Privacy Policy

Last updated: 11 September 2026

This Privacy Policy explains what data Glowful, operated by WaspThemes ("Company," "we," "us"), collects when you create a scheduling page, share your link, or book a time with someone through it, how we use that data, who we share it with, how long we keep it, and the choices you have. It reflects the real data flows of the product and the providers we rely on.

Two kinds of people use Glowful. A host signs in, builds a scheduling page and shares its link. An invitee opens that link and books a time. Invitees never create an account.

1. Information We Collect

Account and sign-in (hosts). You sign in with your Google account, or with your email address and a one-time code we send to it. There is no password. When you sign in we collect and process:

  • Your email address, used as your account identifier.
  • A 6-digit sign-in code, stored only as a hash and only for the ten minutes it is valid, after which it is discarded. If you sign in with Google, we receive your name, email address and profile picture from Google instead.
  • An account identifier and a session cookie issued after you sign in, valid for 14 days.

Your scheduling page (hosts). We store the page you build: your name, a welcome message, a cover image if you choose one in Canva, the theme, your time zone, the event types you offer (title, description, duration, location, booking questions, limits) and your schedules (weekly hours and date overrides).

Bookings (invitees and hosts). When someone books a time through your link we store their name and email address, the guest email addresses they optionally add, their answers to any questions you ask, the meeting location they type when the offer asks for one, their time zone and language, the chosen start time, and the booking status (confirmed, rescheduled or cancelled, with any reason given). Bookings are visible to the host on their own page and to the invitee through the manage link in their confirmation email.

Google Calendar (hosts, optional). If you connect Google Calendar we store the connection described in section 3, including an encrypted refresh token, the calendars you chose to check for conflicts and the calendar that receives new events.

Canva. When you create a page from the Glowful app inside Canva, the app sends us your Canva user id, the id of the design you are working on and the exported image of that design. We store the ids so we can match the design to your page when you return, and the image as your page cover.

Technical and usage data. Standard server logs (IP address, user agent, requested path, timestamp) are recorded by our hosting provider for operational diagnostics. We use the IP address of requests that create or change a booking for rate limiting, so a script cannot fill a calendar in a loop; these counters live in memory for a few minutes and are not written to a database. We also use analytics services described in section 4.

2. How We Use Information

  • Operate the service: host your scheduling page, compute your open times and record bookings.
  • Sign you in with Google or an emailed code, and keep you signed in.
  • Send booking emails: confirmations with a calendar (.ics) file and notices when a booking is rescheduled or cancelled go to the host, the invitee and any guests the invitee added; reminders one day and one hour before a meeting go to the invitee.
  • Show your open times to invitees while hiding the times you are busy.
  • Put bookings on your Google Calendar when you have connected it, or serve them as a calendar feed you subscribe to.
  • Protect the service against bots, abuse and fraud, and enforce our Terms.

We do not sell personal information. We do not use your data to train machine-learning models. We do not run advertising networks, retargeting pixels or third-party advertising cookies on this service.

3. Google Calendar Integration

Connecting Google Calendar is optional. When you connect it we ask Google for these permissions:

  • calendar.events.freebusy: to read when you are busy on the calendars you select. It shows free and busy times only, never what your events are.
  • calendar.calendarlist.readonly: to list your calendars so you can choose which ones to check for conflicts.
  • calendar.app.created: to create one calendar named Glowful in your account and add, move and remove the events for bookings made through Glowful on it. It gives no access to your other calendars' events.
  • Your basic profile (openid, email) so we can show which Google account is connected.

Here is exactly what we do with that access:

  • We read free and busy times from the calendars you selected, only to hide taken slots from your booking link. We do not store the titles, attendees or details of those events.
  • We create, update and delete only the events of bookings made through Glowful, and only on the Glowful calendar. We cannot see or change any other event.
  • The refresh token Google issues is stored encrypted and is used only to obtain short-lived access tokens for the two purposes above.
  • You can disconnect at any time from the Google Calendar section of your page, which deletes the stored token and asks Google to revoke it. You can also revoke Glowful's access from your Google account's security settings.
  • We do not share Google user data with third parties, we do not use it for advertising, and no human reads it except to resolve a support request you make or as required by law.

