Calendar by J6 Venture is scheduling software you run on your own WordPress site. This policy sets out exactly what data the plugin touches, where it lives, and the lines we never cross, in the detail Google and Microsoft require.
Calendar by J6 Venture ("the plugin", "we", "us") is a WordPress booking plugin published by J6 Venture. It gives a website owner ("the operator") a booking page where their invitees pick a time for a meeting, and it connects to the operator's Google Calendar or Microsoft Outlook to read availability and place events.
In data-protection terms the operator is the controller of the bookings taken on their site. The plugin is the tool they use; J6 Venture builds and maintains that tool.
The plugin ships in two editions that differ only in how the calendar connection is authorised. What each touches is otherwise identical.
When an operator connects Google, the plugin requests only the scopes it needs to schedule: their basic profile (openid, email, profile) and Google Calendar access (calendar.events and calendar.freebusy) to read availability and manage the events bookings create, including the Google Meet link on each. It requests no access to Gmail, Drive, Contacts or any other Google service.
Google Calendar tokens obtained during connection are stored on the operator's own site (see Where data is stored) and used solely to keep the calendar in sync. They are removed when the operator disconnects or uninstalls.
When an operator connects Microsoft Outlook, the plugin requests only: their basic profile (User.Read, openid, email, profile), calendar access (Calendars.ReadWrite) to read availability and manage booking events, online-meeting access (OnlineMeetings.ReadWrite) to attach a Microsoft Teams link, and offline_access so the connection can refresh without repeated sign-in. It requests no access to Outlook mail, files or any other Microsoft service.
Microsoft tokens are stored on the operator's own site and used only to keep the calendar in sync. They are removed on disconnect or uninstall.
The J6 Connect service runs on Cloudflare's serverless platform (Cloudflare Workers), which processes the sign-in request in transit only and stores nothing. See Cloudflare's privacy policy.
We do not sell personal data, and we do not share it with third parties for their own purposes. Data moves only where it must to perform the scheduling the operator and invitee asked for, namely to Google or Microsoft to place the calendar event, or where the law requires it. Confirmation and reminder emails are sent through the operator's own WordPress mail setup.
Connections use OAuth 2.0, so the plugin never sees or stores a calendar-account password. Tokens are held on the operator's own site and transmitted over encrypted (HTTPS) connections. The Connect broker holds only the application secret and keeps no user data. No method of storage or transmission is perfectly secure, but we design to request the least access necessary and to keep sensitive material off J6 Venture servers entirely.
Depending on where you live, you may have the right to access, correct, export or delete personal data held about you, and to withdraw a connection at any time. Operators can act on these directly from their WordPress dashboard, which includes built-in GDPR export and erase. Invitees can exercise them through the operator, or by contacting us to be routed to the right operator.
Questions about this policy, or about data handled by Calendar by J6 Venture:
If we make material changes to this policy we will update the date at the top of this page and, where appropriate, note the change here.