Skip to main content

Privacy Policy

Last Updated: July 18, 2026

Effective Date: July 18, 2026

CalendTree ("we," "us," or "our") is a business management platform built for self-employed professionals and small business owners, published by CalendTree LLC. This Privacy Policy describes what information we collect, how we use it, who we share it with, and your rights regarding your data.

By using CalendTree — including our iOS app, web app at app.calendtree.com, and calendtree.com — you agree to the practices described in this policy. If someone using CalendTree has sent you a booking page, invoice, quote, proposal, contract, or questionnaire and you don't have your own CalendTree account, you're an "End Client" under our Terms of Service — this policy still applies to information you submit through those pages.

1. Information We Collect

a. Account Information

When you create a CalendTree account, we collect:

  • Name, email address, and phone number
  • Profile photo (optional)
  • Business name, branding assets, and timezone
  • Your sign-in method — email/password, Sign in with Apple, or Sign in with Google

If you sign in with Apple or Google, we receive the identity token needed to authenticate you and, where the verified email matches an existing account, to link that sign-in method to your account so you keep access to your data across providers. We do not receive or store your Apple or Google password.

b. Business Data You Create

CalendTree stores the business data you enter, including:

  • Client and organization records (names, contact details, notes, custom fields)
  • Bookings and appointments
  • Invoices, quotes, proposals, and contracts (including e-signatures)
  • Payment records and transaction history (amounts, timestamps, and tokenized references — never raw card numbers, see 1(e))
  • Expenses and receipt images, including data extracted via receipt scanning
  • To-do items, projects, and time-tracking sessions
  • Questionnaire configurations and the responses your clients submit
  • Records about Workers/contractors you invite to your account, including information needed for 1099 preparation
  • Business settings, preferences, and uploaded booking-page images

This data is stored in a secure, encrypted database and is associated with your account.

c. Location and Mileage Data

If you enable automatic mileage tracking, CalendTree collects your device's GPS location — including in the background, while the app is not open — to detect and log business drives. We use on-device motion data alongside location to distinguish driving from walking or biking. Trip records are synced to our servers as part of your business data. You can deny or revoke location access at any time in your device Settings; mileage tracking will not function without it, but the rest of the app will.

d. Biometric Data

If you enable Face ID or Touch ID sign-in, authentication happens entirely on your device using Apple's LocalAuthentication framework. CalendTree never receives, transmits, or stores your biometric data — it only unlocks a session already stored securely in your device's Keychain.

e. Payment Information

CalendTree integrates with Square for both your own subscription billing (direct/web) and payments you collect from your clients (invoices, payment links, and Apple Tap to Pay). When you connect Square, we store your Square OAuth tokens to facilitate those payments on your behalf, into your own Square merchant account.

We do not store, process, or transmit raw credit card numbers. Card data collected through Apple Tap to Pay is encrypted at the point of tap using Apple's Secure Element and Square's certified infrastructure — CalendTree only ever sees the transaction amount, timestamp, and a tokenized reference. All card processing is handled directly by Square under their PCI DSS Level 1 certified infrastructure.

If you subscribe via Apple In-App Purchase instead, Apple handles that billing directly and shares only purchase/entitlement receipts with us.

f. Health Insurance and Tax Help Referral Data

If you choose to use the optional Health Insurance or Tax Help referral forms in the app's "Life" section, we forward the name, contact details, and limited demographic/eligibility information you submit to an independent, licensed third-party insurance broker or tax professional so they can contact you. We do not collect medical history, diagnoses, conditions, or medications through these forms. This data is handled separately from your core business data and shared only with the specific partner you're routed to. The in-app consent screen for these features governs if anything here is inconsistent with it.

g. Apple Health (Sleep)

If you connect Apple Health, we read your logged sleep hours to power an optional wellness feature. This data stays on your device and is never uploaded to our servers.

h. Google Calendar Integration

If you connect your Google account, we access — with your explicit permission — your Google Calendar events to populate booking and scheduling features.