Glowful's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Categories of Recipients

We rely on a small number of providers to operate Glowful. Each processes data on our behalf for the purpose described and publishes its own privacy commitments:

  • Google Cloud and Firebase host the application, the database and the authentication service that hold your account, page, offers, hours, bookings and calendar connection.
  • Resend delivers the sign-in codes and the booking emails described above.
  • Google Calendar, when you connect it, receives the events for your bookings and returns your busy times (section 3).
  • Canva runs the app you use to design your cover. Your use of Canva is governed by Canva's own terms and privacy policy; we receive from it only the ids and image described in section 1.
  • Google Analytics 4 and Microsoft Clarity collect aggregate usage data, such as pages visited, interactions and approximate location, to help us understand how the product is used. Clarity may record how a session moves through a page; it masks typed text by default.

Outside of these categories, we share information only when (a) you ask us to, (b) we are required to by law, or (c) it is necessary to protect the safety, rights or property of users or the service. We do not share personal information with advertising networks or data brokers.

5. Calendar Feed

Every page has a private calendar feed (an ICS URL containing a secret token) that you can subscribe to from any calendar application. The feed contains your bookings. Anyone who has the URL can read it, so treat it like a password; you can rotate the token from the Google Calendar section of your page, which invalidates the old URL.

6. Data Retention

  • Sign-in codes: ten minutes, then discarded.
  • Sessions: 14 days, or until you sign out.
  • Your page, offers, hours and calendar connection: until you delete them or delete your account.
  • Bookings, including invitee details: until the host deletes the page or the account. Cancelled bookings stay visible to the host as cancelled until then.
  • Canva design ids and the cover image: until you replace the cover or delete the page.
  • Server logs: retained by our hosting provider under its standard operational window.
  • Analytics data: under the retention settings of Google Analytics and Microsoft Clarity.

7. Your Rights and Controls

Subject to applicable law (including the GDPR and CCPA where relevant), you can:

  • As a host, view and edit your page, its offers, your hours and your bookings on the page itself, and cancel any booking.
  • As a host, delete your account from your account page. This deletes your page, every offer and every set of hours, every booking, the calendar connection (and revokes its Google grant), and your sign-in record.
  • As an invitee, reschedule or cancel your booking from the manage link in your confirmation email.
  • Ask us for a copy of the data we hold about you, or to correct, restrict or delete it, by emailing support@glowful.so. We complete verified requests within 30 days.

If you are in the European Economic Area, the United Kingdom or another region that gives you the right to complain to a data-protection authority, you may contact your local regulator. We would also appreciate the chance to resolve your concern first at support@glowful.so.

8. Data Security

All traffic is served over HTTPS. The database is reachable only from our servers; there is no direct client access. Sign-in codes are stored hashed and expire within minutes, Google refresh tokens are stored encrypted, and calendar feed URLs carry a secret you can rotate. No system is perfectly secure and we cannot guarantee absolute security, but we apply industry-standard practices and respond promptly to reports of vulnerabilities.

9. Children's Privacy

Glowful is intended for use by adults. Accounts and scheduling pages must be created and managed by people who are 18 or older. We do not knowingly collect personal information from children under 18. If you believe a minor has provided us with personal information, contact support@glowful.so and we will delete it.

10. International Data Transfers

Our hosting and most of our providers are located in the United States or the European Union. By using Glowful you understand that your information may be transferred to and processed in countries with different data-protection laws. Where data is transferred outside the EEA or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum where applicable, or another approved transfer mechanism offered by the relevant provider.

11. Cookies

We use a small number of strictly necessary, preference and analytics cookies. For the full list and how to manage them, see our Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy as the product evolves or laws change. We will update the "Last updated" date above and, for material changes, surface a notice in the product. Continued use after an update means you accept the revised policy.

13. Contact

Questions, requests or concerns about this policy: support@glowful.so.