Privacy Policy
Effective date: August 7, 2026 · webfaCe Bookings is operated by webfaCeMEdia ("we", "us"), Toronto, Canada. Contact: tommy@webfacemedia.com.
What this service does
webfaCe Bookings lets a business connect its Google Calendar so visitors to the business's website can book meetings against real availability.
Google user data we access
When a business owner connects their Google account we request these scopes, and use them only as described:
- calendar.events — used solely to create, update, and delete the booking events that guests schedule through this service, on the connected calendar, at the account owner's direction. We do not read, list, or process any other events.
- calendar.freebusy — used solely to read busy/free status so open booking slots can be computed. Free/busy queries return time intervals only; we never access event titles, descriptions, attendees, or any other event content through this scope.
- email — used solely to display which Google account is connected.
How Google user data is stored and protected
- The OAuth refresh token is stored encrypted at rest (AES-256-GCM) on servers located in Toronto, Canada, and is used only to obtain short-lived access tokens for the operations above.
- Busy/free responses are used in-memory to compute availability and are not stored.
- Booking details entered by a guest (name, email, notes, meeting time) are stored so the booking can be managed, and are shared only with the business the guest booked with.
Who we share data with
We do not sell Google user data, and we do not share, transfer, or disclose it to third parties, with these narrow exceptions:
- The business a guest books with: a guest's booking details (name, email, chosen time) are shared with that business only. Availability derived from the connected calendar is shown publicly only as open/closed time slots — never as event content.
- Infrastructure service providers that host and operate this service on our behalf (servers located in Toronto, Canada, operated on DigitalOcean; transactional email delivered through our email delivery provider). These providers process data solely to run the service and are bound by their own confidentiality and security obligations. OAuth tokens and free/busy data are never sent to any other third party.
- Legal requirements: if we are required to disclose information by applicable law or valid legal process.
No advertising networks, data brokers, or analytics companies receive Google user data from this service.
How we protect sensitive data
- All data in transit is encrypted with TLS (HTTPS everywhere, including calls to Google APIs).
- OAuth refresh tokens — the only long-lived Google credential we hold — are encrypted at rest with AES-256-GCM; the encryption key is stored separately from the database and never leaves our servers.
- We request only the narrowest granular OAuth scopes needed (calendar.events and calendar.freebusy — never full calendar or mail access), so the credential could not read event content even if misused.
- Free/busy responses are processed in memory and never written to storage.
- Access to production systems is restricted to authorized webfaCeMEdia operators over key-based authentication; database replicas are kept on access-controlled servers in Canada.
- Tokens are revoked at Google and deleted from our systems on disconnect, and connections that lose validity are disabled automatically.
Limited Use disclosure
The use of raw or derived user data received from Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties, do not use it for advertising, do not sell it, and no humans read it except with the account owner's consent, for security purposes, or to comply with law.
This application does not use artificial intelligence or machine-learning models on Google user data in any form: raw or derived Google user data is never used to develop, improve, or train AI/ML models, and is never transferred to any third-party AI/ML service.
Data retention and deletion
A business can disconnect its Google account at any time (from this service or from Google account permissions); disconnecting invalidates and deletes the stored token. Booking records are retained for the business's own records and deleted on request to tommy@webfacemedia.com.
Changes
We will post any changes to this policy on this page.