"The Bridge, Not the Vault." MultiPick Scheduler connects you to services you already own. Your data lives in your own calendar, your own contacts, and on your own device. Our server is temporary plumbing. We hold nothing permanently.
MultiPick Scheduler is an appointment booking app for solo professionals and small businesses — personal trainers, tutors, massage therapists, photographers, consultants, and anyone who manages their own schedule. The app lets a business owner select available times, generate a single booking link, and send it to a specific client. The client opens the link, picks one time, and the appointment is set. No marketplace. No directory. No central data warehouse.
MultiPick Scheduler is not a platform that stores your clients, owns your appointments, or holds your business data hostage. It is a tool that sits between you and the services you already use — your calendar, your contacts — and facilitates scheduling. When you stop using the app, everything stays exactly where it has always been: in your own accounts.
Because your data lives primarily in your own accounts and on your own device, control over it rests with you — not with us. Here is how to delete your data:
Business owners: Open the app, go to Settings, and tap "Delete My Account." This will:
Your calendar events remain in your own calendar — we created them on your behalf, but they belong to your account and are not affected by deleting your MultiPick account. You can manage them directly in your calendar app.
Clients: Your booking information lives in the business owner's calendar and on their device — not in a MultiPick database. The session data that briefly passed through our server was deleted automatically when your booking closed. A consent record backup may remain on our server for up to 30 days (see Section 10). To request deletion of any data we may hold, contact us using the email at the bottom of this page with your name and the email address you used when booking. We will process your request within 30 days.
If you want your information removed from the business owner's records (their calendar, their device), contact the business owner directly. They hold your record in their own account, and they can delete it. We cannot delete data from their personal accounts on your behalf.
We do not sell your data. We do not sell client appointment data. We do not sell business owner data. We do not share data with advertisers or data brokers. We do not use advertising SDKs or cross-site tracking of any kind.
Data is shared with third-party services only as described in Section 12, and only to the extent those services need it to perform their specific function.
Business owners are professionals who install the app, connect their calendar account, and use it to create and manage appointments. They configure settings, generate booking links, and receive notifications when clients book.
Clients are the people who receive a booking link by email or text and visit a web page to choose a time. Clients do not install the app. They do not create a MultiPick account. They interact only with a single booking web page generated from the business owner's session. Once they book, their interaction with our infrastructure is essentially complete.
Understanding this architecture is the key to understanding our privacy model. Most apps store your data in their own database. MultiPick Scheduler does not. Here is where everything actually lives:
| Data | Where it lives | Who controls it |
|---|---|---|
| Your appointment history | On your device, in a local database on your phone | You. It never leaves your phone unless you export it. |
| Your calendar events | In your own Google, Apple, or Outlook calendar | You — in the same calendar app you've always used. |
| Your client contacts | In your own device contacts | You — we read them briefly to autocomplete a name when you're creating a booking, then we let go. |
| Your settings and themes | On your device | You — stored locally, not synced to our servers. |
| Active booking session data | Temporarily on our server while a booking link is open | Deleted automatically the moment a client books or the link expires. See Section 11. |
| Return-trip booking memory (BUT WAIT round-trip) | Your browser's temporary session storage (per-tab) | A short list of appointments you've already confirmed or canceled during this BUT WAIT round-trip — so when you come back to the page after canceling, you can see what you already handled. Cleared automatically when you close the tab or end the browser session. This is your device, not our server. |
| OAuth tokens (calendar access) | Securely on our server | Used only when you initiate a calendar action. Revocable by you at any time through your calendar provider's settings. |
| Push notification tokens | On our server (business owners only) | Used to send you booking alerts. Deleted when you sign out or delete your account. |
| Consent records | Primarily on the business owner's device; 30-day backup on our server | The business owner holds the durable copy. Our server copy is a short-lived safety net. |
If our server were shut down tonight, you would lose nothing. Your appointment history is on your phone. Your calendar events are in your own calendar. Your contacts are on your device. The server is plumbing, not storage.
