Appointment.to

Privacy Policy

Booking and calendar platform

Effective: August 27, 2026 Last updated: September 14, 2026

This Privacy Policy explains how Appointment.to collects, uses, discloses, stores, and protects personal information when people visit our website, create or administer accounts, use booking pages, make or manage appointments, communicate with us, or connect third-party services such as Google Calendar and Microsoft Outlook.

A publicly accessible booking page does not make the information entered into that page public. We use that information only for the purposes described in this Policy, the applicable organization's instructions, and applicable law.

1. Who we are

Appointment.to is an online booking service of OKay Inc, based in Cornwall, Ontario, Canada ("Appointment.to," "OKay Inc," "we," "us," or "our"). This Policy applies to the Appointment.to website, applications, booking pages, application programming interfaces, communications, and integrations that link to it (the "Service").

Privacy questions, requests, and complaints may be sent to our Privacy Officer at privacy@appointment.to.

2. Our privacy roles

Appointment.to provides the Service to organizations and professionals ("Organizations") that configure booking pages and decide what information to request. For information an Organization collects through its booking page, the Organization generally acts as the controller or organization responsible for that information, and Appointment.to generally acts as its processor or service provider.

Appointment.to acts on its own behalf for account administration, billing, security, fraud prevention, Service analytics and improvement, support, legal compliance, and our direct business communications. These roles may vary under applicable law.

3. Information we collect

3.1 Information provided directly

  • Account information: name, email address, telephone number, password hash, preferences, and authentication details.
  • Organization information: business name, branding, address, staff and resource details, services, schedules, policies, tax information, social links, and payment settings.
  • Booking information: contact details, appointment selections, dates and times, attendee details, questionnaire answers, notes, uploaded files, accessibility requests, contracts, confirmations, cancellations, and rescheduling information.
  • Transaction information: prices, taxes, deposits, retainers, coupon or gift-card information, payment status, and limited transaction identifiers. Payment-card credentials may be collected directly by a payment provider rather than Appointment.to.
  • Communications: support requests, feedback, complaints, and other messages.
  • Optional content: any other information a person chooses to enter. Do not submit unnecessary sensitive information, passwords, government identification numbers, or complete payment-card numbers in free-text fields.

3.2 Calendar and identity integrations

If a user connects Google or Microsoft, we may receive account identifiers, email address and profile information, selected calendar identifiers, availability or free/busy information, event metadata needed to prevent conflicts or create and update appointments, and OAuth access or refresh tokens. The exact information depends on the permissions shown during authorization and the features enabled.

3.3 Information collected automatically

We may collect IP address, browser and device type, operating system, referring pages, requested URLs, timestamps, session and cookie identifiers, approximate location derived from IP address, diagnostic information, security events, and interactions with Service emails.

3.4 Information from other sources

We may receive information from Organizations, their staff, booking participants, connected services, payment providers, communications providers, fraud-prevention services, and publicly available business sources.

4. How we use information

Subject to our agreements, platform rules, consent requirements, and applicable law, we may use information to:

  • provide, personalize, maintain, and troubleshoot the Service;
  • create accounts, booking pages, appointments, tickets, calendar events, reminders, confirmations, contracts, and payment records;
  • check availability and prevent scheduling conflicts;
  • process transactions and administer deposits, refunds, coupons, gift cards, taxes, and billing;
  • communicate with users, Organizations, staff, attendees, and support contacts about the Service or a booking;
  • provide support, respond to requests, and enforce terms and Organization instructions;
  • analyze, test, develop, and improve features, reliability, accessibility, and user experience;
  • operate our business, keep records, forecast demand, measure performance, and create aggregated or de-identified insights;
  • protect accounts, investigate misuse, prevent fraud, maintain security, and comply with law;
  • send lawful product news, offers, and marketing based on information provided directly to Appointment.to, where consent or another valid legal basis exists.

We do not use information obtained from Google Workspace APIs or Microsoft APIs for advertising or marketing. Sections 8 and 9 control if they are stricter than this section.

6. Public booking pages and Organization responsibilities

Anyone with a public booking-page link may be able to view the page's public business content, but answers, contact information, uploaded files, payment details, and booking records are not made public merely because the page is public.

