Datenschutzbestimmungen
Effective date: 20 August 2026
The short version
Nobody reads privacy policies. So here's the whole thing in ten lines, and the full version below it.
You own your data. For bookings made through your Cal.com account, you are the controller and we are the processor. We handle it on your behalf and we don't sell it, to anyone, ever.
We collect the minimum. Names, emails, phone numbers, and whatever your booking questions ask for. Plus the boring technical stuff every website gets: IP address, browser, pages viewed.
The database is where personal data lives. Not in our logs, not in our analytics, not in a spreadsheet. Our own engineering rules ban personal data from logs, error reports, and analytics events. We send IDs, not people.
We use subprocessors, and we name all of them. Email, SMS, video, payments, AI, storage, support. The full table and their purpose is in our Trust Center.
AI features are opt-in and narrow. AI meeting notes send the transcript text (no titles, no attendee list, no links). AI phone agents send the phone number and the guest details needed to place the call. Nothing is used to train anyone's models.
Your apps are your choice. When you connect Google Calendar, Zoom, Salesforce, or a webhook, data flows there because you told it to. Those are your integrations, under your instructions.
No third-party cookies in the product. Our marketing site does run analytics and ad measurement. See the cookies section.
You can get your data out, or delete it. Any time, self-serve or by email. Deleting means deleted, including at our subprocessors.
Questions: privacy@cal.com. Real humans, not a form.
Who's who: controller vs. processor
This trips people up, so it goes first.
Situation | Who decides what happens to the data | Who we are |
|---|---|---|
Someone books a meeting with you through your Cal.com link | You (or your organization) | Processor. We process attendee data on your instructions, under our DPA. |
You sign up, pay us, email support, or browse Cal.com | Us | Controller. |
What it means: if you're an attendee who booked a meeting and you want your data deleted, the fastest route is the person you booked with. We'll help either way, and we'll pass the request on.
What we collect
Data you and your bookers give us
Account data: name, email, username, password hash or SSO identity, time zone, profile photo, and your availability.
Booking data: attendee names and emails, phone numbers where SMS reminders or phone calls are used, meeting titles and locations, answers to your booking questions, notes, guest lists, cancellation and reschedule reasons.
Billing data: company name, billing address, and payment card details. The card goes straight to Stripe, and we never see or store it.
Support data: whatever you write to us, plus the account context attached to the conversation.
Data we collect automatically
IP address, browser and device, referring URL, pages viewed, and timestamps.
Product usage events (which features you used, how often) tied to an opaque ID, not to your email.
Error and performance diagnostics when something breaks.
What we deliberately don't do
We don't collect special-category data on purpose. Your booking questions might, though. If you ask about health, that's health data in your Cal.com account, and it's on you to ask for it lawfully. See "Health information".
We don't knowingly collect data from anyone under 18.
We don't build advertising profiles out of booking data, and we don't sell or rent personal data.
What it means: we hold what's needed to put a meeting on two calendars, bill you, and support you. The interesting personal data, your bookers' answers, we hold for you, not for us.
Why we're allowed to (legal bases, GDPR Art. 6)
What we do | Legal basis |
|---|---|
Run the product you signed up for | Contract |
Bill you and chase unpaid invoices | Contract / legitimate interests |
Keep the service secure, prevent abuse and fraud | Legitimate interests |
Product analytics and diagnostics | Legitimate interests (opt-out available) |
Marketing emails and ad measurement | Consent, where required |
Respond to legal demands | Legal obligation |
Subprocessors: who else touches personal data
We use other companies to run Cal.com. Every subprocessor has a data-processing agreement with us, only gets what it needs, and only processes data on our instructions. What they do and where they process data are listed in our Trust Center.
How you hear about changes. In accordance with our Data Processing Agreement, we may add or replace subprocessors to provide, operate, secure, and support Cal.com. Where required by the DPA, we will tell you before a new or replacement subprocessor starts processing Customer Personal Data.
If you object on reasonable and substantiated data-protection grounds, you can do so as described in the DPA. If you have questions about a subprocessor, write to privacy@cal.com.
Advertising and lead identification (marketing site and marketing tools, not the product)
These are managed by our marketing team rather than wired into the product code, and they only ever see marketing-site and marketing-list data, never booking data, attendee answers, or anything from your Cal.com account.
What it means: if you're in the EEA or UK, the audience-matching and visitor-identification vendors don't run on you. Anywhere else, you can turn them off by declining marketing cookies, or by using Global Privacy Control.
