Privacy policy
Last updated: 26 September 2026
- We use your data only to schedule meetings, send invitations and run your subscription. No advertising, no selling of data, no tracking.
- Everything is hosted in Europe (Belgium) and email is sent from London.
- If a guest shares their calendar, we only see when they are busy, never what their events are.
- You can ask us to access, correct or delete your data at any time.
1. Who we are
Rendezvous (setrendezvous.com) is operated by Rendezvous, Innovation Centre, Rennes Drive, Exeter EX4 4GX, United Kingdom ("we", "us"). We are the controller of the personal data described here. Contact: support@setrendezvous.com.
2. Who this policy covers
- Organizers: people who sign in to Rendezvous with Google or Microsoft to plan meeting series.
- Guests: people an organizer invites. Guests don't need an account; we receive their email address from the organizer.
3. What we collect and why
| Data | Source | Purpose | Legal basis (UK/EU GDPR) |
|---|---|---|---|
| Organizer account: name, email address, profile picture link, Google or Microsoft account ID | Google / Microsoft sign-in | Create and secure your account | Contract |
| Subscription status and Stripe customer ID | Stripe | Provide the features of your plan | Contract |
| Meeting series and meetings: names, descriptions, locations, dates, times, scheduling rules and notes you write | You | Plan and send your meetings | Contract |
| Guests' email addresses | The organizer | Send invitations, availability requests, updates and cancellations | Legitimate interests (delivering the organizer's invitations) |
| Guests' replies: availability messages, RSVP answers (yes / maybe / no) | Guests (email, web form, calendar reply) | Schedule meetings and show the organizer who is coming | Legitimate interests |
| Guests' shared calendar: busy/free time ranges for the next 90 days, and an encrypted access token | Guests who choose to connect their Google or Microsoft calendar | Avoid scheduling meetings when the guest is busy: only for the meetings the guest approves, or for all meetings they are invited to if they choose so | Consent (can be withdrawn at any time) |
| Delivery problems: addresses that bounced or reported our email as spam | Our email provider | Stop emailing addresses that can't or don't want to receive our email | Legitimate interests |
| Scheduling rules read from written text (for example "not on Fridays"), with the words they come from, and the guest's time zone when they reply through the web form | Organizers' and guests' written text; the guest's browser | Plan meetings that respect everyone's constraints, and show the organizer what was understood | Contract (organizer); legitimate interests (guests) |
| Feature requests: the idea you send, with your name, email address and plan | You | Improve Rendezvous and reply to you | Legitimate interests |
| Meeting notes and documents that organizers and moderators add to a rendezvous or series | Organizers and moderators | Share them with the meeting's guests | Contract (organizer); legitimate interests |
| Enterprise enquiries: company details, contact name, role, work email and phone, and the size of your use, sent through the Enterprise form | You | Answer your enquiry and prepare an offer | Steps at your request before a contract; legitimate interests |
| Support requests: your messages, the replies, your name, email address and plan | You | Answer your questions and fix problems | Contract; legitimate interests |
| Activity log: AI requests and results, availability submissions, RSVPs | The service | Troubleshooting, abuse prevention, improving scheduling | Legitimate interests |
We don't collect payment card details: payments are handled entirely by Stripe.
4. Your Google and Microsoft data
When an organizer grants access, Rendezvous uses it only for the actions the organizer starts:
- Calendar: add, update and remove the organizer's Rendezvous meetings in their own calendar, and create Google Meet or Microsoft Teams links. We don't read or store the organizer's other calendar events.
- Contacts: search contacts when the organizer types in the guest search box, to fill in email addresses. Results are not stored.
These access tokens stay in the organizer's browser session and are sent to our server only for the action being performed; we don't store them. For guests who connect a calendar, we read only free/busy time ranges (never event titles, descriptions, locations or attendees) and keep an encrypted token so the busy times stay up to date until the guest disconnects. When connecting, guests choose whether their calendar is used only for the meetings they approve (they are asked each time) or for any meeting they are invited to through Rendezvous; they can change this or disconnect on the availability page at any time.
Rendezvous's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google or Microsoft user data for advertising, don't sell it, and don't use it to train AI models.
5. AI (scheduling rules and support)
When you write scheduling rules in plain words (for example "avoid bank holidays"), or guests describe their availability, that text is sent to Google's Gemini model on Google Cloud Vertex AI, in the EU (Belgium), together with the series dates and time zone. The model only turns the text into structured conditions (days, dates, hours); it doesn't see calendars or choose meeting times. The organizer sees every condition that was understood, and meeting times are then chosen by Rendezvous's own scheduler. When an organizer or moderator asks for a notes proposal ("Suggest with AI"), the notes, the name, description, location and meeting dates of that rendezvous or series are sent to the same model to write the proposal, which is only shown to them. Support requests are first read by an AI assistant (the same Gemini model, in the EU) that answers from our help guide when it can. Requests it can't close are later read by our support agent (also Gemini), which answers simple questions itself and prepares the others (bugs, billing, data requests) for our developers, who decide what to do. Every request and answer is also sent to our team. Under Google Cloud's terms, this data is not used to train Google's models. If no such text is written, no AI is used.
6. Who we share data with
We use these service providers (processors), under contracts that require them to protect the data:
| Provider | What for | Where |
|---|---|---|
| Google Cloud (Cloud Run, Firestore, Vertex AI) | Hosting, database, document storage (Cloud Storage), AI (reading scheduling rules, support assistant and agent) | EU (Belgium; Firestore in a European multi-region) |
| Amazon Web Services (Simple Email Service, SNS) | Sending email, delivery reports | UK (London) |
| Cloudflare | Domain name service, receiving email replies | Global network |
| Stripe | Payments | EU / US |
Sign-in is provided by Google and Microsoft under their own privacy policies. Guests' email addresses and the meeting details are, of course, visible in the invitations we send on the organizer's behalf. We may disclose data if required by law. Where data leaves the UK/EEA (for example Stripe or Cloudflare), the transfer is covered by adequacy decisions or standard contractual clauses.
7. How long we keep data
- Organizer accounts, series and meetings: until you delete them or ask us to delete your account.
- Guests' availability and RSVP answers: as long as the organizer keeps the series.
- Shared calendars: until the guest disconnects (one click on the availability page) or asks us to delete them.
- Scheduling rules read from text: up to one year, then read again if still needed.
- Feature requests: until they are no longer useful to improve the service, or until you ask us to delete them.
- Notes and documents: until the organizer deletes them or the rendezvous or series.
- Enterprise enquiries: up to two years, or until you ask us to delete them.
- Support requests: as long as needed to help you and keep a record of the exchange, or until you ask us to delete them.
- Activity log: 90 days.
- Bounce and complaint records: kept so that we don't email those addresses again; ask us to remove yours.
8. Security
All traffic uses HTTPS. Guest links are individually signed, calendar tokens are encrypted at rest, and access to data is limited to what each part of the service needs.
9. Your rights
Under UK and EU data protection law you can ask to access, correct, delete, restrict or port your data, and object to processing based on legitimate interests. Guests can also disconnect a shared calendar at any time. Email support@setrendezvous.com. We reply within one month. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.
10. Cookies and similar technologies
We don't use advertising or analytics cookies. Your sign-in session is kept in your browser's session storage and ends when you close the tab. Google, Microsoft and Stripe may set their own cookies during sign-in or payment.
11. Children
Rendezvous is not intended for children under 16.
12. Changes
If we change this policy, we'll update the date at the top and, for significant changes, tell organizers by email.