Your privacy and security

Calendly is a cloud service that simplifies meeting scheduling by securely connecting to calendar providers to check availability. We follow strict security practices.

With OAuth calendar integration, Calendly doesn't need access to your device. However, if you use the Calendly Outlook Plug-in, it must be installed to read calendar conflicts and schedule events.

Calendly’s commitment to trust

Customer trust is key to everything we do at Calendly. Our software asks for only the necessary access to provide smooth scheduling. We protect your privacy by limiting access to customer data internally. Employees receive security training, and access to internal systems is secured with multi-factor authentication.

Physical infrastructure

The Calendly application is hosted on Kubernetes / Google Cloud Services (GCS). GCS' data center operations have been accredited under:

  • ISO 27001
  • SOC 1 and SOC 2/SSAE 16/ISAE 3402 (Previously SAS 70 Type II)
  • PCI Level 1
  • FISMA Moderate
  • Sarbanes-Oxley (SOX)

PCI compliance

Calendly uses Stripe, a PCI-compliant pay processor for encrypting and storing credit card details. More information on Stripe’s commitment to security and compliance can be found here. We utilize the direct Stripe javascript integration, so your credit card information never reaches Calendly’s servers.

Customer security best practices

We avoid collecting third-party passwords by utilizing OAuth authentication with Office365 and Google Calendar.

Data Encryption:

  • All connections from the browser to the Calendly platform are encrypted in transit using TLS SHA-256 with RSA Encryption.
  • All data is encrypted when written to disk.
  • User passwords are stored as salted password hashes and never accessible by any Calendly employee.

Is Calendly GDPR compliant?

Calendly is committed to General Data Protection Regulation (GDPR) compliance. We understand the importance of incorporating standards put forth by the GDPR into our data practices and making sure our customers feel secure and confident to continue using Calendly.

Calendly has designed its data privacy program to be compliant with GDPR and other applicable privacy laws, both now and as future.