GetCalendario.com
Home Pricing Docs Why Us / Contact Us
Login Register
Home
Pricing Docs Why Us / Contact Us
Login Register

Privacy Policy

Effective date: 20 August 2026
Last updated: 30 September 2026

This policy explains what GetCalendario collects, why we collect it, who we share it with, and the control you have over it. It covers https://getcalendario.com and the GetCalendario application.

GetCalendario exists to keep your calendars in sync. We are not an advertising business. We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not analyze the content of your calendar events for any purpose other than performing the sync you asked for.

1. Who we are

GetCalendario is a service operated by Syncromate, LLC, which is the data controller for the personal information described in this policy.

Syncromate, LLC
5404 S. Florence Ct
Greenwood Village, CO 80111
United States
Email: support@syncromate.com
Phone: (720) 500-3087

2. What we collect

Account information. Your name, email address, and a securely hashed version of your password. Optionally a profile image if you upload one. We never store your password in a readable form.

Security information. If you enable two-factor authentication we store either a one-time code sent to your email, or a secret used by your authenticator app. We also keep ordinary session data so you stay signed in.

Calendar connection credentials. When you connect a calendar account we store the access and refresh tokens issued by that provider (Google, Microsoft, or Cronofy). These let us keep syncing without asking you to sign in repeatedly. We never see or store your password for those accounts.

Calendar event data. To copy an event from one calendar to another, and to detect when it later changes or is deleted, we store a record of the events covered by your connections. That record can include the event's title, description or notes, start and end time, time zone, location, meeting link, and whether the event is marked private. We also keep a short history of changes to those events so that syncs stay consistent.

Daily Backups. On every plan except Free, we can keep a copy of your calendars each night so you can get back what they held on an earlier day. Backups are off until you choose where they go: your own storage (Amazon S3 or a compatible service, Azure, Dropbox, Google Drive or OneDrive), locked or not, or our servers, locked or not. If you sign in with a passkey and have not chosen, we keep them on our servers locked so that only your passkey or your recovery code can open them; we cannot read them. A backup is the full event as your calendar provider holds it, including attendees' names and email addresses. When backups go to your own storage we write each night's file there and keep no copy; the credentials you give us for it are kept encrypted, and deleted when you disconnect it. For Amazon S3 and Azure we can work with upload-only access, and we check after every delivery that we still cannot read what we wrote. Which calendars are included, and whether other people's shared calendars are, is up to you.

We want to be plain about this, because it is the question people most often ask: syncing calendars is not possible without holding a copy of the events being synced. What we do not do is read that content for any other purpose, profile you with it, use it for advertising, or sell it. You can delete it at any time by removing a connection or your account, and we delete it automatically when you do.

Sharing information. If you share a calendar view with someone, we store the email address you shared it with, a hashed version of the invite link, its expiry, and a hashed one-time code used to verify that person's email. One-time codes expire after ten minutes and are deleted once used.

Billing information. Payments are processed by Stripe. We store your Stripe customer and subscription identifiers and your plan status. We never receive or store your full card number.

Technical and diagnostic information. Our servers log standard request data such as IP address, browser type, pages visited, and timestamps. If something goes wrong we collect error reports containing technical details of the failure.

3. Why we use it, and our legal basis

Where the UK or EU GDPR applies, we rely on the following bases:

  • To perform our contract with you — creating and running your account, connecting your calendars, performing syncs, storing event records so syncing works, sharing calendars at your request, and taking payment.
  • Our legitimate interests — keeping the service secure, preventing abuse, diagnosing faults, understanding aggregate website usage, and communicating with you about the service. We balance these against your rights and use the least intrusive option that works.
  • Your consent — for optional marketing email, and for any non-essential cookies where consent is required. You can withdraw consent at any time.
  • Legal obligation — retaining billing and tax records, and responding to lawful requests.

4. Google user data and Limited Use

When you connect a Google account, GetCalendario requests access to your Google Calendar data in order to read the events you choose to sync and to write the synced copies.

GetCalendario's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we use Google user data only to provide and improve the calendar syncing features you have asked for. We do not transfer it to others except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to you. We do not use it for advertising, and we do not allow humans to read it except with your explicit permission for support purposes, where required by law, or where it is necessary for security or to comply with applicable law. The same commitments apply to data we receive from Microsoft and Apple calendar accounts.

You can revoke our access at any time from your Google account permissions page, or by removing the account inside GetCalendario.

5. Who we share information with

We use a small number of service providers. They act on our instructions and may use your information only to provide their service to us.

