Privacy Policy.
This policy explains what personal data CalGet collects, why we collect it, who we share it with and what you can do about it — whether you create events with us or you're a guest who received one.
Contents
- 1. Who we are
- 2. What this policy covers
- 3. Personal data we collect
- 4. How we use personal data
- 5. How we share personal data
- 6. How we store and protect it
- 7. Access, correction and deletion
- 8. How long we keep it
- 9. Cookies
- 10. Your choices
- 11. What this policy doesn't cover
- 12. Children
- 13. International transfers
- 14. Europe, the UK and Switzerland
- 15. US state privacy rights
- 16. Changes to this policy
- 17. Contact us
1Who we are
CalGet is an add-to-calendar and event platform. We give people tools to create event pages, generate calendar links, publish calendars others can subscribe to, and collect RSVPs and registrations. Our website, apps, embeds and everything we provide through them are together the “Services”.
Two kinds of people use CalGet, and this policy applies differently to each:
- Organizers — people who create events with CalGet. You don't need an account to create an event, so organizers include both registered users and people who create an event as a guest.
- Guests — people who open an event page, add an event to their calendar, subscribe to a calendar, or RSVP to an event someone else created.
The Services are provided by CalGet LLC, a Wyoming limited liability company. You can reach us any time at [email protected].
2What this policy covers
This policy covers personal data: information that identifies you or could reasonably be linked to you. It applies to personal data we collect through the Services.
It doesn't cover information that can't identify anyone — aggregated counts, anonymized statistics and similar. If we combine that kind of information with personal data, we treat the combination as personal data for as long as it stays linkable to you.
3Personal data we collect
From everyone
- Information you give us — what you type into our forms, such as when you contact support, subscribe to updates or answer a question we ask.
- Technical information — collected automatically when you use the Services: IP address, browser and device details, pages viewed, referring page, and timestamps. Some of this comes from cookies and similar technologies.
From organizers
- Account details — name, email address and password, or the profile information Google shares with us if you sign in with Google. Your Google password is never shared with us.
- Event content — everything you put into an event: titles, descriptions, dates, locations, images, links, and any questions you add to a registration or RSVP form.
- Billing information — if you subscribe to a paid plan, our payment processor Stripe collects and processes your card details directly. We never see or store full card numbers. We do receive billing contact details, card type, the last four digits and transaction references so we can manage your subscription and support you.
- Support conversations — messages you send us by email or through the live chat on our site.
From guests
- What you submit to an event — your name, email address, RSVP response and answers to any other questions the organizer added to their form. Organizers decide what their forms ask for; we don't control that.
- Interaction with an event — which calendar you chose, whether you opened or clicked an event email, and similar activity, which we report back to the organizer for their own event.
When you submit something to an event, you're giving that information to the organizer. We handle it on their behalf — see section 5.
4How we use personal data
- To run the Services — create and publish event pages, generate calendar files and links, deliver RSVPs to organizers, and send the event emails organizers have asked us to send.
- For the purpose you gave it — if you email us a question, we use your address to answer it.
- To manage accounts and billing — authentication, subscriptions, invoices and receipts.
- To support you — answering questions and investigating problems, which sometimes means looking at the affected event or account.
- To improve CalGet — understanding which features get used and where people get stuck, mostly through aggregated statistics.
- To keep the Services safe — preventing abuse, spam and fraud, investigating violations of our Terms of Service, and protecting our systems and users.
- To send you service messages — changes to your account, billing notices, security alerts and important updates to the Services or our policies.
- To send you marketing — occasional email about features or news, if you're a registered user or asked to hear from us. You can unsubscribe from these at any time.
- To meet legal obligations — tax and accounting records, and responding to lawful requests.
We don't use your event content or guest lists to build advertising profiles, and we don't use them to train machine learning models of our own. If we ever want to use personal data in a way this policy doesn't describe, we'll tell you first and get your consent where the law requires it.
6How we store and protect it
We take reasonable technical and organizational measures to protect personal data against loss, misuse and unauthorized access — encryption in transit and at rest, restricted access to production systems, logging and monitoring, and regular backups. Annex B of our Data Processing Addendum describes these in detail.
No system is perfectly secure, and we can't guarantee absolute security. Please keep your password safe and think about what you put into an event page, which is often public by design.
7Access, correction and deletion
You can ask us for a copy of the personal data we hold about you, and ask us to correct or delete it. If you have an account, you can view, edit, export and delete most of it yourself from your account settings. Otherwise, email [email protected] and we'll help.
