Privacy.

Skedday reads your calendar. This page says exactly what that means, what is kept, and how to get it back.

Plain English first

The short version

Your calendar holds the details of your week, and Skedday has to read it to offer an hour you can actually keep. That is the most sensitive thing we touch, so this notice starts there.

  • We read the timing of events on the calendars you connect. We do not need their contents and we do not store them.
  • We store what a booking needs: who booked, when, which link, and any answers they gave you on the booking page.
  • We do not sell anything to anyone, and we do not run advertising.
  • Disconnect a calendar and its access tokens are destroyed straight away. Delete a workspace and everything follows within thirty days.

What we collect

From the person who owns the workspace

Name, email address, password hash or identity-provider subject, workspace and team membership, plan and billing details, and the settings you configure: schedules, event types, workflows and routing rules.

From the person who books

Name, email address, the time zone their browser reports, the slot chosen, and any answers they give to the questions you set. If you take payment, Stripe or PayPal handles the card and we hold only the reference.

From the browser

A first-party session cookie, a theme preference in local storage, and aggregate, non-identifying page counts. No third-party advertising or cross-site tracking cookies are set by Skedday.

What we read from your calendar

Skedday requests the narrowest scope each provider offers. From every connected calendar we read the start time, end time and busy status of events in the booking window, and we write the events Skedday itself creates.

  • Event titles, descriptions, attendees and attachments are not read or stored.
  • Free/busy is held only long enough to render a page and is not retained afterwards.
  • Events Skedday creates are ours to update and cancel; nothing else on your calendar is ever modified.

How we use it

To compute availability, create and update meetings, send the notifications and workflows you configure, take payment where you have asked for it, answer support requests, keep the service secure, and meet our accounting obligations. That is the complete list.

Legal basis for processing

Under the UK GDPR and the EU GDPR we rely on the following bases.

  • Contract. Running the workspace you signed up for, including availability, bookings and notifications.
  • Legitimate interests. Keeping the service secure and working, and understanding aggregate usage. We have balanced these against your rights and you may object.
  • Consent. Connecting a calendar account, and any optional messaging you switch on. You may withdraw it at any time by disconnecting.
  • Legal obligation. Retaining invoices and tax records for the statutory period.

Where you use Skedday to schedule with your own customers, you are the controller of their data and Skedday is your processor. Our data processing agreement is available from the sales team and forms part of the contract.

Sub-processors

These providers process data on our behalf. We give thirty days’ notice before adding to this list, and Enterprise workspaces can subscribe to that notice.

ProviderPurposeWhere
Amazon Web ServicesHosting & storageIreland / chosen region
CloudflareEdge network & DDoSGlobal edge
StripeSubscription billingIreland & United States
PostmarkTransactional emailUnited States
TwilioSMS workflow deliveryUnited States
SentryError monitoringEuropean Union

How long we keep it

  • Calendar tokens. Kept until you disconnect, then destroyed straight away.
  • Free/busy data. Held in memory for the life of one request and no longer.
  • Bookings and answers. Kept for as long as the workspace exists, then thirty days.
  • Audit records. Ninety days on Teams, or whatever period is agreed on Enterprise.
  • Invoices. Seven years, because we are required to keep them.

Your rights

You can ask us for a copy of your data, correct it, delete it, restrict or object to processing, or take it elsewhere in a portable format. Workspace owners can export everything from the settings page without asking us at all.

We answer within thirty days. If you are not satisfied, you may complain to the Information Commissioner’s Office in the UK, or your local supervisory authority in the EEA.

International transfers

Workspace data lives in the region you choose when the workspace is created. Where a sub-processor operates outside the UK or EEA, transfers are covered by the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, with a transfer risk assessment on file.

Contacting us

Write to us through the contact page. Data protection questions are answered by the same small team that builds the product.

Preview build · This document is a well-formed template written for the Skedday marketing site. It has not been reviewed by a lawyer and must be replaced with counsel-approved wording before Skedday takes a single real customer.