Privacy Policy: BizzyBot · Version 2.2 · Effective August 21, 2026
This explains how BizzyBot LLC (“BizzyBot,” “we,” “us”) collects, uses, and shares personal information when you use the Service.
1. Information we collect. You provide: account info (first name, email, and a salted-hashed password), the business-plan content you enter (idea, notes, names, entity/state selections, cost estimates, journal entries), and, if you buy a plan, limited payment details via our payment processor (we don't store full card numbers). We also collect basic usage/device analytics through PostHog, our product-analytics provider; and, only if you accept our cookie/consent banner, PostHog session replays (recordings of your on-screen actions, with text input fields masked). We store your progress in your browser. If you use the survey features, people you invite may submit responses to you through the Service. We don't want sensitive data (health, biometric, precise location, race, religion, sexual orientation, citizenship): please don't enter it or collect it from respondents. One exception: the optional team map lets your team save work locations, including a home or base address a teammate chooses to share, so crews can plan jobs and travel. Enter only what your team is comfortable sharing (a city or ZIP works fine). Map locations can be edited or deleted at any time, and a teammate's home pin is removed when they leave the team or delete their account. Team owners and admins may also keep an employee record for each teammate, which can include up to two emergency contacts (a name, relationship, phone, and email entered by the teammate or an admin) and, if someone is deactivated, a short reason. Enter emergency contact details only with that person's knowledge. The record is visible to the team's owner and admins, is included in that teammate's data export, and is deleted with their team membership or account.
Google Calendar connection. If you choose to connect a Google account, we receive your Google account email and permission to list calendars you subscribe to and read event titles, descriptions, locations, dates and times, and meeting links from the calendars you select. We keep a bounded server-side cache of selected events so they can appear in BizzyBot and block unavailable booking times. For each selected calendar, you choose whether event details stay visible only to you or may be shown to authorized members of the current BizzyBot workspace. Events marked Only me still contribute a busy interval to availability, but their title, notes, location, link, calendar name, and guest list are not disclosed to teammates. If you turn on calendar sync, we send meeting details and guest email addresses you enter in BizzyBot to Google so Google can create or update events on calendars you own, notify attendees, and, when requested, create a unique Google Meet link. We store your Google account email, connection preferences, selected calendars, cached event data, identifiers for Google events created from BizzyBot, and an encrypted OAuth refresh token needed to keep the connection working. Temporary access tokens are used only to make the Google Calendar requests you authorize.
2. How we use it. To provide and operate the Service, save and sync your progress, process payments and manage subscriptions (including renewal reminders and receipts), respond to support, secure the Service and prevent abuse, understand and improve usage, and comply with law. Google Calendar data is used only to provide the connected calendar, availability, event-sync, and Google Meet features you choose to enable. We do not use Google Calendar data for advertising, unrelated analytics, or profiling, and we do not sell it.
3. How we share it. We do not sell your personal information for money. We use advertising and measurement tools, currently the Meta (Facebook/Instagram) Pixel, that set cookies and send limited activity (such as page views and purchases) to those platforms to measure and improve our ads; under some U.S. state privacy laws this counts as “sharing” for cross-context behavioral advertising, which you can opt out of (see Section 5). Whether these tools load depends on where you are: in regions that require consent first (including the EEA, the UK, and Switzerland), they load only if you accept our cookie/consent banner; elsewhere, including the United States, they may load when you visit, and you can turn them off at any time with the “Privacy choices” control in the site footer or in Settings. Your choice is saved so you are not asked again. We do not sell or share respondent data. We do not sell Google user data or transfer Google Calendar data to advertising platforms. We disclose Google Calendar data only to service providers acting on our behalf when necessary to operate and secure the connection, when you direct us to share an event with its attendees, or when disclosure is required for legal or safety reasons. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. If your team uses the map, addresses you save are sent once to our address-lookup provider to place the pin, and when you open the map the background imagery loads from our map-tile provider, which receives your device's IP address as part of serving it. We share personal information only with service providers under contract (hosting, database, payment processing, email, analytics, address lookup and map display for the team map), with legal or safety recipients when required by law, or with a successor in a business transfer.
4. Third-party AI tools. If you choose to use independent AI tools we link to, you do so under their terms and privacy policies; we don't control or receive what you send them.
5. Do Not Track and Global Privacy Control. If your browser sends a Global Privacy Control (GPC) “do not sell/share” signal, we treat it as an opt-out of the advertising tools that “share” data (such as the Meta Pixel): they stay off and advertising cookies stay declined, in every region, even if you accepted the banner. Analytics tools that only measure how the Service is used may still run under the regional rules in Section 3 unless you turn them off with the “Privacy choices” link. There's no industry-standard response to DNT; our product-analytics tool does not record your activity when your browser sends DNT, and other tools do not currently respond to it.
