Privacy

Last updated 17 August 2026

What this covers

This covers the Meetsy service at meetsy.app, which we (doubleslash.studio) operate. If you sign up as a host, your account and your bookings live on our servers in the UK (London). We are the data controller for that; you are the controller for whatever you then collect from the people who book with you.

What we store about people who book

When someone books, we store the name, email address and timezone they entered, a phone number if the meeting type needs one, and the time they picked. That's what the confirmation email, the calendar invite and the reminders are built from. We don't buy, sell or enrich this data, and there is no advertising or third-party analytics in the booking page.

If the person booking adds guests, we store the email address they gave for each one, and a name where they supplied it. Guests are sent the invitation, the reminders and any cancellation notice for that meeting, and nothing else. Their details come from the person who booked, not from us, and they are removed with the booking.

What we store about hosts

Your email address, your name, a password hashed with scrypt (never the password itself), and your booking settings. If you connect a calendar, the access tokens are encrypted at rest with AES-GCM and can be deleted at any time by disconnecting it.

Who else sees it

There is no analytics, no advertising and no tracking anywhere in Meetsy, not on the booking page, not in the emails. Fonts are served from our own servers, so simply opening a booking page doesn't tell a third party you did.

Data leaves our servers in only two cases: our email provider, to deliver a confirmation or reminder; and a video provider (Zoom or Google Meet) to create a meeting link, and only if the host has connected one.

Video providers (Zoom and Google Meet)

A host can connect their own Zoom or Google account so that each booking gets a real meeting link, created in theiraccount. When a booking is made we send the provider the meeting title, description, start time, duration and timezone, nothing else. We store what comes back: the join link and the meeting's ID (so the meeting can be cancelled or moved if the booking is), and the email address of the connected account, shown only to the host so they can see which account is linked.

The OAuth tokens that make this work are stored encrypted (AES-256-GCM), are used solely to create, update or cancel the meetings belonging to bookings, and are deleted immediately when the host disconnects the provider, or when they remove the app from the provider's own settings. We never read calendars beyond checking free/busy times, and we never access meeting content, recordings, transcripts or participant lists.

Cookies

Booking pages set no cookies at all.Someone booking a meeting with you is not tracked, is not profiled, and never sees a consent banner. The embeddable widget carries no analytics either, so putting it on your site doesn't add tracking to your site.

For hosts who sign in, there is one strictly necessarycookie, the session cookie that keeps you logged in. It needs no consent because without it you couldn't stay signed in.

On the admin dashboard only, we ask whether you'll allow Google Analytics, which sets its own cookies and sends usage data to Google. It is off until you say yes: decline and the script is never loaded and no Google cookie is set. You can change your mind at any time with the analytics link in the footer, which also deletes the cookies it set.

How long bookings are kept

By default a booking is kept until the host deletes it, either on its own or by deleting the whole organisation.

A host can also switch on 30-day deletion in their settings. With it on, every booking is deleted outright 30 days after the meeting finishes: the name, email address, phone number and timezone, anything written on the booking form, the guests who were added, and the record of the meeting itself. It is permanent, and we cannot recover it afterwards. It is off unless the host turns it on, so if you want to know what applies to a booking you have made, ask the person you booked with.

Deleting your data

Invitees can cancel a booking from the link in their confirmation email. Hosts can disconnect a calendar at any time, which deletes the stored tokens immediately.

Hosts can delete their whole organisation from Settings. That removes the account, its booking pages, availability, calendar connections, uploaded logo and every booking ever made with it. It is immediate and irreversible. We can't recover it for you afterwards.

Your rights

Under UK GDPR you can ask us for a copy of the personal data we hold about you (access), ask us to correct it (rectification), ask us to delete it (erasure), ask for it in a portable format, and object to or restrict how it's used. Much of that you can do yourself, the section above covers deletion, and for anything else, email meetsy@doubleslash.studioand we'll sort it within a month, as the law requires.

If you're unhappy with how we've handled your data, you can complain to the UK's Information Commissioner's Office at ico.org.uk.

A caveat worth reading

This is a draft, not legal advice. If you take bookings from the public, especially in the UK or EU, have someone qualified check this against your actual setup before you rely on it.

← Back to Meetsy