Privacy Policy
This policy explains what data AppConnect handles, why, how long it is kept, who it is shared with, and how to withdraw its access.
Applies to: AppConnect, at getappconnect.com, and the calendar connections it makes on behalf
of the workspaces that use it.
Last updated: 26 September 2026.
1. Who operates AppConnect
AppConnect is operated by Velocity Automation Corp ("we", "us"). AppConnect is the calendar integration used by the business software platforms Velocity Automation Corp operates, and by the customer workspaces running on them.
Registered address: [JP: confirm registered address of Velocity Automation Corp]
Place of incorporation: [JP: confirm jurisdiction of incorporation]
Privacy contact: privacy@getappconnect.com
2. What AppConnect does
A user of a business software workspace connects their own calendar account to that workspace. Once connected, AppConnect does three things and nothing else:
- lists the calendars on the connected account so the user can choose which one the workspace should use;
- writes appointments booked in the workspace to that calendar, and updates or removes those events when the appointment is rescheduled or cancelled;
- reads the busy periods already on that calendar so the workspace does not offer a time the user is already committed to.
AppConnect acts only on the one calendar the user selects on the account they authorised.
3. Google user data: what is accessed and why
When a user connects a Google account, AppConnect asks Google for the user's permission using the two OAuth scopes below. Google shows the user what is being requested before anything is granted.
-
https://www.googleapis.com/auth/calendar.events
Purpose: to create, update and remove calendar events that correspond to appointments booked in the user's workspace. This is the write access that makes a booking show up on the user's calendar, moves it when it is rescheduled, and removes it when it is cancelled.
-
https://www.googleapis.com/auth/calendar.readonly
Purpose: to list the calendars on the account so the user can choose which one to connect, and to read the busy and free periods on that calendar so that times the user is already booked for are not offered to anyone else.
What is stored from the connected calendar
For each event AppConnect reads from the connected calendar, it stores only what is needed to know that a time is taken:
- the event's identifier as issued by Google;
- the event's title;
- its start time and end time, and whether it is an all-day event;
- when it was last synchronised.
Event descriptions, attendee lists, locations, attachments, conferencing details and guest email addresses are not stored. For events AppConnect itself creates from a workspace appointment, it also keeps the identifier Google returns, so that the same event can later be updated or removed rather than duplicated.
To act on the user's behalf until they disconnect, AppConnect also stores the access token and refresh token Google issues for the connection, and the identifier of the calendar the user selected.
[JP: this list describes what the connector stores today. If the connector is changed to store more Google data — attendees, descriptions, locations — this section must be updated before that ships, or the policy becomes false.]
What is not requested
AppConnect does not request access to Gmail, Google Drive, Google Contacts, or any Google data outside the calendar scopes listed above.
4. Google API Services User Data Policy and Limited Use
AppConnect's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means:
- Data received from Google APIs is used only to provide and improve the user-facing features described in this policy — connecting a calendar, keeping appointments in sync, and not double-booking the user.
- Data received from Google APIs is not transferred to anyone else, except as needed to provide those features with the user's consent, for security purposes such as investigating abuse, to comply with applicable law, or as part of a merger, acquisition or sale of assets, in which case we would give notice before Google user data became subject to a different privacy policy.
- Humans do not read data received from Google APIs, except with the user's explicit agreement (for example when they ask us to look into a specific problem with their connection), where necessary for security purposes, where required by law, or where the data is aggregated and de-identified for internal operations.
- Data received from Google APIs is not used for advertising of any kind, and is not sold or transferred to data brokers, advertising platforms or information resellers.
We do not use Google Workspace APIs, or data obtained through them, to develop, improve or train generalised or non-personalised artificial-intelligence or machine-learning models.
5. Storage, protection and retention
Where it is stored. Calendar connection records — the authorisation tokens, the selected calendar and the imported busy times described in section 3 — are stored in the database of the platform that runs the user's workspace, operated by Velocity Automation Corp.
