Legal

Privacy Policy

Effective date: June 14, 2026 · Last updated: July 28, 2026

SynqSlot, which operates SynqSlot ("SynqSlot", "we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our scheduling service at synqslot.com and related applications (collectively, the "Service"). Please read this policy carefully. By using the Service you agree to the practices described here.

1. Information we collect

Account information

When you sign in via Google OAuth or Microsoft OAuth we receive your name, email address, and profile picture from the identity provider. We do not receive or store your Google or Microsoft account password.

Calendar access

To power the scheduling service, we request access to read and write calendar data via the Google Calendar API and Microsoft Graph API. Specifically, we:

  • Read your free/busy windows — the start and end times when you are already occupied — to prevent double-bookings.
  • Create calendar events when an invitee books a meeting with you.
  • Delete or update those events when a meeting is cancelled or rescheduled.
  • Store OAuth access tokens and refresh tokens securely to maintain calendar sync.

We access only the calendar scopes necessary to provide the scheduling service. For Google Calendar we request the free/busy scope rather than a read-all scope, which means we can see when you are busy but never the title, description, attendees, or any other content of your existing events.

Booking data

We store data submitted by invitees when they book a meeting, including their name, email address, and any answers to intake questions you have configured. This data is stored in connection with your SynqSlot account.

Usage data

We collect standard server logs including IP addresses, browser type, pages visited, and timestamps. This data is used to maintain, secure, and improve the Service.

Payment information

Payments are processed by Stripe. We do not store your full card number, CVV, or bank account details — these are handled entirely by Stripe. We receive and store a Stripe customer ID and subscription status.

2. How we use your information

  • To provide the scheduling service — syncing calendars, creating bookings, sending confirmations.
  • To send transactional emails — booking confirmations, reminders, and follow-ups configured in your workflows.
  • To send billing communications — receipts, renewal notices, and payment failure alerts.
  • To improve the Service — analysing usage patterns to fix bugs and build better features.
  • To comply with legal obligations — responding to lawful requests from authorities.

We do not use your calendar data to train machine learning models, serve advertisements, or for any purpose other than providing the scheduling service.

3. How we share your information

We do not sell your personal data. We share information only in these limited cases:

Service providers

  • Google LLC — Calendar API OAuth to sync your Google Calendar.
  • Microsoft Corporation — Microsoft Graph API to sync your Outlook/Office 365 calendar.
  • Stripe, Inc. — Payment processing for paid plans.
  • Resend — Transactional email delivery (confirmations, reminders, follow-ups).
  • Vercel Inc. — Application hosting and serverless functions, and Vercel Blob storage for profile images you upload.
  • Neon Technologies — PostgreSQL database hosting. Data is encrypted at rest.
  • Cloudflare, Inc. — Turnstile bot protection on public booking submissions. Cloudflare receives the challenge token and the submitting IP address.

Each provider is bound by their own privacy policies and data processing agreements and is permitted to use your data only to provide the services they supply to us.

Services you connect

If you connect an integration to your account, we send booking data — including the invitee's name, email address, and the meeting details — to that service on your instruction. You choose which of these to connect, you can disconnect them at any time, and once the data reaches them it is governed by their privacy policy and by your relationship with them, not by ours:

  • HubSpot, Inc. and Salesforce, Inc. — the invitee is created or updated as a contact/lead and the meeting is logged.
  • Intuit Mailchimp — the invitee is added to the audience you select.
  • Zoom Communications, Inc. — a meeting is created for the booking.
  • Slack Technologies and Microsoft Corporation (Teams) — a booking notification is posted to the channel behind the webhook you supply.
  • Any endpoint you configure as a webhook — receives the full booking payload.

Legal requirements

We may disclose information if required by law, subpoena, court order, or other governmental authority, or where we believe disclosure is necessary to protect the rights, property, or safety of SynqSlot, our users, or the public.

Business transfers

If SynqSlot is acquired or merges with another entity, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on the Service before that transfer occurs.

4. Data storage and security

Your data is stored in a PostgreSQL database hosted on Neon (AWS infrastructure, US East region). Connections to the database use TLS, and the database provider encrypts all stored data at rest.

In addition, the credentials for the services you connect are encrypted by SynqSlot using AES-256-GCM before they are written to the database, so they are not readable from the database alone. That covers the OAuth access and refresh tokens for your Google and Microsoft calendars, the app-specific passwords used where a calendar is connected over CalDAV, and the access tokens and webhook URLs for your other connected services — Zoom, HubSpot, Salesforce, Mailchimp, Slack, and Teams.

