Privacy Policy
Last updated: 27 September 2026
In short
- We collect only what's needed to book a visit: names, email addresses and visit times.
- Hosts and roommates sign in with Google. We get their name and email address, and nothing else from their account.
- Calendars are checked for busy times only. We never read event details.
- Bookings are deleted automatically 30 days after the visit.
- No cookies, no tracking, no selling of data.
1. Who we are and our role
Plan my visit is a free service run by Andrea Vendrame, an individual developer based in Denmark (“we”, “us”). It is not operated by a company. You can reach us at dev.andreavendrame@gmail.com.
Plan my visit is used by a household (through its hosts, the people who set it up or join it) to let prospective tenants book a visit to a room. Our role depends on whose data it is:
- Account data (the hosts who sign in with Google to set up or manage a household): we are the data controller.
- Visitor data and household member data entered or connected through the service: the household decides why the data is collected and is the data controller. We process it on the household's behalf as a data processor (Art. 28 GDPR), under our Terms of Service.
This policy describes all of that processing so everyone involved knows what happens to their data.
2. What data we process
Visitors (people booking a visit)
- Your name and email address, which you enter when booking.
- The visit you choose: date, time and whether it is in person or online.
- For in-person visits, the visit address set by the household is attached to your booking.
- For every visit, a Google Calendar event is created and your email address is added to that event as a guest, so the visit appears in your calendar. For online visits, the event also includes a Google Meet link; for in-person visits, the visit address.
People who sign in (hosts and roommates)
- When you sign in with Google: your name, email address and Google account ID, which we use to create your account and recognise you when you come back.
- Signing in also connects your Google Calendar, so we receive a Google access token for your calendar's free/busy information (see below).
- The households you set up or join: household name, booking page link and visit address.
- A sign-in session, so you stay signed in (see “Technical data”).
Household members
- Name and email address, added by the household's admin or by another member. A member who joins through an invite link signs in with Google, and their email address is replaced by the one of that Google account.
- For members who haven't joined yet: a personal invite link, which stops working once it is used.
- The weekly time windows in which each member is available for visits.
- If a member connects Google Calendar: a Google access token allowing us to read their calendar's free/busy information. We only see when they are busy, never event titles, descriptions, guests or locations. Busy times are read when someone opens the booking page and are not stored.
The household's sending account
- The email address of the Gmail account connected to send booking confirmations, and a Google access token allowing us to send those emails and to create the calendar event for each visit (with a Google Meet link for online visits).
- The visit address entered in the admin page.
Technical data
- Server logs: IP address, time and type of request, and error details (which may include a household member's name if reading their calendar fails).
- No cookies and no analytics or advertising trackers. We only use your browser's storage for what's strictly needed to keep you signed in: the admin passcode is kept in session storage until you close the tab or log out, and a sign-in token is kept in local storage until you log out. That token stops working after 30 days, and we store only a scrambled (hashed) copy of it.
- Pages load their fonts from Google Fonts, so your browser sends your IP address to Google when a page loads.
3. Why we process it and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Showing available slots, recording bookings, sending confirmations and creating Meet links | Performance of the contract with the household (our Terms of Service), Art. 6(1)(b); for visitors, steps they request before a possible tenancy |
| Creating your account, signing you in and letting you join a household | Performance of the contract, Art. 6(1)(b) |
| Checking household members' calendars to avoid double-booking | Performance of the contract, Art. 6(1)(b), based on the member's own action of connecting their calendar |
| Keeping the service secure, fixing errors and handling legal claims | Legitimate interest, Art. 6(1)(f) |
4. How we use Google user data
When you sign in with or connect a Google account, you grant only the permissions listed below:
- Basic profile (name, email address, account ID), when you sign in: to create your account and recognise you.
- Calendar free/busy (read only), for household members, requested as part of signing in: to hide times when they are busy.
- Send email (Gmail), for the sending account: only to send booking confirmations to the visitor and household.
- Create calendar events, for the sending account: only to create, and on cancellation delete, the event for each visit (and its Google Meet link for online visits).
- Email address: to show which account is connected.
Plan my visit's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not use it to train AI models, and no person reads it except where needed for security, to comply with the law, or with your permission to fix a problem.
You can withdraw access at any time at myaccount.google.com/permissions or by asking the household admin or another member to remove you.
5. How long we keep data
We keep data only as long as the booking process needs it:
- Bookings (visitor name, email, visit time, address, Meet link): deleted automatically 30 days after the visit.
- Calendar free/busy information: not stored; read only when the booking page is loaded.
- Household members, availability and Google access tokens: kept while the member is part of the household account. They are deleted immediately when the member is removed from the household, and all of a household's data is deleted within 30 days of a host asking us to delete it, or of the service shutting down.
- Your account (name, email address, Google account ID and calendar access token): kept until you ask us to delete it by writing to dev.andreavendrame@gmail.com. Leaving a household does not delete your account; withdrawing access at Google stops us from reading your calendar immediately.
- Sign-in sessions: deleted when you log out, and automatically after 30 days.
- Invite links: deleted when used, or when the invited member is removed.
- Server logs: kept for no more than 30 days.
Confirmation emails and calendar events are also stored in the Google account used to send them, and in recipients' inboxes. Those copies are controlled by their account owners, not by us.
7. Security
Data travels over encrypted HTTPS connections. Google access tokens stay on our server and are never sent to browsers. Household pages are only open to their members, who sign in with Google; the original admin page is protected by a household passcode. Sign-in tokens are stored only as hashes, and each household's data is kept separate from every other household's. Access to the servers is limited to the people who operate the service.
8. Your rights
Under the GDPR you can ask to:
- access your data and receive a copy of it;
- correct inaccurate data;
- delete your data;
- restrict or object to its processing;
- receive the data you provided in a portable format.
Write to dev.andreavendrame@gmail.com. If your data was collected for a household (as a visitor or household member), you can also contact the household directly; if you write to us, we will pass your request on to them and help them answer it. We reply within one month.
You also have the right to complain to the Danish Data Protection Agency, Datatilsynet, or to the data protection authority in your country of residence.
9. Children
Plan my visit is intended for adults. We do not knowingly process data of anyone under 18.
10. Changes to this policy
We may update this policy when the service changes. The “Last updated” date at the top will always show the current version, and we will notify hosts by email of significant changes.