← Back to home
Privacy Policy
Last updated: July 31, 2026
Calign is a booking and storefront platform for service businesses, operated as a sole proprietorship by its owner. This policy explains what data we collect and how we use it. It is maintained by Calign and is not legal advice or a certification. It should be read together with our Terms of Service.
Who is responsible for your data
- Business account data — Calign is the controller. We decide how account, billing, and platform-usage data is handled.
- Customer booking data — the Business you booked with is the controller and Calign is its processor. We handle that data on the Business's instructions to run its bookings, messages, and payments.
- If your request concerns a specific booking, contact the Business first. We will help where we can, and we may need the Business's authorisation before acting.
What we collect
- Account data you give us — name, email, business details, service configuration.
- Booking data your customers submit — name, email, phone, address, appointment details.
- Content you create — storefront copy, photos, logos, quotes, messages, and reviews.
- Usage data such as log entries and error reports needed to run the service.
- Marketplace and analytics data — storefront impressions, page views, time on page, clicks, and a random session identifier that is not linked to your identity.
- Payment metadata (never full card numbers) when using paid features.
- Approximate location derived from an address you enter, used for travel-radius and distance filtering.
How we use it
We use your data to run the platform, send you and your customers transactional messages (confirmations, reminders, quotes), improve the product, and meet our legal obligations. We also use it to detect fraud and abuse, secure accounts, measure storefront performance, and deliver and pace promoted listings. We don't sell personal data, and we don't run third-party advertising trackers.
Legal bases
Where the GDPR or similar law applies, we rely on: performance of a contract (running your account and bookings), legitimate interests (security, fraud prevention, product improvement, measuring platform performance), consent (optional marketing and connected integrations), and legal obligation (tax, accounting, and lawful requests).
Subprocessors
We use trusted subprocessors to operate, each given only the data it needs for its role and bound by contract:
- Cloud hosting and edge delivery — serving the app and APIs.
- Managed database and authentication — storing account, booking, and content data.
- Email delivery — sending transactional and account email.
- Stripe — payment processing, connected payouts, and subscription billing.
- AI model providers — powering the receptionist, quotes, summaries, and moderation, accessed through a gateway.
- Mapping and geocoding — converting addresses into approximate coordinates for distance checks.
AI processing
When you use an AI feature, the content needed for that feature is sent to a model provider — for example a booking or job description for a quote estimate, review text for summaries and sentiment, message text for moderation and replies, and photos you attach to a quote request. We instruct our providers not to use this content to train their models, and we do not use Google user data for model training. AI output is generated automatically and may be inaccurate; see Section 9 of the Terms.
Marketplace, analytics, and promoted listings
To power the storefront Performance dashboard and to pace promoted campaigns, we record events such as impressions, storefront visits, clicks, conversions, and approximate time on page. These are tied to a random per-session identifier stored in your browser, not to your name. Aggregated figures are shown to the Business whose storefront you viewed; individual visitors are not identified to them.
Cookies and local storage
We use cookies and browser storage that are necessary to run the service: keeping you signed in, remembering preferences such as theme and dismissed prompts, and holding the anonymous session identifier used for analytics. We do not use third-party advertising or cross-site tracking cookies.
Google user data
When you connect your Google account (for example, to sync Google Calendar), Calign accesses Google user data solely to provide the features you enable — such as reading and writing calendar events to prevent booking conflicts. Calign's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Calign requests only the minimum Google OAuth scopes needed for these features:
Google user data is never sent to any AI or machine-learning service. Our AI features (booking assistant, receptionist, summaries, and moderation) operate exclusively on data entered directly into Calign by businesses and their customers. No Google user data — raw, aggregated, anonymized, or derived — is used in AI prompts, embeddings, fine-tuning, or to create, train, or improve any foundational or generalized AI/ML model.
We do not sell, rent, or share Google user data with third parties for advertising, marketing, or any purpose unrelated to the features you enable. We do not use Google user data to train generalized or large language models (AI/ML models).
Google user data is only shared with the following categories of recipients, and only to the extent necessary to operate the service you requested:
You can disconnect Google at any time from your dashboard, or request full deletion by writing to privacy@calign-ai.com.
Calign requests only the minimum Google OAuth scopes needed for these features:
openid, email, and https://www.googleapis.com/auth/calendar.events. When importing your existing calendar commitments, Calign stores only the opaque Google event identifier and the event's start and end times. Event titles, descriptions, attendees, locations, organizers, and conference details are never stored.Google user data is never sent to any AI or machine-learning service. Our AI features (booking assistant, receptionist, summaries, and moderation) operate exclusively on data entered directly into Calign by businesses and their customers. No Google user data — raw, aggregated, anonymized, or derived — is used in AI prompts, embeddings, fine-tuning, or to create, train, or improve any foundational or generalized AI/ML model.
We do not sell, rent, or share Google user data with third parties for advertising, marketing, or any purpose unrelated to the features you enable. We do not use Google user data to train generalized or large language models (AI/ML models).
Google user data is only shared with the following categories of recipients, and only to the extent necessary to operate the service you requested:
- Our infrastructure subprocessors — cloud hosting (Cloudflare) and our managed database (Supabase), which store event metadata and OAuth tokens on our behalf under contract.
- Members of your own business account — owners and staff you invite may see calendar availability and event data connected to your business, so appointments can be scheduled and managed.
- Law enforcement or regulators — only where we are legally required to disclose data in response to a valid legal request.
You can disconnect Google at any time from your dashboard, or request full deletion by writing to privacy@calign-ai.com.
Retention
We keep booking and account data for as long as your account is active and for a reasonable period afterward to meet legal, accounting, and dispute-resolution needs. You can request deletion at any time. Payment and invoice records may be retained longer where tax or accounting law requires it, and backups are cycled out on a rolling schedule.
Your choices
You can update your data from your dashboard, unsubscribe from marketing email at any time, and request export or deletion by writing to privacy@calign-ai.com. Depending on where you live, you may also have the right to access, correct, port, restrict, or object to processing, and to complain to your local data-protection authority. We will not discriminate against you for exercising these rights.
International transfers
Calign and its subprocessors operate globally, so your data may be processed in countries other than your own, including the United States. Where required, we rely on recognised transfer mechanisms such as standard contractual clauses with our providers.
Children
Calign is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
Legal requests and disclosures
We may disclose data where we reasonably believe it is required by law, to respond to a valid legal request, to enforce our terms, to prevent fraud or harm, or in connection with a sale, merger, or reorganisation of the business — in which case this policy continues to apply to the transferred data.
Security
We use industry-standard controls including encryption in transit, hashed credentials, row-level security on our database, and least-privilege access. No system is perfect; report suspected issues to security@calign-ai.com. If a breach affects your personal data, we will notify affected users and any required regulators without undue delay once we have assessed the incident.
Changes to this policy
We may update this policy as the product changes. The "last updated" date above will change, and material changes will be highlighted in the app or by email where appropriate.