CheckTheCal

Privacy Policy

Last updated 25 August 2026

This policy explains what CheckTheCal collects, why, who else touches it, and what you can do about it. It is specific rather than generic, because a privacy policy that could describe any company tells you nothing about this one.

The short version: we hold your email address, the calendar URLs you give us, and the contents of the calendars we fetch for you. We use Stripe for payments. There is no analytics, no tracking, no advertising and no third-party script anywhere on this site. We do not sell your data and we never will.

1. Who is responsible for your data

The data controller is CheckTheCal in California, United States.

We are small enough that this address reaches a person directly, and we have not appointed a data protection officer because we are not required to.

2. What we collect

Your account

Your session

When you are signed in we store a session record containing the IP address and browser user-agent the session was started from, and its expiry. We keep these to let you and us tell a legitimate session from a stolen one.

We never store your session token. We store a SHA-256 hash of it. The same is true of sign-in links and recipient confirmation links. A stolen copy of our database therefore yields no usable sessions and no usable links.

The calendars you watch

The calendars themselves may contain other people's data

A school calendar names teachers; a club fixture list names opponents and venues. When you ask us to watch a feed, we store and process whatever that feed contains, including personal data about people who have never heard of us.

For that event data you decide what is collected and why — you choose the calendar, the recipients and the retention. We process it on your instruction in order to provide the service to you, and for nothing else. We do not mine it, analyze it across accounts, or use it to train anything. If you are watching feeds on behalf of an organization, that organization is responsible for having a lawful basis to do so.

Recipients

For every address you add as a recipient we store the address, an optional label, whether and when it confirmed, and whether and when it unsubscribed.

Sending records

For every message we send we store the destination address, which watch it was for, a hash of its contents, whether it succeeded, and the provider's message id. The content hash is what stops us sending you the same alert twice.

We also keep a suppression list of addresses that hard-bounced or reported us as spam. It is global, it is keyed on the address, and we keep it indefinitely — see retention for why.

Payments

If you subscribe, Stripe collects and holds your payment details. We never receive your card number. What we store is Stripe's customer and subscription identifiers, your plan, its status, and when the current period ends. Your name, billing address and tax details live with Stripe, and you edit them there.

Operational logs

Our servers keep short-lived logs of requests and errors, which can include IP addresses. Neither is used to profile you.

What we do not collect

No advertising identifiers. No cross-site tracking. No analytics of any kind — no Google Analytics, no Plausible, no PostHog, no session recording, no heatmaps. No third-party scripts, fonts or pixels load on this site at all. We do not buy data about you from anyone.

For anyone in the UK, the EU or the EEA, the GDPR requires us to name a legal basis for each purpose. Ours are:

We do not use your data for automated decision-making that has a legal effect on you, and we do not profile you.

4. Who else we share it with

We do not sell your personal information, we do not share it for advertising, and we do not disclose it to anyone except the payment processor.

We will also disclose data where we are legally required to — a valid court order or lawful request — and, if the service ever changes hands, to the acquirer, in which case we will tell you by email beforehand.

5. Where your data is processed

Everything is processed in the United States. Our payment processors is a US company, and our servers are in California.

If you are in the UK, the EU or the EEA, that means your personal data is transferred outside your country. For those transfers we rely on the European Commission's Standard Contractual Clauses, and for the UK on the International Data Transfer Addendum, entered into with each processor, together with the safeguards described in section 9. You can ask us for details of these arrangements at any time.

We are telling you this up front, because for some users it is a reason to choose a different service, and you should be able to make that decision before you sign up.

6. Cookies

One cookie. It is called `ctc_session`, it holds your sign-in session, and it is strictly necessary — without it we cannot keep you signed in. It expires after 30 days or when you sign out, whichever is first.

That is the entire list. There are no analytics cookies, no advertising cookies and no third-party cookies, which is why you have never seen a consent banner here: there is nothing optional to consent to.

Signing out deletes the cookie and revokes the session on our side.

7. How we protect it

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data and is likely to put you at risk, we will tell you and the relevant supervisory authority without undue delay, and within 72 hours of becoming aware of it where the GDPR requires.

8. How long we keep it

9. Your rights

Wherever you live, you can ask us to:

Email support@checkthecal.com to exercise any of these. We will respond within one month. We do not charge for a request, and we will not treat you differently for making one.

If you are in the UK, the EU or the EEA, you also have the right to complain to a supervisory authority — the Information Commissioner's Office in the UK, or your national authority in the EU. We would much rather you came to us first, but the right is yours and we will not stand in the way of it.

If you are in California or another US state with a privacy law

You have the right to know what we collect and why, to access it, to correct it, to delete it, and to receive it in a portable form. You also have the right not to be discriminated against for exercising any of these.

We do not sell personal information and we do not share it for cross-context behavioural advertising. We have not done so in the past twelve months, and we do not have a "Do Not Sell or Share My Personal Information" link because there is nothing to opt out of. We collect no sensitive personal information as that term is defined by the CPRA, other than what a calendar you point us at may happen to contain.

10. Deleting your account

You can delete your account yourself, from your billing page. It takes effect immediately and it cannot be undone.

What deletion removes: your account and user record, your watches and their settings, your change history, your recipients, your sending records, your usage counters, and your session — you are signed out on the spot. Any active subscription is cancelled at the same time, with no refund for the remainder of the period you have paid for.

What deletion does not remove, and why:

If you would rather we did it for you, or you cannot sign in, email support@checkthecal.com and we will do it within one month, usually the same week.

11. If you are a recipient, not a customer

You may be reading this because somebody added your address to a watch and you got an email.

12. Children

The service is not directed at children and is not for anyone under 16. We do not knowingly collect data from a child. If you believe a child has created an account, email us and we will delete it.

A calendar you watch may of course concern children — a school's term dates, a junior team's fixtures. That data reaches us as calendar content under section 2, on your instruction, and is treated the same as any other event data.

13. Changes to this policy

The date at the top of this page always says when this policy last changed. If a change materially affects how we handle your data, we will email the address on your account at least 14 days before it takes effect, so that you can delete your account first if you would rather not continue.

14. Contact

Any question, any request, any complaint:

support@checkthecal.com

CheckTheCal P.O. BOX 57770, Tarzana, CA 91357 US