When you connect your calendar to MultiPick Scheduler, you authorize through your provider's standard OAuth flow. You see exactly what you are authorizing before you approve it. Here is what we request and why:
| Permission | Why we need it |
|---|---|
| Read your calendar events | To check your existing events and show your availability (free/busy information) when you are creating a new booking. We read event times to determine which slots are open — not to inspect the content of unrelated events. |
| Create and edit calendar events | To add a confirmed appointment to your calendar when a client books, and to update or remove it if the appointment changes or cancels. |
| Read your contacts (People API) | Read-only access to suggest a client's name, phone, and email as you type — pulling from your own contacts so you do not have to retype information you already have. We do not modify, store, or export your contacts. |
We do not read your email inbox. We do not access the detailed content of calendar events we did not create — we read event times to determine your availability, nothing more. We do not read contacts beyond the autocomplete lookup you trigger. We request only what the app needs to function — nothing more.
You can revoke these permissions at any time through your calendar provider's account settings. Revocation immediately ends the connection and terminates our ability to access your calendar. No data is retained on our end after revocation.
When a client opens a booking link and completes their appointment, they provide their name, email address, and optionally a phone number. This information is used for one purpose: completing and servicing their appointment.
When an appointment is confirmed, the client's email address is added as a guest on the calendar event in the business owner's Google Calendar. Google processes this data under its own privacy policies. No automatic invitation emails are sent by Google — all client notifications come through MultiPick Scheduler.
Once the booking is processed, the client's information lives in two places: the business owner's calendar (the business owner's own account — not ours) and the business owner's device. We do not retain a copy on our server beyond the short-lived consent record backup described in Section 10. We do not build a client database. We are not the custodian of client records — the business owner is, in their own accounts.
Transactional emails sent on behalf of the business owner include a way to manage your communication preferences.
Before completing a booking, clients are asked to give clear, affirmative consent. We use two separate checkboxes — not one bundled agreement — following the FCC's April 2025 one-to-one consent rules.
Checkbox 1 — Email consent (always shown). This checkbox covers:
This checkbox is required to complete a booking.
Checkbox 2 — SMS consent (shown only when a phone number is provided and the business owner's plan supports SMS). This checkbox covers:
This checkbox is optional. Clients can book without checking it — they will simply receive email communications only.
Each consent can be granted or revoked independently. Opting out of SMS does not affect email reminders, and vice versa. Neither checkbox is ever pre-checked — the client must actively check each one.
When a client checks a consent box and taps Book, the app creates a consent record. This protects both the client and the business owner by creating a clear, auditable trail of exactly what was agreed to and when. Here is what a consent record contains:
| Field | What it is |
|---|---|
| Timestamp | The exact date and time consent was given (UTC). |
| Client email | The email address provided at booking. |
| Client phone | The phone number, if one was provided. |
| Checkbox text (snapshot) | The exact wording of the checkbox the client saw — not a reference, but the literal text. If we later reword a checkbox, old records still show what that specific client agreed to. |
| Privacy policy version | The version identifier of this policy that was in effect at the time of consent. |
| App version | The version of the booking page that was displayed. |
| IP address | The client's IP address at the time of booking. |
| Browser/device info | The browser and device used to complete the booking (user agent string). |
| Consent scope | An explicit list of what was consented to (e.g., appointment booking, email reminders, SMS reminders, age 13+ confirmation). |
| Consent ID | A unique identifier for each consent record, used to reference and retrieve it without ambiguity. |
| Privacy policy URL | A link to the exact version of the privacy policy that was active when you consented, so the full text of that version is always retrievable. |
| Booking page version | The version of the booking page you were viewing when you consented, ensuring the exact interface and wording you saw is documented. |
| Revocation date and method | If you later opt out of email or SMS communications, the date and method of your opt-out (for example, "SMS STOP keyword" or "email unsubscribe link") are recorded in the same consent record. |
Where consent records are stored: The durable copy lives on the business owner's device, consistent with our bridge-not-vault design. A backup copy is held on our Firebase server for 30 days as a safety net in case the business owner's device is lost or replaced, after which the server copy is automatically deleted.
How long consent records are kept: Consent records are retained for 6 years from the booking date, in line with TCPA federal requirements and state consumer protection statutes of limitations. After 6 years, the record is permanently deleted from the business owner's device. The business owner can also delete individual records sooner if they choose.
Why we capture all of this: If a question ever arises about what a client agreed to, the consent record proves it — down to the exact checkbox wording, the exact time, and the exact version of the policy. This protects clients from being signed up for things they did not agree to, and protects business owners from false claims.
Active booking session data. When a business owner creates a booking link, the available time slots are uploaded to our server so that the client's web page can display them. This data exists on our server only while the booking link is active. The moment a client books or the link expires, this data is deleted automatically. No archive. No backup. Gone.
