Privacy Policy
Last updated: August 18, 2026
Introduction
Calendar Force is operated by Calendar Force Pty Ltd (ABN 58 695 616 794), an Australian company.
This Privacy Policy explains how we collect, use, disclose, and safeguard information across both of our surfaces: the Google Calendar add-on, and the web application at app.calendarforce.com. It applies to both, and to the staff portal offered through the web application.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Which Features Collect What
Not every feature is available on both surfaces, and what we collect depends on what you use.
- The Google Calendar add-on accesses your calendar events and your email address, in order to set and send SMS reminders. It does not access Gmail, Drive, or Sheets.
- The web application provides SMS reminders plus invoicing, service records, remittance matching, and the staff portal, and therefore accesses more — as set out below.
Information We Collect
Account Information
When you sign in with Google, we collect your email address to create and manage your account.
Calendar Event Data
We access events in the Google Calendars you connect, in order to schedule and send SMS reminders and to build service records. This includes event titles, times, locations, descriptions, colours, and attendee information.
Phone Numbers and Recipient Details
Phone numbers are entered by you in event descriptions, in your connected spreadsheets, or directly in our interface. We use these numbers solely to send the SMS reminders you schedule. We never sell them and never use them for our own marketing.
Business and Banking Details
If you use the invoicing features, we collect the business details needed to produce an invoice — business and trading name, ABN, address, contact details, director name and contact details — and your banking details for the payment instructions printed on your invoices. Banking details are encrypted at the column level using AES-256-GCM and are decrypted only server-side when generating your documents.
Client, Service and Invoice Records
Where you use invoicing, we process the client records, service logs, rates, and invoice data held in the Google Sheets you create through the service or explicitly select. Where you upload a remittance document, we extract payment data from it to reconcile against your invoices.
Photographs
You and your staff may upload photographs in support of invoicing. These are stored in your own Google Drive, not on our servers, and are referenced by our systems in order to match them to the correct job and invoice.
Staff Portal Users
If your organisation uses the staff portal, staff members sign in with their own Google accounts and grant read-only access to their calendar so the portal can show them their assigned jobs. We collect their name, email address, profile information, the calendar events assigned to them, and any photographs they upload. Their employer — the Calendar Force account holder — determines what is collected and why.
Usage and Billing Data
We collect information about your usage of the service (reminders sent, credits and invoice tokens used, delivery outcomes) and billing information for purchases. Payment card details are processed by Stripe and are never stored on our servers.
Reminder Instructions You Type
If you describe a reminder schedule in plain language, the phrase you type is sent to OpenAI to be converted into reminder timings. Only the phrase you type is sent — no calendar event content, attendee details, or phone numbers are included. This feature is optional.
Information About Other People
Much of the information we handle is about people other than you — your clients, your appointment attendees, and your staff. You provide that information to us, and you decide what is collected and how it is used. In relation to that information you are responsible for having the necessary consents in place and for giving those individuals any privacy notice required of you. We handle it only to provide the service to you, and on your instructions.
How We Use Your Information
- To send SMS reminders for your calendar events
- To generate invoices and related documents in your Google Drive
- To send email from your Google account on your behalf, where you ask us to
- To reconcile remittances against your invoices
- To operate the staff portal and show workers their assigned jobs
- To process payments and manage your credit and token balances
- To provide customer support
- To maintain the security and integrity of the service, and to prevent fraud and abuse
- To improve our service and develop new features
- To communicate important updates about the service
We do not sell personal information, and we do not use it for advertising.
Google API Services User Data Policy
Calendar Force's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described in this policy.
- We do not transfer Google user data to third parties except as necessary to provide those features, for security purposes, or to comply with applicable law.
- We do not use Google user data for advertising, and we do not sell it.
- We do not allow humans to read Google user data, except with your explicit consent for a specific issue such as a support request, where necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
- We do not use Google user data to develop, improve, or train generalised artificial intelligence or machine learning models.
We request the following access, and use it only as stated:
- Google Calendar — to read your events so reminders can be scheduled, and to write changes you make through our interface.
- Google Drive (drive.file) — limited to files our service creates and files you explicitly select through the Google Picker. We cannot see the rest of your Drive.
- Gmail (gmail.send) — to send email on your behalf when you choose to send an invoice or share an event. This permission allows sending only; we cannot read your mailbox.
- Your email address and basic profile — to identify your account.
You can revoke our access at any time at myaccount.google.com/permissions.
Third-Party Services
We use the following third-party services to operate Calendar Force:
- Google APIs - Authentication, Calendar, Drive, Sheets, Docs and Gmail sending
- Supabase - Database and backend services (hosted PostgreSQL)
- Vercel - Application hosting and privacy-friendly, cookieless usage analytics
- Telnyx - SMS delivery
- Stripe - Payment processing
- OpenAI - Optional natural-language parsing of reminder instructions you type
Overseas Disclosure
Calendar Force is an Australian company, but some of our service providers store or process data outside Australia. By using the service you acknowledge that your information, and information you provide about others, may be handled in the following locations:
- Supabase — our database is hosted in the United States (AWS us-west-2, Oregon). This is where account records, reminder schedules, phone numbers, and encrypted business and banking details are stored.
- Vercel — United States, with global edge delivery.
- Stripe — United States, Australia, and Ireland.
- Telnyx — United States, with regional routing for message delivery.
- Google — global infrastructure, including the United States.
- OpenAI — United States (optional feature only).
We take reasonable steps to ensure these recipients handle personal information consistently with the Australian Privacy Principles, including through their contractual terms and security commitments.
Data Retention and Deletion
We retain your data for as long as your account is active. You can request deletion of your account and associated data at any time by contacting admin@calendarforce.com.
On account closure or a deletion request, we delete calendar event data, phone numbers, and associated personal information within 90 days. Google OAuth tokens are revoked and deleted within 30 days. Encrypted backups may retain data for up to a further 30 days before being overwritten.
Billing and payment records are retained for seven years to comply with Australian financial record-keeping requirements, and are not deleted on request. Full detail is in our Data Retention Policy.
Documents created in your own Google Drive — including invoices — are not deleted by us, because they are yours and are held in your Google account, not ours.
Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Withdraw consent for data processing, including by revoking our Google access
To exercise these rights, contact us at admin@calendarforce.com. We will respond within 30 days. If you are a staff portal user or a client of one of our customers, please contact that organisation first, as they control the information held about you.
Complaints
If you believe we have mishandled your personal information, contact us at admin@calendarforce.com with the details. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days, and we will tell you the outcome and our reasons in writing.
If you are not satisfied with our response, you may refer the complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
Data Breaches
We maintain a data breach response process. If a breach occurs that is likely to result in serious harm to any affected individual, we will notify those individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).
Cookies and Analytics
We use minimal, session-based cookies only for authentication and maintaining your session. We do not use tracking cookies or third-party advertising cookies. Our website uses Vercel Analytics, which collects aggregate page-view statistics without cookies and without building a profile of you across sites.
Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit and at rest, column-level encryption of banking details, row-level access controls so each account can reach only its own data, encrypted storage of Google OAuth tokens, and regular security reviews.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the service.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Calendar Force Pty Ltd — ABN 58 695 616 794