Privacy Notice
How Haab Calendar handles personal data, who is responsible for what, and how to exercise your rights.
Last updated: 2026-08-25
1. Who is responsible for your data
Haab Calendar is operated by Bernardo Soriano, an individual sole proprietor based in Mexico, reachable at bsorianodev@gmail.com. This notice is issued under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP).
Two different relationships are covered here, and the difference matters. When a business signs up to run a booking page, Haab Calendar is the data controller for that business's own account data. When that business takes bookings from its clients, the business is the data controller for its clients' information and Haab Calendar acts only as its service provider, storing and transmitting that information on the business's instructions.
In practice: if you booked an appointment through a booking page, your relationship is with the business that runs that page. Haab Calendar holds the booking on their behalf. Requests about that data are answered by the business, and we will help them respond.
2. What we collect from businesses
Account identity: the email address used to sign in, and the authentication records that keep the session valid.
Booking page configuration: business name, public URL slug, time zone, language, services and prices, availability rules, booking policies, and any images uploaded for the page.
Subscription state: the plan a business is on, and the identifiers needed to reconcile it with the payment processor. Card numbers are never sent to, or stored by, Haab Calendar.
3. Booking data handled for businesses
When someone books, the booking page collects the name, email address, phone number, and any notes the client chooses to add, together with the service, date, and time.
This information is used to create and manage the booking and nothing else. It is not sold, not rented, not used to build advertising profiles, and not used to train machine learning models.
Each booking gets a private management link containing an unguessable token. Anyone holding that link can view, reschedule, or cancel that booking, which is why those pages are served with instructions not to index them and are excluded from search engines.
4. Google Calendar data and Limited Use
Connecting a Google Calendar is optional and is initiated by the business. Nothing is requested from Google unless a business connects an account.
When connected, Haab Calendar requests exactly four scopes and no others: openid and email, to show which account is connected so a business can audit it; https://www.googleapis.com/auth/calendar.events, to create and update the events representing bookings; and https://www.googleapis.com/auth/calendar.calendarlist.readonly, to list the calendars a business could write to. The broader calendar scope is deliberately not requested, because it would grant read access to the contents of every event on every calendar, which this feature has no use for.
Events written into a business's calendar carry the service name and an opaque internal identifier. They do not carry a client's name, email address, phone number, or notes. A calendar can be shared, and Haab Calendar does not decide who may read a client's name. This is enforced by an automated test, not only by policy.
Google refresh tokens are encrypted with AES-256-GCM before they are written to the database, so a copy of the database alone does not yield a usable token. Disconnecting a Google account from the settings page revokes the token with Google and removes it.
Haab Calendar's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Who else processes this data
Supabase — database, authentication, and file storage. Holds account and booking records.
Vercel — application hosting and image storage. Processes requests and serves uploaded images.
Stripe — subscription payments. Handles card data directly; Haab Calendar never receives it.
Google — only for businesses that connect a Google Calendar, and only for the scopes listed above.
These providers process data on our behalf under their own terms. Some of them operate infrastructure outside Mexico, which means personal data may be transferred and stored abroad.
7. How long data is kept, and deletion
Account and booking data is kept while the account is active, because it is the record the business relies on.
Deleting an account is permanent. It removes the account, the booking page and its configuration, the bookings held under it, and the uploaded images, and it revokes any connected Google account. There is no recovery afterwards.
If you booked through a business's page and want that booking removed, contact the business. They control it, and deletion on their side removes it from our systems too.
8. Security
Access to booking data is enforced in the database itself through row-level security, so a business can only reach its own records regardless of how a request arrives.
Google refresh tokens are encrypted at rest with AES-256-GCM. Booking management links use unguessable tokens rather than sequential identifiers.
No system is perfectly secure, and this notice does not claim otherwise. If you believe you have found a vulnerability, please write to bsorianodev@gmail.com.
9. Your ARCO rights
Under the LFPDPPP you may exercise your ARCO rights: Access, to know what personal data is held about you; Rectification, to correct it when it is inaccurate or incomplete; Cancellation, to have it removed; and Opposition, to object to a particular use of it. You may also withdraw consent at any time.
To exercise any of these, write to bsorianodev@gmail.com describing which right you are exercising and enough detail to locate your records. We will respond within the periods the law establishes.
If your data was submitted through a business's booking page, the request is properly directed to that business, which is the data controller. Send it to us anyway if you cannot reach them and we will help identify the right contact.
10. Changes to this notice
This notice may change as the service changes. The effective date at the top of this page always reflects the current version, and material changes will be announced in the application before they take effect.
11. Contact
Questions about this notice, or about how your data is handled, go to bsorianodev@gmail.com.