RoomPolicy processes minimal booking metadata to apply room policies. It does not store event titles or descriptions.
Tenant, resource and calendar identifiers; times; attendee counts; sync status; policies and derived findings. OAuth tokens are encrypted before server-side storage and are not exposed to other users.
We use Google Calendar data only to discover authorized calendars, calculate booked utilization, and show policy warnings. We do not sell, rent, use for advertising, or allow third parties to use Google user data for their own purposes. We do not transfer Google user data to third parties except: (a) to Google when retrieving data authorized by the administrator through the API; (b) to Cloudflare, our infrastructure provider hosting the application and database under RoomPolicy instructions; or (c) when required by law. We do not use Google user data to train generalized AI or machine-learning models.
The application uses HTTPS in transit, AES-GCM encryption for refresh tokens at rest, HttpOnly, Secure and SameSite OAuth cookies, and server-side access controls. Access is limited to the requested read-only scope, and RoomPolicy does not create, change or delete Calendar events. We use data solely for booking governance, warnings and booked-utilization metrics. An administrator can request export or deletion. On uninstall, synchronization stops and operational data is deleted after the configured retention period.
For privacy or data-rights requests, use the support page.