Legal
Privacy Policy
Last updated: 14 August 2026
Independent product notice. MySlotHub is an independent booking product operated by its own team. It is not a Google product and is not affiliated with, endorsed by, sponsored by, or officially connected to Google LLC. “Google”, “Google Calendar”, and “Google Meet” are trademarks of Google LLC. Optional calendar and video-meeting features use Google APIs only when a business chooses to connect their own Google account.
MySlotHub (“we”, “us”, “our”) provides appointment, slot-booking, communication, reporting, integration, and payment-enablement software for businesses and professionals. This Privacy Policy explains how we handle personal data when you use myslothub.vercel.app, its public booking pages, admin tools, APIs, and related services (the “Service”).
1. Who this policy applies to
- Business users, including organization owners and administrators who create or manage a MySlotHub organization.
- Customers who visit a business’s booking page, request or manage a booking, make an advance payment, or receive booking communications.
- Website visitors and support contacts who browse our public pages, contact us, or submit a support ticket.
For account administration, subscriptions, security, and direct support, MySlotHub decides why and how data is processed. For customer booking data, the business normally decides the purpose of processing and MySlotHub processes the data to provide the Service. Businesses must give their customers an appropriate privacy notice and have a lawful basis for using customer data.
2. Information we collect
Account, organization, and security data
- Name, email address, phone number, role, business name, category, timezone, currency, and public page slug
- When phone verification is enabled for an organization, phone-verification status and Firebase authentication data used to confirm customer phone ownership
- Branding, logo, business contact details, policies, working hours, blocked dates, and other configuration
- Authentication and security data, including password hashes, session and verification records, optional two-factor authentication secrets stored in encrypted form, hashed recovery codes, and security events
- Plan, trial, billing cycle, subscription status, and payment-provider transaction identifiers
Booking and customer data
- Services, calendars, availability, slots, delivery mode, capacity, price, and assigned resources
- Customer name, email, phone number, booking reference, selected service and time, booking status, and details the customer or business supplies for the appointment
- Cancellation requests, provider no-show records, refund status, advance-payment status, and related transaction references
- Check-in records when a business marks arrival, including checked-in time, method (for example check-in code, phone last digits, or manual), and related booking identifiers used in admin reports and exports
- Optional video meeting link (when the business connects their own calendar account) or in-person location, when applicable to the business’s plan and service
Payments, subscriptions, and Razorpay KYC
Razorpay processes MySlotHub subscriptions, optional customer advance payments, refunds, and standalone payment links. We receive and retain operational metadata such as Razorpay customer, account, order, payment, subscription, transfer, refund, settlement, and status identifiers. We do not receive or store complete card, UPI credential, or other payment-instrument details entered into Razorpay Checkout.
If a business activates Razorpay Route, the business may enter legal-business, owner or stakeholder, PAN, address, and settlement-bank information in MySlotHub. We transmit that information to Razorpay to create or update the linked account and do not intentionally store the submitted raw PAN or bank-account details in the MySlotHub database. We retain the linked-account, stakeholder, product, activation-status, and requirements identifiers needed to show setup progress and operate payments. Razorpay processes KYC and payment information under its own privacy policy and regulatory obligations.
Optional calendar and video-meeting integration data
When an eligible business connects their own Google account for calendar features, MySlotHub receives that connected account’s email address and OAuth tokens. At the business’s direction, the integration can create, update, or delete booking-related events in the connected primary calendar. An event may contain the booking time, service, customer and business attendee email addresses, reminders, and a video conference link generated through that account’s calendar provider settings.
For private (one-person) online bookings, MySlotHub typically creates a calendar event and meeting link for that booking. For group-capacity online slots, MySlotHub may create or reuse one shared calendar event and meeting link for that time: confirmed customers’ email addresses can be added as calendar attendees so they receive the same meeting link, and removed when a booking is cancelled while other confirmed bookings remain. Join access for people who have the link is controlled by the connected account’s invite and host settings, not by a separate MySlotHub login gate.
Data received from Google APIs is used only to identify the connected account and provide the optional calendar and video-meeting features the business requests. OAuth tokens are encrypted at rest. We do not sell that user data, use it for advertising, determine creditworthiness, or use it to train generalized artificial-intelligence or machine-learning models. Humans do not read that user data unless necessary for security, legal compliance, or support that the user requests and authorizes.
A business can disconnect the integration in Settings. Disconnecting removes the stored OAuth tokens and connected email from active MySlotHub records and attempts to revoke access. The user can also revoke access from their Google Account permissions. MySlotHub’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This does not make MySlotHub a Google product or imply Google endorsement.
Communications, templates, and support
- Default or customized email subjects and bodies, recipient addresses, scheduled delivery time, delivery status, retry information, and provider error logs for booking and account emails
- Support-ticket category, priority, subject, description, messages, status, and optional screenshots or image attachments
- Name, email address, subject, and message submitted through our public contact form
Do not include passwords, card details, API keys, health records, government identifiers, or other unnecessary sensitive information in support tickets, screenshots, booking details, or customized email templates.
