Google Calendar
Google Calendar API Privacy Disclosure
Supplement to Zenitup Privacy Policy. Last updated: July 20, 2026.
This page is the Google Calendar API Privacy Disclosure and supplements the main Zenitup Privacy Policy.
Google Calendar API — Privacy Disclosure
Supplement to Zenitup Privacy Policy
Last updated: July 20, 2026 — v2.1
1. Purpose of This Disclosure
This document supplements Zenitup’s general Privacy Policy and describes specifically how Zenitup will collect, use, store, and share data obtained through Google Calendar APIs when a user chooses to connect their Google Calendar account to the Zenitup platform.
The Google Calendar integration is an upcoming feature of Zenitup. This disclosure describes the data practices that will apply upon activation of the integration. Users will be asked to grant explicit authorization through Google’s OAuth 2.0 consent flow before any Google Calendar data is accessed.
This disclosure applies to professional users, coaches, staff members, and administrators who choose to connect a Google Calendar account to Zenitup.
2. About Zenitup
Zenitup is a SaaS scheduling and coaching management platform provided by Zenitup LLC, a limited liability company incorporated under the laws of the State of New Mexico, United States of America (EIN: 423061040), with principal business address at 501 Silverside Road, Suite 105 #5583, Wilmington, DE 19809, USA. Contact: info@zenitup.app.
Depending on the applicable legal framework, Zenitup LLC may act:
as an independent data controller with respect to the management of professional accounts, platform security, billing, technical support, and the technical management of the Google Calendar integration; or
as a data processor (pursuant to Art. 28 GDPR or equivalent legislation) when processing personal data of end clients on behalf of the professional or business customer using Zenitup.
Where Zenitup acts as a data processor, the relationship is governed by a separate Data Processing Agreement with the relevant professional or business customer.
3. Google Calendar Integration
The Google Calendar integration is optional. Users may choose at any time whether to connect their Google Calendar account to Zenitup. The integration will not be activated without the user’s explicit action.
When a user selects “Connect Google Calendar” or an equivalent function, they will be redirected to Google’s OAuth consent screen, which displays the permissions requested by the platform. Zenitup will access Google Calendar data only if the user explicitly grants authorization through the OAuth consent flow.
The user may disconnect Google Calendar at any time through Zenitup’s settings, or by revoking access directly from their Google account settings.
4. Google Calendar Scopes
When the Google Calendar integration is activated, Zenitup will request only the following Google Calendar OAuth scopes:
https://www.googleapis.com/auth/calendar.freebusy — used to check the connected calendar’s free/busy status, calculate availability, and prevent overlapping appointments.
https://www.googleapis.com/auth/calendar.events.owned — used to read events on Google Calendars owned by the connected user, display those events in the user’s Zenitup dashboard, create Zenitup appointment events in the user’s Google Calendar, and update or delete events created or managed through Zenitup.
https://www.googleapis.com/auth/calendar.calendarlist.readonly — used to identify the connected user’s primary calendar and display the list of calendars available to the user, so the user can select which calendars should be used for availability and conflict checks. This scope does not allow Zenitup to read event contents.
Zenitup will not request the following broader Google Calendar scopes:
https://www.googleapis.com/auth/calendar.events.readonly
https://www.googleapis.com/auth/calendar.events
https://www.googleapis.com/auth/calendar
Zenitup requests only the permissions necessary to implement the user-facing scheduling, availability, booking, and calendar synchronization features. No scope is requested for future-proofing purposes or for features not yet implemented.
5. Data Accessed via Google APIs
When a user connects their Google Calendar account to Zenitup, the platform may access and process the following categories of data, within the limits of the authorized scopes:
Calendar identifier of the connected calendar
Calendar list metadata, such as calendar ID, calendar name or summary, primary calendar flag, access role, and calendar time zone
Event ID, iCalUID, sync token, and other technical identifiers necessary for synchronization
Free/busy status and availability information
Event title
Event start and end date and time
Time zone
Event status
Transparency / busy information
Location, if present in the event
Event description, if present and necessary for display or synchronization of events within the user’s owned calendars
Meeting link, if present
Technical identifiers of events created or managed through Zenitup
OAuth access token and refresh token, necessary to maintain the integration while active
Zenitup will not store event attachments, the full attendees list, extended notes, or other content not necessary for the calendar, availability, booking, and synchronization features.
