Privacy Policy
Last updated: 2026-08-03
What CalendarPal is
CalendarPal follows sports fixtures (football, F1, and more) and keeps them up to date in a calendar you already use. This policy explains what data we collect, why, and how you can remove it.
What we collect
- Your email address and Google account identifier, from Google sign-in.
- The teams, leagues, or drivers you choose to follow, and your calendar preferences (timezone, how many weeks ahead to sync, which calendar to write to).
- If you connect Google Calendar sync: an OAuth access/refresh token, encrypted at rest (AES-256-GCM) and used only to create, update, and delete fixture events on your calendar via the Google Calendar API.
- If you use the subscribable calendar feed instead: a private feed URL token, which acts as a bearer credential — anyone who has that link can view the fixture list it generates until you reset it from your dashboard.
- Basic, non-identifying product analytics: an anonymous per-browser id, event names (e.g. “followed a team”), and, if you're signed in, your user id. We don't put emails, names, or other personal identifiers into analytics event properties.
What we deliberately don't do
- We don't read the events already on your calendar. The one exception is a brief, internal technical check: if your connection to Google needs to be re-verified after an authorization hiccup, we make a single lightweight call that touches at most one existing event, solely to confirm access is restored — nothing from that call is stored, displayed, or used for any other purpose. Outside of that, the Google Calendar permission we request is used only to create, update, and delete the fixture events CalendarPal itself creates.
- We don't sell your data, and we don't share it with advertisers.
Who else sees this data (subprocessors)
- Google — hosts your calendar and processes the events we create there via the Google Calendar API (calendar.events scope).
- Supabase — hosts our database and handles Google sign-in on our behalf.
- Vercel — hosts the CalendarPal application.
- Inngest — runs the background jobs that keep your calendar in sync; it processes the same fixture/event data described above, on our behalf.
Google user data — Limited Use disclosure
CalendarPal's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Deleting your data
Remove CalendarPal's access at any time from myaccount.google.com/permissions, or email us (below) to request full deletion of your account data. Revoking access stops future syncing immediately; previously created calendar events are yours to keep or delete as you like.
Children
CalendarPal is not directed at, and we do not knowingly collect data from, children under 13.
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page.
Contact
Questions or deletion requests: bossuyt.arthur@gmail.com