Legal

Privacy Policy

Last updated: July 2026  ·  Effective: July 2026

This Privacy Policy explains how Calendyfy (“we”, “us”, or “our”) collects, uses, shares, and protects information about you when you use our platform. By using Calendyfy, you agree to the practices described in this policy.

1. Information We Collect

Account Information

When you register as a business owner, we collect your full name, email address, phone number, business name, and country of operation.

Booking Data

When customers make bookings through Calendyfy, we collect the customer's name, email address, phone number, selected service or space, and appointment date and time.

Payment Information

We process web payments through Paystack (Nigerian businesses) and Paddle (international businesses). Mobile app subscriptions are processed through Apple (In-App Purchase) for iOS users and Google (Google Play Billing) for Android users. We do not store your full card or payment details. All payment data is handled directly by the respective processor in accordance with their security standards.

Usage Data

We collect information about how you interact with the Calendyfy platform, including pages visited, features used, and actions taken within your dashboard.

Communications

We store records of notifications sent to you and your customers via email, including booking confirmations, reminders, and cancellation notices.

2. How We Use Your Information

Service Delivery

We use your information to operate the Calendyfy platform: processing bookings, preventing scheduling conflicts, sending notifications, and facilitating payments between businesses and customers.

Communications

We send transactional messages related to your account and bookings, including OTP verification codes, booking confirmations, appointment reminders, payout notifications, and platform updates.

Analytics & Improvements

We use aggregated and anonymised usage data to improve the platform, fix bugs, and develop new features. Individual user data is never sold to third parties.

Commission & Payouts

We use transaction data to calculate and apply our 1.4% platform commission on each booking, and to process payout requests from business owners.

3. Third-Party Services

Paystack

Used to process payments for Nigerian businesses. Paystack handles card data under PCI-DSS compliance. Their privacy policy applies to data shared with them during payment processing.

Paddle

Used to process international web payments and subscriptions. Paddle acts as the Merchant of Record for international transactions.

Apple (App Store / In-App Purchase)

Used to process subscriptions purchased through the Calendyfy iOS app. Billing, payment data, and refunds are managed entirely by Apple. Their privacy policy governs data collected during Apple IAP transactions.

Google (Google Play Billing)

Used to process subscriptions purchased through the Calendyfy Android app. Billing, payment data, and refunds are managed entirely by Google. Their privacy policy governs data collected during Google Play Billing transactions.

Mailjet

Used to send transactional emails. Email content and recipient data is processed by Mailjet in accordance with their privacy policy.

Cloudinary

Used to store and serve business logos, banners, and space photos uploaded by Pro plan users.

Google Calendar

Available as an optional integration. If you connect your Google Calendar, we access only your calendar events to sync confirmed bookings. We store your OAuth tokens in encrypted form and never read unrelated calendar data.

Groq & Deepgram (AI Features)

Calendyfy includes AI-powered features: an AI booking assistant on public booking pages, and an in-app AI Assistant for business owners in our mobile app. To generate responses, these features send data to two third-party AI providers - Groq, Inc., which provides the underlying large language model, and Deepgram, Inc., which provides speech-to-text transcription and text-to-speech.

Data Shared With AI Providers

The data sent may include the messages you type or speak to the assistant, any voice recordings you submit, and the business data needed to answer your request, such as your services, bookings, revenue figures, and customer contact details (name, email, and phone number). In the mobile app, this data is only sent after you have reviewed an in-app disclosure identifying these providers and given your explicit consent. If you decline, no data is sent to any AI provider.

How AI Providers Use This Data

Groq and Deepgram process this data solely to provide the requested feature, meaning generating a response, transcribing your voice, or producing spoken audio. They do not use your data to train their models, and the data is not retained by them for any other purpose.

AI Provider Data Protection

Groq and Deepgram act as data processors on our behalf and are contractually required to safeguard your information and to provide a level of data protection equivalent to that described in this Privacy Policy. Their respective privacy policies also apply to any data processed through their services.

4. Data Sharing

With Business Owners

When a customer makes a booking through a business's Calendyfy page, the business owner can see the customer's name, contact details, and booking information.

With Customers

Customers receive confirmation of their booking details. Business contact information is shared to allow customers to reach the business if needed.

No Sale of Data

We do not sell, rent, or trade your personal information to any third party for marketing purposes.

Legal Requirements

We may disclose information if required to do so by law or in response to a valid request from a governmental authority.

5. Data Retention

Account Data

We retain your account information for as long as your account is active. If you request account deletion, we will remove your personal data within 30 days, except where retention is required for legal or financial compliance purposes.

Booking Records

Booking and payment records are retained for a minimum of 5 years for financial and tax compliance purposes.

Notification Logs

Records of sent notifications are retained for 12 months.

6. Security

Technical Measures

We use industry-standard security practices including HTTPS encryption in transit, hashed passwords, encrypted OAuth token storage, and access-controlled infrastructure.

No Guarantee

While we take reasonable steps to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

7. Your Rights

Access & Correction

You may request a copy of the personal data we hold about you and ask us to correct any inaccuracies.

Deletion

You may request deletion of your account and associated personal data. Certain data may be retained as required by law.

Withdrawal of Consent

Where processing is based on consent (e.g. Google Calendar integration), you may withdraw consent at any time by disconnecting the integration from your dashboard.

Contact Us

To exercise any of these rights, contact us at privacy@calendyfy.com.

8. Cookies

Session Cookies

We use session cookies to maintain your login state. These are essential for the platform to function and cannot be disabled.

No Tracking Cookies

We do not use third-party advertising or tracking cookies.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you via email or a prominent notice on the platform. Continued use of Calendyfy after changes become effective constitutes your acceptance of the revised policy.

10. Contact

If you have any questions about this Privacy Policy, please contact us at privacy@calendyfy.com or write to: Calendyfy, Lagos, Nigeria.

11. Google API Services - Limited Use Disclosure

The use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Scope of Access

Calendyfy's use of Google Calendar data is limited to syncing confirmed bookings to the connected Google Calendar account. We access only the calendar data needed to create, update, and delete booking events on behalf of the authenticated user.

No Transfer or Sale

We do not transfer, sell, or use Google user data for advertising purposes, nor do we allow humans to read Google user data except as required for security, to comply with applicable law, or when you have given explicit permission.