Privacy Policy
The publishable-hours editor (the "Service") handles the information it collects from users as described below.
1. Information we collect
- Google account information: your email address, name, and Google account ID. Your profile image URL is received from Google and used only for on-screen display; it is not stored by the Service.
- Google calendar list information: the ID, name, color, and whether each calendar is the primary one, for the calendars you own or subscribe to, obtained through the Google Calendar permission granted to the Service. This is used to display and let you select which calendars to sync; in principle the Service stores only the IDs of the calendars you select for syncing.
- Google calendar event information: the time ranges and titles of events on the calendars you select, obtained through the Google Calendar permission granted to the Service.
- Information about events the Service writes to your Google Calendar for bookings (Google event ID, calendar ID).
- Service settings: your selected sync calendars, business hours, days treated as holidays, time zone, candidate booking titles, buffer time reserved before and after a booking, and similar.
- Information about the booking slots you generate and publish: dates, time ranges, publication status, and the token contained in the public URL.
- Information provided by guests: the name, email address, and optional note entered into the booking form.
- Access and refresh tokens issued by Google OAuth (to continue reading and writing your calendar).
- For a Zoom account you optionally connect to the Service, the access and refresh tokens issued by Zoom OAuth (to continue making API calls that create meetings on your own Zoom account).
- Information about meetings the Service creates on your Zoom account (meeting ID, join URL).
- Information collected automatically for analytics: the pages viewed, the referring source, browser / OS / device type, approximate region, and IP address (see "8. Cookies and analytics" below).
2. Purposes of use
- To provide the features that generate, edit, and publish the booking slots you choose to make public, based on the free time in your Google Calendar.
- To write an event to the Google Calendar you specify when a booking is confirmed, reflecting the appointment for both the guest and you.
- To issue confirmation and cancellation URLs for guests and users, and to display booking status.
- For users who have connected Zoom, to automatically create a meeting on your own Zoom account when a booking is confirmed, and to include the generated join URL on the booking confirmation screens of both the guest and you and in the Google Calendar event.
- To understand service usage, respond to failures, and address misuse.
3. Handling of Google user data
The Service's use of Google user data and its transfer to other apps comply with the Google API Services User Data Policy, including the Limited Use requirements. Specifically, calendar information obtained from the Google API is used only within the "Purposes of use" above; it is not used for advertising, sold or transferred to third parties, or used for data analysis unrelated to the Service's core features.
The parties with which the Service shares or transfers the Google user data it obtains are as follows.
- Google API (google.com): the Service calls the API only to provide its core features, such as writing events to your own Google Calendar.
- Google Cloud Firestore (asia-northeast1 region): used as the Service's database to store user settings, booking information, and the like.
- Zoom API (zoom.us): only when you enable the Zoom integration, the Service accesses the Zoom API to create a meeting when a booking is confirmed. Google user data itself is not transferred to Zoom.
The Service does not share, transfer, or disclose Google user data to any third party other than the above.
4. About the Zoom integration
You may optionally connect your own Zoom account to the Service. When connected, at the time a booking is confirmed the Service automatically creates a meeting on Zoom using your own Zoom account, and includes the generated join URL on the booking confirmation screens of both the guest and you and in the Google Calendar event.
The only permission scope the Service requests for the Zoom integration is meeting:write (permission to create meetings). The Service does not obtain or view your Zoom profile information, list of existing meetings, recordings, chat history, participant information, or the like.
If you run "Disconnect Zoom" in the Service, or if the refresh token expires on Zoom's side, the Service promptly deletes the Zoom OAuth access and refresh tokens it holds. The ID and join URL of a Zoom meeting created by the Service are stored as part of the corresponding booking record within the booking history, and are deleted together when an account deletion request is received or when the relevant booking record is deleted. The Service complies with Zoom Marketplace data-handling requirements and does not use information obtained from Zoom outside the purposes stated in this policy.
5. Provision to third parties
Except as required by law, we do not provide the information we collect to third parties. To provide the Service, we call the Google API and (when connected) the Zoom API with your own authorization to access and write to your own calendar and Zoom account; this constitutes "data processing on your behalf" and does not amount to provision to a third party.
To improve the Service we use an analytics tool (Google Analytics) and send it information about page views. This is an outsourcing of analytics work and does not amount to provision to a third party. What is sent, and how to stop it, is described in "8. Cookies and analytics" below. We never send the analytics tool any data obtained from Google Calendar or Zoom, nor the name, email address, or note a guest enters into the booking form.
6. Where data is stored and for how long
The information we collect is stored in Google Cloud (Firestore, asia-northeast1 region). Google/Zoom OAuth tokens, user settings, generated and published booking slots, and booking history (including the name, email address, and note provided by guests) are retained during your period of use in order to keep providing the Service.
You can delete your account at any time from the "Profile and Account" screen of the Service. When you do, the Google/Zoom access and refresh tokens, calendar settings, generated and published booking slots, public URLs, and booking history (including guests' names, email addresses, and notes) are completely deleted without delay, and any live booking URLs become invalid. This action cannot be undone. Deletion requests by email are also accepted at the contact below.
7. Data protection and security
- All communication is encrypted with HTTPS / TLS.
- Confidential information such as OAuth access and refresh tokens is stored in Google Cloud Firestore, and access from anything other than the Service's internal processing is prohibited by Firestore Security Rules and Cloud IAM.
- The Service's backend runs on Google Cloud Run, with secrets managed by Secret Manager and the principle of least privilege applied through IAM.
- Access to Google user data is limited to what is necessary to run the Service's core features, and unnecessary data is not collected or stored.
- Personal information (PII) such as guests' names and email addresses is automatically deleted once its retention period has elapsed: 180 days after the meeting date for confirmed bookings, and 30 days after cancellation for cancelled bookings. Deletion runs as a daily batch, so it takes effect on the first run after the period passes.
8. Cookies and analytics
The Service issues an HttpOnly authentication session cookie to maintain your sign-in state and to prevent CSRF. It does not use third-party cookies for advertising or behavioral tracking, and it never uses or discloses the information it collects for advertising purposes.
To understand how the Service is used and to improve it, we use Google Analytics (GA4), provided by Google LLC. It uses cookies issued on this Service's own domain (such as _ga) to collect the pages viewed, the referring source, browser / OS / device type, and approximate region. IP addresses are used to estimate region and are not stored in Google Analytics.
A booking page's URL — and a group-poll page's — is itself the authorization to book or respond: knowing it is enough. The analytics tool is therefore not loaded on those pages, and nothing is sent to it from them. And where such a URL could be reported as the referrer of a page you move on to, the token is stripped and replaced with a uniform placeholder such as /p/[token] before anything is sent. No individual host's booking URL is ever recorded on the analytics side.
To stop collection by Google Analytics, install Google's opt-out browser add-on or disable cookies in your browser. Booking still works normally either way. For how Google handles this data, see the Google Privacy Policy.
9. Operator, contact, and requests for disclosure
Personal information handler: Take Hiramatsu, operator of the publishable-hours editor
Contact: take.hiramatsu@gmail.com
For inquiries about this policy, or to request notification of the purpose of use, disclosure, correction, addition, deletion, suspension of use, or suspension of provision to third parties of your retained personal data, please contact us at the address above. After verifying your identity, we will respond promptly in accordance with the Act on the Protection of Personal Information and other applicable laws.
Last updated: July 13, 2026