Privacy Policy
Effective date: August 7, 2026
Calenvite is a scheduling product that gives you a booking page (so other people can book time with you) and an optional scheduling assistant that helps protect time on your calendar. Calenvite is built under the Viciens brand, operated by Viciens, LLC, and is operated in the United States. This policy explains what personal data Calenvite collects, how we use it, who we share it with, and the choices you have. It covers both the people who run a Calenvite account (“owners”) and the people who book time through an owner’s booking page (“invitees”).
Contact
If you have questions about this policy or about your data, contact us at support@calenvite.com.
A note on pre-launch status
Calenvite is a new, pre-launch product. We describe only the data practices that are actually built into the product today. We do not claim any security certifications or audits (for example, we make no SOC 2, ISO 27001, or HIPAA claims), we do not promise specific uptime, and we do not guarantee that data can never be accessed by an unauthorized party. As the product grows, this policy will change, and we will update the effective date above when it does.
What data we collect
Account owner data. When you create and use a Calenvite account, we store: your email address, your display name, your time zone, and a record of whether you have given marketing consent and when you consented to data processing. If you customize your booking page, we also store your public booking handle, your brand color, a brand logo you upload, a welcome headline, and your display preferences and booking-load settings.
Connected Google account data. If you connect a Google Calendar, we store the email address of that Google account and your encrypted Google access and refresh tokens (see “How we secure your data”). We also store the configuration you set up: your event types and their titles and descriptions, your availability rules, which calendars you have connected, and the labels for any protected time windows you create.
Invitee data. When someone books time through an owner’s booking page, we collect that invitee’s name and email address (both required), and optionally their time zone and any notes they choose to add. We store the resulting appointment details (start and end time, status, and identifiers for the calendar event and calendar invite). If an event type requires email confirmation, the invitee’s email is also stored temporarily with a one-time verification token.
Payment data. If you subscribe to a paid plan, payment is handled by Stripe, our payment processor. Your card details are entered on Stripe’s secure checkout and are never stored on Calenvite’s servers; we store only a Stripe customer and subscription reference and your subscription status. See “Service providers we share data with” and “Payments and Stripe.”
What we do not collect. Calenvite does not itself collect or use your IP address, device fingerprints, advertising identifiers, or analytics/tracking data for tracking purposes, and it does not use tracking or advertising cookies. (Our hosting and infrastructure providers may keep standard server access logs, which can include IP addresses, as part of operating and securing their platforms.) See “Cookies and sessions” for the only cookies we set.
A note for booking-page owners about invitee data
If you use Calenvite to publish a booking page, people who book time with you (your invitees) submit their personal data through that page. You are responsible for the relationships with the people you invite and for handling their information appropriately. Calenvite stores invitee data only to create and manage the bookings on your behalf and to send the related emails.
How we use your data
We use the data above only to operate the product. Specifically, we use it to:
• Sign you in and keep your account secure.
• Show your real availability by reading your calendar’s busy times.
• Create, reschedule, and cancel bookings, including writing those bookings to your connected calendar.
• Send transactional emails such as booking confirmations, reminders, and (where required) booking-verification messages.
• Generate optional, opt-in scheduling suggestions during onboarding (see “AI-assisted suggestions”).
• Process subscription payments and manage your plan through Stripe (see “Payments and Stripe”).
We do not use your data for advertising, we do not sell it, and we do not use it for any purpose that is not described in this policy.
Google Calendar data we access
When you connect a Google Calendar, Calenvite requests only the narrowest Google OAuth scopes that its features actually need: https://www.googleapis.com/auth/calendar.events (calendar events), https://www.googleapis.com/auth/calendar.events.freebusy (busy/free times), and https://www.googleapis.com/auth/calendar.calendarlist.readonly (the read-only list of your calendars), plus openid and email so we can identify your Google account.
The events scope includes write access, because creating the event for a booking is how the product works. Using these scopes, Calenvite:
• Reads the email address of the connected Google account.
• Reads your list of calendars — read-only — to find the ones you can book on.
• Reads your busy/free times (free-busy) so the booking page only offers times you are actually available.
• Reads event details on your calendars when you run the onboarding scan and when checking the calendar you book on.
• Creates calendar events for the bookings you accept, and updates or deletes those events when a booking is rescheduled or canceled.
We deliberately do NOT request the full Google Calendar scope. Calenvite cannot create or delete calendars, cannot change who a calendar is shared with, and cannot read or change your Google Calendar settings.
If you connected a Google account before this narrowing took effect, that earlier connection may still carry the broader permission Google recorded at the time. Disconnecting and reconnecting the account, or removing Calenvite's access at myaccount.google.com/permissions, replaces it with the narrower set above.
We access this Google data only to provide the scheduling features described in this policy.
Google Limited Use
Calenvite’s use of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
In line with those requirements, we confirm that data obtained from Google Calendar is:
• Used only to provide and improve the user-facing scheduling features described in this policy.
• Not used or transferred for advertising of any kind, including retargeting, personalized, or interest-based advertising.
• Not sold, and not transferred to data brokers, advertising platforms, or other third parties except as needed to provide the service to you.
• Not used to train or improve any generalized artificial intelligence or machine-learning models.
• Not read by any human, except where you have given consent, where it is necessary for security purposes (such as investigating abuse), or where we are required to do so by law.
