Privacy Policy
Effective 13 August 2026 · scalendar.app
1. Who we are
Scalendar is a product of Code Ninjas Software Ltd (company number 12528130), registered in England and Wales at 189 Runcorn Road, Birmingham, England, B12 8QY. We act as the data controller for the personal information described below.
If you have a privacy question or want to exercise any of your rights under UK or EU data protection law, email us at hello@scalendar.app.
2. What this policy covers
This policy explains what personal information we collect when you visit our marketing site, sign up for our waitlist, or install and use the Scalendar Slack app, and what we do with it.
3. What we collect
The minimum needed to run a calendar inside Slack:
- Slack workspace identifiers — your Slack team ID and team name, the channels Scalendar has been added to, and the Slack user IDs, display names, and timezones of people who interact with the app (timezones are how everyone sees event times in their own timezone). We also see whether a user is a workspace admin, and your workspace's member count (used to determine your pricing band).
- Event data — the calendars and events you create inside Scalendar: titles, descriptions, dates, times, categories, and reminder settings.
- OAuth tokens — issued by Slack when you install Scalendar in your workspace. Stored encrypted at rest.
- Billing data (paid plans, once payments are live) — we receive a customer ID and current plan from Stripe. We never see or store full card details; Stripe handles those directly.
- Support requests — if you contact support from inside Slack, we receive your email address (pre-filled so we can reply to you) and the message you send.
- Waitlist signups — if you join our pre-launch waitlist, we collect the email address you give us and the page you signed up from.
- Marketing site visit data — basic server logs (IP address, browser type, pages requested, time of request) needed to deliver the site and protect it from abuse.
4. What we don't collect
- Slack messages. Scalendar does not have permission to read your channel conversations and does not request that access.
- Slack profile data beyond what's listed above (display name, timezone, admin status). We never collect phone numbers or custom profile fields, and we only receive your email address if you contact support from inside Slack.
- Anything from channels Scalendar has not been explicitly added to.
- Special category data (race, health, political views, etc.). We do not solicit or store it.
5. How we use it
We use the information described above to:
- Provide the Scalendar service — render your calendars, post reminders at the right times, run the App Home view, and respond to slash commands.
- Bill you correctly on paid plans (via Stripe).
- Respond to support requests you send us.
- Send transactional emails about your account (billing receipts, important service changes).
- Send pre-launch updates to people who joined the waitlist (you can unsubscribe at any time).
- Protect the service from abuse, fraud, and security threats.
We do not sell your data. We do not share it with advertisers. We do not use your event data to train machine-learning models.
6. Legal bases for processing
Under UK GDPR we rely on the following legal bases:
- Performance of a contract — when you install Scalendar and use it, we process the data described above because we need to in order to deliver the service you've asked for.
- Legitimate interests — for things like keeping the service secure, preventing abuse, and improving the product. These interests are balanced against your rights.
- Consent — for waitlist signup and any marketing email. You can withdraw consent at any time.
- Legal obligation — where we have to retain data (for example, billing records) to comply with UK law.
7. Who we share it with (sub-processors)
We use a small set of third-party services to run Scalendar. Each one has a data processing agreement in place with us, and is itself bound by UK or EU data protection law.
- Slack Technologies LLC — the platform Scalendar runs on. We use Slack APIs to receive commands and post messages back to your channels.
- Supabase — our database and application hosting. Your event data and OAuth tokens are stored in Supabase's EU region.
- Loops — handles our waitlist signups and any pre-launch email updates.
- PostHog — product analytics, hosted in PostHog's EU region. We use it to count visits and button clicks on this site and usage events in the app. It is configured without cookies and without session recording.
- Stripe (once payments are live) — payment processing for paid plans. Stripe is the data controller for full card details; we only receive a customer reference.
We do not share your data with anyone else. If we add a new sub-processor we'll update this list, and where the change is material we'll let workspace owners know by email before it takes effect.
8. Where your data is stored
All Scalendar production data — your event data, OAuth tokens, and account records — is stored in the European Union (Supabase EU region). Where a sub-processor is based outside the UK/EEA (for example Slack, Stripe), data may transit to those services to deliver the functionality you've asked for. Those providers maintain appropriate safeguards under their own data protection commitments.
9. How long we keep it
We hold your data for as long as your workspace has Scalendar installed. When you uninstall Scalendar from your Slack workspace:
- Your content is deleted immediately — calendars, events, reminders, and categories are permanently deleted the moment Slack tells us the app was removed. If you reinstall later, you start with a clean slate.
- A minimal workspace record is kept — the workspace ID and name, install and uninstall dates, and plan history. Access tokens are scrubbed at uninstall so the record cannot be used to act on your workspace; we keep it so a returning workspace is recognised and its billing history connects up. You can ask us to delete this record entirely at any time.
- Billing records and similar records we are legally required to retain are kept for the period required by UK law (typically six years). Stripe retains its own customer record under its own retention policy.
- Waitlist signups are kept until you ask us to delete you, or until 12 months after we move out of waitlist mode — whichever comes first.
You can ask us to delete your data at any time — see "Your rights" below.
10. Your rights
Under UK and EU data protection law you have the right to:
- Ask for a copy of the personal information we hold about you.
- Ask us to correct anything that's wrong.
- Ask us to delete your data (subject to the legal retention obligations above).
- Object to or restrict certain processing.
- Withdraw consent for marketing communications at any time (every email has an unsubscribe link).
- Lodge a complaint with the UK Information Commissioner's Office at ico.org.uk if you think we've handled your data badly.
To exercise any of these rights, email hello@scalendar.app. We aim to respond within 30 days.
11. How we keep your data safe
- All traffic to the Scalendar app and website is served over HTTPS (TLS 1.2 or higher).
- Slack OAuth tokens are encrypted at rest.
- Production database access is restricted to a small number of named accounts protected by multi-factor authentication.
- Slack request signatures are verified on every incoming webhook so we know requests genuinely come from Slack.
- Daily encrypted database backups, retained for 30 days.
If we ever became aware of a personal-data breach affecting you, we'd notify you and the ICO in line with our obligations under UK GDPR — within 72 hours of becoming aware, where required.
12. Data Processing Agreements
If you need a signed Data Processing Agreement to record the controller/processor relationship between your organisation and Code Ninjas Software Ltd, email hello@scalendar.app and we'll send one across.
13. Cookies and similar technologies
Our marketing site (scalendar.app) uses a small number of essential cookies and similar technologies needed to deliver the site and remember basic preferences. We do not use advertising cookies or third-party tracking cookies.
Our analytics (PostHog) runs in a cookieless configuration — it does not set cookies or store identifiers in your browser.
The Scalendar Slack app itself does not set cookies in your browser — it runs inside Slack and uses Slack's authentication.
14. Children
Scalendar is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we've collected information from a child, email hello@scalendar.app and we'll delete it.
15. Changes to this policy
We may update this policy from time to time. We'll post any changes here with a new "last updated" date at the top of the page. If a change is material — for example, a new sub-processor or a change to how we use data — we'll email workspace owners at least 30 days before it takes effect.
16. Contacting us
For privacy questions, data requests, or to report a concern:
Email: hello@scalendar.app
Post: Code Ninjas Software Ltd, 189 Runcorn Road, Birmingham, England, B12 8QY.