Privacy Policy
Effective date: July 22, 2026
DPSTUDIOS CRM ("we," "us," "our") provides an AI-powered booking and field-service management platform ("Service") used by service businesses (each, a "Business") to manage phone bookings, technician scheduling, invoicing, and calendar sync. This Privacy Policy explains what data we collect, how we use it, and — specifically — how we handle data obtained through Google APIs.
1. Who this applies to
This policy covers two groups: (a) the Business that signs up for DPSTUDIOS CRM and its staff/technicians who log into the dashboard, and (b) that Business's own customers, whose booking details (name, phone, address, appointment) are entered into the Service by the Business.
2. Google User Data — what we access and why
A Business may optionally connect its own Google account to enable Google Calendar sync. When connected, we request the following OAuth scopes:
https://www.googleapis.com/auth/calendar.events— to create, update, and delete calendar events that correspond 1:1 to bookings made in the Service (new booking, status change, reschedule, or cancellation).https://www.googleapis.com/auth/calendar.readonly— to read the connected account's primary calendar identifier (e.g., email) so we can show the Business which account is connected.
We use this access only to keep the Business's own Google Calendar in sync with its own bookings inside DPSTUDIOS CRM. We do not read, analyze, or otherwise use the content of any other calendar events already on that calendar, and we do not access any other Google product or data (Gmail, Drive, Contacts, etc.).
3. How Google user data is stored and who can see it
- Google Calendar data is never transferred to, sold to, or shared with any third party, advertiser, or data broker.
- We do not use Google user data for advertising, ad targeting, or to determine creditworthiness or for lending purposes.
- No human at DPSTUDIOS CRM reads or reviews the content of a Business's Google Calendar. Access is used exclusively through automated, server-to-server API calls triggered by booking events.
- Only the OAuth refresh token needed to make those API calls is stored, on our servers, associated with that Business's account. It is never shared with the Business's own customers or with other Businesses on the platform.
- Disconnecting Google Calendar (available any time from the Business's dashboard) immediately revokes our access and deletes the stored token from our systems.
4. Other information we collect
Beyond Google Calendar data, the Service stores: business account details (name, login credentials, phone number used for AI call answering); booking/customer details entered by the Business or its AI receptionist (customer name, phone, address, service requested, appointment time); invoices, quotes, and payment records (processed via Stripe — we do not store full card numbers); and SMS delivery logs (sent via Twilio on the Business's behalf).
5. Data retention
Booking, invoice, and calendar-sync data is retained for as long as the Business's account is active, so historical records (e.g., tax filing summaries) remain available. A Business can request deletion of its account and associated data at any time by contacting us below.
6. Security
Data is transmitted over encrypted connections (HTTPS/TLS). OAuth tokens and API credentials are stored server-side and are never exposed to end users' browsers.
7. Your choices
A Business may disconnect Google Calendar at any time from its dashboard settings. This immediately stops all further calendar sync and deletes our stored access token. Reconnecting later requires granting access again through Google's own consent screen.
8. Changes to this policy
We may update this Privacy Policy from time to time. Material changes affecting how Google user data is used will be reflected here with an updated effective date.
9. Contact us
Questions about this policy or your data can be sent to support@dpstudios.in.