AI-assisted suggestions
Calenvite includes an optional onboarding step that proposes protected-time windows based on patterns in your calendar. To refine those suggestions, Calenvite may send a limited set of derived signals to Anthropic (the maker of Claude), our AI service provider.
What is sent is limited by design: only aggregated statistics and the titles of recurring event clusters. Your raw event list and the titles of one-off (non-recurring) events are never sent. This processing personalizes suggestions for your account only; it is not used to train a generalized AI model, consistent with the Google Limited Use commitments above.
Payments and Stripe
Calenvite uses Stripe to process subscription payments. When you start a paid plan, you enter your card details on Stripe’s secure checkout. Those card details are never stored on Calenvite’s servers — Stripe handles them directly. Calenvite stores only a Stripe customer and subscription reference and your subscription status, which we use to know whether your plan is active. We do not collect, store, or log credit card data ourselves. Stripe’s handling of your payment information is governed by Stripe’s own terms and privacy policy.
Service providers we share data with
We use a small number of service providers (subprocessors) to run Calenvite. They process data on our instructions to provide their part of the service, and this is not a sale of your data. They are:
• Supabase: our database and authentication, including storage for any brand logo you upload.
• Vercel: hosting for the Calenvite web application.
• Resend: delivery of transactional emails (confirmations, reminders, and verification messages) to owners and invitees.
• Google: the Google Calendar API and Google sign-in for connected calendars.
• Anthropic: AI-assisted onboarding suggestions, limited to the derived signals described in “AI-assisted suggestions.”
• Stripe: payment processing for paid subscriptions, as described in “Payments and Stripe.”
How we secure your data
We apply the following safeguards that are actually built into the product:
• Encryption of calendar tokens at rest. Your Google access and refresh tokens are encrypted using AES-256-GCM before they are stored in our database. We do not store these tokens in plain text.
• Per-user data isolation. Every record is tied to a single user, and our database enforces row-level security so that an account can only access its own rows.
• Encryption in transit. Calenvite is served over encrypted HTTPS connections by our hosting provider.
No product can promise perfect security. We do not claim any security certification or audit, and we cannot guarantee that data will never be accessed by an unauthorized party.
How long we keep your data
We keep your account data and your bookings for as long as your account is active. Calenvite does not currently delete old or canceled bookings, audit records, or completed account data on a fixed schedule; this data is retained until you delete your account. Short-lived items such as unverified booking holds and expired verification tokens are cleaned up automatically.
When you delete your account, we remove your account data as described in “Your rights and choices.”
Your rights and choices
Export your data. From your account, you can download a JSON copy of your data. This export now includes your full account dataset: your profile, your event types, your availability rules, your protected (guardian) windows and their exceptions, your calendar connections and connected calendars, your bookings, your entitlement records, and your account audit log. The connected-calendar records in the export include your encrypted token fields; these are stored as encrypted ciphertext, not as usable credentials, and cannot be used to access your Google account.
Delete your account. From your account, you can delete your account. When you do, we cancel your future confirmed bookings and retract any reminder emails we had scheduled for them, then delete your account, which cascades and removes the database records tied to your account (subject to the limits below regarding uploaded files and Google).
Limits of deletion you should know. Deleting your Calenvite account does not, by itself, revoke Calenvite’s authorization on your Google account, and it does not remove calendar events Calenvite already created on your Google Calendar. It also may not remove a brand logo you previously uploaded to our file storage. To fully disconnect Google and remove created events, follow the steps in “Disconnecting Google and revoking access.”
If you need help with a request that the in-product tools do not cover, contact us at support@calenvite.com.
Disconnecting Google and revoking access
You can disconnect a Google Calendar from within Calenvite at any time. You can also revoke Calenvite’s access directly from your Google Account at myaccount.google.com under the security/connections settings.
Disconnecting or revoking stops Calenvite from any further calendar access. Events that Calenvite already created on your Google Calendar will remain on your calendar unless you remove them yourself.
Cookies and sessions
Calenvite uses cookies only to make the product work. We set a session cookie to keep you signed in, which our system refreshes as you use the app. During the Google connection flow, we briefly set a single security cookie (a short-lived, server-only nonce that expires within about ten minutes) to protect that flow.
We also set one small preference cookie that remembers whether you have collapsed the sidebar in your dashboard, so it looks the same the next time you open it. It contains no personal data and is never used for tracking.
We do not use advertising cookies, analytics cookies, or third-party tracking cookies.
Email communications
Calenvite sends transactional emails through Resend. These include booking confirmations (which can include a calendar invite attachment), booking reminders, and, where an event type requires it, a booking-verification email. These messages are operational and are part of using the service; Calenvite does not currently send marketing emails.
Children’s data
Calenvite is intended for business and professional use by adults and is not directed to children. Consistent with our Terms, the service is not for anyone under 18, and we do not knowingly collect personal data from minors. If you believe a minor has provided us personal data, contact us at support@calenvite.com and we will take appropriate steps to remove it.
Where your data is processed
Calenvite is a US-based product, and the service providers listed above process data to deliver the service. If you book time with an owner from outside the United States, your data may be processed in the United States. We do not make region-specific legal guarantees beyond the practices described in this policy.
Changes to this policy
Because Calenvite is pre-launch and still developing, we may update this policy over time. When we make a material change, we will post the updated policy on this page and update the effective date at the top. Your continued use of Calenvite after an update means you accept the revised policy.