logo
WhenPick
Log in

Privacy Policy

Last updated August 13, 2026

This policy explains what personal information WhenPick collects, why we collect it, who we share it with, and what you can do about it. It covers the hosted service at whenpick.com. If someone is running their own copy of the WhenPick open-source software, this policy does not apply to them. Ask them for theirs.

1. Who we are

WhenPick operates this service and is the data controller for the information described in this policy, except where we say otherwise in section 3. You can reach us at [email protected] . We do not currently publish a postal address; please use email for all privacy requests.

2. A note on the two roles

WhenPick is a scheduling tool, so most information passes through it on behalf of somebody else:

  • We are the controller for your account, your settings, your connected integrations, and the technical records needed to run the service.
  • We are a processor for information a host collects from participants: the answers you give on someone's poll, the details you enter to book a meeting, and anything a host asks for through custom questions. The host decides what to ask and what to do with the answers. If you want that information changed or removed, the fastest route is usually to contact the host; you can also contact us and we will help.

3. What we collect

If you have an account

  • Your name, email address, and username.
  • A hashed version of your password. We never store your password itself.
  • Your timezone, availability preferences, and the sleep window you set so we do not offer people your middle of the night.
  • Two-factor authentication secrets and recovery codes, if you enable two-factor authentication.
  • Your branding uploads: logos and background images, if you add them.
  • The single sign-on provider you use, if you sign in with Google, Microsoft, SAML or OIDC.
  • If you belong to a team, an activity log of actions taken in that team, visible to team administrators.

If you respond, sign up or book without an account

You can use most of the service without registering. When you do, we collect:

  • Poll responses. The name you give, your email address if you provide one, and your availability selections.
  • Signup sheets. The name you give, your email address if you provide one, and any notes you add.
  • Bookings. Your name, your email address (required, so we can send you a confirmation and let you cancel), your timezone, and any notes you write.
  • Answers to the host's custom questions. Free text, choices, and any files you upload. We do not control what a host asks for. Do not upload anything you would not want the host to hold.
  • A random identifier stored in a cookie so you can come back and edit your own response. See the Cookie Policy.

Collected automatically

  • Your IP address and browser user agent, stored with your session record while that session is active.
  • Server and error logs, which may include IP addresses and request URLs.
  • The cookies listed in the Cookie Policy.

We do not run analytics, advertising or third-party tracking of any kind. There is no Google Analytics, no advertising pixel, and no cross-site tracking on this service.

From services you connect

  • Calendars. If you connect Google Calendar, Outlook, or an iCal feed, we read your events so we can avoid double-booking you. We request read-only calendar access. Where we publish your availability to other people, we show only that you are busy, not the title, attendees or details of your events.
  • Video conferencing. If you connect Zoom, Google Meet, Microsoft Teams or Webex, we store your account identifier and access credentials so we can create meeting links for your bookings.
  • Stripe. If you enable payments, we store your Stripe connected account identifier and its status: whether charges and payouts are enabled, your country and default currency. We do not receive or store card numbers.

4. Why we use it, and our legal bases

  • To provide the service: creating polls, finding times, taking bookings, sending confirmations and reminders. Legal basis: performance of a contract, or the legitimate interest of the host who invited you.
  • To keep the service secure: authentication, fraud and abuse prevention, rate limiting, and audit logs. Legal basis: legitimate interests.
  • To take payments where a host charges. Legal basis: performance of a contract, and compliance with legal obligations such as anti-money-laundering rules that apply to our payment processor.
  • To operate optional integrations you switch on: calendars, video conferencing, AI generation, outbound webhooks. Legal basis: your consent, which you can withdraw by disconnecting the integration.
  • To communicate with you about your account and the bookings you are part of. Legal basis: performance of a contract and legitimate interests. These are service messages, not marketing.

5. Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

We do share it with:

  • The host whose poll, sheet or booking page you used. That is the point of the service.
  • Other participants, where the host has set a poll or sheet up so that responses are visible to everyone who can see it.
  • Service providers acting on our behalf. The current list, what each one receives, and when it applies is on our Subprocessors page.
  • Authorities, where we are legally required to, or where it is necessary to protect someone's safety or our legal rights.
  • A buyer or successor, if the service is acquired or merged. We will tell you before your information becomes subject to a different privacy policy.

AI features

Some features let you generate poll and meeting content from a prompt. When you use one, the text of your prompt and the surrounding context are sent to OpenAI or Anthropic, depending on which provider is selected in your settings. Do not put confidential information into those prompts. These features are optional and are only used when you choose to use them.

Outbound webhooks

Hosts can configure webhooks that post booking and response data to a URL of their choosing. Once data reaches a destination you configured, it is outside our control and this policy no longer governs it.

6. International transfers

We are based in the United States and our service providers operate globally, so your information will be processed in the United States and potentially other countries. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), or on another lawful transfer mechanism offered by the provider concerned.

7. Security

Traffic to the service is encrypted with TLS. Passwords are stored as salted hashes and are never recoverable. Two-factor authentication is available on every account and we recommend turning it on. Access to production systems is limited to people who need it.

To be straightforward with you: access and refresh tokens for connected calendar, video and login providers are currently stored in our database without an additional layer of application-level encryption at rest. We are working on that. If that matters for your threat model, you can disconnect an integration at any time from your settings, which deletes the stored credentials.

No online service can promise perfect security, and we do not.

8. How long we keep it

  • Account data: while your account exists.
  • Sessions: a session record, including its IP address and user agent, expires after 2 hours of inactivity.
  • Polls, sheets, bookings and their responses: while the host keeps them. Hosts can delete their own polls, sheets, meeting types and bookings.
  • Synced calendar events, webhook delivery records and team activity logs: retained while the account is active. We do not currently run automatic pruning on these.
  • Backups: deleted data may persist in routine backups for a short period before those backups roll over.

9. Deleting your account, and what survives it

You can delete your account at any time from your profile settings. It requires your password and it is immediate. There is no recovery period. Deleting your account removes your profile, your settings, your connected accounts and their stored credentials, and your calendar sync configuration.

Some information does not disappear when you delete your account, and we would rather tell you than surprise you. Responses and signups you submitted to other people's polls and signup sheets remain part of that host's records, along with the name and email address you entered at the time. The same is true of bookings you made with other hosts, and of content you contributed to a team that still exists. Those records belong to the host, and removing them unilaterally would corrupt their event.

If you want that information erased too, email [email protected] and tell us what to look for, or ask the host directly. We will action valid erasure requests, subject to any legal obligation we have to keep certain records, in particular transaction records that payment and tax rules require us or Stripe to retain.

10. Your rights

Wherever you live, you can email us to:

  • Ask what personal information we hold about you and get a copy of it.
  • Correct anything that is wrong.
  • Ask us to delete it.
  • Ask us to restrict or stop a particular use of it.
  • Withdraw consent for an optional integration, at any time.

If you are in the EEA, UK or Switzerland

You have the rights above under the GDPR and UK GDPR, plus the right to data portability and the right to object to processing based on our legitimate interests. Withdrawing consent does not affect processing that already happened. You also have the right to complain to your local data protection authority. In the UK, that is the Information Commissioner's Office.

If you are in California

Under the CCPA/CPRA you have the right to know what we collect and why, to request deletion, to request correction, and not to be discriminated against for exercising those rights. We do not sell your personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of.

How to make a request

Email [email protected] . We will respond within 30 days. We may need to verify your identity first, usually by confirming you control the email address on the record in question. We do not charge for this.

11. Children

The service is not intended for children under 16 and we do not knowingly collect their personal information. If you believe a child has given us information, email us and we will delete it.

12. Changes to this policy

We will update this page when our practices change and revise the date at the top. If a change is material, we will notify account holders by email or through the service before it takes effect.

13. Contact

Privacy questions and requests: [email protected] .

Terms of Service Privacy Policy Cookie Policy Subprocessors

© 2026 WhenPick. All rights reserved.