1. Who we are (data controller)
BeezTime is the controller of your personal data. For any privacy request, contact us at privacy@beeztime.com.
2. Personal data we collect
When you create an account
- Your email address and (optionally) your name.
- A password, stored only as a salted hash by our authentication provider — we never see it. If you choose “Continue with Google”, we receive your email and name from Google instead of a password.
When you set up a booking page (as a host)
- Your booking handle, time zone, weekly availability, and meeting settings (title, slot length, video-call platform and link).
When you book a meeting (as a guest)
- Your name, email address, chosen time slot, and time zone. You do not need an account to book.
If you connect a Google Calendar (optional)
- OAuth access/refresh tokens, stored encrypted at rest and used only to check your free/busy times and add confirmed meetings to your calendar. You can disconnect at any time.
If you opt in to sponsor updates (optional)
- Your email and name are added to a mailing list we operate. This is never pre-checked, and every message has a one-click unsubscribe. We do not transfer your personal data to the sponsor.
Automatically, for security
- Limited technical data (e.g. IP address, request time) in server logs, used to operate the service and prevent abuse (such as rate-limiting bookings). No advertising or cross-site tracking.
3. Why we use your data & our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide accounts, booking pages and process bookings | Performance of a contract |
| Send booking confirmations and calendar invites | Performance of a contract |
| Google Calendar sync | Consent (you connect it) |
| Sponsor mailing list | Consent (explicit opt-in) |
| Security, abuse prevention, service operation | Legitimate interests |
| Non-essential cookies / local storage | Consent |
4. Who we share your data with (processors)
We do not sell your personal data. We use trusted providers who process data on our behalf under data-processing agreements:
- Supabase — database & authentication (stores your account and booking data).
- Render — application hosting; Cloudflare — DNS/CDN and security.
- Google — only if you use “Continue with Google” or connect Google Calendar.
- Email provider — to deliver transactional emails (confirmations, invites) and, if you opted in, sponsor updates.
- Google Fonts — our pages request fonts from Google’s servers, which receives your IP address to serve them.
5. Cookies & local storage
BeezTime does not use advertising or cross-site tracking cookies. We use your browser’s local storage and a small number of cookies in these categories:
| Category | What & why | Consent needed? |
|---|---|---|
| Strictly necessary | Your sign-in session/token (to keep you logged in) and your saved cookie choice. | No (required for the service) |
| Functional | Your preferences — theme, clock style, brightness, chosen time zone. | Yes |
| Marketing | Recording your opt-in to sponsor updates. | Yes (explicit opt-in) |
| Third-party (Google) | Set by Google only when you actively use Google sign-in or connect Calendar. | Yes (by your action) |
On your first visit we ask for your cookie choice. You can change it at any time via the link (also in the site footer). Declining non-essential storage will not stop you using the core clock and scheduling features; some preferences simply won’t be remembered between visits.
6. How long we keep your data
- Account & booking data — for as long as your account is active; deleted when you delete your account.
- Guest booking details — kept with the host’s meeting record; removed when the meeting is deleted or the host’s account is deleted.
- Server/security logs — kept for a short period, then deleted.
- Mailing-list consent — until you unsubscribe or ask us to erase it.
7. Your rights
Under the GDPR you have the right to: access your data, rectify inaccurate data, erase your data (“right to be forgotten”), restrict or object to processing, data portability, and to withdraw consent at any time (without affecting prior processing).
- Delete your data yourself: sign in → Meetings → “Delete my account & data”. This permanently removes your account, booking pages, and bookings.
- Withdraw marketing consent: click “unsubscribe” in any sponsor email, or update your Cookie settings.
- Any other request: email privacy@beeztime.com.
You also have the right to lodge a complaint with your local data-protection supervisory authority.
8. International data transfers
Some of our providers may process data outside your country (e.g. in the United States). Where required, such transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
9. Security
Data is transmitted over HTTPS. Passwords are hashed by our auth provider, OAuth tokens are encrypted at rest, and database access is restricted to our server. Booking data is protected by row-level security so only the relevant account can access it.
10. Children
BeezTime is not directed to children under 16 and we do not knowingly collect their data.
11. Changes to this policy
We may update this policy; we’ll revise the “Last updated” date above and, for material changes, provide a more prominent notice.
12. Contact
Questions or requests: privacy@beeztime.com.