Last updated: July 29, 2026
Privacy Policy
This Privacy Policy explains how TimeTap ("TimeTap", "we", "us") collects, uses, stores and protects your personal information when you use our online scheduling and appointment booking platform at timetap.ai.
1. Information we collect
- Account information: your name, email address, profile photo, time zone and authentication details.
- Google account information: when you sign in with Google we receive your basic profile (name, email address, profile picture, Google account ID) via the OpenID Connect
openid,emailandprofilescopes. - Google Calendar data: only if you separately choose to connect a calendar. We read busy/free times and event metadata and create or update events for bookings made through TimeTap.
- Booking data: scheduled meetings, invitee names, email addresses and intake form responses.
- Payment data: billing details are processed by our payment provider (Stripe); we never store full card numbers.
- Usage data: log data, device and browser information, and cookies used to keep you signed in and improve the service.
2. How we use your information
We use your information to provide scheduling services, display accurate availability, create calendar events, send confirmations and reminders, process payments, prevent abuse, and improve TimeTap. We do not use your data for advertising and we do not sell personal data.
3. How we use Google account information
Google sign-in information is used solely to create and authenticate your TimeTap account, to identify you within the application, and to contact you about your account and bookings. Signing in with Google never grants TimeTap access to your calendar — calendar permissions are requested separately and only when you click "Connect" on the Integrations page.
4. Google user data
When you connect Google Calendar, TimeTap requests the following Google OAuth scopes:
calendar.calendarlist.readonly— to show you which of your Google calendars you can connect to TimeTap.calendar.events.freebusy— to read busy time blocks from your connected calendars so we can calculate open booking slots.calendar.events— to create, update, and cancel calendar events for bookings made through TimeTap, and to read attendee RSVP status on events we created.
We do not use Google user data for advertising, we do not sell it, and we do not use it to train machine learning or AI models.
TimeTap's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. How we use Google Calendar data
When you connect Google Calendar, TimeTap uses the granted calendar scopes to:
- read busy/free times so booking pages never offer a slot when you are unavailable;
- create, update and cancel calendar events for meetings booked through TimeTap;
- attach conferencing links (such as Google Meet) to those events.
Calendar data is used exclusively to deliver these user-facing scheduling features. We do not use it for advertising, we do not sell it, we do not transfer it to third parties except the infrastructure providers required to run TimeTap, and we do not use it to train generalized AI or machine-learning models.
6. How OAuth tokens are stored
OAuth access tokens and refresh tokens are exchanged and stored server-side only. They are encrypted at rest with AES-256-GCM using a key held in our secret store, are never exposed to the browser or included in client-side code, and are accessible only to the backend routines that call the provider on your behalf. Access to the underlying database is restricted by row-level security so that only your account can reference your connections.
7. Data we store
- OAuth tokens: Google access and refresh tokens, encrypted at rest with AES-256-GCM.
- Calendar identifiers: the calendar IDs you choose to connect.
- Cached busy time blocks: start and end times only. We do not cache event titles, descriptions, or attendee lists from calendars we did not create.
- Booking records: scheduled meetings, invitee details, and intake responses.
8. Revoking access
You can revoke TimeTap's access at any time by opening Integrations in the app and clicking Disconnect next to the Google connection. Disconnecting immediately deletes the stored access and refresh tokens, cached busy time blocks, and calendar identifiers from our systems and stops all calendar reads and writes. You may additionally revoke access from your Google Account at myaccount.google.com/permissions.
9. Data retention and deletion
We retain account and booking data for as long as your account is active. You can delete individual bookings and connections at any time from within the app. To delete your account and all associated data, email support@timetap.ai from your account address or use the Contact page; we process deletion requests within 30 days, after which data is removed from live systems and from backups on their normal rotation.
10. Data sharing
We share data only with service providers who help us operate TimeTap: Supabase (database and hosting), Stripe (payment processing), our email delivery provider, and the calendar or conferencing providers you choose to connect (such as Google). We also share data where required by law.
11. Security
We protect data using encryption in transit (TLS), encryption at rest for credentials, row-level access controls, and least-privilege server-side access. No system is perfectly secure, but we work to protect your information and to notify affected users promptly if an incident occurs.
12. Your rights
You may access, correct, export or delete your personal data, and object to or restrict certain processing. Contact us and we will respond within the time frames required by applicable law.
13. Contact us
Questions about this Privacy Policy or your data? Email support@timetap.ai or use our Contact page.
