Last updated 21 September 2026
This page explains what Whensday collects, why we collect it, who else sees it and how to have it removed. It is written to be read, not to be survived. If you would rather take any of it up with a person, write to support@whensday.xyz.
Your account. Your email address and a password, handled by our authentication provider — we never see the password itself, only a hash it keeps. Everything else on your profile is optional: your name, phone number, photo, language, region and suburb, how you prefer to be contacted, and any standing note you choose to share with the businesses you book.
Your bookings. Which business and practitioner you booked, the service, the time, and anything you typed into the booking itself. Businesses you book with see this — that is the point of it.
Payments. Whensday does not take payment for appointments — you pay the business directly, so no card details of yours pass through us at all. Where a business pays Whensday for its own subscription, our payment processor handles the card and the number never reaches our servers; we keep only the amount, the status and the processor's reference.
Reviews. Anything you publish about a business, under your display name.
You can book without registering. When you do, we ask for four things, and we ask for all four because a booking made without an account has nothing else standing behind it:
These go to the business you booked with and to nobody else, and they are used to run that appointment and nothing more. We do not market to you on the strength of a guest booking, and we do not sell or share these details.
What a guest booking cannot do. Without an account there is no way for us to establish that you are the person who made it, so you cannot move it, cancel it, or review the business yourself. Those all go through the business until you have an account. This is a limit on us, not a nudge: acting on an appointment because somebody typed the right name into a form is not something we are willing to do.
If you register later. When you create an account and confirm the email address, every guest booking made with that same address moves into it, and you can manage and review them from then on. Nothing moves until the address is confirmed — the confirmation is the proof, and without it anyone could claim anyone's bookings by typing their address. If you register with a different address, the guest bookings stay as they are; write to support@whensday.xyz and we will sort it out.
Deleting them. A guest booking has no account to delete, so ask us instead — write to support@whensday.xyz from the address you booked with, and we will remove what the law does not require us to keep.
This section applies only to practitioners who choose to connect their own work calendar. It is optional, it is off until you turn it on, and nothing below happens to clients booking appointments.
Connecting a calendar synchronises it in both directions, and each direction is held to the narrowest thing that makes it work — we read only when your time is taken, and we write only the appointments Whensday itself made.
What we read. Whensday reads the events in your calendar for the period ahead solely to know which times are already taken, so that Whensday does not offer a slot you cannot keep.
What we store from your calendar is only this:
We do not store, and never transmit off the provider's servers, the title, description, location, guest list, attachments, conferencing links or organiser of any event. A meeting in your calendar becomes nothing more than a rectangle of unavailable time.
What we write. When a client books, reschedules or cancels an appointment with you, Whensday creates, updates or cancels a matching event in your calendar, so your working diary is right in the place you already look. We write only events Whensday itself created, and we recognise them by the identifiers we recorded when creating them — we never modify or delete an event we did not create.
The access and refresh tokens that permit this are encrypted before they are written to our database, and are used for no purpose other than the sync described here. No human at Whensday reads your calendar data. It is never sold, never used for advertising, never used to build profiles, and never used to train machine-learning or AI models.
Whensday's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting. Use the Disconnect button on the staff member's page in Whensday, or revoke Whensday's access directly at myaccount.google.com/permissions. Disconnecting deletes the stored tokens and every imported busy time immediately.
Businesses you book with see the booking and the contact details you chose to share. Beyond that, we share data only with the providers that make the service run: our hosting and database provider, our email provider, and our payment processor. Each handles it on our instructions and for no purpose of their own. We do not sell personal information, and we do not share it for advertising.
We may disclose information where the law requires it, or to protect the safety of a person or the integrity of the service.
Bookings are kept while your account is open, and afterwards only for as long as tax and accounting law requires us to keep the underlying records. Imported calendar busy times are kept only while the calendar is connected and are deleted the moment it is disconnected. Delete your account and the rest goes with it.
You may ask for a copy of what we hold, ask us to correct it, ask us to delete it, or object to how we use it. Write to support@whensday.xyz and we will answer within 30 days. If our answer does not satisfy you and you are in South Africa, you may complain to the Information Regulator.
Traffic is encrypted in transit. Calendar tokens are encrypted at rest. Access to the production database is limited to the people who need it to keep the service running. No system is perfect, and we will tell you promptly if something happens that puts your data at risk.
If we change this policy in a way that matters, we will say so on this page and update the date at the top before the change takes effect.
Whensday — support@whensday.xyz.