We implement appropriate technical and organisational measures to protect your information. However, no method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at hello@synqslot.com.

5. Your rights and choices

Access and correction

You can view and update your account information in the Settings section of your dashboard at any time.

Disconnecting calendars and integrations

You can disconnect any connected calendar from Settings → Calendars. When you do, we delete the stored connection, including its access and refresh tokens, so we stop reading your availability and stop writing events. We do not call the provider's revoke endpoint on your behalf, so the app also stays listed in your Google or Microsoft account until you remove it there — you can do that at any time from your provider's security settings.

Disconnecting an integration from Settings → Integrations stops SynqSlot sending anything to that service. The stored credentials are kept so you can reconnect without re-authorising; if you want them erased, ask us and we will delete them, and they are deleted with your account.

Data deletion

To delete your SynqSlot account and all associated data, contact us at hello@synqslot.com with the subject line "Delete my account". We will process your request within 30 days. Note that we may retain certain information where required by law (e.g., billing records).

GDPR rights (EEA and UK users)

If you are located in the European Economic Area or the United Kingdom, you have the right to: access your personal data, rectify inaccurate data, erase your data, restrict processing, data portability, and to object to processing. To exercise these rights, contact us at hello@synqslot.com.

California privacy rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you additional rights. We collect the following categories of personal information, as described in section 1:

  • Identifiers and account information — your name, email address, and profile picture from Google or Microsoft OAuth, and a Stripe customer ID.
  • Booking and invitee details — names, email addresses, and intake question answers submitted when someone books with you.
  • Calendar data — event start/end times and busy/free status used to calculate your availability, and events we create, update, or delete on your behalf.
  • Internet and usage data — IP addresses, browser type, pages visited, and timestamps from standard server logs.

We collect this information for the business purposes described in section 2 and share it only with the service providers listed in section 3. As a California resident you have the right to know what personal information we collect and to request a copy of it, the right to delete it, the right to correct inaccurate information, the right to opt out of the sale or sharing of personal information, and the right not to be discriminated against for exercising any of these rights — we will not deny you the Service, charge you a different price, or give you a lower level of service because you made a request.

SynqSlot does not sell your personal information and does not share it for cross-context behavioural advertising, so there is nothing to opt out of. We also do not use or disclose sensitive personal information for purposes beyond providing the Service.

To exercise any of these rights, email us at hello@synqslot.com. We will verify your request using the email address associated with your account and respond within the time required by law. You may use an authorised agent to submit a request on your behalf.

6. Data retention

We keep personal information only for as long as we need it to provide the Service or to meet a legal obligation. In general terms:

  • Account data — retained while your account is active. When you delete your account we delete your account data from our production systems within 30 days.
  • Booking records — retained while your account is active so that you keep your booking history. They are deleted together with your account.
  • Email and notification logs — delivery records for confirmations, reminders, and follow-ups are retained for approximately 90 days.
  • Operational logs — server and security logs are retained for approximately 90 days, then deleted or aggregated.
  • Billing records — retained for as long as required by applicable tax and accounting law, even after account deletion.

After deletion, residual copies of your data may remain in encrypted backups for a limited period before those backups are rotated and overwritten in the ordinary course. We do not restore deleted data from backups except to recover from a system failure.

7. Google API data use disclosure

SynqSlot's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Information received from Google APIs is used only to provide and improve features visible to the user within SynqSlot. It is not transferred to third parties except as necessary to provide the Service (see "Service providers" above), or as required by law. It is not used for serving advertisements. It is not used for any purpose not explicitly described in this Privacy Policy.

8. Cookies

We use a session cookie to keep you signed in (managed by NextAuth.js). This cookie is essential for the Service to function and is deleted when you sign out or close your browser. We do not use third-party advertising cookies. If you connect analytics integrations (Google Analytics, Meta Pixel) on your booking page, those providers may set their own cookies — you are responsible for disclosing this to your invitees.

9. Children's privacy

The Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us at hello@synqslot.com.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice on the Service at least 14 days before the change takes effect. Your continued use of the Service after the effective date constitutes your acceptance of the updated policy.

11. Contact

Questions, requests, or concerns about this Privacy Policy or our data practices:

Email: hello@synqslot.com
Operator: SynqSlot
Service: SynqSlot (synqslot.com)