6. Purposes of Use
Zenitup will use data obtained via Google Calendar APIs exclusively to provide the features requested by the user. In particular, Google Calendar data will be used to:
read the connected calendar’s free/busy status;
identify the connected user’s primary calendar and display the list of calendars available for connection or availability and conflict selection;
calculate available booking slots;
prevent overlapping appointments and overbooking;
display the connected user’s calendar events or availability in the Zenitup dashboard;
create events in the user’s Google Calendar when an appointment is booked through Zenitup;
update or delete events created or managed through Zenitup when an appointment is rescheduled or cancelled;
keep Zenitup appointments synchronized with the connected Google Calendar;
manage technical errors, security, maintenance, and the correct functioning of the calendar integration.
7. External Events Not Created by Zenitup
Where the user connects a Google Calendar that contains events not created by Zenitup, the platform may read data relating to those events exclusively to:
display the calendar to the connected user;
calculate availability and prevent overbooking;
manage synchronization and ensure the correct functioning of the integration.
External or personal Google Calendar events not created by Zenitup will be visible only to the user who connected the calendar. Other workspace users will not see the details of the connected user’s personal or external events. Where necessary for booking or availability purposes, other workspace users may see only the “busy / not available” status.
Zenitup will not modify or delete external or personal events that were not created or managed through the platform. Modifications and deletions are limited to events created by Zenitup or formally managed through Zenitup.
8. Google API Limited Use Requirements
| Zenitup’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. |
|---|
In compliance with the Google API Services User Data Policy, Zenitup:
will use Google Calendar data only to provide or improve user-facing features that are visible and prominent in the Zenitup interface;
will not sell Google Calendar data to third parties;
will not transfer or disclose Google Calendar data to advertising platforms, data brokers, or information resellers;
will not use Google Calendar data for advertising, retargeting, personalized or interest-based advertising;
will not use Google Calendar data to train, improve, test, or develop artificial intelligence or machine learning models, whether internal to Zenitup or belonging to third-party providers;
will not use Google Calendar data to determine credit-worthiness or for lending purposes;
will not allow human access to Google Calendar data except as described in Section 10 below.
9. No Use for Advertising, Data Sale, or AI/ML Training
Google Calendar data obtained through the Zenitup integration will never be used for:
advertising or retargeting of any kind;
sale, licensing, or transfer to data brokers or third-party data buyers;
commercial profiling or behavioral analytics for marketing purposes;
training, fine-tuning, testing, or improving any artificial intelligence or machine learning model, including but not limited to large language models, recommendation engines, or predictive systems.
Zenitup will not send Google Calendar data to AI providers for training, profiling, advertising, or any purposes beyond the specific user-facing scheduling and booking features described in this disclosure.
10. Human Access to Google Calendar Data
Human access to Google Calendar data is strictly limited. As a general rule, calendar data is visible only to the user who connected the calendar and, within the configured permissions, to authorized users of the relevant workspace.
Zenitup personnel or authorized contractors may access Google Calendar data only when strictly necessary for:
technical support, debugging, or error resolution — only where necessary and, where applicable, after the user’s affirmative agreement to view the specific data concerned;
security investigation and abuse prevention;
compliance with applicable law.
Such access is subject to internal authorization controls, need-to-know restrictions, and access limitation policies. Zenitup personnel will not read Google Calendar data for purposes beyond those listed above.
11. Sharing with Technical Service Providers
Zenitup does not share Google Calendar data with third parties for advertising, commercial, data sale, or profiling purposes.
Google Calendar data may be processed by technical service providers strictly necessary for the operation of the platform, such as hosting, database, security, logging, monitoring, and application infrastructure services. These providers:
process data only for the specific technical purpose for which they are engaged, under Zenitup’s instructions;
are contractually prohibited from using Google Calendar data for their own purposes, advertising, commercial profiling, data sale, or AI/ML model training;
are subject to appropriate data processing agreements and technical and organizational security measures.