Developer, reporting, and technical data
- API-key prefix, hashed secret, label, scope, expiry and last-used time; webhook endpoint, encrypted signing secret, delivery attempts, response status, and error information
- Reports and derived analytics, such as booking totals, status trends, revenue or advance totals, check-in timing, repeat customer rate, and peak booking hours, plus emailed CSV exports the business requests
- IP address, browser or device information, requested page, timestamps, request identifiers, and application, audit, security, and reliability logs
- Essential cookies, session storage, and local storage used for authentication, organization selection, security, and user-interface preferences
MySlotHub does not currently use customer data for third-party behavioural advertising. If we introduce non-essential cookies or similar tracking, we will provide additional notice and obtain consent where required.
3. How and why we use information
- Provide booking pages, calendars, availability, approvals, cancellations, refunds, and customer lookups
- Operate plan-specific online, in-person, hybrid, advance-payment, reporting, and developer features
- Send verification, security, subscription, support, booking, cancellation, refund, and reminder communications
- Process subscriptions and enable Razorpay Checkout, Route transfers, payment links, and reconciliation
- Create booking-related calendar events and video meeting links when the business authorizes the optional integration
- Produce organization reports and aggregated operational analytics
- Authenticate users, enforce permissions and quotas, prevent fraud and abuse, and protect the Service
- Investigate errors, provide support, maintain audit trails, and improve reliability and usability
- Comply with legal, tax, accounting, regulatory, and lawful-enforcement obligations
Depending on the relationship and applicable law, we rely on performance of our contract, the user’s request or consent, compliance with law, and legitimate interests such as security, fraud prevention, support, and product reliability. We do not use booking analytics to make solely automated decisions that produce legal or similarly significant effects about customers.
4. When we share information
We do not sell personal data. We disclose it only as needed to:
- Businesses and their customers: the organization receives its booking data, while customers receive booking details and business information needed to manage the appointment.
- Service providers: hosting, database, cache and queue, storage, monitoring, email delivery, support, and security providers that process data for us under appropriate restrictions.
- Google (optional integration): only when a business connects their own Google account so MySlotHub can create booking-related calendar events or video meeting links they requested.
- Razorpay and financial or regulatory participants: for subscriptions, KYC, payments, transfers, refunds, settlement, fraud prevention, and legal compliance.
- Authorities and professional advisers: when required by law or reasonably necessary to protect rights, safety, users, or the Service.
- A successor: in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice required by law.
5. Retention and deletion
We retain each category only for as long as reasonably needed for the purposes above. Retention depends on the account’s status, the booking or subscription lifecycle, support needs, fraud and security risk, provider reconciliation, and legal, tax, accounting, or dispute requirements.
- Active organization, booking, template, and integration data is kept while needed to provide the Service.
- Google credentials are removed from active records when the integration is disconnected, as described above.
- Payment, refund, settlement, invoice, support, security, and audit records may be retained longer where required to reconcile transactions, enforce agreements, prevent abuse, or comply with law.
- Expired sessions, verification records, queue jobs, delivery logs, and temporary files are deleted or overwritten through operational cleanup processes.
- Data deleted from active systems may remain for a limited time in protected rolling backups and is removed through the normal backup lifecycle.
6. Security
We use measures designed for the current Service, including HTTPS in production, hashed passwords and API secrets, encrypted OAuth and two-factor secrets, signed payment and developer webhooks, role-based access, organization-scoped database controls, rate limits, audit logging, and restricted administrative access. No transmission, storage system, or security control is completely secure. Business users must protect their credentials, recovery codes, API keys, webhook secrets, and connected-provider accounts.
7. Your choices and rights
Subject to applicable law, you may ask to access, correct, update, delete, or restrict your personal data, or withdraw a consent you previously provided. We may verify your identity and may retain information where law, security, fraud prevention, accounting, or an active dispute requires it.
- Business admins can update organization settings, templates, services, policies, and bookings.
- Businesses can disconnect Google, revoke API keys, and remove webhook endpoints in the admin panel.
- Customers can use the available booking-status or cancellation link, or the limited account portal when offered, and should contact the booking business first for appointment questions.
- If the business cannot resolve a customer-data request, or for MySlotHub account and privacy requests, contact us using the details below.
8. Children and minors
MySlotHub organization accounts are intended for adults who can enter a binding contract. The Service is not directed to children. If a business offers appointments involving a minor, that business is responsible for obtaining any parent or guardian authorization required by law and for limiting the data it collects.
9. International processing
The Service and its providers may process data in countries other than the user’s country. Where required, we use contractual or other lawful safeguards for international transfers. Businesses are responsible for any additional localization or transfer duties that apply to their own customer-data use.
10. Third-party services and trademarks
MySlotHub is an independent booking product operated by its own team. It is not a Google product and is not affiliated with, endorsed by, sponsored by, or officially connected to Google LLC. “Google”, “Google Calendar”, and “Google Meet” are trademarks of Google LLC. Optional calendar and video-meeting features use Google APIs only when a business chooses to connect their own Google account. Razorpay, email providers, and websites reached through external links likewise have their own terms and privacy practices. Review those policies before enabling an integration or submitting information to them. MySlotHub does not control a third party’s independent processing.
11. Changes to this policy
We may update this policy when the Service, providers, or legal requirements change. We will publish the revised version and update the date above. For a material change, we will provide additional notice through the Service or email where reasonably practical or required by law.
12. Contact and privacy requests
Email info.myslothub@gmail.com or use the Contact form. Clearly describe the organization, booking reference (if relevant), request, and email address involved, but do not send passwords, payment credentials, API keys, or unnecessary identity documents.