OAuth authorization tokens. To perform calendar operations on your behalf, our server stores the authorization token your calendar provider issues when you connect your account. This token is encrypted at rest and used only when the app needs to interact with your calendar. You can invalidate it instantly by revoking access in your calendar provider's account settings.
Firebase Auth user records. When a business owner signs into the app, Firebase Authentication creates a lightweight account record containing a unique user ID (UID), email address, display name, and the authentication provider used (e.g., Google). This record exists as long as the account is active and is deleted when the business owner deletes their account.
Consent record backups. As described in Section 10, consent records are backed up on our server for 30 days after a booking, then automatically purged. The durable copy lives on the business owner's device.
Push notification tokens. For business owners only, we store the device token needed to deliver push notifications (e.g., "A client just booked"). These tokens are deleted when the business owner signs out or deletes their account. Clients do not have push notification tokens — they do not install the app.
That is the complete list of server-stored data. No appointment history. No client lists. No business records. No analytics profiles. Everything on our server is temporary and operational — designed to disappear as quickly as its purpose allows.
We use a small number of established third-party services to operate the app. Each receives only the minimum data needed for its specific function.
| Service | What it does | What data it handles |
|---|---|---|
| Firebase by Google |
Hosts the client-facing booking web pages. Manages business owner authentication (Firebase Auth). Temporarily stores active booking session data and consent record backups. Manages push notifications to the business owner's device. Runs background functions for reminders, expiration checks, and calendar sync. | Active session slot data while a booking link is open — deleted when the session closes. Firebase Auth records (UID, email, display name). Consent record backups — deleted after 30 days. Push notification tokens for the business owner's device only. |
| Resend via Amazon SES |
Delivers all transactional emails — booking confirmations, reminders, cancellation notices — from notifications@multipickapp.com, branded with the business owner's name. Resend uses Amazon SES infrastructure for email delivery. | Recipient email address and the appointment details needed to compose the email. Not used for advertising or profiling. Resend may retain delivery logs per their own privacy policy. |
| Twilio Premium Gold only |
Sends appointment-related text messages to clients when the business owner has enabled SMS notifications on a Premium Gold subscription. | Client phone number and the appointment information for the message. Only active when SMS is enabled by the business owner. |
| RevenueCat | Manages Free, Premium, and Premium Gold subscription status through Google Play and the App Store. | App store subscriber ID and subscription status only. No appointment data, calendar data, or booking information. |
| Google Calendar API Apple Calendar Microsoft Outlook |
Read and write calendar events using the permissions you authorize through each provider's OAuth flow. Read contacts (People API) for name autocomplete. | Only the calendar and contact data you authorize. Each provider's own privacy policy governs how they handle your data within their platforms. |
None of these services receive data for advertising. None of them see the full picture of your app — each sees only the narrow slice needed to do their specific job.
MultiPick Scheduler's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
SMS text messaging is an optional Premium Gold feature — not active by default. When a business owner with a Premium Gold subscription enables SMS, clients receive appointment-related texts at the phone number they provided when booking — but only if the client checked the separate SMS consent checkbox (see Section 9).
These messages are transactional only: booking confirmation, appointment reminders, and cancellation notices. No marketing messages are ever sent via SMS.
Opting out of SMS. Clients can opt out of SMS at any time by texting any of the following keywords to the number that sent the message:
Opt-out requests are processed within 10 business days. Opting out of SMS does not affect email reminders — email and SMS are independent, and revoking one does not revoke the other.
When you opt out, we record the date and method of your opt-out request (for example, "SMS STOP keyword" or "email unsubscribe") as part of your consent record. This protects both you and the business owner by creating a clear record that your opt-out was received and processed.
To re-enable SMS after opting out, text START to the same number.
SMS delivery operates under an approved A2P (Application-to-Person) 10DLC campaign registration, meaning our business identity and messaging use case have been reviewed and approved by mobile carriers.
MultiPick Scheduler offers a Free tier and a Premium subscription (Monthly and Yearly plans). All purchases are processed through the Google Play Store or Apple App Store. We never see or store your credit card number, billing address, or any financial information. Payment processing is handled entirely by Google or Apple under their own terms and privacy policies.
Subscription status is communicated to the app through RevenueCat, which verifies your purchase with the app store. RevenueCat receives your app store subscriber ID — not your payment details.
