Privacy Policy
Last updated: July 24, 2026
Spothello ("Spothello", "we", "us") runs a scheduling tool that reads a host's calendar and email so it can offer meeting times directly inside a conversation. This page explains what we collect, why, and what you can do about it.
This policy covers two kinds of people: hosts (the people who sign up for a Spothello account and connect a calendar) and recipients (the people hosts email, who receive a booking invite and may or may not ever create an account themselves).
Information we collect
Account information. When a host signs up, we collect a name, email address, and password (stored hashed, never in plain text). Company accounts also include the company name and the details of any team members added.
Calendar data. When a host connects Google Calendar, we receive an OAuth token that lets us read free/busy availability and write new events. That token is encrypted at rest. We only read and write the one calendar the host selects as their source of truth, not every calendar on the account.
Email content. Spothello's bot only looks at a thread when the host has deliberately CC'd it. From that thread, it reads the message needed to identify the host, work out who else is on the thread, and compute open slots to offer. It does not read a host's inbox generally, and it does not act on threads it wasn't looped into.
Names and time zones we infer. When a recipient replies to a booking invite, Spothello may pick up their first name from a greeting or sign-off, and their approximate time zone from the reply's timestamp, so future invites are addressed correctly and shown in the right local time. This is inferred passively from replies the bot is already CC'd on. We don't scrape contacts or ask recipients to fill out a profile.
Booking data. Once a meeting is booked, we store the slot time, the calendar event it created, and which invite it came from, so both sides can see, reschedule, or cancel it later.
Email engagement. We use our email provider's built-in open tracking to know whether a booking invite was opened, which feeds the funnel a host sees in their analytics tab. We don't use tracking pixels of our own.
Payment information. Billing is handled by Razorpay. We receive confirmation that a payment succeeded and basic order details; we never see or store full card or bank details ourselves.
How we use it
- To compute real availability and send accurate booking invites.
- To create, reschedule, and cancel calendar events on the host's behalf, only for slots that were actually offered.
- To personalize invites with a recipient's name and local time once we've learned them.
- To show hosts their own booking and engagement history.
- To run billing, enforce trial and seat limits, and provide support.
- To keep the service secure, including detecting abuse of the booking flow.
Who we share it with
We don't sell data. We share the minimum needed with the services that make Spothello work:
- Google, to read calendar availability and write events via the Google Calendar and Gmail APIs.
- SendGrid, to deliver booking-invite emails and report opens.
- Razorpay, to process payments for subscriptions and premium features.
- Our database and hosting infrastructure, which stores the information above so the service can function.
We may also disclose information if required by law, or to protect the rights, safety, or property of Spothello, our users, or others.
Data retention
We keep account, calendar, and booking data for as long as the account is active. If a host permanently deletes their account, we remove their calendar connection, bookings, availability settings, and invite history. Some records may be kept longer where we're required to for accounting or legal reasons.
Security
Calendar OAuth tokens are encrypted at rest. Passwords are hashed, never stored in plain text. All traffic to Spothello runs over HTTPS. No system is perfectly secure, but we design for the principle that a breach of one tenant's data should never expose another's.
Your choices
- Hosts can review, correct, or export their own account and booking data by signing in.
- Hosts can permanently delete their account and associated data from their dashboard at any time.
- Recipients who don't want the bot to pick up their name or time zone from a reply can simply not include one, or can ask the host to remove them via hi@spothello.com.
Children's privacy
Spothello is a business scheduling tool and isn't directed at, or knowingly used by, children. We don't knowingly collect information from anyone under 18.
Changes to this policy
If we make a material change to how we handle data, we'll update the date at the top of this page and, where appropriate, notify hosts directly.
Contact
Questions about this policy or your data can go to hi@spothello.com.
Controller of this data: Spothello
New Delhi, India