CalendTree's use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not transfer it to third parties except as necessary to provide the service, and do not allow humans to read your Google data unless you explicitly request support, it is necessary for security, or required by law.

i. Zoom Integration

If you connect Zoom, we store your Zoom OAuth credentials to allow you to attach Zoom meeting links to bookings. We do not record, access, or store Zoom meeting content.

j. Device Permissions

CalendTree may request the following device permissions. Each is optional (except where core functionality depends on it) and can be denied or revoked at any time in your device Settings:

  • Location (When in Use / Always) — mileage tracking; approximate location for weather
  • Motion & Fitness — driving vs. walking/biking detection for mileage accuracy
  • Calendar — sync bookings with Apple Calendar
  • Contacts — import contacts as clients (optional)
  • Camera — profile photos, branding images, receipt scans
  • Photo Library — select branding or receipt images
  • Microphone — voice commands for the in-app AI assistant
  • Face ID — biometric app unlock (on-device only, see 1(d))
  • Apple Health — sleep hours for an optional wellness feature (on-device only, see 1(g))
  • Notifications — booking, invoice/payment, and business alerts

k. Usage and Technical Data

We automatically collect limited technical information to operate the service:

  • Device type, operating system, and app version
  • Pages visited within the app and feature usage patterns (processed locally for personalization, synced only to our own servers — see Section 8)
  • Approximate geography of visitors to your booking pages (IP addresses are processed transiently to derive approximate location and may appear briefly in standard infrastructure logs)
  • Push notification device tokens
  • Error logs and crash reports (used for debugging only)

l. Communications

If you contact our support team, we retain your email address and message content to respond to and resolve your inquiry.

m. Partner and Referral Program

If you apply to or participate in the CalendTree partner program, we collect your name, business name, and contact information, along with referral attribution details. When an account is created through a partner referral, we track which partner the account is attributed to so we can administer the program.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the CalendTree platform, including sign-in and account linking across Apple/Google/email
  • Sync your business data across your devices (iOS, iPad, web)
  • Send invoices, contracts, quotes, proposals, and booking confirmations on your behalf
  • Support your own subscription billing and payments you collect from your clients through Square or Apple In-App Purchase
  • Track mileage and generate expense/receipt records for your own business recordkeeping
  • Connect with third-party integrations you authorize (Google, Square, Zoom, Apple services)
  • Route Health Insurance or Tax Help referral submissions to the appropriate independent partner, if you use those optional features
  • Send transactional emails (booking confirmations, invoice reminders, contract signatures)
  • Respond to support requests and troubleshoot issues
  • Detect and prevent fraud, abuse, or security incidents
  • Comply with legal obligations

We do not sell your data. We do not use your data for advertising. We do not build advertising profiles from your information.

3. How We Share Your Information

We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:

a. Service Providers

We work with trusted third-party providers to operate CalendTree. These providers are contractually obligated to protect your data and may only use it to perform services on our behalf:

  • Cloud infrastructure provider (AWS) — secure hosting, database, authentication, and file storage
  • Google — calendar and authentication integrations (per your authorization)
  • Square — your subscription billing and payments you collect from clients (per your authorization)
  • Apple — Sign in with Apple, In-App Purchase billing, push notifications, WeatherKit, MapKit, Tap to Pay (per your authorization/device settings)
  • Zoom — video meeting links (per your authorization)
  • Email delivery providers — for sending invoices, contracts, and booking emails to your clients
  • Independent insurance brokers / tax professionals — only if you submit a Health Insurance or Tax Help referral form, and only the information on that form

b. Your Clients

When you send an invoice, contract, quote, proposal, or booking confirmation through CalendTree, your client's name, email, and the relevant document are transmitted to them. You control what you send and to whom.

c. Legal Requirements

We may disclose information if required by law, subpoena, or government request, or if we believe disclosure is necessary to protect the rights, property, or safety of CalendTree, our users, or the public.

d. Business Transfers

If CalendTree is acquired, merged, or undergoes a change in ownership, your data may be transferred as part of that transaction. We will notify you via email or prominent notice on our platform before your data becomes subject to a different privacy policy.

4. Data Storage and Security

  • All data is stored in the United States on secure, enterprise-grade cloud infrastructure (AWS)
  • Databases and files are encrypted at rest and in transit using TLS/SSL
  • Authentication uses industry-standard token-based security (AWS Cognito)
  • Access to production systems is restricted to authorized personnel only
  • Local files on your device use iOS complete file protection
  • We regularly review and improve our security practices

If you access CalendTree from outside the United States, your information is transferred to and processed in the United States, which may have different data-protection laws than your jurisdiction.

While we implement strong safeguards, no method of electronic transmission or storage is 100% secure. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorized access to your account.

5. Data Retention

We retain your data for as long as your account is active or as needed to provide the service.

