Privacy policy
Last updated: October 5, 2026
DoorCal is a free, open-source scheduling service. People connect their Google Calendar, publish booking links, and others use those links to book meetings with them. This policy explains what data DoorCal collects, how it is used and shared, how it is protected, and how you can delete it. It applies to the service at doorcal.com. Copies of the open-source code run by other people are separate services with their own policies.
In this policy, a host is someone who signs in with Google and shares booking links, and an invitee is someone who books a meeting through a host's link.
1. Information we collect
From hosts, through Google sign-in
- Your name, email address, profile picture and Google account ID.
- An OAuth refresh token that lets DoorCal reach your Google Calendar while you are not on the site, for example when someone books you. It is stored encrypted.
From hosts, through Google Calendar
DoorCal asks for three Google Calendar permissions and uses each one only as described here:
- See your free/busy information (
calendar.freebusy). When someone opens your booking page or books a time, we check which times you are busy across the calendars you chose, so nobody can book you when you are not free. We only receive busy time ranges, not event details, and we don't store them. - See the list of your calendars (
calendar.calendarlist.readonly). On the Settings page we list your calendars so you can choose which ones count for conflicts and which one new bookings go to. We store only the IDs of the calendars you select. - View and edit events on your calendars (
calendar.events). We use this to show your events in your DoorCal dashboard, to create the calendar event (with a Google Meet link for online meetings) when someone books you or when you create a meeting in DoorCal, to update it when a booking is rescheduled, and to delete it or remove an attendee when a booking is cancelled. We store the ID and Google Meet link of events DoorCal creates for bookings. We don't store the contents of your other events; they are fetched when you view your dashboard and not kept.
Settings hosts create
Your username, display name, headline, welcome message, time zone, availability schedules and event types, including any questions you ask invitees.
From invitees
When you book a meeting we collect the details you enter: your name, email address, any guest email addresses, a phone number if the meeting is a phone call, your answers to the host's questions, your notes, and your time zone. Invitees don't need an account and we don't access invitees' calendars.
Technical information
- Cookies: a session cookie that keeps hosts signed in (30 days) and a short-lived cookie used during Google sign-in (10 minutes). We don't use analytics, advertising or tracking cookies.
- IP addresses, used to limit abuse of booking pages. We store only a one-way hash of your IP address in short-lived request counters, never the address itself.
- Standard request logs kept by our hosting provider for operating and securing the service.
2. How we use information
- To provide scheduling: show availability, take bookings, and create, update and cancel calendar events.
- To show hosts their calendar, bookings and settings in the dashboard.
- To let invitees view, reschedule or cancel their own booking.
- To keep the service secure and working, including preventing spam and abuse.
We don't use your data for advertising, we don't sell it, and we don't build profiles of you.
3. Google user data and Limited Use
DoorCal's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide and improve the scheduling features you use.
- We don't transfer it to others except as needed to provide the service, to comply with law, or as part of a merger or acquisition with notice to you.
- We don't use it for advertising, including retargeting, personalized or interest-based ads.
- We don't sell it, and we don't use it to train or improve generalized AI or machine-learning models.
- No person reads your Google data unless you ask us to (for example for support), it is needed for security or to investigate abuse, or the law requires it.
4. How information is shared
- Between host and invitee. When an invitee books, the host sees the details the invitee entered, and both see the meeting details. These details are written into the host's Google Calendar event, and Google sends the invitation and any updates to the invitee and their guests.
- Service providers that run DoorCal for us and may process data only on our instructions: Vercel (hosting) and Neon (database). Data may be processed in the United States and other countries where these providers operate.
- Google, to read and update your calendar as described above.
- When required by law, or to protect the rights, safety and security of users and the service.
We don't sell or rent personal information to anyone.
5. How information is protected
- All traffic to DoorCal is encrypted with HTTPS.
- Google refresh tokens are encrypted at rest with AES-256-GCM. We don't store Google access tokens.
- A host's dashboard, calendar and bookings are available only to that host after signing in. A host's public profile and event types are visible to anyone with the link, by design. Invitees can reach only their own booking, through its private link.
- Our database provider encrypts stored data, and access to production systems is limited to the operator.
No system is perfectly secure, but we work to protect your data and will notify affected users of a breach as required by law.
6. How long we keep data, and how to delete it
- Hosts: your data is kept while your account exists. You can delete your account at any time in Settings → Delete account. This immediately deletes your profile, settings, event types, schedules and booking history from our database and revokes DoorCal's access to your Google account. Calendar events already on your Google Calendar stay there, under your control.
- Disconnecting Google (Settings → Disconnect) deletes the stored token and revokes access without deleting your account. You can also revoke access at any time at myaccount.google.com/permissions.
- Invitees: booking details are kept as part of the host's booking history until the host deletes their account, or until you ask us to delete them.
- Deleted data may remain in our database provider's backups for a short period (up to about 30 days) before it is overwritten.
7. Your choices and rights
You can see and change your data in the dashboard, and delete it as described above. You can also ask us to access, correct, export or delete your personal information, including booking details you entered as an invitee, by contacting us. Depending on where you live, you may have further rights under privacy laws such as PIPEDA, the GDPR or US state laws, and you may complain to your data protection authority.
8. Children
DoorCal is not directed to children under 13 and we don't knowingly collect their personal information. If you believe a child has given us information, contact us and we will delete it.
9. Changes to this policy
We will post any changes on this page and update the date above. If a change materially affects how we use Google user data or other personal information, we will tell hosts by email before it takes effect.
10. Contact
Email hadi.fariborzi@gmail.com. We aim to reply within 7 days.
See also the terms of service.