HoldSync

Privacy Policy

Last updated: December 15, 2024

1. Introduction

HoldSync ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered calendar synchronization service.

2. Information We Collect

We collect the following types of information:

  • Personal Information: Email address and basic profile fields from Google OAuth (name, avatar). Only OpenID identity scopes are used.
  • Google API Data: When you connect your Google account, we access the following through Google OAuth 2.0 authentication:
    • Profile Information: Name, email address, and profile picture via OpenID Connect scopes (openid, email, profile)
    • Calendar List Data: Calendar IDs, calendar summaries, and primary calendar status to identify which calendars to monitor and sync
    • Calendar Event Metadata: Event start times, end times, event IDs, calendar IDs, and event tags to identify "[HoldSync]" marked events for synchronization

    We use the following Google API scopes: openid, email, profile, https://www.googleapis.com/auth/calendar, and https://www.googleapis.com/auth/calendar.events. We do not access or store event titles, descriptions, attendee information, location data, or any other event content beyond what is necessary for conflict detection and synchronization.

  • Usage Information: Sync statistics, service usage patterns, error logs, and performance metrics
  • Technical Data: IP address, browser information, and device details
  • Cookies and Tracking Technologies: We use cookies, session storage, and local storage to maintain your session, remember preferences, and improve your experience
  • Advertising Data: When viewing ads, we collect anonymized interaction data and website usage patterns for advertising purposes.
  • Advertising Data (Free Plan Only): Anonymous ad interaction data. Google Calendar data is never used for advertising.

3. How We Use Your Information

We use your information for the following purposes:

  • Read event start/end times to detect scheduling conflicts
  • Identify “[HoldSync]” tagged events for syncing
  • Create and update only HoldSync-generated hold events
  • Authenticate your account and connected calendars
  • Maintain reliability, performance, and security

4. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

Google User Data: We do not share, sell, or transfer Google Calendar data or Google account information to any third parties, except as required by law or as necessary to provide our service through our hosting infrastructure (Vercel, Heroku). Google Calendar data is never used for advertising, marketing, or shared with advertising partners. HoldSync's use of Google user data follows the Google API Services User Data Policy, including the Limited Use requirements. All Google user data is processed securely and only for the purpose of providing calendar synchronization services.

  • With trusted third-party services that help us operate our platform
  • When required by law or to protect our rights and safety
  • In connection with a merger, acquisition, or sale of assets
  • When you explicitly consent to sharing

5. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption in transit and at rest
  • Secure OAuth 2.0 authentication with Google
  • Regular security audits and updates
  • Google Calendar data is processed only as needed and never shared
  • Limited access controls and monitoring
  • Secure data centers and infrastructure

6. Your Rights and Choices

You have the following rights regarding your personal information:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and data
  • Portability: Export your data in a machine-readable format
  • Opt-out: Disconnect your Google Calendar at any time

To exercise these rights, contact us at support@holdsync.com

7. Data Retention

We retain your information for as long as necessary to provide our services:

  • Account Data: Until you delete your account
  • Calendar Data: We do not store Google Calendar event content. Temporary metadata (event IDs, timestamps, sync markers) is retained only while the account remains connected.
  • Usage Data: Up to 2 years for analytics and improvement
  • Legal Requirements: As required by applicable law

11. Google API Limited Use Disclosure

HoldSync complies with the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used only to detect conflicts, identify “[HoldSync]” tags, and create synchronized hold events across user-selected calendars.

HoldSync never modifies or deletes user-created events and only updates events generated by HoldSync. Calendar data is never used for advertising or shared with third parties.

8. Cookies and Tracking Technologies

We use various technologies to enhance your experience:

  • Session Cookies: Maintain your login session and authentication status
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Help us understand how you use our service
  • Advertising Cookies: Enable relevant ads to be displayed to support our free service

You can control cookies through your browser settings. Note that disabling certain cookies may limit service functionality.

9. Advertising and Third-Party Ad Services

To support our free service, we display advertisements on our platform:

  • Google AdSense: We use Google AdSense to display relevant ads. Google may use cookies and collect data about your interactions with ads
  • Advertising Data Collection: Ad providers may collect information about your device, browsing behavior, and interaction with ads
  • Personalized Advertising: Ads may be personalized based on your interests and browsing patterns
  • Opt-Out: You can opt out of personalized advertising through Google's Ad Settings or your browser's cookie settings

For more information about how Google uses data for advertising, visit Google's Privacy & Terms

10. Third-Party Services

Our service integrates with the following third-party services:

  • Google Calendar API: For calendar access and synchronization
  • Apple Calendar API: For calendar access and synchronization
  • Microsoft Outlook API: For calendar access and synchronization
  • Google OAuth: For secure authentication
  • Google AdSense: For displaying advertisements
  • Stripe: For payment processing (if applicable)
  • Vercel: For hosting and deployment
  • Heroku: For backend hosting and deployment

These services have their own privacy policies, and we encourage you to review them.

11. Children's Privacy

HoldSync is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

12. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data in accordance with applicable privacy laws.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date
  • Sending an email notification to registered users (for material changes that affect how we use your data)
  • Displaying an in-app notification when you next log in (for material changes)

You are advised to review this Privacy Policy periodically for any changes. Your continued use of our service after any changes to this Privacy Policy constitutes your acceptance of the updated policy.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us: