Privacy Policy

Last updated: December 3, 2024

1. Introduction

Venn ("Company," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our scheduling platform at venn.team and related services (collectively, the "Service").

By using the Service, you consent to the data practices described in this policy. If you do not agree with the data practices described, you should not use the Service.

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

2. Information We Collect

2.1 Information You Provide

We collect information you provide directly to us, including:

  • Account Information: Name, email address, and profile picture when you create an account
  • Team Information: Team names, member lists, and team settings
  • Booking Information: Meeting titles, descriptions, attendee lists, and scheduling preferences
  • Communication Data: Messages you send to us for support or feedback
  • Payment Information: Billing address and payment details (processed securely by Stripe)

2.2 Calendar Data

When you connect your calendar accounts (Google Calendar or Microsoft Outlook), we access:

  • Free/Busy Information: Time blocks showing when you are available or busy
  • Event Metadata: Event start/end times, titles (for events you create through Venn), and attendee information
  • Calendar Settings: Your timezone, working hours preferences, and calendar visibility settings

2.3 Automatically Collected Information

When you use the Service, we automatically collect:

  • Device Information: Browser type, operating system, device identifiers
  • Usage Data: Pages visited, features used, actions taken within the Service
  • Log Data: IP address, access times, referring URLs, error logs
  • Cookies and Similar Technologies: As described in our Cookies section below

3. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Calculate availability overlaps, create booking links, schedule meetings, and send calendar invitations
  • Manage Your Account: Create and maintain your account, authenticate your identity, and process payments
  • Communicate: Send you service-related notifications, respond to inquiries, and provide customer support
  • Improve the Service: Analyze usage patterns, troubleshoot issues, and develop new features
  • Security: Detect and prevent fraud, abuse, and security incidents
  • Legal Compliance: Comply with legal obligations and enforce our Terms of Service

We process your data based on: (a) your consent; (b) performance of our contract with you; (c) our legitimate business interests; or (d) compliance with legal obligations.

4. Information Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

4.1 With Your Consent

We share information when you explicitly authorize us to do so, such as when you share availability with team members or external booking participants.

4.2 With Team Members

When you join a team, your availability (free/busy times) is visible to other team members. Your detailed calendar events are not shared—only your available time slots.

4.3 With Booking Participants

When someone books a meeting through your booking link, they see available time slots. After booking, both parties receive meeting details including names, email addresses, and any notes provided.

4.4 With Service Providers

We work with third-party service providers who perform services on our behalf:

  • Stripe: Payment processing
  • Resend: Email delivery
  • Vercel: Hosting and infrastructure
  • Database providers: Data storage

These providers are contractually obligated to protect your information and may only use it to provide services to us.

4.5 For Legal Reasons

We may disclose information if required by law, legal process, or government request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5. Third-Party Calendar Integrations

5.1 Google Calendar

When you connect Google Calendar, we request access through Google's OAuth system. We access:

  • Your calendar list and free/busy information
  • Ability to create events on your behalf (when you book meetings)
  • Your Google profile information (name, email, profile picture)

Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

5.2 Microsoft Outlook

When you connect Microsoft Outlook, we request access through Microsoft's OAuth system. We access:

  • Your calendar free/busy information
  • Ability to create events on your behalf
  • Your Microsoft profile information

5.3 Revoking Access

You can disconnect your calendar accounts at any time through your Venn account settings or directly through Google/Microsoft account settings. Disconnecting will stop us from accessing your calendar data, but will not delete data already collected.

6. Data Security

We implement appropriate technical and organizational security measures to protect your information, including:

  • Encryption: Data is encrypted in transit (TLS/HTTPS) and at rest
  • Access Controls: Limited access to personal data on a need-to-know basis
  • Secure Authentication: OAuth-based authentication with calendar providers
  • Regular Audits: Periodic security assessments and monitoring
  • Secure Infrastructure: Hosting on enterprise-grade cloud infrastructure

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.

7. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:

  • Account Data: Retained while your account is active and for a reasonable period after deletion
  • Calendar Data: Availability information is refreshed regularly; we don't store historical calendar snapshots
  • Booking Data: Retained for record-keeping and may be deleted upon request
  • Usage Data: Aggregated analytics may be retained indefinitely

When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required for legal obligations, dispute resolution, or enforcement of our agreements.

8. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

8.1 Access and Portability

You can access most of your information through your account settings. You may request a copy of your personal data in a portable format.

8.2 Correction

You can update your account information at any time through your account settings, or contact us to correct inaccuracies.

8.3 Deletion

You can delete your account at any time. Upon deletion, we will remove your personal information as described in the Data Retention section.

8.4 Opt-Out

You can opt out of marketing communications by clicking "unsubscribe" in any marketing email or adjusting your notification preferences.

8.5 GDPR Rights (European Users)

If you are in the European Economic Area, you have additional rights including: the right to object to processing, the right to restrict processing, and the right to lodge a complaint with a supervisory authority.

8.6 CCPA Rights (California Residents)

California residents have the right to: know what personal information is collected, request deletion, and not be discriminated against for exercising these rights. We do not sell personal information as defined by the CCPA.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Essential Cookies: Required for the Service to function (authentication, security)
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how you use the Service

You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service.

We do not respond to "Do Not Track" signals, as there is no industry standard for how to respond to such signals.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws than your country.

When we transfer data internationally, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, or rely on adequacy decisions, to ensure your information receives adequate protection.

11. Children's Privacy

The Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us. If we discover that a child under 16 has provided us with personal information, we will delete it promptly.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page, updating the "Last updated" date, and, where appropriate, sending you an email notification. We encourage you to review this Privacy Policy periodically for any changes.

13. Contact Us

If you have any questions about this Privacy Policy, your personal data, or would like to exercise your rights, please contact us:

For GDPR-related inquiries, you may also contact our Data Protection Officer at [email protected].