Privacy Policy
Effective date: August 7, 2026 · webfaCe Bookings is operated by webfaCeMEdia Inc. ("we", "us"), Toronto, Canada. Contact: tommy@webfacemedia.com.
What this service does
webfaCe Bookings lets a business connect its Google Calendar so visitors to the business's website can book meetings against real availability.
Google user data we access
When a business owner connects their Google account we request these scopes, and use them only as described:
- calendar.events — used solely to create, update, and delete the booking events that guests schedule through this service, on the connected calendar, at the account owner's direction. We do not read, list, or process any other events.
- calendar.freebusy — used solely to read busy/free status so open booking slots can be computed. Free/busy queries return time intervals only; we never access event titles, descriptions, attendees, or any other event content through this scope.
- email — used solely to display which Google account is connected.
How Google user data is stored and protected
- The OAuth refresh token is stored encrypted at rest (AES-256-GCM) on servers located in Toronto, Canada, and is used only to obtain short-lived access tokens for the operations above.
- Busy/free responses are used in-memory to compute availability and are not stored.
- Booking details entered by a guest (name, email, notes, meeting time) are stored so the booking can be managed, and are shared only with the business the guest booked with.
Limited Use disclosure
webfaCe Bookings' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties, do not use it for advertising, do not sell it, and no humans read it except with the account owner's consent, for security purposes, or to comply with law.
Data retention and deletion
A business can disconnect its Google account at any time (from this service or from Google account permissions); disconnecting invalidates and deletes the stored token. Booking records are retained for the business's own records and deleted on request to tommy@webfacemedia.com.
Changes
We will post any changes to this policy on this page.
