CommonTime

by AH Datalytics

Privacy Policy

Effective August 10, 2026

What CommonTime is

CommonTime, operated by AH Datalytics LLC ("we"), helps project teams that span multiple organizations find meeting times. Team members share when they are busy or free; authorized coordinators see combined availability so they can propose meeting times without long email chains.

What we collect

  • Busy/free intervals only. From every connected calendar — Google, Microsoft, or an iCalendar (ICS) feed — we store only the start and end times of periods when you are busy. We never request, store, or process event titles, descriptions, locations, attendees, or any other event content. Where a calendar provider offers a busy/free-only permission (such as Google's calendar.freebusy scope), that is the only calendar permission we request. When an ICS feed is read, event details present in the feed are discarded immediately during processing and only busy start/end times are retained.
  • Basic identity. Your name and email address, used to label your availability for your team's coordinators and to sign coordinators in.
  • Connection credentials. OAuth refresh tokens or ICS feed URLs, stored encrypted (AES-256-GCM) and used solely to refresh your busy/free times.

How we use it

For exactly one purpose: showing authorized coordinators on your project team when you are busy or free, so they can schedule meetings. We do not use this data for advertising, we do not sell or rent it, we do not share it with third parties except the infrastructure providers that host the service (Vercel; Neon, for encrypted database storage in the United States), and we do not use it to train artificial-intelligence or machine-learning models.

Google user data

CommonTime's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The only Google Calendar permission CommonTime requests is read-only free/busy status; Google account sign-in additionally provides your name and email address.

Who can see your availability

Only coordinators authorized for your team's CommonTime workspace — access is restricted to an approved list. Your busy/free times appear alongside your teammates' as colored availability slots; coordinators never see why you are busy.

Booking pages

Some workspaces publish booking links where anyone with the link can schedule a meeting. If you book a meeting as a guest, we collect the name, email address, and optional notes you enter, plus the meeting time — used solely to create the meeting, send calendar invitations (delivered by Resend), create the video-conference link if the workspace has video configured, and let you or the hosts cancel. To prevent abuse of the public form we also store a one-way cryptographic hash of the booking request's network address — never the address itself. Booking pages show open time slots only; they never reveal who is busy, why, or any calendar contents. Cancelled and past bookings are retained for the workspace's records; email us for deletion requests.

Meeting polls

Some workspaces publish poll links where anyone with the link can say which of several proposed times works for them. Answering a poll requires no account and no sign-in. We collect the name you enter, the times you mark, an optional email address, and an optional note to the organizer — used solely to show the organizer and, unless the poll is set to hide answers, the other respondents who can make which time. An email address, if you give one, is used only to let you return and change your answer. To prevent abuse of the public form we also store a one-way cryptographic hash of the network address the answer came from — never the address itself. Where a member of the workspace team has connected a calendar, their row is filled in from their busy/free intervals, so a poll shows only whether they are free at a proposed time — never any calendar contents. Polls and their answers are retained for the workspace's records; email us for deletion requests.

Retention and deletion

Cached busy/free intervals cover roughly the next 60 days and are replaced on every refresh. You can disconnect a calendar at any time by asking the coordinator who invited you (or emailing us); removal deletes the connection, its credentials, and all cached intervals immediately. Removing a person from a roster deletes everything associated with them.

Security

All traffic is encrypted in transit (TLS). Refresh tokens and feed URLs are encrypted at rest with AES-256-GCM. Coordinator access requires sign-in with a Google or Microsoft account on an approved list.

Contact

Questions or deletion requests: bhorwitz@ahdatalytics.com.
AH Datalytics LLC · New Orleans, LA · ahdatalytics.com

Changes

If this policy changes materially, we will update this page and note the new effective date above.