CalFlow
Back to Homepage
Legal

Privacy Policy

Effective Date: July 8, 2026. This policy explains how CalFlow handles personal data belonging to account holders ("hosts") and the people who book meetings with them ("attendees").

This document is a working draft prepared by the CalFlow team and has not yet been reviewed by qualified legal counsel. It will be finalized following counsel review; material changes will be announced per Section 12.

1. Who We Are & How to Contact Us

CalFlow ("CalFlow", "we", "us") operates the scheduling platform available at calflow.dev. We act as the data controller for host account data and, in most cases, as a data processor for attendee data that we store on a host's behalf. For any privacy question or request — whether you are a host or an attendee — contact us at support@calflow.dev.

2. Data We Collect

Account data (hosts): name, email address, username, password (stored only as a salted hash), timezone, availability schedule, profile details, and connected calendar or payment account identifiers.

Booking data (attendees):attendee name, email address, notes and answers provided when booking, uploaded attachments, meeting date and time, and the attendee's timezone. We store this on behalf of the host you booked with.

Payment data: payments are processed by Stripe. We never receive or store card numbers or bank credentials. We store transaction metadata only (amounts, currency, payment status, and Stripe identifiers) to reconcile bookings and payouts.

Usage and log data: IP addresses, browser/device information, and request logs, used for security, debugging, and abuse prevention.

3. Why We Process Data (Lawful Bases)

We process personal data on the following legal bases: performance of a contract — providing scheduling, booking confirmations, reminders, payments, and payouts; legitimate interests — securing the platform, preventing fraud and abuse, and maintaining service reliability; and consent — where required, such as optional integrations you explicitly connect (e.g., Google Calendar). We do not sell personal data and do not use it for third-party advertising.

4. Processors & Sub-Processors

We share data with the following service providers, only to the extent needed to run CalFlow:

ProviderPurpose
StripePayment processing and payouts (Stripe Connect)
ResendTransactional email (confirmations, reminders, receipts)
MongoDB AtlasPrimary database hosting
Google Cloud RunApplication hosting and infrastructure
Cloudflare R2File and attachment storage
GoogleOAuth sign-in and calendar sync, where you connect them

5. Data Retention

Account data is retained until you delete your account. Booking data (including attendee details) is retained while the host's account exists, so hosts keep their scheduling history. Financial and transaction records are kept for as long as tax, accounting, and anti-fraud laws require, even after account deletion. Log data is retained for a limited period for security purposes.

6. Your Rights

Depending on where you live (including under the GDPR and CCPA/CPRA), you have the right to access, rectify, erase, and receive a portable copy of your personal data, and to object to or restrict certain processing. You will not be discriminated against for exercising these rights.

Hosts: you can export your data in-app (Dashboard → Profile → Export my data) and delete your account from the same page.

Attendees: because we hold your data on behalf of the host you booked with, please contact that host first, or email support@calflow.dev — we will assist with any access, correction, or deletion request within 30 days.

7. International Transfers

CalFlow runs on infrastructure located in the United States and the European Union. Where personal data of EU/EEA, UK, or Swiss residents is transferred outside those regions, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and UK/Swiss equivalents) entered into with our sub-processors.

8. Cookies

We use essential cookies only: secure session cookies set by NextAuth to keep you signed in and to protect against cross-site request forgery. We do not use advertising cookies, cross-site trackers, or third-party analytics scripts, so no cookie consent banner is required for our essential cookies.

9. Security

We protect personal data with encryption in transit (HTTPS/TLS everywhere), salted password hashing, role-based access controls, tenant isolation between accounts, presigned time-limited URLs for file access, and rate limiting on authentication endpoints. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify affected users and regulators as required by law.

10. Children

CalFlow is not directed at children and is not intended for anyone under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact support@calflow.dev and we will delete it.

11. Roles: Hosts and Attendees

When an attendee books through a host's CalFlow page, the host is generally the data controller for that booking data and CalFlow acts as their processor. Hosts are responsible for using attendee data lawfully (for example, not adding attendees to marketing lists without a proper basis). CalFlow processes attendee data only to deliver the scheduling service described in this policy.

12. Changes to This Policy

We may update this policy as the product and the law evolve. Material changes will be announced by email to hosts and by a notice on this page before they take effect. This version is effective as of July 8, 2026.

Questions about privacy? Email support@calflow.dev — we respond to all requests within 30 days.