Organizations determine which questions and services appear and must have authority to collect and use the requested information, provide additional notices or consents required for their activities, configure reasonable retention, protect account access, and respond to privacy requests for information they control.

7. When we disclose information

We may disclose information only as reasonably necessary:

  • to the relevant Organization, authorized staff and resources, and booking participants;
  • to service providers supporting hosting, storage, email, messaging, analytics, security, support, payments, tax calculation, and other operations, under appropriate restrictions;
  • to Google, Microsoft, video-conferencing, payment, and other services a user or Organization chooses to connect;
  • to comply with law or valid government requests, protect rights and safety, or investigate fraud and misuse;
  • in a financing, reorganization, merger, acquisition, or sale of assets, subject to applicable law and the integration-specific restrictions below;
  • with the person's direction or consent.

Appointment.to does not sell personal information. We do not share it for cross-context behavioural advertising, and we do not provide Google or Microsoft API data to advertising platforms or data brokers.

8. Google API and Google Workspace data

8.1 Access and use

When a user connects Google, Appointment.to accesses only the Google account and calendar information authorized by that user and needed to provide visible features such as sign-in, calendar selection, availability checks, conflict prevention, and creating, updating, or deleting Appointment.to-related calendar events.

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

8.2 Prohibited uses

Appointment.to does not use Google user data for advertising, personalized advertising, marketing, creditworthiness or lending decisions, surveillance, unrelated profiling, training general-purpose artificial-intelligence or machine-learning models, or building an unrelated user database. We do not sell Google user data.

8.3 Human access and transfers

Humans do not read Google user data unless the user gives affirmative consent for a specific support or feature purpose; access is necessary for security or abuse investigation; access is required by law; or the data has been aggregated and de-identified for permitted internal operations. We transfer Google user data only as necessary to provide or improve the user-facing feature, for security, to comply with law, or as part of a transaction for which we obtain any explicit prior consent required by Google policy.

8.4 Disconnecting Google

Users may disconnect Google in Appointment.to's calendar-connection settings and may revoke access through Google Account third-party connections. Revocation stops new access. Section 13 explains deletion.

9. Microsoft API and Outlook data

9.1 Access and use

When a user connects Microsoft, Appointment.to uses Microsoft identity services and Microsoft Graph, Outlook, or Exchange data only within the permissions authorized by the user and only for requested features such as sign-in, calendar selection, availability checks, conflict prevention, and creating, updating, or deleting Appointment.to-related events.

9.2 Restrictions

We do not sell Microsoft API Data or use it for advertising, marketing, unrelated profiling, scraping, surveillance, credit decisions, or training general-purpose artificial-intelligence models. We do not access Microsoft mail, files, contacts, or other resources unless a separate feature clearly requires that access and the user expressly authorizes the corresponding permission.

9.3 Disconnecting Microsoft

Users may disconnect Microsoft in Appointment.to's calendar-connection settings. Personal Microsoft accounts can manage consent through Microsoft account permissions; work or school accounts may use My Apps or ask their Microsoft 365 administrator. Revocation stops new access. Section 13 explains deletion.

10. Service and marketing communications

We may send operational communications such as verification messages, booking notices, reminders, receipts, security alerts, policy updates, and support replies. These are part of providing the Service and may continue while an account or booking remains active.

Where permitted, we may send OKay Inc's product news or offers using contact information supplied directly to us. Recipients may unsubscribe using the message link or contact us. We do not use Google or Microsoft API data to determine or deliver marketing.

11. Cookies and similar technologies

The Service may use essential cookies and local storage for sessions, authentication, security, preferences, booking flows, and load balancing. We may use limited analytics technologies to understand performance and improve the Service. Browser controls can block cookies, but essential features may then fail. Where law requires it, non-essential technologies are used only after the applicable choice or consent.

12. International processing

Appointment.to, a service of OKay Inc, is based in Canada. We and our service providers may process information in Canada, the United States, and other countries where privacy laws may differ. We use contractual, organizational, and technical safeguards required for applicable transfers, but information may be accessible to courts, law enforcement, or national-security authorities under local law.

