StitchLink Privacy Policy

1. Introduction

At StitchLink, a service provided and operated by Project Kaz LLC ("Company," "we," "us," or "our"), we believe your schedule is your business, not ours. This Privacy Policy explains how we collect, use, and protect your information when you use our scheduling utility.

Our Core Privacy Promise:

StitchLink is designed with "Architectural Blindness" and minimal data retention. While we connect to your Google and Microsoft calendars to find free time, we do not persist (store) your event titles, descriptions, locations, or attendee lists in our database. We only process this data ephemerally in memory to calculate "Free/Busy" status.

Important Notice Regarding Health Information:

StitchLink is not HIPAA compliant. You agree not to use the Service to collect, store, or process Protected Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act of 1996.

2. Information We Collect

A. Information You Provide

  • Account Information: When you register, we collect your name, email address, and authentication credentials (managed via OAuth).
  • Profile Settings: Working hours, time zone preferences, and meeting templates.
  • Meeting Details: Information you explicitly create within StitchLink, such as meeting titles ("Project Sync"), descriptions, and participant email addresses.

B. Information from Third-Party Calendars

When you link a Google or Microsoft account, we access your calendar data via their APIs.

  • What We Access: We fetch your calendar events to determine availability.
  • How We Process It: This data is processed in real-time (in memory) to identify conflicts.
  • What We Store: We only store the access tokens (encrypted) required to fetch this data. We do not store the actual event details from your third-party calendars.

C. Usage Data

We collect log data indicating when you log in, create meetings, or link calendars ("Activity Logs") to ensure security and debug issues.

D. Referral Program Data

When you participate in the StitchLink Referral Program (Terms of Service §17), we collect the following category of personal information, separate from the data described above:

  • Your referral code: An 8-character identifier assigned to your account so others can attribute a sign-up to you. This code is a StitchLink-internal identifier, not personal information on its own.
  • Applied code (if any): If you signed up after clicking a referral link or applying a code, we record which code was applied to your account.
  • Attribution records: Entries linking a referring user to a referred user, including user IDs and the referred user's email address at the time of enrollment, along with the referral status (pending or completed).
  • Reward records: Entries showing which accounts earned which Reward Months, the grant date, the expiration date, and whether the Reward is currently active.

Referral-program data is a distinct category of personal information under applicable state privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA and similar). It is not sold, shared for cross-context behavioral advertising, or disclosed to any third party for independent use.

Business or commercial purpose of referral-program data (CCPA §1798.130(a)(5)(B)). We collect referral-program data solely to (i) attribute a new Referred User sign-up to the Referrer who introduced them, (ii) calculate, grant, and expire the dual Reward Months described in Terms of Service §17, (iii) enforce the Prohibited Conduct and Claw-back provisions of §17, and (iv) detect and prevent referral fraud. We do not use referral-program data for advertising, profiling, or any other purpose outside those four.

Scope of our Architectural Blindness promise. The "Architectural Blindness" commitment described in §1 above refers specifically to third-party calendar data (Google Calendar and Microsoft Calendar event details). It is not modified by this §2.D and does not extend to referral-program data, account data, payment data, or usage logs, each of which is disclosed separately in this Policy.

Biometric data. The Referral Program does not collect, store, or process biometric identifiers or biometric information as defined by the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14), the Texas Biometric Privacy Act (Tex. Bus. & Com. Code §503.001), or the Washington My Health My Data Act. Spam prevention is handled by hCaptcha, which analyzes behavioral signals only.

No Protected Health Information. Consistent with §1 of this Policy, you must not transmit Protected Health Information (PHI) as defined by HIPAA through the Referral Program. Do not enter patient email addresses when applying a referral code or sharing a referral link.

No minors. Consistent with §8 below, the Referral Program is not directed to anyone under 13. Do not knowingly share referral links with minors. If we learn that we have collected personal information from a child under 13 through the Referral Program, we will delete it promptly.

3. How We Use Your Information

We use your information strictly to provide the scheduling service:

  • To Facilitate Scheduling: Calculating intersections of availability between multiple parties.
  • To Send Notifications: Sending invites, confirmations, and nudges via email.
  • To Improve Security: Detecting abuse or unauthorized access.
  • To Maintain Service: Ensuring API quotas are managed and the system remains stable.
  • For Aggregated Analytics: We may aggregate and anonymize platform usage data (e.g., booking velocities, peak scheduling times) to improve our service, publish industry insights, or for promotional purposes. This aggregated data will never identify any individual user or contain proprietary meeting details.

We do not sell your personal data to advertisers or third parties.

Referral Program processing

We process referral-program data to (a) attribute a referred user to a referring user, (b) calculate and apply Reward Months, (c) enforce the prohibitions and claw-back provisions in Terms of Service §17, and (d) detect and prevent referral fraud. Where you are located in the European Economic Area, the United Kingdom, or Switzerland, our lawful basis for this processing is (i) performance of the contract you accepted (GDPR Article 6(1)(b)) and (ii) our legitimate interest in correctly calculating rewards and preventing fraud (GDPR Article 6(1)(f)); we have completed a balancing test and determined that your interests are not overridden. You may object to processing based on legitimate interest by contacting privacy@stitchlink.ai.

4. Data Sharing and Sub-Processors

We do not share your personal information with third parties except as necessary to provide the Service. We utilize the following trusted sub-processors:

Sub-ProcessorPurposeLocation
SupabaseDatabase & AuthenticationUSA
VercelHosting & Serverless FunctionsUSA
CloudflareCDN & Edge NetworkUSA
GoogleCalendar API IntegrationUSA
MicrosoftCalendar API IntegrationUSA
StripePayment ProcessingUSA
ResendTransactional EmailsUSA
PostHogProduct Analytics (with consent)USA
SentryError MonitoringUSA
hCaptchaSpam PreventionUSA
UpstashRate Limiting (Redis)USA

International Data Transfers

Your data may be transferred to and processed in the United States. Our sub-processors listed above maintain Standard Contractual Clauses (SCCs) and/or participate in recognized data transfer frameworks to ensure adequate protection of personal data transferred from the European Economic Area, United Kingdom, and Switzerland to the United States.

