Draft for legal review. The company name and mailing address in section 12 are placeholders until confirmed.

Privacy

Privacy policy

Version 1.0 | Effective [date of publication]

MyAnnualCalendar is a shared calendar for families, teams and Entrepreneurs, made by NorthPointe ("we", "us"). This policy explains what we collect, why, who helps us run the service, and the choices you have. We keep only what the service needs, and we never sell your information.

1. What we collect

  • Your account: your name, email address, the accounts you belong to and your role on each, your settings (time zone, colors, the hours your day shows), and a profile photo if you add one.
  • What you put on the calendar: events, reminders, chores, Daily To Do's and whether they were checked off, birthdays, categories and notes.
  • People you add: names and email addresses of people you invite, and for children, a first name, a birth year (optional), a username and a PIN. We store PINs only in scrambled (hashed) form.
  • Connected calendars: if you connect Outlook or Google, the events on the calendars you choose, and the access key that lets us keep them in sync (see section 3).
  • Weather: the city you choose for the weather card. We do not collect your device's location.
  • Phone alerts: if you turn them on, the push address your browser gives us for each device.
  • Billing: your plan and its status. Payments are taken by Paddle; we never see or store card numbers.
  • Service records: sign-in times, a record of important changes, and error logs, used to keep the service secure and working.

2. How we use it

We use your information only to provide the service: to show your calendar to you and the people you share it with, to sync with the calendars you connect, to send the reminders and emails you ask for, to run billing, to keep the service secure, and to answer support requests. We do not use your information for advertising, and we do not sell or rent it.

3. Google and Microsoft calendar data

When you connect a Google or Microsoft (Outlook) account, you choose which calendars sync. We read and write events on those calendars only to keep them in step with MyAnnualCalendar, and, if you ask, to import birthdays once. The access key the provider gives us is stored encrypted in a secure vault and is used only by our sync service. You can disconnect at any time from Settings; we then stop syncing and erase the access key, and events that came from that account are taken off your calendar here. You can also remove our access from your Google or Microsoft account settings.

Google API Services. MyAnnualCalendar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve or train generalized AI or machine learning models, we do not use it for advertising, and people at NorthPointe do not read it except with your permission, for security, or as the law requires.

4. Who can see your information

People on your account see the calendars their role allows. An event marked private shows as "Busy" to others. Children see only their own day. Event professionals see the calendars of their own clients, and a client's family, guests and vendors see only that client's calendar.

5. Companies that help us

We share information only with the providers that run parts of the service for us, under contracts that limit their use of it:

  • Supabase hosts our database, sign-in and file storage.
  • Cloudflare serves the website and app.
  • Postmark sends our emails (invitations and account emails).
  • Paddle sells our subscriptions as our reseller and merchant of record, and handles payments, taxes and invoices.
  • OpenWeather provides forecasts for the city you choose (we send only the city's position).
  • Google and Microsoft, only when you connect them, to sync your calendars.
  • Epic Games' Kids Web Services, to verify a parent's consent before a child's account is created.

We may also disclose information if the law requires it, to protect people's safety, or as part of a sale or merger of the business, in which case this policy continues to apply.

6. Children

Children's accounts are created only by a parent or guardian on a Family plan, after that parent gives verifiable consent. A child account holds a first name, an optional birth year, a username and a hashed PIN, plus the events and chores the family puts on it. Children cannot invite people or change the plan. A parent can review, change or delete a child's information at any time from Members, and can withdraw consent by removing the child. Write to us at the address below with any question about a child's information.

7. How long we keep it

We keep your information while your account is open. Removed events and calendars can be restored for 30 days and are then deleted. When you close an account we delete its information, except billing records we must keep by law. Backups roll over and are deleted on a fixed schedule.

8. Security

Information is encrypted in transit and at rest. Each account's data is walled off from every other account at the database level, and we test that wall regularly. Access keys for connected calendars are kept in an encrypted vault. Staff access is limited to what is needed to run and support the service.

9. Your choices and rights

You can see and change your information in the app, and ask us for a copy of it or to delete it. Depending on where you live, you may have the right to access, correct, delete or move your information, or to object to some uses. Write to [email protected] and we will answer within 30 days.

10. Where your information is stored

Our service is run from the United States. If you use it from elsewhere, your information is transferred to and stored in the United States.

11. Changes

If we change this policy in a way that matters, we will tell you in the app or by email before the change takes effect, and the version number above will change.

12. Contact

NorthPointe [legal entity name]
[mailing address]
[email protected]