1. Overview
Freeslot is built so hosts can share availability and accept bookings without exposing more data than the product needs. We combine encrypted connections, scoped calendar permissions, access controls, and careful handling of tokens and booking records.
No online product can promise perfect security. We continuously improve controls as the product and threat landscape change.
2. Encryption in transit
Traffic to Freeslot - including the marketing site, app, public booking pages, and embeds - is served over HTTPS. Session and API requests use encrypted channels so credentials and booking details are not sent in the clear.
3. Accounts and access
Account passwords are stored using modern one-way hashing, not reversible encryption. After you sign in, the app uses signed session tokens over HTTPS for authenticated API requests, along with standard web safeguards.
Team workspaces use roles so owners and admins can control who manages pages, hosts, and assignments. Hosts only see the scheduling data their role and page configuration allow.
4. Calendar connections
When you connect Google, Microsoft, Zoho, or another supported calendar, Freeslot requests only the permissions needed to read busy times and write confirmed bookings - according to the provider’s OAuth flow and what you approve.
- Access tokens are stored securely and used only for sync and booking writes
- You can disconnect a calendar at any time from your settings
- We do not use connected calendar content for advertising
5. Booking data
Guest details collected on a booking page (name, email, time, optional phone or notes) are stored so confirmations, cancellations, and calendar events can work as configured.
Hosts choose which fields to request. Guests interact with the host’s page; Freeslot processes that data to complete the booking flow. See our Privacy Policy for retention and sharing details.
6. Infrastructure
Freeslot runs on reputable cloud infrastructure with network isolation, monitored services, and regular updates to application dependencies. Databases and backups are restricted to authorized systems and personnel.
We apply least-privilege access for production systems and review privileged access as the team grows.
7. People and operations
Access to customer data is limited to team members who need it to operate or support the Service. We use secure devices and practices for production access, and we avoid using live customer data for casual testing whenever possible.
Payment card details for paid plans are handled by our payment provider - Freeslot does not store full card numbers on our servers.
8. What you can do
Security is shared. We recommend that you:
- Use a strong, unique password for your Freeslot account
- Review who has admin or host access in team workspaces
- Only request guest fields you actually need on booking forms
- Disconnect calendars you no longer use, and revoke app access in the calendar provider if you leave Freeslot
- Keep your own site secure if you embed Freeslot or use a custom domain
9. Report a concern
If you believe you’ve found a vulnerability or unusual activity related to Freeslot, email us at notifications@freeslot.me with enough detail for us to reproduce and investigate. Please do not publicly disclose an issue until we’ve had a reasonable chance to assess and address it.
For general account help, see the Help Center or Contact page.
10. Privacy and terms
How we collect and use personal information is described in the Privacy Policy. Use of the product is governed by the Terms of Service.