Legal · Privacy

Privacy Policy

LAST UPDATED · 2026-05-12 · PLAIN-ENGLISH SUMMARIES IN grey

Last updated May 2026.

§01 Who we are

Slotsy is operated by Safety Tech Solutions, Tirana, Albania. Data lives on Cloudflare's EU edge.

Slotsy ("we", "us") is operated by Safety Tech Solutions, a sole-proprietorship registered in Tirana, Albania (NIPT on file). The booking platform runs on Cloudflare Workers with EU data residency (region hint weur) and uses Cloudflare D1, R2, and KV for storage. Data controller contact: [email protected].

§02 What we collect

Your account email, your bookings, your invitees' booking data, payment metadata (never card numbers). No advertising trackers.

From you (the account holder): email, hashed password, billing details (held by our payment processor, not by us), custom-domain CNAME, and calendar connections — Google OAuth tokens (encrypted at rest, see §05) or an iCal feed URL.

From your invitees: name, email, the scheduled time, any intake-form fields you defined, and payment metadata if you took a paid booking through your own Stripe key (we never see card numbers — Stripe does).

Automatically: server request logs (IP, user-agent, timestamp, response status) retained 30 days for abuse detection. The marketing site uses Plausible (cookieless, server-side, no fingerprinting). No Meta Pixel, no Google Analytics, no Hotjar, no advertising or cross-site trackers.

§03 How we use it

To make the bookings work. Never to advertise to you or your invitees.

We use account-holder data to operate the service: serve your booking page, read your calendar's busy times, and send confirmation/reminder emails on your behalf from your sender domain.

Invitee data is used exclusively on your behalf to operate your booking flow. We do not sell, share, license, rent, or otherwise transfer invitee data to third parties.

§04 Calendar connections

We read your busy times to show accurate availability. We never write to your calendar.

You can connect availability two ways: a Google Calendar connection, or an iCal feed URL you paste. In both cases Slotsy reads busy/free times only — to compute the slots your invitees can book. We do not create, edit, or delete events on your calendar.

§05 Google user data (Limited Use)

If you connect Google Calendar, Slotsy requests read-only access (the Google Calendar read-only scope, calendar.readonly) to read your busy times so we can render accurate availability. We do not create, modify, or delete calendar events. Google OAuth tokens are encrypted at rest using AES-256-GCM with a per-account key.

Slotsy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we use Google user data solely to provide the calendar-availability feature; we do not transfer or sell it, do not use it for advertising, and do not use it to train generalized AI/ML models. No humans read your Google data except where necessary for security, to comply with applicable law, or with your explicit consent.

§06 Lawful basis (GDPR)

  • Contract · Art. 6(1)(b) · processing account-holder data to provide the service you signed up for.
  • Legitimate interest · Art. 6(1)(f) · abuse-detection logs, fraud prevention.
  • Consent · Art. 6(1)(a) · optional marketing emails (opt-in only).

§07 Sub-processors

Cloudflare (hosting + storage, EU region) · our subscription billing provider (Paddle, as merchant of record — when subscriptions are live) · Stripe (your connected key, for your booking payments — not ours) · Resend (transactional email). Calendar data is read directly from Google/your iCal feed and is not shared onward.

§08 Your rights

Access · rectification · erasure · restriction · portability · objection · withdrawal of consent. Exercise any of them by emailing [email protected]. We respond within 30 days.

§09 Retention

Account data: for the lifetime of your account, plus 90 days after deletion (backups). Invitee booking data: same. Request logs: 30 days. Earlier deletion on request.

§10 Cookies

The marketing site sets no cookies. The application sets one session cookie (HttpOnly, SameSite=Lax). That's the cookie surface.

§11 International transfers

Data stays in the EU by default. Where a sub-processor transfers outside the EU (e.g. Stripe), Standard Contractual Clauses apply.

§12 Changes

Material changes get 30 days' email notice with a redline diff. No silent updates.


Questions? [email protected] · Privacy / DSAR: [email protected]