Privacy policy
Last updated 2026-08-15
Punctual is a scheduling service. This policy describes what Punctual collects when you use the hosted service at https://punctual.sh, and why.
What we collect
If you are a host (you have an account)
- Your email address and name — to identify your account and send you booking notifications.
- Your timezone and availability — to calculate which times you can be booked.
- Calendar connection tokens — encrypted at rest with AES-GCM, used only to read your busy times and write bookings you receive.
If you are a guest (you booked a meeting)
- Your name and email address — to identify the booking and send you the confirmation and calendar invitation.
- Answers to questions the host asked — passed to the host, and included in the calendar event.
- Your timezone — to show you times in your own timezone. Detected from your browser or your network location, and you can change it.
We do not use cookies for advertising or analytics. The booking page sets no cookies at all. A session cookie is set only when a host signs in.
Google Calendar and Microsoft 365 data
When you connect a calendar, we request the narrowest scopes that let the product work:
- Free/busy times — we read when you are busy. We do not read the titles, descriptions, attendees or locations of your existing events.
- Events — we create, update and delete only the events that Punctual itself books. We do not modify events created elsewhere.
- Calendar list — read-only, so you can choose which calendars to check and which one to write to.
Free/busy data is not stored. It is fetched when a booking page is rendered, cached for at most 60 seconds to avoid hammering the provider, and never written to our database.
Punctual's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to others except as needed to provide the service, do not use it for advertising, and do not allow humans to read it except with your explicit consent, for security purposes, or where required by law.
Who we share with
We do not sell personal data. We share only with processors required to run the service: our hosting provider (Cloudflare) and our transactional email provider. Booking details are shared with the other party to the meeting — which is the point of a booking.
How long we keep it
- Bookings are kept while your account exists, so you have a record of your meetings.
- Calendar tokens are deleted immediately when you disconnect a calendar.
- Deleting your account deletes your bookings, availability and connections.
Your rights
You can export or delete your data, and revoke calendar access at any time — from your Punctual settings, and independently from your Google account permissions page. If you are a guest and want your booking data removed, email us and we will remove it.
Under GDPR you have the right of access, rectification, erasure, restriction, portability and objection. Contact hello@punctual.sh.
Security
Calendar refresh tokens are encrypted with AES-GCM before storage. Session identifiers and API keys are stored only as hashes. Links in emails that let a guest reschedule or cancel are signed and expire.
Self-hosting
Punctual is open source. If you run your own instance, you are the data controller for it: your data stays in your own infrastructure and this policy does not apply to it.