Apps and integrations you connect
When you connect an app, you're telling us to send data to it. We do exactly that and nothing more.
Calendars: Google Calendar, Microsoft Outlook, Apple/CalDAV, Zoho: event titles, descriptions, times, locations, organizer and attendee names and emails, and free/busy data.
Video: Zoom, Google Meet, Microsoft Teams and others: meeting details needed to create the link.
CRM and automation: Salesforce, HubSpot, Pipedrive and similar: attendee name and email, meeting details, and your booking-question answers.
Webhooks and your own SMTP server: you supply the endpoint or mail server; it receives whatever the events you subscribed to contain.
What it means: these are your processors, not ours. Their privacy policies apply, and disconnecting the app stops the flow. We can't delete what's already in your CRM.
Health information (PHI)
Cal.com isn't a health product, but bookings can carry health information: an intake question, a meeting title, notes. If you use Cal.com for anything HIPAA-regulated, that data is only as protected as the agreement behind it: get a BAA in place at go.Cal.com/BAA before you collect it, and keep it out of booking fields that get copied into third-party apps.
How long we keep it
Data | Retention |
|---|---|
Account and booking data | While your account is active |
After you close your account | You get an export window of at least 30 days, then we delete the data on our standard schedule, except what we must keep by law and what sits in backups, logs and security records until those roll over |
Invoices and tax records | As long as tax law requires (typically 7-10 years) |
Logs and diagnostics | Short-lived, and they don't contain personal data by design |
Recordings and transcripts | Until you delete them |
Where your data goes
We're a US company and data is processed in the United States. Some subprocessors process it elsewhere. For transfers out of the EEA, UK or Switzerland we rely on Standard Contractual Clauses or an adequacy mechanism such as the EU-US Data Privacy Framework. If you need EU data residency, contact us at privacy@cal.com.
Cookies
In the app: cookies for logging you in, remembering preferences, and security. No third-party advertising cookies.
On the marketing site: the analytics and ad-measurement cookies listed above. You can decline them.
We honour Global Privacy Control and Do Not Track signals.
Your rights
Wherever you live, you can ask us to: access your data, correct it, delete it, export it, restrict or object to processing, or withdraw consent. If you're in California, add: know what we collect, delete it, correct it, and opt out of sale or sharing. We don't sell or share it, so there's nothing to opt out of. If you're in the EEA or UK, you can also complain to your data protection authority.
Most of this is self-serve in your settings. Otherwise email privacy@cal.com and we'll respond within 30 days. We'll ask you to verify who you are first, and we won't treat you worse for asking.
Security
Encryption in transit and at rest, least-privilege access, SSO and 2FA, audited infrastructure, and a bug bounty. Details and our current reports: cal.com/security. No system is perfectly secure; if something goes wrong we'll tell affected customers without unnecessary delay and per our DPA.
Changes to this policy
We'll post the new version here and update the effective date. For anything material, such as a new subprocessor category or a new use of data, we'll email you before it takes effect.
Contact
Data Protection Officer: privacy@cal.com\
Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, United States
EU representative (GDPR Art. 27): Felix Kolodziej, felix@cal.com, address on request
Everything else: privacy@cal.com
Cal.com® und Cal® sind ein eingetragenes Warenzeichen
von Cal.com, Inc. Alle Rechte vorbehalten.
Unsere Mission ist es, bis 2031 eine Milliarde Menschen
durch Kalenderplanung zu verbinden.
Brauchen Sie Hilfe? support@cal.com oder besuchen Sie cal.com/help.
Lösungen
Anwendungsfälle
Ressourcen
Cal.com® und Cal® sind ein eingetragenes Warenzeichen
von Cal.com, Inc. Alle Rechte vorbehalten.
Unsere Mission ist es, bis 2031 eine Milliarde Menschen
durch Kalenderplanung zu verbinden.
Brauchen Sie Hilfe? support@cal.com oder besuchen Sie cal.com/help.
Lösungen
Anwendungsfälle
Ressourcen
Cal.com® und Cal® sind ein eingetragenes Warenzeichen
von Cal.com, Inc. Alle Rechte vorbehalten.
Unsere Mission ist es, bis 2031 eine Milliarde Menschen
durch Kalenderplanung zu verbinden.
Brauchen Sie Hilfe? support@cal.com oder besuchen Sie cal.com/help.
Lösungen
Anwendungsfälle
Ressourcen
