Legal · Privacy

Privacy Policy

How WPStack handles your information — including exactly what data the Booking module accesses when you connect Google Calendar.

Last updated: 28 August 2026

Overview

WPStack ("WPStack", "we", "us", "our") builds a suite of WordPress plugins and modules and operates the licensing and account hub at wpstack.io. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

It also describes — in the Google Calendar integration section below — exactly how the WPStack Booking module accesses and uses Google user data when you choose to connect a Google Calendar. If you do not agree with this policy, please do not use our website or plugins.

Information we collect

  • Account & billing — when you register on wpstack.io: your name and email address, and for purchases your company and billing details. Card payments are handled by Stripe; we never receive or store full card numbers.
  • License & activation — the domains where you activate a license, plus basic environment data (plugin and module versions) used to deliver updates and enforce per-site limits.
  • Support — the messages and any attachments you send us.
  • Google account data — only if you connect Google Calendar in the Booking module. This is covered in full under Google Calendar integration.
  • Usage & technical — standard server logs such as IP address, browser type and pages visited, used to keep the service secure and reliable.

Google Calendar integration (Booking module)

The WPStack Booking module can connect to your Google Calendar so that appointments booked through your website stay in sync with your calendar. This connection is optional and is established only when you explicitly authorise it through Google’s consent screen.

Google API Services User Data Policy

WPStack’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What we access

When you connect a calendar, the module requests the https://www.googleapis.com/auth/calendar scope. It uses this access only to:

  • Read your busy/free times on the selected calendar, so the booking form never offers a time slot when you are already busy — preventing double-bookings.
  • Create, update and delete calendar events that correspond to bookings made on your website, so a new appointment appears on your calendar and a cancelled one is removed.

The module does not read the content of your existing personal events beyond their busy/free status, and it does not access any other Google service or product.

Where your data is stored

The Booking module runs on your own WordPress server. When you connect a calendar, the authorisation tokens Google issues, the ID of the calendar you selected, and the IDs of the events the module creates are stored in your site’s own database. They are used solely to maintain the connection and keep bookings in sync. This Google user data is not transmitted to WPStack’s servers, sold, transferred to third parties, used for advertising, or used to develop, improve or train generalised AI/ML models, and it is never accessed by a human except where needed to provide support at your request, to comply with applicable law, or as required for security.

Revoking access

You can disconnect at any time from the Booking module’s calendar settings, which deletes the stored tokens from your site. You can also revoke access directly from your Google Account at myaccount.google.com/permissions. After revocation the module can no longer read your availability or manage events on your calendar.

Microsoft Outlook

The Booking module offers an equivalent optional connection to Microsoft Outlook Calendar (using the Calendars.ReadWrite permission). The same handling described above applies: tokens and event references are stored on your own server and used only to sync bookings.

How we use information

  • To deliver plugins, licenses and software updates, and to run your account.
  • To process payments and issue invoices (via Stripe).
  • To provide customer support and respond to your requests.
  • To keep the service secure, prevent abuse, and improve reliability.
  • To comply with legal obligations.
  • Google user data is used strictly for the calendar-sync purposes described in Google Calendar integration — nothing else.

How we share information

We do not sell your personal data. We share it only with:

  • Stripe — to process payments securely.
  • Infrastructure and email providers acting on our behalf to host the service and deliver transactional email.
  • Authorities where we are legally required to do so.

Google and Microsoft calendar data stays on your own server and is shared with no one.

Data retention

We keep account and billing records for as long as your account is active and thereafter as required by law (for example, tax records). Support messages are kept for as long as needed to assist you. Google and Microsoft calendar tokens are kept on your server only until you disconnect the calendar or revoke access, at which point they are deleted.

Security

We protect information with encryption in transit (HTTPS), access controls, and signed, integrity-checked update delivery. Calendar authorisation tokens are stored on your own server. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address any issues.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent. You may also lodge a complaint with your local data-protection supervisory authority. To exercise any of these rights, contact us at [email protected].

Cookies

wpstack.io uses essential cookies to keep you signed in and to run the checkout. We do not use them to track you across other websites. Your browser can block or delete cookies, though some features may then stop working.

Children’s privacy

Our website and plugins are intended for businesses and are not directed to children under 16. We do not knowingly collect personal data from children.

Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest version, and we will highlight material changes where appropriate. Your continued use of the service after an update means you accept the revised policy.

Contact us

Questions about this policy or your data? Contact us at [email protected].

WPStack
Belgium