Chronacal Privacy
Privacy Policy
This policy describes how Chronacal collects, uses, and protects personal information submitted through Chronacal-powered websites and service workflows.
Information collected
Chronacal may collect personal information that users provide directly, including name, email address, phone number, booking details, and other information required to complete account, authentication, or scheduling workflows.
Chronacal may also collect technical and service usage information needed to secure accounts, troubleshoot issues, and improve product reliability.
If a business owner chooses to connect Google Calendar, Chronacal accesses the owner's Google Calendar event information only as needed to identify unavailable times and synchronize Chronacal appointments. This may include event identifiers, titles, and start and end times. Chronacal also stores the connected Google account email address and an authorization token needed to maintain the connection.
How information is used
- To create and manage user accounts
- To verify user identity with one-time passwords
- To send booking confirmations and service-related notifications
- To operate, secure, and improve Chronacal services
- When a business owner elects to connect Google Calendar, to read busy times and create, update, or delete the matching Calendar events for Chronacal appointments
Google user data: sharing and disclosure
Chronacal does not sell Google user data, use it for advertising, or allow third parties to use it for their own advertising or marketing purposes. We do not share, transfer, or disclose Google user data to third parties except as necessary to provide and secure the Chronacal service, as directed by the user, to comply with applicable law, or as part of a merger, acquisition, or asset sale where the recipient is bound to protect the data in accordance with this policy.
Service providers that process data for Chronacal may access Google user data only to operate, maintain, or secure our service on our behalf and under contractual confidentiality and security obligations. Chronacal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data protection
Chronacal protects Google user data using technical and organizational safeguards. Google Calendar refresh tokens are encrypted at rest using AES-256-GCM, and access to stored connection data is restricted to systems and personnel authorized to operate or support the service. Tokens are not returned in Chronacal's application API responses.
Data is transmitted using HTTPS. We maintain reasonable administrative, technical, and physical safeguards designed to protect data against unauthorized access, alteration, disclosure, or destruction.
Artificial intelligence services and Google user data
Chronacal uses OpenAI API services for optional business-website content and image-generation features. Google Calendar data, including event details, busy-time information, connected Google account email addresses, and Google authorization tokens, is not sent to OpenAI or any other artificial intelligence or machine-learning service.
Chronacal does not use Google user data, whether raw, aggregated, anonymized, or derived, to create, train, or improve generalized or foundational artificial intelligence or machine-learning models. Our use and transfer of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements.
Google user data retention and deletion
Google Calendar connection data and imported busy-time information are retained only while the business owner keeps the Google Calendar connection active and while needed to provide the synchronization feature. Access tokens are short-lived and refreshed only as necessary to operate an active connection.
A business owner can disconnect Google Calendar at any time in Chronacal's Settings and Connections area. On disconnection, Chronacal revokes the stored Google refresh token when possible and deletes the Calendar connection record and imported Google Calendar busy-time data. Users may also contact support to request deletion of their Chronacal account and associated data.
SMS data handling
Phone numbers collected for transactional messaging are used only for the service interactions the user requested, such as OTP verification, booking confirmations, and service notifications.
Chronacal does not sell phone numbers or use them for unrelated promotional messaging within this program.
Mobile opt-in data and consent collected for SMS messaging will not be shared with third parties or affiliates for marketing or promotional purposes.
User choices
Users may choose whether to provide personal information, but some service features cannot function without it.
Users may opt out of SMS messaging at any time by replying STOP. Users may request help by replying HELP.
Contact
Questions about this policy may be sent to support@chronacal.com.