Legal

Privacy Policy

Last updated: July 24, 2026

Spothello ("Spothello", "we", "us") runs a scheduling tool that reads a host's calendar and email so it can offer meeting times directly inside a conversation. This page explains what we collect, why, and what you can do about it.

This policy covers two kinds of people: hosts (the people who sign up for a Spothello account and connect a calendar) and recipients (the people hosts email, who receive a booking invite and may or may not ever create an account themselves).

Information we collect

Account information. When a host signs up, we collect a name, email address, and password (stored hashed, never in plain text). Company accounts also include the company name and the details of any team members added.

Calendar data. When a host connects Google Calendar, we receive an OAuth token that lets us read free/busy availability and write new events. That token is encrypted at rest. We only read and write the one calendar the host selects as their source of truth, not every calendar on the account.

Email content. Spothello's bot only looks at a thread when the host has deliberately CC'd it. From that thread, it reads the message needed to identify the host, work out who else is on the thread, and compute open slots to offer. It does not read a host's inbox generally, and it does not act on threads it wasn't looped into.

Names and time zones we infer. When a recipient replies to a booking invite, Spothello may pick up their first name from a greeting or sign-off, and their approximate time zone from the reply's timestamp, so future invites are addressed correctly and shown in the right local time. This is inferred passively from replies the bot is already CC'd on. We don't scrape contacts or ask recipients to fill out a profile.

Booking data. Once a meeting is booked, we store the slot time, the calendar event it created, and which invite it came from, so both sides can see, reschedule, or cancel it later.

Email engagement. We use our email provider's built-in open tracking to know whether a booking invite was opened, which feeds the funnel a host sees in their analytics tab. We don't use tracking pixels of our own.

Payment information. Billing is handled by Razorpay. We receive confirmation that a payment succeeded and basic order details; we never see or store full card or bank details ourselves.

How we use it

Who we share it with

We don't sell data. We share the minimum needed with the services that make Spothello work:

We may also disclose information if required by law, or to protect the rights, safety, or property of Spothello, our users, or others.

Data retention

We keep account, calendar, and booking data for as long as the account is active. If a host permanently deletes their account, we remove their calendar connection, bookings, availability settings, and invite history. Some records may be kept longer where we're required to for accounting or legal reasons.

Security

Calendar OAuth tokens are encrypted at rest. Passwords are hashed, never stored in plain text. All traffic to Spothello runs over HTTPS. No system is perfectly secure, but we design for the principle that a breach of one tenant's data should never expose another's.

Your choices

Children's privacy

Spothello is a business scheduling tool and isn't directed at, or knowingly used by, children. We don't knowingly collect information from anyone under 18.

Changes to this policy

If we make a material change to how we handle data, we'll update the date at the top of this page and, where appropriate, notify hosts directly.

Contact

Questions about this policy or your data can go to hi@spothello.com.

Controller of this data: Spothello
New Delhi, India