Legal

Privacy Policy

Effective date: June 24, 2026

Summary:We collect only what we need to run the service. We do not sell your data. Guests only share their name and email, which is visible to the Host they're booking with. You can request deletion of your data at any time.

1. Who We Are

Slotsra("we", "us", "our") operates the appointment scheduling platform at slotsra.site. This Privacy Policy explains how we collect, use, store, and share information when you use our Service.

For privacy-related questions, contact us at: contact.anuragdev@gmail.com

2. Information We Collect

2.1 Host accounts (registered users)

When you sign in with Google, we receive from Google:

NameTo pre-fill your profile display name
Email addressTo identify your account and send notifications
Profile photo URLTo display on your public booking page
Google OAuth tokensTo sync with your Google Calendar

We also store information you provide when setting up your profile: bio, timezone, social links, availability hours, and meeting type details.

2.2 Guest data (booking guests)

When a guest makes a booking, we collect:

NameTo identify the booking for the host
Email addressTo send the OTP verification code
Custom question answersIf the host has added custom questions to their meeting type

Guests do not need to create an account. Their email address is verified via a one-time code before the booking is confirmed.

2.3 Usage and technical data

We may automatically collect standard server logs including IP addresses, browser type, pages visited, and timestamps. This data is used solely for security monitoring and debugging and is not linked to individual profiles.

3. How We Use Your Information

Providing the ServiceCreating your booking page, managing availability, processing bookings
Calendar syncReading your Google Calendar to check availability; creating events on confirmed bookings
Email verificationSending OTP codes to guests to confirm bookings
Account managementEnforcing plan limits, processing payments, sending account-related notices
SecurityDetecting abuse, fraud, and violations of our Terms of Service
Service improvementAggregated, anonymised usage analysis — never individual tracking

We do not use your data for advertising, and we do not sell or rent your personal information to any third party.

4. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA), we process your personal data on the following legal bases:

  • Contract:Processing necessary to provide the Service you've signed up for
  • Legitimate interests: Security monitoring and fraud prevention
  • Consent: Google Calendar access (you may withdraw this at any time)
  • Legal obligation: Compliance with applicable laws

5. Google API Data

Slotsra's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we:

  • Only request Google Calendar scopes necessary to read your availability and create booking events
  • Do not share Google user data with any third party except as necessary to operate the Service
  • Do not use Google user data to serve advertisements
  • Do not allow humans to read your Google data unless you explicitly grant access or it is required for security purposes

6. Data Sharing

We share your data only in the following limited circumstances:

6.1 Between Hosts and Guests

When a guest completes a booking, their name and email are visible to the Host. The Host may use this information to contact the guest about the meeting outside of Slotsra. Guests should be aware of this before submitting a booking.

6.2 Service providers

We use the following third-party processors to operate the Service:

SupabaseDatabase and authentication infrastructuresupabase.com/privacy
ResendTransactional email delivery (OTP codes)resend.com/privacy
RazorpayPayment processing for Indiarazorpay.com/privacy
Dodo PaymentsPayment processing for international usersdodopayments.com/privacy
GoogleOAuth login and Calendar APIpolicies.google.com/privacy

6.3 Legal requirements

We may disclose your information if required to do so by law, court order, or government authority, or to protect the rights, property, or safety of Slotsra, our users, or the public.

7. Data Retention

Host account dataRetained while your account is active; deleted within 30 days of account deletion request
Booking recordsRetained for 12 months after the booking date, then deleted
Guest email addressesRetained with the booking record; deleted when the booking record is deleted
Payment recordsRetained for 7 years as required by Indian financial regulations
Server logsDeleted after 90 days

8. Data Security

We take reasonable technical and organizational measures to protect your personal data:

  • All data is encrypted in transit via TLS/HTTPS
  • Data at rest is encrypted by Supabase's infrastructure
  • OTP codes are stored as SHA-256 hashes, never in plain text
  • Google OAuth tokens are stored encrypted and scoped to minimum required permissions
  • Access to production data is restricted to necessary personnel only

No method of transmission or storage is 100% secure. If you become aware of a security issue, please contact us immediately at contact.anuragdev@gmail.com.

9. Cookies

We use only essential cookies required to maintain your login session (set by Supabase Auth). We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

You can disable cookies in your browser settings, but doing so will prevent you from staying logged in to your Host account.

10. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

AccessRequest a copy of the personal data we hold about you
CorrectionRequest correction of inaccurate or incomplete data
DeletionRequest deletion of your personal data
PortabilityReceive your data in a machine-readable format
ObjectionObject to processing based on legitimate interests
Withdraw consentDisconnect Google Calendar access at any time via settings

To exercise any of these rights, email us at contact.anuragdev@gmail.com. We will respond within 30 days. We may need to verify your identity before fulfilling requests.

If you are in the EEA and believe we are not handling your data lawfully, you have the right to lodge a complaint with your local data protection authority.

11. Children's Privacy

The Service is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us at contact.anuragdev@gmail.com and we will delete it promptly.

12. International Data Transfers

Our service providers (Supabase, Resend, etc.) may store or process data outside of India. When we transfer data internationally, we ensure appropriate safeguards are in place in accordance with applicable data protection laws.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on the website before the changes take effect. The "Effective date" at the top of this page indicates when the policy was last updated.

Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Slotsra

Email: contact.anuragdev@gmail.com

Website: slotsra.site