Privacy Policy
ZagCal is built so that we hold as little of your information as possible. By default it processes only your calendars' busy/free status — never your event details. An optional, per-sync full-detail mode (off unless you turn it on) can copy a calendar's real event titles to another of your own calendars; even then, we never store your event content.
1. Who we are
ZagCal ("ZagCal", "we", "us") is operated by ZAGRAL LLC, a limited liability company registered in Arizona, United States, which is the data controller for the personal data described here. Questions? Email privacy@zagcal.com.
2. The data we process
- Account data: your email address, display name, and a securely hashed password.
- Connected-calendar credentials: OAuth tokens (Google, Microsoft) or an app-specific password (Apple), stored encrypted at rest. We request only the access needed to read busy/free (plus, for syncs you switch to full-detail mode, that calendar's event details) and to write the events ZagCal creates for you.
- Availability data: the busy/free time ranges we read to compute your schedule, and the placeholder events we create. We do not store your event titles, guests, notes, or locations. If you switch a specific sync to full-detail mode, we read that calendar's event titles (and, if you ask, descriptions) only to write them onto another of your own calendars — we still don't store that content, and we keep only a one-way fingerprint to detect changes.
- Organization data: the organizations you create or join and your membership/role.
- Booking data: if you publish a booking page, the name, email, and any notes a booker provides when they book time with you, plus the booker's IP address (kept only for abuse prevention). If you are the booker, this is the data we process about you: we use it to create and manage the booking on the host's behalf, and the rights in section 6 apply to you too.
- Billing data: for paid plans, a Stripe customer identifier and subscription status. Payments are processed by Stripe; we never receive or store your card details.
- Technical data: limited log and request metadata (such as IP address) used for security, rate-limiting, and reliability.
3. How and why we use it (legal bases)
- To provide the service — syncing availability, booking pages, account management (performance of a contract).
- Security and abuse prevention — authentication, rate-limiting, threat mitigation (legitimate interests).
- Billing — managing subscriptions via Stripe (performance of a contract).
- Advertising measurement — if you reach us through one of our Google ads, reporting that a signup happened, server-side, so we can measure our advertising (legitimate interests; you can object at any time — see "Your rights").
- Legal compliance — where we must retain or disclose data by law (legal obligation).
4. Sharing and sub-processors
We do not sell your personal data. We share it only with providers that help us run ZagCal:
- Your calendar providers (Google, Microsoft, Apple) — we access your data there at your direction.
- Stripe — payment processing for paid plans.
- Google Ads — if you reach us by clicking one of our Google ads, we report that conversion (that a signup happened, and when) to Google Ads to measure and improve our advertising. This is a server-side signal only: we do not run Google's advertising scripts, and we never track you across sites. If you sign up with Google, Microsoft, or Apple sign-in, the ad-click id from our own landing page is carried through the handshake in a short-lived first-party cookie that is deleted right after — it is never readable by Google or any other site (see "Cookies & analytics").
- Our email delivery provider — to send account and booking emails (such as booking confirmations and password resets) on our behalf.
- Our hosting/infrastructure provider — to operate the service.
Google API Limited Use
ZagCal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to provide the calendar-sync and scheduling features you enable. We do not transfer or sell this data, we do not use it for advertising, and we do not let humans read it — except with your explicit consent, as needed for security or to comply with law, or in limited aggregated form for internal operations consistent with the Limited Use policy.
5. Retention
We keep your data for as long as your account is active. When you delete your account we remove your data and tear down the placeholders ZagCal created on your providers; routine backups cycle out thereafter. You can export your data or delete your account at any time from your account settings.
6. Your rights
Subject to applicable law (including the GDPR), you have the right to access, rectify, erase, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. You can export your data and delete your account directly from your account settings; for any other request, contact privacy@zagcal.com and we'll action it. You may also lodge a complaint with your local data-protection supervisory authority.
US state privacy laws: we honour the rights above for everyone, wherever you live. We do not sell personal data. Our only advertising-related disclosure is the server-side conversion signal described in section 4, which you can object to at any time.
7. International transfers
ZagCal is operated from the United States, so your data is processed on servers there. Where personal data protected by the GDPR (or its UK and Swiss equivalents) is transferred to us, we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) as the transfer mechanism, supplemented by the UK International Data Transfer Addendum and the Swiss FDPIC adaptations where they apply. Organizations using ZagCal for a team can rely on our Data Processing Agreement, which incorporates those clauses together with our technical and organizational security measures.
8. Cookies & analytics
We use a small number of first-party, essential cookies: one keeps you signed in, and short-lived ones secure the sign-in handshake (including, if you arrived through a Google ad, one that carries the ad-click id from our own landing page through sign-up and is deleted right after). We do not use third-party advertising or cross-site tracking cookies. If you arrive through a Google ad we measure that conversion server-side (see “Sharing and sub-processors” above) — no advertising script and no third-party cookie is ever placed on your device.
Our website analytics are first-party and cookieless: we measure aggregate traffic (page views, a daily count of unique visitors, and which calls-to-action are clicked) without setting any cookie or storing your IP address or a cross-site identifier. Unique visitors are counted with a salted hash that rotates every day, so a visitor cannot be tracked across days, and we never link an anonymous visitor to a specific account. We honour Do Not Track and Global Privacy Control, and aggregate marketing data is kept for at most 90 days. Because no personal data is stored and nothing is read from or written to your device, this needs no cookie banner.
9. Children
ZagCal is not directed to children and is not intended for anyone under 16.
10. Changes
We'll post any changes here and update the effective date above; material changes will be communicated to account holders.
11. Contact
privacy@zagcal.com · ZAGRAL LLC, registered in Arizona, United States. Governing law: the State of Arizona, United States.