GDPR compliance,
without the legalese.
Effective: 2026-05-21 · Last updated: 2026-05-21
The 30-second version
- Your calendars are read and merged on your device, not in our cloud. They stay in your browser's local storage. There is nothing for us to "process" under GDPR because we do not receive them.
- The only personal data we handle is your email address and payment information, processed through Stripe, for billing purposes.
- You are the data controller of your calendar data. We are the data controller of billing records. We never act as a processor of your calendar data because we never have access to it.
- Your rights are straightforward. Access, correction, deletion, portability, and objection. Email us and we will respond within 30 days.
- This applies to GDPR, UK GDPR, and CCPA. Same rights, same commitments, regardless of where you are.
1. Scope
manyCalendars is a local-first browser extension. The core product runs entirely within your browser. Calendar events, feed URLs, settings, and preferences are stored in your browser's localStorage and never transmitted to our servers.
This means our data processing footprint is unusually small. Most of the GDPR machinery (data processing agreements, processor obligations, cross-border transfer safeguards for calendar data) simply does not apply because we never receive that data in the first place.
This agreement covers the limited personal data we do process: billing information and license management.
2. Data controller vs. data processor
Your calendar data
You are the sole data controller. Your calendar events, attendees, locations, and descriptions live in your browser. We have no technical ability to access, read, copy, or transmit this data. We are not a data processor for this data because we never process it.
Billing and account data
We are the data controller for the limited personal data we collect to operate the service: your email address, subscription plan, license key, and payment timestamps. Stripe acts as a joint controller / independent controller for payment card data (see Section 4).
When E2E encrypted sync ships (Q3 2026)
Your calendar data will be encrypted on your device before upload. Our servers will store opaque ciphertext. We will act as a data processor for that encrypted blob, but since we cannot decrypt it, the practical privacy risk remains near zero. A separate addendum to this DPA will be published before sync launches.
3. Lawful basis for processing
Under GDPR Article 6, we rely on the following lawful bases:
- Contract performance (Art. 6(1)(b)). We process your email and payment data to deliver the subscription you purchased, send receipts, and manage your license.
- Legitimate interest (Art. 6(1)(f)). We perform a daily license-key check to verify active subscriptions. This request contains only the license key (not your email or any personal identifier). Our legitimate interest is preventing unauthorized use of paid features.
We do not rely on consent as a lawful basis for any processing, because we do not engage in marketing automation, behavioral profiling, or optional data collection that would require it.
4. Sub-processors
We use two sub-processors. That is the complete list.
- Stripe, Inc. (San Francisco, CA, USA) processes payments and stores card information on our behalf. Stripe is certified under the EU-US Data Privacy Framework. Stripe Privacy Policy · Stripe DPA
- Cloudflare, Inc. (San Francisco, CA, USA) hosts our website and license-check API. Cloudflare processes standard HTTP metadata (IP addresses, timestamps, user-agent strings) as part of CDN and DDoS-protection operations. Cloudflare is certified under the EU-US Data Privacy Framework. Cloudflare Privacy Policy · Cloudflare DPA
If we add a sub-processor in the future, we will update this page and notify subscribers by email at least 30 days before the new sub-processor begins processing data.
5. International data transfers
manyCalendars LLC is based in the United States. Stripe and Cloudflare are also US-based companies.
For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States, we rely on:
- EU-US Data Privacy Framework certifications held by Stripe and Cloudflare
- Standard Contractual Clauses (SCCs) incorporated into our agreements with both sub-processors as a fallback mechanism
Since the only personal data that crosses borders is billing information (email address and payment metadata), the transfer risk is minimal. Your calendars are read and merged on your device, not in our cloud, and are not subject to any international transfer.
6. Security measures
We implement the following technical and organizational measures to protect the billing data we do handle:
- All communications with our license server use TLS 1.3
- Payment card data is handled exclusively by Stripe and never touches our systems
- License keys are cryptographically generated and cannot be reverse-engineered to recover account information
- Access to billing systems is restricted to authorized personnel with multi-factor authentication
- Cloudflare provides DDoS protection, WAF, and bot management for our infrastructure
- We do not store passwords (authentication is handled via email-based license recovery)
For a detailed breakdown of our security architecture, see our Security page.
7. Data subject rights
Under GDPR, UK GDPR, and CCPA, you have the following rights regarding the personal data we hold about you (billing and account information):
- Right of access. Request a copy of all personal data we have associated with your account.
- Right to rectification. Correct your email address or other account details.
- Right to erasure. Request deletion of your account and all associated billing records. We will delete your data within 30 days, except where retention is required by tax or financial regulations.
- Right to data portability. Receive your account data in a structured, machine-readable format (JSON).
- Right to object. Object to processing based on legitimate interest (license checks). If you object, we may not be able to continue providing paid features.
- Right to restriction. Request that we limit processing of your data while a dispute is resolved.
To exercise any of these rights, email dpa@manycalendars.com from the email address associated with your account. We will respond within 30 days.
California residents (CCPA)
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. You have the right to know what data we collect, request deletion, and opt out of any future sale (though we have nothing to sell). These rights are exercised through the same email address above.
8. Breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33
- Notify affected individuals without undue delay if the breach is likely to result in a high risk, as required by GDPR Article 34
- Document the breach, its effects, and the remedial actions taken
Given that the only personal data we hold is billing information (not calendar data, health data, or other sensitive categories), the impact of any potential breach is limited in scope.
9. Data retention
- Active accounts: billing data is retained for the duration of your subscription.
- Cancelled accounts: billing records are retained for 12 months after cancellation for tax and financial reconciliation, then permanently deleted.
- License check logs: server-side request logs (containing only the license key and timestamp, no personal identifiers) are retained for 30 days for abuse detection, then automatically purged.
Your calendar data has no server-side retention period because it is never sent to our servers.
10. Contact
Data protection inquiries, rights requests, or DPA questions:
General privacy questions: privacy@manycalendars.com
If you believe we have not adequately addressed your data protection concern, you have the right to lodge a complaint with your local supervisory authority.