Back to homeLegal

Privacy Policy

Last updated: July 22, 2026

1. What we collect

We collect information you give us directly (name, email, organization, listing details, payment info) and information we generate as you use Subler (bookings, messages, log and device data). If your organization connects a Google or Microsoft calendar, we also receive certain calendar data described in Section 3.

2. How we use it

We use your information to operate the Service: authenticate you, process bookings and payments, send transactional emails, prevent fraud and abuse, and improve the product.

3. Google Calendar data (and other connected calendars)

Subler offers an optional calendar-sync feature so a facility owner's existing calendar stays in agreement with their Subler bookings. Only an organization administrator can turn this on, from that organization's Settings > Integrations page — individual renters never connect a Google account through Subler. We use Nylas as the calendar-sync provider that brokers this connection with Google on our behalf.

What Google user data we access

When an administrator connects a Google Calendar account, we request:

  • See, edit, share, and permanently delete events (calendar.events) on the specific calendar the administrator selects for a given facility, so we can create the events described below.
  • See, edit, share, and permanently delete calendars (calendar) — used to list the account's calendars so the administrator can pick which one to bind to a facility.
  • View resource calendars in a Google Workspace domain, read-only (admin.directory.resource.calendar.readonly) — requested only when the organization uses Google Workspace, so shared room/facility calendars (e.g. a gymnasium or auditorium) can appear in that same picker alongside the administrator's personal calendars.

We request only the scopes above; we don't request access to Gmail, Drive, Contacts, or any other Google product.

How we use it

Once connected, the integration works in both directions:

  • Outbound.When a booking on a connected facility is confirmed, cancelled, or rescheduled, we create, update, or delete a matching event on the connected calendar. The event carries the facility name, the booking time, and the renter's name and contact details (email, phone if provided, and outside-organization affiliation) so organization staff can see who booked without opening Subler. The renter is listed as a guest on the event, but we suppress Google's invite email so they aren't emailed directly from the organization's calendar.
  • Inbound.We read events already on the connected calendar(s) so that time already committed elsewhere on that calendar (e.g. a school assembly entered directly in Google Calendar) is reflected as unavailable in Subler. We store the event's time range, title, and description for this purpose; we do not extract or separately store the guest list of external events.
  • Resource calendar lookup. The read-only Workspace directory scope is used only to populate the calendar-picker dropdown described above — we do not store or otherwise use the broader directory listing.

Who we share it with

Google user data obtained through this integration is shared only with Nylas, strictly as the technical intermediary that relays the requests above between Subler and Google on our behalf under its own security and privacy commitments. It is also visible to other people with access to the organization's connected Google Calendar, since that visibility is the point of the feature. We do not sell this data, share it with advertisers or data brokers, or use it to build advertising profiles.

Subler's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect it

  • Subler never sees or stores the Google OAuth token itself — it's held by Nylas on our behalf. Our database stores only an opaque connection reference for the org.
  • All traffic between Subler, Nylas, and Google is encrypted in transit (TLS).
  • Inbound calendar notifications are authenticated with an HMAC signature before we act on them.
  • Only organization members with permission to manage that organization can connect, view, or disconnect its calendar integration.

Retention and deletion

The connection stays active until an administrator disconnects it (Settings > Integrations > Disconnect) or the authorization is revoked from the Google Account side. Disconnecting immediately revokes Subler's access and stops all further syncing. Facility-availability records already derived from external calendar events may be retained afterward to preserve historical availability, but are no longer updated. To request deletion of any Google user data we hold, email privacy@getsubler.com and we'll act on it promptly.

4. Sharing, generally

Outside of the Google/Microsoft calendar integration above, we share information only when needed to operate Subler:

  • With the counterparty to a booking (e.g. a renter sees the facility owner's listing and contact info, and vice versa).
  • With service providers (payment processors, email delivery, hosting, analytics) under contracts that restrict their use of the data.
  • When required by law, or to protect the rights, property, or safety of Subler, our users, or the public.

5. Cookies and similar technologies

We use cookies and local storage to keep you signed in, remember preferences, and measure how the product is used. You can clear them from your browser at any time.

6. Data retention

We keep account and booking records for as long as your account is active and for a reasonable period afterward to satisfy tax, audit, and dispute-resolution obligations.

7. Security

Data in transit is encrypted via TLS. Payment data is handled by PCI-compliant processors and never stored on our servers in raw form. No system is perfectly secure, but we work to keep yours safe.

8. Your choices

You can review and update most account information from your settings. To request export or deletion of your data, email us at the address below.

9. Children

Subler is not directed to children under 13. We do not knowingly collect personal information from them. If you believe we have, contact us and we'll delete it.

10. Changes

We'll post material changes to this policy in the product or by email. The “Last updated” date above reflects the most recent revision.

11. Contact

Privacy questions? Email privacy@getsubler.com.