13. Retention and deletion

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, Organization instructions, legal obligations, dispute resolution, security, fraud prevention, and enforcement. Retention varies by record:

  • Account and Organization records are normally kept while the account is active and for a limited period afterward for recovery, legal, accounting, and security needs.
  • Booking records, questionnaires, contracts, and uploads are kept according to Organization settings and instructions, subject to legal and operational requirements.
  • OAuth tokens are kept only while the integration is connected and needed to provide the requested feature.
  • When a Google or Microsoft connection is revoked, an account is closed, or deletion is validly requested, associated integration data is deleted or de-identified from active systems ordinarily within 30 days, unless a shorter period is required or retention is legally necessary. Residual encrypted backup copies ordinarily expire within 90 days and are not restored for ordinary business use.
  • Security logs may be kept longer where reasonably necessary. Aggregated or de-identified information may be retained when it can no longer reasonably identify a person.

We may delay or limit deletion to preserve transaction records, comply with law, investigate abuse, resolve disputes, protect users, or follow an Organization's lawful instructions. When we act as a processor, the Organization may control the applicable retention period.

14. Security

We use reasonable administrative, technical, and physical safeguards designed to protect information, including access controls, encryption in transit, protected credential storage, logging, backups, vendor review, and least-privilege practices. No system is completely secure. Users must use strong unique passwords, protect devices and recovery channels, limit staff access, and promptly report suspected misuse.

15. Privacy and security incidents

We investigate suspected incidents and notify affected Organizations, individuals, regulators, or platform providers when required by law or contract. Notices may be delivered through account contact information or the Service.

16. Children's information

The Service is not directed to children under 13, and they may not independently create an administrative account. An Organization may use the Service to arrange services involving a minor when a parent, guardian, school, club, healthcare provider, or other authorized person provides the information and any required consent. Organizations are responsible for complying with laws that apply to their collection of children's information.

17. Privacy choices and rights

Depending on location and our role, rights may include access, correction, deletion, restriction, portability, withdrawal of consent, objection to certain processing, opting out of marketing, and challenging our compliance.

  1. Use available Appointment.to account, Organization, booking, or integration controls to review, correct, export, disconnect, or delete information.
  2. For information submitted to a booking Organization, contact that Organization first when it controls the information. We will assist as required by law and our agreement.
  3. For Appointment.to account information or an unresolved request, contact privacy@appointment.to and identify the relevant account, Organization, booking, or email address.
  4. Revoke Google or Microsoft access using the links in Sections 8.4 and 9.3. Revocation stops new access but does not automatically delete records that lawfully must be retained.

We may verify identity and authority before completing a request. Legal exceptions may apply, including for security, fraud prevention, accounting, disputes, and the rights of others. We do not discriminate against a person for exercising a privacy right.

In Canada, a person may contact the Office of the Privacy Commissioner of Canada or an applicable provincial privacy regulator after first giving us an opportunity to address the concern.

18. Do Not Track and targeted advertising

Because there is no universally accepted browser Do Not Track standard, the Service may not respond to every such signal. Where legally required and technically supported, we honour recognized opt-out preference signals. Appointment.to does not sell personal information or share it for cross-context behavioural advertising.

19. Third-party services and links

The Service may link to or interoperate with websites and services we do not control. Their privacy practices are governed by their own notices. Organizations may also place their own links, documents, questions, payment accounts, plugins, and integrations on booking pages. Users should review applicable third-party and Organization terms before submitting information.

20. Changes to this Policy

We may update this Policy to reflect changes in the Service, law, vendors, or data practices. We will post the revised Policy with a new Last updated date and provide additional notice or seek renewed consent when required. If we change how we use Google Data or other information in a materially different way, we will notify affected users and obtain consent before the new use when required by platform policy or law.

21. Contact us

Privacy Officer of OKay Inc

Appointment.to

Cornwall, Ontario, Canada

privacy@appointment.to

Include enough information to identify the relevant account, Organization, booking, or integration without sending passwords, complete payment-card numbers, or unnecessary sensitive information.