Privacy Policy
Last updated: July 27, 2026
This policy explains what data Rylo CRM ("we", "us") collects and how it's used, with particular detail on our optional Google Calendar integration.
Google Calendar integration
If you choose to connect your Google Calendar from Settings → Integrations, we request access to:
- Calendar events (calendar.events scope) — to create, update, and delete events on your Google Calendar that correspond to appointments you book in the CRM. We do not read or modify any other events on your calendar.
- Your email address (userinfo.email scope) — to identify which Google account is connected, shown to you in Settings → Integrations.
Data protection and security
We apply the following measures to protect Google user data accessed through this integration:
- Encryption at rest — access and refresh tokens are stored encrypted using Supabase Vault (backed by libsodium/AES encryption), not as plain text.
- Encryption in transit — all communication between your browser, our servers, and Google's APIs happens over HTTPS/TLS.
- Access control — tokens are only ever read server-side to make calendar API calls; they are never sent to or exposed in the browser, and are scoped so only the connected user's own account can access them.
Data sharing and disclosure
We do not sell, rent, or share your Google user data with third parties for advertising or any purpose unrelated to providing this feature. Google user data is processed by the following service providers on our behalf, solely to operate the application, and they are not permitted to use it for their own purposes:
- Supabase — our database provider, which stores the encrypted tokens described above.
- Vercel — our application hosting provider, through which requests to our servers pass.
We do not transfer Google user data to any other third party, and we do not use it to train AI/ML models.
Who sees your calendar events
Events created by this integration include, as attendees, any contact linked to the appointment and any additional people you explicitly add. Google will send those attendees a calendar invitation.
Revoking access
You can disconnect Google Calendar at any time from Settings → Integrations, which revokes our access and deletes the stored tokens. You can also revoke access directly from your Google Account permissions page. Disconnecting does not delete events already created on your calendar.
Contact
Questions about this policy or your data: saiteja2145@gmail.com