MultiPick Scheduler does not process any payment between a business owner and their clients. Service fees are a matter between the business and their client, handled outside the app entirely. No payment information from either party flows through our infrastructure.
MultiPick Scheduler is intended for users aged 13 and older. Clients confirm they are at least 13 years old as part of the email consent checkbox on the booking page (see Section 9). We do not knowingly collect personal information from children under 13.
All communication between the app, our server, and third-party services uses encrypted HTTPS/TLS connections. OAuth tokens stored on our server are encrypted at rest. All data stored in Firebase/Firestore is encrypted at rest by default as part of Google Cloud infrastructure — this applies to every piece of data our server holds, not just OAuth tokens. We never store calendar provider passwords — the OAuth system means your credentials are handled entirely by your provider and never pass through our servers.
Our server infrastructure runs on Firebase (Google Cloud), which holds industry security certifications including SOC 2, SOC 3, and ISO 27001. The business owner's admin interface is authenticated through their own account and is not publicly exposed.
Our minimal data footprint is itself a security feature. A server that holds almost nothing cannot leak much.
The following table lists all categories of personal data the app collects or processes. This information supports Google Play Data Safety and Apple App Privacy disclosures.
| Data type | Collected from | Purpose |
|---|---|---|
| Name | Business owners (sign-in), Clients (booking form) | Account identity, calendar event creation |
| Email address | Business owners (sign-in), Clients (booking form) | Account identity, transactional emails (confirmations, reminders, cancellations) |
| Phone number | Clients (optional, booking form) | SMS confirmations and reminders (Premium Gold only, with separate consent) |
| Calendar data | Business owners (via OAuth) | Availability display, event creation and management |
| Contacts data | Business owners (via People API, read-only) | Name/email/phone autocomplete when creating a booking |
| Device identifiers (push tokens) | Business owners only | Delivering push notifications for booking alerts |
| IP address | Clients (at booking time) | Consent record documentation |
| Browser/device info (user agent) | Clients (at booking time) | Consent record documentation |
We do not collect location data, financial information, health data, browsing history, or any data beyond what is listed above.
Applicable privacy laws (including GDPR, CCPA, and others) may give you rights regarding your personal data. Because of how MultiPick Scheduler is built, most of those rights are exercised directly through your own accounts rather than through us:
See Section 22 for contact information.
MultiPick Scheduler is a general-purpose scheduling tool, not a HIPAA-certified medical platform. If your business is subject to HIPAA or other medical privacy laws — such as California's CMIA or Washington's My Health My Data Act — you are responsible for your own compliance. That includes the appointment titles you set, the communication channels you use, and any patient authorizations you obtain. We don't currently offer Business Associate Agreements. If HIPAA applies to you, please evaluate a dedicated healthcare scheduling platform.
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights. Here is how MultiPick Scheduler addresses them:
Categories of personal information we collect: Names, email addresses, phone numbers, calendar data (via OAuth), device identifiers (push notification tokens), IP addresses, and browser/device information. See Section 17 for the complete list.
Sources: Directly from you — when you sign in (business owners), when you fill out a booking form (clients), and when your device connects to our server (push tokens, IP address, browser info).
Purposes: Providing the scheduling service, sending transactional communications (confirmations, reminders, cancellations), maintaining consent records, and managing subscriptions. We do not use personal information for advertising, profiling, or any purpose unrelated to the appointment booking service.
Third parties: We share data only with the service providers listed in Section 12 (Firebase, Resend, Twilio, RevenueCat, calendar providers), and only the minimum data each needs to perform its function.
Your rights under the CCPA:
To exercise any of these rights, contact us using the email at the bottom of this page. We will verify your identity and respond within 45 days as required by law.
If we make material changes, we will update the effective date at the top of this page and notify business owners through the app before the changes take effect. Continued use of the app after the effective date of a revised policy constitutes acceptance of the updated terms.
Every prior version is publicly archived at its own permanent dated link (for example, /privacy/archive/2026-04-23). Consent records reference the policy version that was active at the time each consent was given, so you can always verify which version of this policy applied to a specific booking.
The current version is always at multipickapp.com/privacy.
For data-related requests (deletion, access, correction, CCPA inquiries):
Email: privacy@multipickapp.com
We aim to respond to all privacy-related inquiries within 30 days.