Privacy Policy
Last updated: January 26, 2025
1. Introduction
At VardaCal ("we," "our," or "us"), we are committed to protecting your privacy and ensuring the security of your data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered scheduling platform and services.
By using VardaCal, you consent to the data practices described in this policy. If you do not agree with our policies and practices, please do not use our Services.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
2. Information We Collect
Information You Provide
- Account Information: Name, email address, password, company name, profile picture
- Calendar Data: Event details, meeting times, attendee information, availability preferences
- Billing Information: Credit card details (processed by our payment partners), billing address
- Communication Data: Messages you send through our platform, support tickets
- API Integration Data: OAuth tokens, API keys for connected services
Information We Collect Automatically
- Usage Data: How you interact with our Services, features used, scheduling patterns
- Device Information: Browser type, IP address, operating system, device identifiers
- Performance Data: Meeting success rates, attendance patterns, optimization metrics
- Cookies: Session cookies, preference cookies, analytics cookies
AI Learning Data
Our AI analyzes your scheduling patterns to provide optimization recommendations. This includes:
- Meeting frequency and duration patterns
- Optimal time preferences
- Attendance and cancellation rates
- Energy and productivity patterns
3. How We Use Your Information
We use the information we collect to:
- Provide and maintain our Services
- Process your bookings and manage your calendar
- Train our AI to optimize your scheduling
- Process payments and manage subscriptions
- Send you notifications about meetings and updates
- Provide customer support
- Improve and develop new features
- Comply with legal obligations
- Protect against fraud and abuse
4. Information Sharing
We do not sell your personal information. We share your information only in the following circumstances:
With Your Consent
We share information with your explicit consent, such as when you authorize calendar integrations or share booking links.
Service Providers
We work with trusted service providers who help us operate our Services:
- Cloud hosting providers (AWS, Cloudflare)
- Payment processors (Stripe)
- Email service providers
- Analytics providers (privacy-focused)
Platform API Users
If you use VardaCal through a third-party application via our Platform API, that application will have access to your scheduling data as authorized by you.
Legal Requirements
We may disclose information if required by law, court order, or government request, or to protect our rights and safety.
5. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit (TLS/SSL) and at rest (AES-256)
- Regular security audits and penetration testing
- Access controls and authentication measures
- Regular backups and disaster recovery procedures
- Employee training on data protection
- SOC 2 Type II compliance (in progress)
6. Your Rights and Choices
You have the following rights regarding your data:
Access and Portability
You can access and export your data at any time through your account settings.
Correction
You can update your personal information through your account profile.
Deletion
You can request deletion of your account and associated data. Some data may be retained for legal compliance.
Opt-Out
You can opt-out of marketing communications and certain data processing activities.
AI Learning
You can disable AI learning features, though this will limit optimization capabilities.
7. Data Retention
We retain your data for as long as necessary to provide our Services and comply with legal obligations:
- Active account data: Retained while account is active
- Deleted account data: Removed within 30 days
- Billing records: Retained for 7 years for tax compliance
- AI learning data: Anonymized after 90 days of inactivity
8. International Data Transfers
VardaCal operates globally. Your data may be transferred to and processed in the United States or other countries. We ensure appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses for EU data transfers
- Privacy Shield framework compliance (where applicable)
- Data localization options for enterprise customers
9. GDPR Compliance
For users in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR):
- Legal Basis: We process data based on consent, contract fulfillment, or legitimate interests
- Data Protection Officer: Contact our DPO at dpo@vardacal.com
- Rights: Access, rectification, erasure, portability, restriction, and objection
- Complaints: You may lodge complaints with your local supervisory authority
10. CCPA Compliance
For California residents, we comply with the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information (we don't sell data)
- Right to non-discrimination for exercising privacy rights
11. Children's Privacy
VardaCal is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If we discover we have collected information from a child, we will delete it immediately.
12. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your session and preferences
- Analyze usage patterns and improve our Services
- Provide personalized experiences
- Prevent fraud and ensure security
You can manage cookie preferences through your browser settings. Disabling cookies may limit some features of our Services.
13. Third-Party Links
Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or through our Services. Your continued use after changes constitutes acceptance.
15. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@vardacal.com
- Data Protection Officer: dpo@vardacal.com
- Address: VardaCal, Inc., 123 Tech Street, San Francisco, CA 94105