An up-to-date list of Zenitup’s technical service providers is available at: zenitup.app/subprocessors
12. Data Retention, Disconnection, and Deletion
Google Calendar data is retained only for as long as necessary to provide the integration. The following retention periods apply and are implemented at the technical level:
OAuth access token and refresh token: retained only while the Google Calendar integration remains active; deleted without delay upon disconnection or revocation.
Cache of external Google Calendar events (events not created by Zenitup): deleted within a maximum of 7 days from disconnection or revocation.
Accounts in revoked, inactive, or “needs re-authentication” status: permanently cleared after 30 days without re-authorization.
Technical synchronization, security, and error logs: retained for a maximum of 90 days. Logs do not contain OAuth tokens, event descriptions, attendees, or event content; they contain only minimized technical data such as provider identifier, internal account ID, error type, timestamp, and synchronization status.
Upon disconnection or revocation: Zenitup immediately stops synchronization; tokens are deleted locally without delay; where technically possible, Zenitup also revokes the token with Google.
Events already created by Zenitup in the user’s Google Calendar remain in the user’s calendar after disconnection, unless the user deletes them manually. After revocation, Zenitup cannot access, modify, or delete those events unless the user grants a new authorization.
13. Security Measures
Zenitup applies technical and organizational measures designed to protect Google Calendar data, including:
transmission of data via encrypted connections (TLS);
protection of OAuth tokens, secrets, and credentials;
limitation of administrative access to authorized personnel only;
logical segregation of data by workspace and tenant;
logging and monitoring of technical access, errors, and synchronization status;
data minimization in storage and processing;
exclusion of Google Calendar event content from unnecessary logs;
procedures for token deletion and revocation upon disconnection.
14. International Data Transfers
Zenitup LLC is incorporated in the United States. Processing operations related to the Google Calendar integration may involve the transfer of personal data to the United States.
Where processing involves a transfer of personal data to third countries, Zenitup LLC applies the safeguards required by applicable data protection law. For processing carried out as a data processor on behalf of professional or business customers subject to the GDPR or UK GDPR, transfers are governed by:
Standard Contractual Clauses (SCCs) adopted by the European Commission — Decision 2021/914, Module 2 (Controller-to-Processor);
UK International Data Transfer Addendum (IDTA), ICO Version B1.0, where applicable;
Transfer Impact Assessment (TIA) in accordance with EDPB Recommendations 01/2020, as supplementary measure.
Zenitup LLC is not certified under the EU–U.S. Data Privacy Framework (DPF) or the UK–U.S. Data Bridge. Transfers to Zenitup LLC are therefore governed by the instruments listed above.
EU Representative pursuant to Article 27 GDPR:
Giuseppe Lo Presti, Avvocato
Reggio Calabria (RC), Italy
Email: avv.giuseppelopresti@legalmail.it
15. User Rights
Users may exercise their rights under applicable data protection law — including the right of access, rectification, erasure, restriction of processing, objection, and data portability — by contacting Zenitup at: info@zenitup.app
If the user is an end client of a professional or business that uses Zenitup, certain requests relating to personal data must be directed to that professional or business, which acts as the data controller. Zenitup will assist the professional or business customer within the limits of its role as data processor.
16. Changes to This Disclosure
This disclosure may be updated in the event of changes to the Google Calendar features, OAuth scopes, technical providers, data retention practices, or applicable law. Material changes will be communicated through the platform, the Zenitup website, or other appropriate channels. If the Google Calendar integration is extended to new scopes, this disclosure will be updated and users will be prompted to consent before any new data access begins.
17. Contact
For questions about this disclosure or the use of Google Calendar data in Zenitup:
Zenitup LLC
State of New Mexico, United States of America
Principal address: 501 Silverside Road, Suite 105 #5583, Wilmington, DE 19809, USA
Privacy: info@zenitup.app
Website: zenitup.app
EU Representative (Art. 27 GDPR):
Giuseppe Lo Presti, Avvocato
Reggio Calabria (RC), Italy