6. Your choices and rights. You can review and update your account information and business-plan content in the Service; delete your account and associated data from Settings (or by emailing customer@bizzybot.com), except records we must keep by law, and except that if you own a shared workspace that other people are working in you close the workspace rather than deleting your account on its own, because deleting it would delete their work too (see Section 7 for what happens then and when); opt out of marketing email using the unsubscribe link in any marketing message (we honor opt-outs within 10 business days; transactional messages like receipts and password resets aren't marketing); manage respondent data, which we delete when your account closes; and mark individual calendar events and tasks Private, which keeps them off your teammates' screens, keeps them out of any transfer to a manager, and stops anyone else being added to them. Older records of other types that were marked Private before this control was narrowed keep those protections. Section 7 explains what happens to Private items if you leave a company workspace. You can disconnect Google Calendar at any time from Calendar or Settings. Disconnecting asks Google to revoke the token and deletes the stored Google connection credentials, account email, preferences, calendar selections, and imported event cache from BizzyBot. Events already created in Google Calendar and meetings already saved in BizzyBot remain in their respective systems until you delete them there. Deleting your BizzyBot account also deletes the stored Google connection. Depending on where you live, you may have additional rights (access, correction, deletion, portability, opt-out): email customer@bizzybot.com to exercise them.
7. Data retention. We keep personal information for as long as your account exists. Closing your account is what ends that, it warns you first, and you can undo it. Leaving a company workspace is different: the work you own there is either transferred to your manager and removed from your account, or, if you marked it Private, destroyed. That is set out at the end of this section, and it cannot be undone.
Leaving your account alone. We do not delete accounts for being unused. There is no period of inactivity after which your account or your work is removed, so if you do not sign in for a year, or two, or longer, everything is still there when you come back. Deleting your account is something you choose to do, and you can do it at any time from Settings or by emailing customer@bizzybot.com. If you own a shared workspace that other people are working in, you close the workspace instead, which is what the next paragraph describes.
Closing your account. If you shut your account down from Settings, everything stays live for you and your team until the end of the period you have already paid for. After that the workspace becomes read only: you and your team can still open and export everything, and nobody can change it. 30 days later the workspace and the data it shares are deleted permanently, and that cannot be undone. You can cancel the shutdown at any point before that deletion date. Respondent data you collected is deleted along with the account.
Leaving a company. Work you do in a company workspace belongs to the company. If you leave a company workspace or are removed from one, the work you own there that is not marked Private is transferred to your manager. If you have no manager, or your manager has already left, it goes to the person who owns the workspace. This covers your documents, your folders, your archived documents, your forms, and your tasks and projects, including tasks and projects you created for yourself on your own list. The transfer is a move, not a copy: exactly the work that goes to your manager is removed from your account, so you do not keep company work after you leave. You keep your account itself, work that belongs to somebody else stays with them, and if there is nobody to transfer the work to then nothing is transferred and nothing is removed. If you use the Service on your own, without a company workspace, none of this applies to you.
Anything you marked Private is deleted instead, permanently, and nobody can get it back. When you leave a company workspace or are removed from one, everything you marked Private in that workspace is deleted for good, including your own copy of it. It is not transferred to your manager, it is not archived, and neither you nor we can recover it. Current Private controls are available only for calendar events and tasks. The same deletion rule also continues to cover older private projects, templates, documents, folders, notes, messages and contacts that still carry the legacy flag. It is limited to the workspace you left: if you also belong to another company workspace, what you marked Private there is untouched, and if you use the Service on your own without a company workspace, nothing you mark Private is deleted this way. So everything you own in the workspace you left takes one of two paths and never both: what is not marked Private is transferred to your manager and removed from your account, and what is marked Private is deleted outright and nobody receives it. Please choose what to mark Private with this in mind.
When we delete an account we keep a record that we deleted it, and when, as evidence that we honored this policy. Records we must keep longer by law are the exception: for example, auto-renewal consent and transaction records for at least 3 years or 1 year after termination, whichever is longer.
8. Security. We use reasonable safeguards including encryption in transit, hashed passwords, access controls, and server-side encryption for stored Google OAuth refresh tokens. No method is perfectly secure. If a breach affecting your personal information occurs, we'll notify you and authorities as required by applicable state law.
9. Children. The Service is for users 18 and older. We don't knowingly collect personal information from children under 13; contact customer@bizzybot.com and we'll delete it.
10. Changes. We may update this policy and will post a new effective date, with additional notice for material changes where required.
11. Contact. BizzyBot LLC · customer@bizzybot.com (mailing address available on request).