Legal

Privacy, without the fog.

This policy explains what Schedra collects, why we need it, who receives it and the controls available to you.

Last updated 30 August 2026

1. Who this policy covers

This policy applies when you create or use a Schedra account, join a Schedra team, connect an integration, visit a Schedra booking page, or make a booking through Schedra. In this policy, “Schedra”, “we”, “us” and “our” refer to the operator of the Schedra service.

Questions and privacy requests can be sent to support@schedra.xyz.

2. Information we collect

Account and profile information

We collect information you provide, such as your name, email address, username, password verifier, timezone, profile biography and profile photo. Team accounts also contain organization details, roles, invitations and membership history.

Scheduling and booking information

We process schedules, availability rules, event types, meeting locations, booking questions and the information a guest supplies when booking. This can include a guest’s name, email address, timezone, additional guests and answers to booking questions.

Connected services

If you connect a calendar or video provider, we receive the account identifier, account label, granted permissions and OAuth credentials needed to operate the integration. Access and refresh tokens are encrypted before database storage.

For Google Calendar, Schedra reads the calendars you select for conflict checking and writes booking events to the calendar you choose. For Zoom, Schedra creates, updates and deletes meetings for bookings whose location is Zoom. Schedra does not access Zoom meeting audio, video, chat, recordings, transcripts, participant activity or analytics.

Billing information

For paid team plans, we keep subscription, seat, invoice, currency and payment-status information. Payment providers process card and bank details; Schedra does not store complete payment-card or bank-account numbers.

Technical and security information

We process session identifiers, IP addresses, browser request data, security and rate-limit events, delivery attempts and integration error records to operate and protect the service.

We use Umami for cookieless, aggregate usage analytics. Analytics requests first go through a Schedra endpoint and are then forwarded to Umami. Umami can process page views, visits, referring-site domains, browser and device information and approximate country. The proxy forwards the requesting IP address and browser user agent so Umami can estimate anonymous visits, device types and country, but it does not forward Schedra cookies or authorization details. Before a page view is sent, Schedra replaces dynamic URL values with general route categories and removes paths and query values from referrers. Usernames, team slugs, booking and invitation identifiers, private-link tokens, query strings, form values and email addresses are not sent to Umami.

3. How we use information

  • Provide booking pages, availability calculations, reminders and account features.
  • Prevent double-booking and keep connected calendars and meetings synchronized.
  • Authenticate users, prevent abuse and investigate security or reliability incidents.
  • Deliver service messages, including verification, booking and billing emails.
  • Administer team subscriptions, invoices and occupied seats.
  • Understand visitor journeys and improve the usability and reliability of Schedra.
  • Comply with legal obligations and enforce our Terms.

We do not sell personal information and we do not use third-party advertising trackers.

4. When information is shared

We share information only as needed to provide the service, follow your instructions, protect Schedra and its users, or comply with law. Recipients can include:

  • The host, guest and invited attendees involved in a booking.
  • Members of a team, according to their role and the team features they use.
  • Google and Zoom when a user connects and uses those integrations.
  • Infrastructure, database, analytics, email-delivery and payment providers acting for Schedra, including Umami for aggregate usage analytics.
  • Authorities or professional advisers where disclosure is legally required or necessary to protect rights and safety.

Providers are given only the information required for their function and are expected to protect it under contract and applicable law.

5. Retention and deletion

Account and scheduling data is kept while the account is active. Operational security logs, delivery records, completed booking records and billing records may be retained for a limited period where needed for security, support, accounting, dispute resolution or legal compliance.

Disconnecting Google Calendar or Zoom revokes the connection and removes the encrypted credentials stored by Schedra. Zoom’s deauthorization event also removes the related local meeting mappings and join links. Deleting a Schedra account removes the account’s booking links, schedules, bookings and connected-service credentials, subject to records we must retain by law and short-lived infrastructure backups that expire through their normal cycle.

Team owners must transfer ownership or archive their teams before deleting their account so a team cannot be left without an owner.

6. Your choices and rights

You can update profile and scheduling information, disconnect integrations, export your data, or delete your account from Settings. Depending on where you live, you may also have rights to access, correct, delete, restrict or object to processing, or receive a portable copy of your data.

Send a request to support@schedra.xyz from the email address associated with your account. We may need to verify your identity before acting.

Umami does not use analytics cookies on Schedra, and Schedra respects your browser’s Do Not Track setting. You can enable Do Not Track in your browser to prevent these page-view measurements.

7. Security and international processing

Schedra uses access controls, encrypted transport, encrypted integration credentials, request validation, rate limiting and database constraints designed to protect personal information. No online service can guarantee absolute security, so please use a unique, strong password and contact us if you believe your account is at risk.

Schedra and its providers may process information in countries other than your own. Where required, we use contractual and legal safeguards for those transfers.

8. Children and changes to this policy

Schedra is not directed to children under 16, and we do not knowingly collect account data from them. If you believe a child has provided information, contact us so we can investigate.

We may update this policy as Schedra changes. We will publish the revised policy with a new effective date and provide additional notice when a change materially affects your rights.