Privacy Policy
Last revised:
1. Data Controller
The controller of personal data in Scalendar is Individual Entrepreneur Orest Mykolaiovych Kostiuk. The contact for privacy questions and exercising data rights is kostiuk.orest.m@gmail.com. The Service is available at scalendar.bitbrothers.dev.
The Ukrainian version of this Policy is legally controlling. The English version is its translation.
2. Data We Process
• Account data: e-mail, first and last name, time zone, profile image, technical account identifiers and, for sign-in with Google, the Google identifier and basic profile data Google provides with the user's consent.
• Google Calendar data: the connected calendar e-mail, OAuth identifier, granted scope, encrypted access and refresh tokens and their expiry; busy-time and calendar-event information needed to display the schedule, calculate availability, create or update booking events, send invitations and create Google Meet links. Scalendar stores the created event identifier and meeting link on the relevant booking; other calendar data received is processed to the extent needed for synchronization.
• Scheduling and booking data: event settings, available hours, time off, time zone, location, teams and invited participants, as well as the Guest's name and e-mail, time, description, status and technical booking identifier. For a registered Guest, the booking may also be linked to their account.
• Telegram data: bot type, chat identifier, one-time connection token and connection time, as well as commands and technical data needed to link the account and deliver booking and payment notifications.
• Payment data: the selected Plan or paid booking, amount in Ukrainian hryvnias, status, time, internal reference, Monobank invoice identifier and technical payment-webhook response. For an organizer's connected business profile, merchant name and identifier and an encrypted API token are also processed. The full card number, expiry date and security code are entered on Monobank's payment page and are not stored in Scalendar.
• Technical data: IP address, browser and device information, session cookies, requested page addresses, request time and outcome, application logs, diagnostic data, error reports and information needed to protect against abuse. Sensitive parameters, including passwords, tokens, cookies and payment secrets, are filtered from logs and monitoring events.
3. How We Receive Data
We receive data directly from a User or Guest; from Google after sign-in or permission to access Calendar; from Telegram after a bot is connected; from Monobank when an invoice is created, a browser returns from the payment page and a signed webhook is received; and automatically when the website and application operate.
If a User enters data about a Guest, team participant or another person, the User confirms that they have a proper legal basis to provide that data and use it for the relevant Scalendar feature.
4. Purposes and Legal Bases
We process data to: create and protect accounts; provide booking pages, schedule, teams, availability and time off; synchronize Google Calendar, prevent meeting conflicts, create and update events, invitations and Google Meet links; deliver booking requests and service messages; connect Telegram notifications; accept payment for Plans, route booking payment to the profile connected by the organizer and reconcile statuses; provide support; prevent fraud, diagnose errors and protect the Service; perform the agreement and comply with law.
Depending on the operation, processing is based on performance of an agreement or steps before entering into one, consent to connect an optional integration, legitimate interests in Service security and support, or compliance with a legal obligation.
We do not sell personal data or use it for third-party behavioral advertising.
5. Cookies and Similar Technologies
Scalendar uses only strictly necessary cookies and local preferences to maintain a session, authenticate users, select a language, protect forms, remember the interface theme and enable sign-in and booking to function correctly. We do not use third-party advertising cookies or create advertising profiles of users.
6. Google API Data and Limited Use
Scalendar's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google data is used only for sign-in, connecting a calendar and providing user-visible synchronization features: displaying the schedule, determining busy time, avoiding conflicts, and creating and updating events, invitations and Google Meet links. We do not use Google data for advertising, retargeting, determining advertising audiences or selling data.
We do not transfer Google data to third parties except where necessary to provide or protect a feature requested by the user, with the user's explicit consent, or where required by law. Humans do not read a user's Google data unless the user has given affirmative consent; it is necessary to investigate a security issue or abuse; or it is required by law. Google data is not used for general research, lending or purposes unrelated to calendar features.
A user can disconnect Google Calendar in Scalendar, which deletes the stored connection tokens, and can also revoke access in the settings of their Google account.
7. Subprocessors and Processing Locations
• Hetzner Online GmbH (Germany, EU) — server infrastructure on which the Scalendar application and PostgreSQL operate.
• Google — OAuth sign-in, access to Google Calendar, and creation of calendar events, invitations and Google Meet links under Google's terms and the user's permissions.
• Sentry (EU region) — monitoring errors, performance and technical logs through a European data-ingestion endpoint.
• Telegram — bot linking and delivery of notifications requested by the user.
• Monobank (Ukraine) — creation and confirmation of payments for Plans and paid bookings, the payment page and refunds.
Core application data and the database are stored on Hetzner infrastructure in the EU; Sentry data is sent to the selected EU region. Google, Telegram and Monobank process the data needed for the relevant operation under their own terms and in locations they determine, which may be outside the EU. We provide each subprocessor only the data necessary for its function.
8. Retention
Account data and settings are retained while the account is active. After an account is deleted, related operational data is deleted or anonymized in the ordinary technical cycle, except for data that must be retained to comply with law, keep accounting and tax records, protect legal rights or handle a request already submitted.
Booking, payment and support data is retained for as long as needed to provide the Service, evidence transactions, resolve disputes and comply with mandatory retention periods. Technical logs and Sentry events are retained for the periods configured for security and diagnostics and are then deleted or aggregated.
When Google Calendar is disconnected, its tokens are deleted from Scalendar. When Telegram is disconnected, the stored chat identifier and connection tokens are cleared.
9. User Rights
A user may request access to, a copy of, correction, updating or deletion of personal data, restriction of or objection to processing where applicable, and may withdraw consent without affecting the lawfulness of earlier processing. An account can be deleted in settings; individual integrations can be disconnected without deleting the account.
To exercise these rights, write to kostiuk.orest.m@gmail.com from the address associated with the account and describe the request. We may ask the requester to verify their identity. Requests are handled on business days within 10 business days or, where the law requires a different period, within that period.
10. Security and Policy Changes
We use access controls, encryption of Google Calendar and payment-profile tokens in the database, secret filtering in logs, secure cookies, signature verification for payment webhooks, Telegram webhook secrets, HTTPS and infrastructure backups. No transmission or storage method guarantees absolute security, so we also limit data to what is needed for its purpose.
The current Policy is published on this page. Material changes apply after the updated version is published; where required by law or the nature of the change, we will provide an additional notice or obtain consent.