  • Account and business data is retained until you delete your account
  • After account deletion, data is permanently purged within 30 days, except records we are required to retain for tax, accounting, security, or legal compliance
  • Signed contracts (including the electronic signature, IP address, timestamp, and audit trail) are retained even after you delete your account, because they are the other signing party's legal record of an executed agreement. Unsigned contract drafts are deleted along with the rest of your account data.
  • Health Insurance / Tax Help referral data is retained only as long as necessary to complete the referral, plus any period required for our own recordkeeping or legal compliance
  • Support communications are generally retained for up to 1 year after resolution
  • Technical logs and crash data are generally retained for up to 90 days

You may export your data or delete your account at any time from Settings → Privacy & Data in the app or web dashboard.

6. Your Rights and Choices

You have the following rights regarding your data:

Access and Portability

You may download a structured copy of your records at any time from Settings → Privacy & Data → Download My Data; uploaded files (such as receipts and contracts) are listed in the export and can be retrieved in the app.

Correction

You may update or correct your account information at any time from your profile settings.

Deletion

You may permanently delete your account and all associated data from Settings → Privacy & Data → Delete Account. Deletion is irreversible. We will purge your data within 30 days.

Third-Party Integrations

You may disconnect Google, Square, or Zoom at any time from Settings → Integrations. Disconnecting revokes our access to those services going forward.

California Residents (CCPA/CPRA)

California residents have the right to know what personal information we collect, the right to correct inaccurate personal information, the right to delete personal information, the right to opt out of the sale or sharing of personal information, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising any of these rights. We do not sell or share personal information as defined by the CCPA. The only sensitive personal information we use is precise location, and it is used only to provide the mileage tracking you enable.

To exercise your rights, contact us at Legal@CalendTree.com. We verify requests using the email address associated with your account, and an authorized agent may submit a request on your behalf with your written permission. Because we do not sell or share personal information, opt-out preference signals such as Global Privacy Control do not change how we process your data.

European Users (GDPR)

If you are located in the European Economic Area, you have the right to access, rectify, port, and erase your data, as well as the right to restrict or object to certain processing. Our legal bases for processing are: performance of our contract with you (to provide the core service); your consent (for optional integrations, location, and health-related referrals); our legitimate interests (security, fraud prevention, and improving the service); and compliance with legal obligations. You may withdraw consent at any time, and you may lodge a complaint with your local supervisory authority. Contact us at Legal@CalendTree.com to exercise these rights.

End Clients

For End Client data stored in a CalendTree user's account, that business decides how the data is used — CalendTree processes it on the business's behalf as a service provider. End Clients should direct privacy requests to the business they worked with; we assist businesses in honoring those requests.

7. Cookies and Tracking

CalendTree uses cookies and similar technologies to operate the web application:

  • Essential cookies — required for authentication and session management
  • Preference cookies — to remember your language and display settings

We do not use third-party analytics SDKs, advertising cookies, third-party tracking pixels, or behavioral analytics/advertising networks. Any in-app usage analytics are processed locally on your device and synced only to our own servers. You may disable cookies in your browser settings, but some features of the app may not function correctly.

8. Health-Related Information & HIPAA

CalendTree's core business-management features — client records, booking notes, invoicing, and the like — are a scheduling and business-management tool. They are not designed to handle Protected Health Information (PHI) under HIPAA, and CalendTree LLC does not sign Business Associate Agreements or act as a HIPAA-covered entity for these features.

If you operate a wellness or healthcare-adjacent business, you may use these core features for appointment scheduling, contact management, invoicing, and general business records. Do not enter health, medical, treatment, diagnosis, or insurance information into client notes, booking descriptions, or any other core-feature field.

The one narrow exception is the optional Health Insurance referral form described in Section 1(f), which exists specifically to route limited demographic/eligibility information (not medical history) to an independent, licensed insurance broker at your request.

9. Children's Privacy

CalendTree is intended for users 18 years of age and older. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will promptly delete it.

If you believe a child has provided us with their information, please contact us at Legal@CalendTree.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this page and, where appropriate, by sending an email notification to the address associated with your account.

Continued use of CalendTree after changes take effect constitutes your acceptance of the updated policy.

11. Contact Us

For privacy questions, data requests, or concerns, please contact us:

CalendTree LLC

General inquiries and privacy requests

Legal@CalendTree.com

calendtree.com

We aim to respond to all privacy requests within 30 days.