If you're a guest asking us to delete data you gave to an organizer, we can remove it from CalGet — even where that means the organizer loses access to it through us. But if the organizer already exported or received that data, it may still exist in their own systems, and you'll need to ask them directly.
We respond to requests as the applicable law requires, and we'll verify your identity before acting on one.
8How long we keep it
We keep personal data for as long as we need it to provide the Services to you — for an account, that generally means as long as the account is open. After an account is closed or an organizer asks us to delete their data, we remove it from our production systems within 90 days, and it ages out of backups on their normal cycle.
We keep some records longer where the law requires it, such as invoices and tax records, and we may keep limited information needed to enforce our terms, resolve disputes or prevent abuse.
10Your choices
- Give us less. You can browse most of our site without giving us personal data. Some things need it, though — you can't RSVP to an event without whatever the organizer's form requires.
- Marketing email. Every marketing email has an unsubscribe link. Opting out can take a short time to take effect across our systems.
- Organizer email. Emails an organizer sends through CalGet carry their own unsubscribe or preferences link, which stops that organizer from emailing you through us. It doesn't stop them contacting you by other means.
- Service email. Messages about your account, billing or security aren't marketing, and you can't opt out of them while your account is open.
- Cookies. Manage them through our cookie banner and your browser settings.
- Do Not Track. Browsers vary in how they send “Do Not Track” signals and there's no shared standard for honoring them, so we don't respond to them.
11What this policy doesn't cover
It doesn't cover what an organizer does with data you gave them, or anything you post publicly through the Services. It also doesn't cover other websites we link to — including sites an organizer links from their event page. Those have their own policies, and linking to them isn't an endorsement.
12Children
CalGet isn't intended for children under 13, and we don't knowingly collect personal data from them. If you believe a child under 13 has given us personal data, email [email protected] and we'll delete it. Organizers who collect data about children through CalGet are responsible for obtaining whatever consent the law requires.
13International transfers
CalGet is based in the United States and our servers and service providers are located there, so using the Services means your personal data is transferred to and processed in the United States. Privacy laws there may differ from those where you live.
Wherever your data goes, it stays covered by this policy, and we put appropriate safeguards in place for transfers out of Europe, the UK and Switzerland — see section 14 and our Data Processing Addendum.
14Europe, the UK and Switzerland
When we're a controller and when we're a processor
Data protection law separates organizations that decide why data is processed (“controllers”) from those that process it on someone else's instructions (“processors”). CalGet is both, depending on the situation.
- We're the controller for our own account holders' details, billing records, support conversations and website analytics.
- We're a processor for what guests submit to an event. The organizer decides what to ask for and why; we just provide the tools. Requests about that data should go to the organizer, and our Data Processing Addendum governs how we handle it.
Our legal bases
- Contract — to provide the Services you signed up for, including your account and billing.
- Legitimate interests — to secure and improve the Services, prevent abuse, and tell existing customers about relevant features, weighed against your rights.
- Consent — for non-essential cookies and marketing where consent is required. You can withdraw it at any time.
- Legal obligation — where a law requires us to keep or disclose data.
Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent. To exercise any of them, email [email protected]. We assess each request individually, since exemptions sometimes apply.
We also apply the GDPR's principles across the Services: processing data lawfully and transparently, collecting only what we need for a specific purpose, keeping it accurate, protecting it with appropriate security, and transferring it internationally only with proper safeguards.
If you're unhappy with how we've handled your data, please tell us first so we can try to fix it. You also have the right to complain to your local supervisory authority.
15US state privacy rights
If you live in California or another US state with a privacy law, you may have the right to know what personal data we collect and why, to request a copy, to ask us to correct or delete it, and not to be treated differently for exercising those rights.
We do not sell personal data, and we do not share it for cross-context behavioral advertising as those terms are defined by California law. To make a request, email [email protected]. You may use an authorized agent, and we'll take reasonable steps to verify the request before acting on it.
16Changes to this policy
We may update this policy as CalGet and the law change. The current version always lives on this page with the date it last changed at the top. For material changes we'll give you additional notice by email or in the app before they take effect. Continuing to use the Services after that means you accept the updated policy.
17Contact us
Questions, requests or complaints about privacy go to [email protected] and reach a person, not a queue. If your question is about data you submitted to someone else's event, contact that organizer — they decide what happens to it.