), salted password hashing, role-based access controls, tenant isolation between accounts, presigned time-limited URLs for file access, and rate limiting on authentication endpoints. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify affected users and regulators as required by law.
10. Children
CalFlow is not directed at children and is not intended for anyone under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact support@calflow.dev and we will delete it.
11. Roles: Hosts and Attendees
When an attendee books through a host's CalFlow page, the host is generally the data controller for that booking data and CalFlow acts as their processor. Hosts are responsible for using attendee data lawfully (for example, not adding attendees to marketing lists without a proper basis). CalFlow processes attendee data only to deliver the scheduling service described in this policy.
12. Changes to This Policy
We may update this policy as the product and the law evolve. Material changes will be announced by email to hosts and by a notice on this page before they take effect. This version is effective as of July 8, 2026.