Privacy policy
Effective August 26, 2026
dtcmvp - meetings (the "service") is a scheduling product operated by dtcmvp ("we", "us"). It lets dtcmvp partners connect a Google or Microsoft account so that e-commerce brands can book meetings with them at times they are actually free, and so that we can prepare follow-up email drafts in the partner's own mailbox after those meetings. This policy explains what data the service touches, why, and the controls you have. Questions go to meetings@dtcmvp.com.
Who this covers
Two groups use the service: partners, who connect a calendar and mailbox, and bookers (brand contacts), who pick a meeting time on a booking page. Bookers provide only the details they type into the booking form: name, email address, and any notes.
Google user data
When a partner connects a Google account, the service requests the following, and uses each item only for the purpose listed:
- Calendar, read (
calendar.readonly): we read busy and free intervals, and event start and end times, from the calendars the partner selects in our connection screen. This is used solely to compute the partner's bookable availability and prevent double-bookings. - Calendar, write (
calendar.events): we create the meeting event on the partner's calendar when a brand books, and update or remove that same event when the meeting is rescheduled or cancelled. We only write events our service created. - Gmail (
gmail.readonlyandgmail.compose): after a meeting, we create a follow-up email as a draft in the partner's own mailbox, threaded onto the conversation with that brand where one exists. To thread and personalize the draft we read only the messages in that specific conversation. We do not send email from the partner's account; the partner reviews every draft and decides whether to send it. We do not scan, index, or analyze the rest of the mailbox. - Account email address (
userinfo.email, OpenID sign-in): used to show the partner which account they connected and to identify their connection in our admin tools.
Limited Use disclosure
dtcmvp - meetings' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google user data only to provide and improve the user-facing features described on this page; we do not sell it; we do not use it for advertising; and we do not allow humans to read it except with the partner's explicit consent, for security purposes, to comply with law, or as part of aggregated, anonymized internal operations.
We do not use Google user data, including Google Workspace data, to develop, improve, or train generalized artificial-intelligence or machine-learning models.
Microsoft user data
When a partner connects a Microsoft account, the service requests calendar read and write access (Calendars.ReadWrite) and mailbox access (Mail.ReadWrite) through Microsoft Graph, and uses them exactly as described for Google above: reading busy and free times from selected calendars to compute availability, placing and maintaining the meeting event on the partner's calendar, and creating follow-up drafts in the partner's mailbox that only the partner can send.
Other data we hold
- Booking records: who booked whom, the chosen time, and booker-entered details.
- Connection records: which account a partner connected and which calendars they selected.
- Operational logs needed to run and secure the service.
Storage and security
OAuth access and refresh tokens are encrypted at rest with AES-256-GCM and are never written to logs. All traffic to and from the service uses TLS. Calendar data is processed to compute availability and is retained only as bounded, non-identifying summaries (busy intervals, not event contents). Access to production systems is limited to dtcmvp staff who need it to operate the service.
Retention and deletion
Tokens and connection records are kept while a partner's account is connected. When a partner disconnects, or asks us to, we delete the stored tokens promptly, which ends all access to their Google or Microsoft data. Booking records are kept as business records of the meetings themselves. To request deletion of any data we hold about you, email meetings@dtcmvp.com and we will act on it within 30 days.
Your controls
- Disconnect inside the service at any time, which revokes our access.
- Revoke access directly from your provider: Google's third-party access settings or Microsoft's app permissions page.
- Every follow-up draft sits in your own mailbox; edit it or delete it like any other draft.
Sharing
We do not sell personal data, and we do not share Google or Microsoft user data with third parties except the infrastructure providers that host the service under confidentiality obligations, or where the law requires it. Meeting details (time, participants, meeting link) are shared between the partner and the brand who booked, because that is what a scheduled meeting is.
Changes
If this policy changes in a way that matters, we will update this page and its effective date, and notify connected partners by email before the change takes effect.