In transit. All communication with Google's APIs, and all traffic to this website and to the workspaces that use AppConnect, takes place over encrypted HTTPS/TLS connections.
Access. [JP: confirm and state the controls that apply to the production database — who can access it, and whether data is encrypted at rest by the hosting provider. Do not claim a control that is not in place.]
Retention.
- Authorisation tokens are kept only while the connection exists. When a user disconnects the calendar, the connection record containing those tokens is deleted.
- Busy times imported from the connected calendar are deleted at the same time as the connection, and an individual imported event is deleted when it disappears from the connected calendar.
- The identifiers of events AppConnect created for workspace appointments are kept for as long as the workspace keeps the appointment record they belong to.
- Operational logs that may reference a connection or a sync attempt: [JP: confirm the log retention period, in days, and state it here].
6. Who the data is shared with
Google user data obtained through AppConnect is not shared with third parties for their own purposes. It is handled by:
- Google, as the source and destination of the calendar data, under Google's own terms and privacy policy;
- the infrastructure providers that host the platform on which the user's workspace runs, which process the data only on our instructions in order to host it: [JP: confirm the hosting and database providers to name here, or link a sub-processor list];
- the organisation that administers the user's workspace, to the extent that the appointments in that workspace are visible to it. Connecting a calendar does not give that organisation access to the rest of the user's Google account, or to the details of events AppConnect did not create.
We may also disclose data where we are legally required to, or where it is necessary to investigate abuse or protect the security of the service.
7. What we do not do with it
- We do not sell Google user data, and we do not accept payment for access to it.
- We do not use it for advertising, ad targeting, retargeting, personalised advertising or interest-based advertising.
- We do not use it to train, develop or improve artificial-intelligence or machine-learning models.
- We do not use it for credit assessment, lending or any decision about the user unrelated to the features described in this policy.
- We do not transfer it to data brokers or information resellers.
8. How to revoke access
Access can be withdrawn at any time, from either side, without contacting us:
- In the workspace. Open the calendar settings where the account was connected and disconnect it. The stored authorisation is deleted, together with the busy times imported from that calendar.
- With Google. Go to myaccount.google.com/permissions, select AppConnect, and choose to remove its access. Google immediately invalidates the authorisation, and AppConnect can no longer read or write to any calendar on that account.
Revoking access does not delete events that were already placed on the calendar: those are real appointments and belong to the calendar's owner. They can be deleted in Google Calendar like any other event, or by cancelling the appointment in the workspace before disconnecting.
9. How to have data deleted
Disconnecting, as described above, deletes the authorisation and the imported calendar data. If you want confirmation of deletion, or you want us to delete anything that may remain — for example a reference in a support record — email privacy@getappconnect.com from the address of the connected account and say what you want removed. We will confirm when it is done.
10. Other data this website handles
This website, getappconnect.com, is a set of static pages. It sets no cookies, runs no analytics or advertising scripts, and asks for no personal information. Our hosting provider records ordinary server request data such as IP address, timestamp and requested URL for the purpose of serving and protecting the site.
If you email the privacy address, we hold your message and your email address in order to answer it.
11. Your rights and how to reach us
Depending on where you live, you may have rights over personal data we hold about you — for example to ask for a copy of it, to have it corrected, or to have it deleted. You do not need to invoke a law to exercise the controls in sections 8 and 9; they are available to every user. For anything else, write to privacy@getappconnect.com and we will respond.
[JP: legal review — confirm whether a formal GDPR / UK GDPR / CCPA section is required for the markets served, who is named as controller versus processor, and whether a representative or data protection officer must be designated. Do not add compliance claims that have not been reviewed.]
12. Children
AppConnect is a business tool. It is not directed to children, and we do not knowingly collect data from children.
13. Changes to this policy
If this policy changes, the updated version is published on this page with a new "last updated" date. If a change materially affects how Google user data is accessed, used, stored or shared, we will not apply it to data already collected without first giving notice to the affected users.
Velocity Automation Corp · privacy@getappconnect.com