1. Who we are
Interactive Calendar is operated by Interactive Net Solutions. The service is available at calendar.interactivenet.app.
For privacy questions, account requests or data-protection enquiries, contact [email protected].
2. What this policy covers
This policy explains the personal data processed when you sign in, connect Google Calendar, use calendar features, manage a paid subscription, contact us, or administer your account.
3. Google data we access
Interactive Calendar requests only the Google permissions required to provide its calendar features. Depending on the permissions you grant, we may access:
- Your Google account identifier, verified email address, name and basic profile information for sign-in and account identification.
- Your Google Calendar list and related calendar metadata so the app can show calendars available to you.
- Google Calendar event data that you are permitted to access, including event title, description, location, start/end time, recurrence information, calendar identifier and event colour.
- OAuth access and refresh tokens required to keep your Google Calendar connection working.
The OAuth scopes currently used are openid, email, profile, https://www.googleapis.com/auth/calendar.events and https://www.googleapis.com/auth/calendar.calendarlist.readonly.
4. How we use Google data
Google user data is used only to provide user-facing Interactive Calendar functionality, including displaying calendars and events, creating or editing events at your request, moving or deleting events, recurring-event operations, search, bulk actions, opt-in automatic rescheduling of flexible personal events, and account reconnection.
Interactive Calendar does not use Google Calendar data for advertising, profiling for ads, credit decisions, data brokerage, or unrelated analytics.
Google Workspace API data is not used to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models.
5. What we store
Interactive Calendar stores only what is needed to operate the service:
- Account data such as Google subject identifier, email, name, role, theme, timezone and login timestamps.
- Google OAuth tokens. Tokens are encrypted before being stored in the application database.
- Stripe customer/subscription identifiers and subscription status for Pro access. Payment card details are not stored by Interactive Calendar.
- Short-lived operation data required for the Undo feature. This may temporarily contain event fields needed to reverse a change. Undo access expires after approximately two minutes and expired records are removed during scheduled maintenance.
- Security and administrative audit records for manual Pro grants and role changes.
- When you opt in to flexible events, event and calendar identifiers, expected start and end times, your time window and time zone, and check status. Pro rules also store priority, deadline, days ahead, weekend preference and gap duration. Move history keeps old and new times, event and calendar identifiers and the move source for up to 90 days. We do not store event titles or descriptions for this feature. Active flexible rules are removed after the event passes or when you disable them; move history follows its separate retention period.
Calendar events are normally retrieved from Google on demand; flexible event identifiers and timing rules are kept temporarily to allow the scheduled background task to run while your app is closed.
6. Payments
Paid subscriptions are processed by Stripe. Stripe receives the information necessary to process payment and manage billing. Interactive Calendar stores Stripe identifiers and subscription state, but does not store full payment-card numbers or card security codes.
Google Calendar event content is not sent to Stripe as part of billing.
7. Cookies and local browser data
Interactive Calendar uses only storage that is necessary to provide and secure the service. The production session cookie is __Host-IC_SESSION; it is used for sign-in state, OAuth security and CSRF protection, expires when the browser session ends, and is configured as Secure, HTTP-only and SameSite=Lax. We do not use analytics, advertising or cross-site tracking cookies.
The app also stores small local-browser values to remember that you have dismissed the cookie notice and whether you collapsed the sidebar, and the PWA may cache static application files for offline shell loading. Personal calendar events and API responses are not stored in that cache. See our Cookie Policy for details.
8. Sharing and service providers
We do not sell personal data or Google user data. Data may be processed by service providers only where necessary to operate the service, such as Google for authentication and Calendar API functionality, Stripe for payments, and infrastructure providers used to host and secure the application.
Google user data is not transferred to advertising platforms, data brokers or information resellers.
9. Security
We use HTTPS, server-side access controls, encrypted Google OAuth token storage, CSRF protections, secure session cookies and signed Stripe webhooks. No internet service can guarantee absolute security, but we limit access and retain only data needed for the service.
10. Your choices and controls
- You can turn off automatic rescheduling for any flexible event in the app. Pro move history lets you restore a move when its earlier time is free and the event has not changed.
- You can disconnect Google from your account. The app attempts to revoke the stored Google refresh token and removes the local Google connection.
- You can delete your Interactive Calendar account from the account menu. Local account data is deleted. Events already stored in your Google Calendar are not deleted merely because you delete your Interactive Calendar account.
- You can manage or cancel an active Pro subscription through the Stripe Customer Portal. Where cancellation is scheduled for the end of the billing period, Pro access continues until that period ends.
- You may contact us to ask about access, correction or deletion of personal data, subject to applicable law.
11. Data retention
Account and subscription records are kept while your account remains active and as reasonably necessary for security, billing, legal and operational obligations. OAuth connection data is removed when the Google connection is disconnected or the account is deleted. Short-lived undo data is retained only for operational recovery and is purged after expiry through scheduled maintenance.
12. International processing
Some service providers may process data outside your country. Where applicable, such processing is handled under the legal mechanisms and contractual protections made available by those providers and required by law.
13. Changes to this policy
We may update this policy when the service, permissions or legal requirements change. The effective date shown at the top of this page will be updated when material changes are published.
14. Contact
Interactive Net Solutions
interactivenet.gr
[email protected]