Privacy Policy
Last updated: August 24, 2026
Timefix (“we”, “us”) is a scheduling service: you share a link like timefix.ai/yourname, and visitors book time with you - by picking a slot or by telling the page when works for them. This policy explains what we collect on timefix.ai and app.timefix.ai, why, and the choices you have. It applies to hosts (people with a Timefix account), guests (people who book time with a host), and anyone who sends an enquiry through a Timefix form that a business has put on their own website - the last of whom may never have seen a Timefix page at all, which is why they have a section of their own below.
What we collect
If you sign up as a host, we collect:
- Your Google account basics - name, email address and profile photo, provided by Google when you sign in.
- Google Calendar data - with your permission, when your calendar is busy (so we never offer a taken slot), the events Timefix creates on your calendar for confirmed bookings, and - only to draw your own week back to you inside your dashboard - the title, time and link of the events already on your calendar.
- Your settings - handle, availability rules, timezone, event types, and the bookings made with you.
If you book time with a host as a guest, we collect:
- Booking details - your name, email address, the time you chose, your timezone, party size where relevant, and any note you add.
- Conversation transcripts - what you type to the booking assistant on a host’s page, kept so the host has context for the meeting and so we can improve the assistant. Every message is understood entirely on our own servers, by our own code. No AI service reads what you type, and nothing you type to the assistant is sent to any third party.
If you send an enquiry through a Timefix form on a business’s website, we collect:
- What you typed - the answers you gave to that business’s questions. Which questions they are is up to them; typically a name, an email address, a phone number, a company and what you are looking for.
- Where the form was - the address of the page you filled it in on, the page you came from before it, and any campaign tags in the link that brought you there. This is how the business knows which of their pages and adverts produce enquiries.
The form sets no cookies and loads no analytics. It does not read anything from your browser, does not know whether you have used Timefix before, and adds no tracking to the website you are on.
We also use analytics to understand how the site performs and where people get stuck signing up: Vercel Analytics and Speed Insights (aggregate traffic and page-performance metrics), Google Analytics 4 (visits, referral source and the steps of the signup funnel), and Microsoft Clarity (heatmaps and session replay of the signup flow, so we can see where it breaks). Clarity records interactions with pages — clicks, scrolling and page content — and masks text input by default. Google Analytics and Clarity run in production only, and both set their own cookies. We do not run advertising or retargeting tags, and we do not sell personal information to anyone.
How we use Google user data
Timefix requests Google’s calendar.freebusy and calendar.events scopes, and uses them for exactly three things:
- Reading availability - we check your calendar’s free/busy status to compute which slots to offer. This returns busy and free intervals only, never titles, guests or notes, and it is what every visitor to your booking page sees the effect of: an hour is simply absent, never labelled. Results are cached for at most 60 seconds.
- Creating bookings - when a guest books, we create the event on your calendar and invite the guest, so both sides get a normal calendar invitation. If a booking is moved or cancelled - by you or by the guest - we update or delete that same event, and we read it back so that a change you make in Google Calendar directly is reflected in Timefix rather than the two drifting apart.
- Showing you your own week - the Bookings page in your dashboard draws your real calendar alongside your Timefix bookings, so the titles and times of your existing events are read and shown back to you. When one of those events already has a Google Meet link, we read that too, so you can join it from the same screen. This is the one place event contents are read at all: they are never shown to a guest, never sent anywhere else, and are held only in the same 60-second cache as free/busy.
Timefix’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not let humans read it except with your consent or for security and abuse investigation, and do not use it to develop, improve or train generalized AI or machine-learning models.
Enquiry forms on other websites
A business with a Timefix account can put an enquiry form on their own site, or share a link to one we host. If you send an enquiry that way, that business decides what the form asks and what happens to your answers- not us. In data-protection terms they are the controller of what you sent and we are their processor: we store it, show it to them, and act on their instructions about it.
What that means in practice, plainly:
- Your answers go to that business, and only to them. They are stored under their account, visible to them, and not shared with other Timefix customers, sold, or used to build a profile of you anywhere else in the product.
- We keep exactly what was sent. The submission is stored as it arrived and is never rewritten, so the business always has the original of what you told them. If their page sent along anything extra beyond the questions you answered, that is kept too.
- Refused enquiries are kept, not deleted. If our filters judge a submission to be automated, or it arrives without a usable email address, it is stored and marked as refused rather than thrown away - so a real enquiry wrongly refused can still be found and answered.
- To correct or delete an enquiry, ask the business you sent it to. They can act on it directly. If it is easier to ask us, email us and we will pass the request to them and see it through.
Where your data lives
Timefix runs on a small set of infrastructure providers, each used only to operate the service: Vercel (hosting, delivery and aggregate analytics), Neon (our Postgres database, hosted on AWS in the United States), Upstash (a short-lived cache), Resend (sending booking confirmation emails), Google (the calendar operations described above, and Google Analytics), Microsoft (Clarity, described above), and OpenAI (the assistant our customers use, described next). Data is encrypted in transit and at rest, and calendar tokens are stored server-side only - they never reach a browser.
The assistant our customers use
A business with a Timefix account has an assistant inside their own dashboard. When they ask it a question, we send that question and the records needed to answer it to OpenAI, which processes them on our behalf and returns an answer. Those records can describe you - your name, a meeting you booked, a task or a note the business wrote about you, or an enquiry you sent through their form.
Three things are true of it, and they are limits in our code rather than promises about how it gets used:
- Nothing you type to the booking assistant is ever sent. Conversation transcripts are not readable by the dashboard assistant at all - there is no way for it to reach them.
- It can only read what that business can already see. It answers from their own account and never from another’s, and never from anything the person asking could not already open on their own screen.
- It cannot change anything on its own. It can offer to create a task or a record, and a person has to read that offer and confirm it before anything is written.
The assistant on a host’s booking page - the one you type to when you book - does not use OpenAI or any other AI service. Every message there is still understood entirely on our own servers, by our own code, exactly as described above.
Cookies
Timefix sets cookies for three purposes:
- Signing you in — a session cookie scoped to app.timefix.ai, set only for hosts with an account.
- Knowing where a signup came from — two first-party cookies, tf_aid (an anonymous visit id) and tf_attr (the referral source, such as a search engine or a campaign link), set on the marketing home page. They contain no name, email or other identifying detail.
- Analytics — Google Analytics and Microsoft Clarity set their own cookies in production, as described above.
You can clear or block these in your browser at any time; the only one the product needs to work is the session cookie.
Retention and deletion
- Hosts can disconnect Google Calendar at any time from the Connections page - this revokes Timefix’s access with Google and deletes our stored tokens immediately.
- Bookings, contacts, transcripts and enquiries are kept while the host’s account is active, so their history keeps working. If the account is deleted, everything in it goes with it, enquiries included.
- To delete your account and its data entirely - or, as a guest, to ask what a booking stored about you and have it removed - email us and we will complete the request within 30 days.
Your rights
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Depending on where you live, local law may give you further rights; we honor requests regardless of where you are.
Children
Timefix is not directed at children under 16, and we do not knowingly collect their personal information.
Changes
If this policy changes materially, we will update this page and its date, and notify hosts by email for significant changes.
Contact
Questions or requests: privacy@timefix.com.