Privacy Policy
Last updated 5 September 2026
Razar gives independent businesses a public page where their customers can browse what they offer and book time with them. This policy explains what we collect, what we do with it, and what we never do.
Two different groups of people appear in this policy. Business owners hold an account with us. Customers book with those businesses without holding an account. Where the difference matters, we say so.
Google user data
Connecting a Google Calendar is optional. Bookings work without it — we simply cannot see existing commitments or write bookings to a calendar. When an owner does connect one, we request the narrowest scopes that make the feature work:
calendar.events— to create an event when a customer books, move it when the booking is rescheduled, and delete it when the booking is cancelled.calendar.freebusy— to read which time windows are already busy, so those slots are hidden from the public booking page and nobody is double-booked.userinfo.email— to show which Google account is connected, so an owner can tell at a glance that it is the right one.
What we read but never store
Availability is read as free/busy windows only — start and end times. We do not receive, and could not display, the titles, descriptions, guests, or locations of existing events. Those windows are used to compute available slots and are never written to our database.
What we store
- Google OAuth access and refresh tokens, encrypted at rest with AES-256-GCM.
- The token expiry time and the list of permissions granted.
- The email address of the connected Google account.
- Which calendar to use — the account's primary calendar.
- For each booking, the identifier of the calendar event we created for it.
What we write to a calendar
One event per booking, containing the customer's name in the title; their name, email address, and any notes they left in the description; the start and end time; and the customer added as a guest. We do not send Google's own invitation emails — the customer receives our confirmation instead.
Limited Use
Razar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell this data, use it for advertising, or allow humans to read it except where required for security, to comply with the law, or with the owner's explicit permission.
Disconnecting
An owner can disconnect at any time from their calendar settings, which deletes the stored tokens immediately. Access can also be revoked directly at myaccount.google.com/permissions. Events already written to a calendar belong to that calendar and stay there — we no longer have any means of removing them.
Other information we handle
From business owners: name, email address, page handle, and the products, services, hours, and content they publish.
From customers who book: name, email address, the time booked, their timezone, and any notes they choose to add. We hold this on behalf of the business being booked; that business decides what happens to it.
Services we rely on
We share only what each service needs to do its job: Google (calendar sync), SendGrid (email), Twilio (text messages), Stripe (payments — card details go directly to Stripe and never reach our servers), Cloudinary (images), and our hosting and database providers.
Keeping and deleting data
Bookings are kept so both sides have a record. Calendar tokens are deleted the moment a connection is removed. Owners can ask us to delete their account and its data by writing to privacy@razar.one. Customers who have booked can ask the business they booked with, or contact us directly.
Contact
Questions about this policy go to privacy@razar.one. See also our Terms of Service.