Slotly ("Slotly", "we", "us") is an online booking and scheduling application for merchants who run stores on the OpoShop platform. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to the Slotly admin application, the storefront booking widget, and any calendar integrations you connect.
https://www.googleapis.com/auth/calendar.readonly and uses it
solely to read your free/busy times through Google's Free/Busy API, so we can stop
customers from booking when you are already busy. Slotly never reads, stores, or displays your event
titles, descriptions, locations, attendees, or any other event content, and we never share Google
user data with third parties or use it for advertising.
1. Information we collect
Account and store data
When Slotly is installed on your store, we receive your store identifier, subdomain, store name, and owner email from the OpoShop platform, plus an access token used to operate on your store. We create an account record so you can sign in to the Slotly dashboard.
Booking data you and your customers create
- Services, staff/resources, availability rules, blackout dates, and pricing you configure.
- Bookings made by your customers: name, email, chosen time, service, and any notes they provide.
- Payment status for a booking (e.g. paid, deposit, pay-in-person). Card payments are processed by the store's own checkout — Slotly does not collect or store card numbers.
Connected calendars (optional)
If you connect a calendar so your existing commitments block booking slots, we store only what is needed to read your availability:
- Google Calendar: an OAuth refresh token for the read-only calendar scope, and a cached list of busy time ranges (start and end times only — no event details).
- Calendar feed (.ics): the secret feed URL you provide, and the same busy-time ranges parsed from it.
Product analytics
We use privacy-respecting product analytics to understand feature usage and fix problems. We do not sell personal data and we configure analytics to avoid collecting unnecessary personal information.
2. How we use information
- To operate bookings: show real-time availability, prevent double-booking, hold slots during checkout, and send booking confirmations and reschedule/cancel links.
- To block times you are unavailable using free/busy data from your connected calendar.
- To provide the admin dashboard, support you, and secure the service.
- To comply with legal obligations.
3. How Slotly's use of Google data complies with the Google API Services User Data Policy
Slotly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We request the minimum scope necessary (read-only calendar) and use it only to provide the user-facing booking feature described here.
- We do not transfer Google user data to third parties except as necessary to provide or improve the feature, comply with law, or as part of a merger with prior notice.
- We do not use Google user data for advertising.
- We do not allow humans to read Google user data unless we have your consent for specific messages, it is necessary for security or to comply with law, or the data is aggregated and anonymized for internal operations.
4. Sharing
We share data only with: (a) the OpoShop platform your store runs on, as needed to operate the app; (b) infrastructure providers that host Slotly under confidentiality obligations; and (c) authorities where required by law. We do not sell your data or your customers' data.
5. Data retention and deletion
We keep booking and configuration data for as long as Slotly is installed on your store. You can disconnect a calendar at any time from the Staff → Calendar screen, which deletes the stored token and cached busy times immediately. When you uninstall Slotly, we mark the store inactive and delete or anonymize associated data on a routine schedule. To request deletion sooner, email us.
6. Security
Data is transmitted over TLS and access tokens are stored server-side. Slotly enforces double-booking prevention at the database level and scopes every request to the authenticated store.
7. Children
Slotly is a business tool and is not directed to children under 13.
8. Changes
We may update this policy; we will revise the "Last updated" date above when we do.
9. Contact
Questions about this policy or a data request? Email brandon@tryfound.io.