Provider Purpose Data involved
DigitalOceanHosting, databases, and outgoing emailAll service data
Amazon Web ServicesFile storage for Daily BackupsCopies of your calendar events, including attendees
StripePayments and subscriptionsName, email, payment details
CronofyCalendar connectivityCalendar credentials and event data
GoogleGoogle Calendar sync, when you connect a Google accountCalendar credentials and event data
MicrosoftOutlook, Office 365 and Exchange sync, when you connect oneCalendar credentials and event data
Keap (Infusionsoft)Customer records and service emailName, email, plan status
Segment (Twilio)Product analyticsName, email, account identifiers, sign-ins and billing events
SentryError monitoringTechnical diagnostic data, which can include email addresses
Fathom AnalyticsPrivacy-focused website analyticsAggregate, non-identifying usage data

We may also disclose information to professional advisers, or to courts, regulators and law enforcement where we are legally required to do so or to establish or defend legal claims. If we are ever involved in a merger, acquisition or sale of assets, we will tell you before your information becomes subject to a different privacy policy.

We do not sell your personal information, and we have not done so in the preceding twelve months.

6. How long we keep it

  • Calendar event records — kept while the connection that created them exists. Delete a connection and the associated event records are deleted with it.
  • Daily Backups — on our servers, each nightly backup is deleted after 30 days. In your own storage, how long they are kept is up to you; we never delete there.
  • Calendar credentials — kept until you disconnect that account or delete your account.
  • Account information — kept for as long as your account is open. When you delete your account we permanently delete your profile, connections, calendars, event records and calendar shares.
  • Shared-calendar recipients — email addresses of people you shared with are removed automatically once they are no longer attached to any share; we run this clean-up weekly.
  • One-time verification codes — expire after ten minutes and are deleted on use.
  • Billing records — retained as long as required for tax and accounting purposes, typically seven years.
  • Server and error logs — retained for a short period for security and debugging, then discarded.

7. Where your information is processed

We process personal information in the United States. If you are in the United Kingdom, the European Economic Area, or another region with data transfer restrictions, transfers are made under appropriate safeguards — typically the European Commission's Standard Contractual Clauses and the UK Addendum, or an applicable adequacy decision. You can ask us for details of the safeguards that apply to you.

8. Your rights

Wherever you live, you can ask us to give you a copy of your information, correct it, delete it, or stop using it in a particular way. Email support@syncromate.com and we will respond within the time your local law requires — within one month under the GDPR, and within 45 days under California law.

If the UK or EU GDPR applies to you, you have the right to access, rectification, erasure, restriction of processing, objection to processing, and data portability, plus the right to withdraw consent at any time without affecting processing already carried out. You also have the right to complain to your local supervisory authority — in the UK, the Information Commissioner's Office.

If you are a California resident, you have the right to know what personal information we collect and why, to obtain a copy of it, to have it deleted, to correct it, and to be free from discrimination for exercising those rights. Because we do not sell or share personal information for cross-context behavioral advertising, there is nothing to opt out of, but we honour Global Privacy Control signals as an opt-out request regardless. We do not use or disclose sensitive personal information for purposes that require offering a right to limit.

We may need to verify your identity before acting on a request, and you may use an authorized agent.

9. Cookies and analytics

We use a small number of cookies, and no advertising cookies.

  • Session — keeps you signed in. Strictly necessary; it expires when you close your browser.
  • XSRF-TOKEN — protects forms against cross-site request forgery. Strictly necessary.
  • gc_ref — set only when you arrive through a customer's referral link, so that customer is credited if you later subscribe. It holds their referral code and nothing about you, and it expires after 90 days.
  • Stripe — only when you start a checkout, our payment processor Stripe loads its checkout script, which sets its own fraud-prevention cookies. See Stripe's cookie policy.
  • YouTube — our homepage has an explainer video. Nothing loads from YouTube until you press play; then the video is played from YouTube's privacy-enhanced mode (youtube-nocookie.com), which may store data in your browser under Google's privacy policy.

On our marketing pages we use Fathom Analytics, which measures traffic without cookies or cross-site tracking.

You can block or delete cookies in your browser settings, though doing so will stop you signing in.

10. Security

Data is encrypted in transit and at rest. Passwords are hashed and never stored in readable form. Access to production systems is limited to the people who need it. Two-factor authentication is available on every account and we recommend turning it on.

No online service can promise perfect security. If a breach affects your personal information we will notify you and the relevant regulators as required by law.

11. Children

GetCalendario is not intended for children. We do not knowingly collect personal information from anyone under 16, or under the minimum age of digital consent in your country if that is higher. If you believe a child has given us personal information, contact us and we will delete it.

12. Other sites

Our site links to services we do not operate, including our calendar partners. Their privacy practices are their own, and this policy does not cover what happens after you leave our site.

13. Changes to this policy

We may update this policy as the service changes or the law does. The date at the top always reflects the current version. If a change materially affects how we handle your information, we will email registered users before it takes effect, and where the law requires it we will ask for your consent.

14. Contact us

Questions, requests, or complaints about privacy:

Syncromate, LLC
5404 S. Florence Ct
Greenwood Village, CO 80111
United States
support@syncromate.com
(720) 500-3087

GetCalendario.com
Terms and Conditions Privacy Policy Docs Contact
Copyright

2026 Syncromate, LLC — All Rights Reserved