Privacy Policy

Last updated: September 19, 2026

Availyx ("we", "us") provides scheduling pages that let people ("guests") book time with an Availyx account holder ("host"). This policy explains what information we collect, how we use it, and the choices you have. It applies to availyx.com and any subdomains.

Information we collect

From hosts

  • Google account details when you sign in: your Google account ID, email address, name and profile image.
  • Settings you create: public username, timezone, availability rules, event types and their descriptions.
  • Google Calendar data, described in the next section, only after you connect a calendar.

From guests

  • Details you enter on a booking page: name, email address, an optional phone number and an optional message.
  • The timezone you select and the time you book.
  • A long random token that lets you cancel or reschedule from your confirmation page or calendar invitation. We store only a hash of it.

Automatically

  • Standard server logs (IP address, browser type, requested page, timestamp) kept briefly for security, abuse prevention and debugging.
  • Product usage events such as "booking confirmed" or "calendar connected". These never include calendar contents or guest messages.
  • A session cookie for signed-in hosts. We do not use advertising or cross-site tracking cookies.

Google Calendar data and Limited Use

When a host connects Google Calendar, we request permission to list their calendars, read free/busy time on the calendars they choose for conflict checking, and create, update and delete the events Availyx schedules. We do not read the titles, descriptions, attendees or locations of existing events; free/busy lookups return only "busy" time ranges.

Availyx's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only to provide the scheduling features you asked for. It is never sold, used for advertising, or shared with third parties except as needed to deliver the service (for example, a booking creates a calendar event that Google then shares with the guest).

OAuth tokens are encrypted at rest with a key held separately from the database and are never sent to the browser. You can revoke access at any time from Availyx (Calendar → Disconnect) or from your Google Account security settings.

How we use information

  • To show hosts' availability accurately and to create bookings without conflicts.
  • To create calendar events that invite the guest, and to update or cancel them when a booking changes.
  • To let guests and hosts manage bookings, and to show hosts their upcoming and past bookings.
  • To keep the service secure, prevent abuse and fix problems.
  • To understand which features are used so we can improve the product.

We do not send marketing email. Booking invitations and updates are delivered by Google Calendar.

Who can see what

  • A host's name, profile image, username and active event types are public on their booking pages.
  • A guest's details are shared with the host they book with, and appear on the calendar event Google creates for both parties.
  • Guests never see other guests' bookings, and a management link only opens the one booking it belongs to.

Service providers

Availyx runs on Cloudflare (hosting, database and network security) and integrates with Google (sign-in and Calendar). These providers process data on our behalf under their own privacy commitments. We do not sell personal information.

Retention and deletion

  • Host accounts and their data are kept until the host deletes the account from Settings, which removes the profile, calendar connection, availability, event types and booking records from Availyx. Events already on Google Calendar remain there.
  • Disconnecting Google Calendar deletes the stored tokens immediately.
  • Booking records, including guest details, are kept for the host's history until the host's account is deleted. Guests may ask a host, or contact us, to have a booking removed.
  • Server logs are retained for a short period, typically under 30 days.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal information, or to object to certain processing. Hosts can do most of this directly in Settings. For anything else, email us and we will respond within 30 days.

Security

All traffic uses HTTPS. Session cookies are HTTP-only and restricted to our site. Calendar tokens are encrypted at rest, and guest management links use unguessable tokens stored only as hashes. No method of transmission or storage is perfectly secure, so please report any concerns to us promptly.

Children

Availyx is not directed to children under 16 and we do not knowingly collect their information.

Changes

We may update this policy as the service evolves. The date at the top shows the latest revision. Material changes will be announced on the site before they take effect.

Contact

Questions or requests about privacy: privacy@availyx.com.