Privacy Policy
Last updated: August 30, 2026
Introduction
Shindig Inc. ("Shindig", "we", "us", or "our") operates the Shindig platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
Information We Collect
- Account data: name, email, password (hashed)
- Workspace data: company name, client records, events, inquiries, contracts
- Usage data: pages visited, features used, session duration
- Payment data: processed by Stripe — we never store payment card numbers
- Google user data: if you connect your Google account, we access your Google Calendar events and your Google account email address — see the Google User Data section below
How We Use Your Information
We use your information to provide and improve the Shindig service, process payments, send transactional emails, and comply with legal obligations. We do not sell your data to third parties, and we do not use your data for advertising.
How We Share, Transfer, and Disclose Your Data
We do not sell your personal information. We share, transfer, or disclose your data only in the following limited circumstances:
- Service providers (sub-processors) who process data on our behalf under contractual confidentiality and security obligations, and only as needed to operate the service:
- Google Cloud / Firebase — application hosting, database, and authentication
- Vercel — web application hosting and delivery
- Stripe — payment processing
- Resend — transactional email delivery
- Google API services — to read and write events in the Google Calendar you connect
- Within your workspace: data you create is accessible to other members you invite to your workspace, according to their assigned role.
- Legal and safety: when required by law, subpoena, or legal process, or to protect the rights, property, or safety of Shindig, our users, or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Privacy Policy.
We do not transfer or disclose Google user data to third parties except as necessary to comply with applicable law, or as part of a merger or acquisition — consistent with the Limited Use requirements described below.
Google User Data and Limited Use
When you connect your Google account, Shindig requests access to your Google Calendar (to create, update, and delete calendar events for your Shindig events) and your basic Google profile email (to identify the connected account). We access this data only to provide the calendar-sync feature you enable, and you can disconnect at any time from Settings → Integrations, which revokes our access.
Shindig's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not transfer or disclose it to third parties except as needed to provide or improve the feature, to comply with applicable law, or as part of a merger or acquisition.
Data Protection and Security
We implement technical and organizational safeguards to protect your data, including sensitive data such as authentication credentials and Google OAuth tokens:
- Encryption in transit: all data is transmitted over TLS/HTTPS
- Encryption at rest: stored data, including OAuth tokens, is encrypted at rest by our cloud infrastructure
- Access controls: tenant isolation and role-based access enforced at the database layer, so each workspace can only access its own data
- Credential handling: passwords are hashed and never stored in plain text; payment card details are handled by Stripe and never stored on our servers
- Least privilege: we request only the Google scopes required for the features you enable, and revoke stored tokens when you disconnect
- Operational controls: administrative access to production systems is restricted to authorized personnel
Data Retention
Your workspace data is retained for the duration of your subscription plus 90 days after cancellation, allowing you to export before deletion. You may request earlier deletion by contacting us. When you disconnect a Google account, the associated OAuth tokens are deleted.
Contact
Questions or requests regarding this policy: privacy@getshindig.com