Referral Program sub-processors

Participation in the Referral Program does not introduce any new sub-processors beyond those listed above. Reward-notification emails are sent through Resend (already listed). The referral code in a URL you share on a third-party platform (for example Twitter, LinkedIn, or an email client) may be logged by that platform according to its own privacy practices; the referral code is not "sold" or "shared" (as those terms are defined under the CPRA) by StitchLink. StitchLink does not email, text, or otherwise contact prospective Referred Users on your behalf; if you use the email-sharing option, your own email client is the sender and you are responsible for compliance with anti-spam laws including the CAN-SPAM Act and the TCPA.

5. Data Retention

  • User Account Data: Retained as long as your account is active.
  • Meeting Metadata: Retained to display your meeting history until you delete the meeting or your account.
  • Calendar Tokens: Retained until you disconnect the calendar or delete your account.
  • Ephemeral Calendar Data: Deleted immediately from memory after availability is calculated.
  • Referral Program Data: Referral records and reward records are retained for as long as your account is active and as a reward-ledger business record for the duration of any unexpired Reward Month plus a fraud-investigation window of up to three (3) years from the grant of the Reward Month, after which referral records tied to inactive accounts are anonymized or deleted. If you exercise your right to delete your account, referral records are handled in accordance with the "business records" exception under applicable law (for example, Cal. Civ. Code §1798.105(d)(1)), and any pointers to your deleted account are anonymized consistent with our hard-delete cascade (see D-618 in the repository history).

6. Your Rights (CCPA & GDPR)

Depending on your location (including California and the EEA), you have specific rights regarding your data:

  • Right to Access: You can request a copy of the data we hold about you.
  • Right to Deletion: You can request that we delete your account and all associated data ("Right to be Forgotten").
  • Right to Rectification: You can update your personal details via your Profile settings.
  • Right to Portability: You can export your meeting data.
  • Right to Object: You can object to the processing of your personal data for direct marketing purposes at any time by unsubscribing from promotional emails or contacting us.
  • Right to Restrict Processing: You can request that we temporarily pause the processing of your personal data while we verify a correction or address an objection.

Data Protection Officer

Based on our assessment under GDPR Article 37, Project Kaz LLC has determined that the appointment of a Data Protection Officer is not required given the nature and scale of our data processing activities. For any privacy-related inquiries, please contact us at privacy@stitchlink.ai.

Referral Program data and your rights

The rights listed above apply to all personal information we collect, including referral-program data described in §2.D. Residents of jurisdictions with comprehensive state privacy laws — including but not limited to California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and Montana (MCDPA) — may exercise these rights by contacting privacy@stitchlink.ai. Where your state recognizes a universal opt-out signal such as the Global Privacy Control (GPC), we honor that signal for all personal information we collect, including referral-program data.

Referral-program data is within scope of our breach-notification obligations under the California Customer Records Act (Cal. Civ. Code §1798.82), the New York SHIELD Act (NY Gen. Bus. L. §899-bb), and substantially similar state laws. In the event of a security incident affecting referral-program data, we will notify affected users without unreasonable delay as required by applicable law.

California Privacy Rights (CCPA & CalOPPA)

Under the California Consumer Privacy Act (CCPA), California residents have the right to request access to or deletion of their personal data, and the right to opt-out of the sale or sharing of their personal information. Project Kaz LLC does not sell your personal information.

Do Not Track Signals: We currently do not respond to "Do Not Track" (DNT) signals from web browsers, as there is no universally accepted standard for how to interpret them.

Email Communications & CAN-SPAM Compliance

You may opt out of receiving promotional emails or non-essential notifications from us at any time by following the "unsubscribe" link located at the bottom of those emails, or by contacting us directly. We will still send you essential transactional emails (such as meeting confirmations or security alerts) as required to provide the Service.

7. Security

We implement industry-standard security measures:

  • Encryption at Rest: All database sensitive fields (like OAuth tokens) are encrypted.
  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted via TLS/SSL.
  • Least Privilege: Our internal services only access the minimum data necessary to function.

Breach Notification

In the event of a confirmed data breach that compromises your personal information, we commit to notifying affected users and applicable regulatory authorities within 72 hours of confirmation, as required by GDPR Article 33. Given our zero-retention architecture, the scope of any potential breach is inherently limited since we do not persist sensitive calendar event data.

8. Children's Privacy

StitchLink is not intended for individuals under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect data from children.

9. Google User Data Policy

StitchLink's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

10. Cookies & Tracking

We use a minimal set of cookies and tracking technologies:

  • Essential Cookies: Session cookies required for authentication (managed by Supabase). These cannot be disabled.
  • Analytics Cookies: We use PostHog for product analytics to understand how StitchLink is used. These cookies are only set after you consent via our cookie banner.
  • Error Monitoring: Sentry collects error data (stack traces, browser information) to help us fix bugs. This does not track your browsing behavior.

You can manage your cookie preferences at any time using the "Cookie Preferences" button in our website footer.

11. Changes to This Policy and Contact Information

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last Updated" date.

Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or need to send formal legal correspondence, please contact us at:

Project Kaz LLC

4001 S Inglewood Ave, Bldg 101 Ste 248, Redondo Beach, CA 90278

Email: privacy@stitchlink.ai

Learn More About Our Approach

Curious about how we protect your data at a technical level? Read more about our architecture and analytics practices: