TaskCalendars.com

Privacy Policy

Last updated: February 15, 2026

TaskCalendars.com, Inc. ("TaskCalendars.com", "us", "we", or "our") operates the taskcalendars.com website and related services (the "Services"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Services.

We will not use or share your information with anyone except as described in this Privacy Policy. By using the Services, you agree to the collection and use of information in accordance with this policy.

Information We Collect

Information you provide directly

When you register for an account, we collect:

  • Email address (required)
  • Username (required)
  • Password (stored in hashed form; never stored in plain text)
  • First name and last name (optional)
  • Phone number and country code (optional, for SMS verification)
  • Department (optional)
  • Timezone preference
  • Profile photo (optional, hosted via Cloudinary)

When you use the Services, we also collect:

  • Tasks, calendars, notes, and documents you create
  • Files and images you upload
  • Calendar membership and collaboration data
  • Approval workflow decisions

Information collected automatically

When you visit our website, we may automatically collect certain technical information, including:

  • IP address
  • Browser type and version
  • Pages visited and time spent
  • Device information
  • Referring URL

Information from third-party authentication

If you choose to register or sign in using a third-party provider (GitHub, Google, Microsoft, or Twitter/X), we receive your name, email address, and profile information from that provider. We do not store OAuth access tokens beyond the authentication session.

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Services
  • Create and manage your account
  • Process payments and subscriptions
  • Send transactional emails (account verification, password resets)
  • Send task deadline reminders and notification emails (configurable in your Settings)
  • Respond to your requests and support inquiries
  • Monitor and analyze usage to improve the Services
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations

Cookies & Tracking Technologies

Essential cookies

We use the following cookies that are strictly necessary for the Services to function:

  • Session cookie (_taskcalendars_key) — An encrypted cookie that maintains your authenticated session. Expires when you close your browser or after the session timeout.
  • Remember me cookie (remember_me) — An optional persistent login cookie. Expires after 30 days. Only set if you choose to stay signed in.

Analytics cookies (consent required)

With your explicit consent, we may use the following analytics services:

  • PostHog — Product analytics to understand how the Services are used. PostHog may set cookies to track sessions. PostHog is only activated if you consent to analytics cookies via the cookie consent banner. You can withdraw consent at any time.

Cookieless analytics

  • Plausible Analytics — A privacy-focused, cookieless analytics service. Plausible does not use cookies, does not collect personal data, and does not track individual users. It operates regardless of your cookie consent preference because it does not require consent under GDPR.

You can manage your cookie preferences at any time using the cookie consent banner at the bottom of the page, or by contacting us.

Third-Party Service Providers

We share your information with the following third-party service providers, solely for the purposes described:

Provider Purpose Data shared
Stripe Payment processing Billing details, payment card information (processed directly by Stripe; we do not store full card numbers)
Postmark Email delivery Email addresses, email content for notifications and transactional emails
Cloudinary Image hosting Uploaded images and profile photos
Cloudflare R2 Document storage Uploaded documents and files
Sentry Error monitoring Error reports, browser session replays (may include page content visible at the time of an error)
PostHog Product analytics (consent required) Page views, feature usage, email address for user identification
Plausible Website analytics (cookieless) Aggregated, anonymous page view data only; no personal data
Twilio SMS verification Phone number (only if you enable phone verification)
Google Fonts Font delivery IP address (for CDN routing)

OAuth authentication providers (GitHub, Google, Microsoft, Twitter/X) receive authentication requests when you choose to sign in through them. We receive your name and email from these providers but do not share your TaskCalendars.com data back to them.

All third-party providers are contractually obligated to protect your data and may only use it for the specific purposes described above.

Data Storage & Security

Your data is stored on servers located in the United States. We implement industry-standard security measures to protect your personal information, including:

  • Encryption of data in transit (HTTPS/TLS with HSTS)
  • Encrypted session cookies with secure signing and encryption salts
  • Password hashing (passwords are never stored in plain text)
  • Content Security Policy (CSP) headers to prevent cross-site scripting
  • Rate limiting on authentication and API endpoints
  • Sensitive data filtered from application logs (passwords, credit cards, emails)

However, no method of transmission over the internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.

Data Retention

  • Active accounts: Your data is retained for as long as your account is active and you continue to use the Services.
  • Deleted accounts: When you delete your account, your personal data is immediately anonymized (name, email, phone, and other identifiers are removed or replaced). The anonymized record is permanently purged from our systems after 90 days.
  • Authentication tokens: Expired login and API tokens are automatically purged after 90 days.
  • Consent records: Records of your consent choices (cookie consent, terms acceptance) are retained for compliance purposes even after account deletion.

Your Rights Under GDPR

If you are a resident of the European Economic Area (EEA), United Kingdom, or Switzerland, you have certain data protection rights under the General Data Protection Regulation (GDPR). We aim to take reasonable steps to allow you to exercise these rights.

Legal basis for processing

We process your personal information on the following legal bases:

  • Contract performance: To provide the Services you have signed up for (account management, task management, email notifications).
  • Consent: For analytics tracking via PostHog (you can withdraw consent at any time via the cookie banner).
  • Legitimate interest: For error monitoring (Sentry), security measures, and service improvement.
  • Legal obligation: To comply with applicable laws and regulations.

Your data rights

You have the right to:

  • Access your data: You can download a complete copy of your personal data in machine-readable JSON format from the Settings page ("Download My Data").
  • Rectify your data: You can update your personal information at any time in your Settings page.
  • Delete your data: You can delete your account from the Settings page. Your data is anonymized immediately and permanently deleted after 90 days.
  • Restrict processing: You can request that we restrict the processing of your personal information by contacting us.
  • Data portability: You can export your data using the "Download My Data" feature, which provides your information in a structured, machine-readable JSON format.
  • Object to processing: You can object to our processing of your personal information by contacting us.
  • Withdraw consent: You can withdraw your cookie consent at any time via the cookie consent banner. You can also withdraw consent for specific email notifications in your Settings.

We may ask you to verify your identity before responding to such requests. You have the right to complain to a Data Protection Authority about our collection and use of your personal information. For more information, please contact your local data protection authority in the EEA.

International Data Transfers

Your information, including personal information, may be transferred to and maintained on servers located in the United States. If you are located outside the United States and choose to provide information to us, please note that we transfer the information to the United States and process it there.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

Children's Privacy

Only persons age 18 or older have permission to access our Services. Our Services do not address anyone under the age of 13 ("Children").

We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you learn that your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from a child under age 13 without verification of parental consent, we will take steps to remove that information from our servers.

Communications

We may use your email address to send you task deadline reminders, update request notifications, and other service-related communications. You can configure which notification emails you receive in your account Settings. Transactional emails (such as account verification, password resets, and access request notifications) cannot be disabled as they are necessary for account security and functionality.

Compliance With Laws

We will disclose your personal information where required to do so by law or subpoena or if we believe that such action is necessary to comply with the law and the reasonable requests of law enforcement or to protect the security or integrity of our Services.

Ownership Transfer

If the ownership of TaskCalendars.com is transferred to a third party, your personal information may be transferred. In such cases, we will provide notice before your personal information is transferred and/or becomes subject to a different Privacy Policy.

Links to Other Sites

Our Services may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over, and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top. If we make material changes, we will notify you either through the email address you have provided us, or by placing a prominent notice on our website.

Your continued use of the Services after we post any modifications to this Privacy Policy will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Privacy Policy.

Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a privacy concern, please contact us at:

  • Email: support@taskcalendars.com