Privacy Policy
SageDesk provides the operating system for business phone calls, currently focused on AI receptionist and front-desk workflows for administrative tasks such as bookings, confirmations, reschedules, and human handoff. This Privacy Policy explains how SageDesk collects, uses, and protects information when a business uses the SageDesk website or product.
Who this policy applies to
This policy applies to visitors to www.sagedesk.in, customers evaluating or using SageDesk, and authorized users who connect third-party tools such as Google Calendar to support scheduling workflows.
Information SageDesk may collect
- Business contact details such as name, company, email address, and inquiry context.
- Operational data needed to provide receptionist and scheduling workflows.
- Appointment and event details required to create, update, or cancel invites.
- Integration metadata, logs, and security records needed to operate and protect the service.
How SageDesk uses connected calendar access
If a customer authorizes SageDesk to access Google Calendar or a similar calendar system, SageDesk uses that access only to provide the scheduling actions requested by the customer. This can include checking calendar availability, creating appointment invites, modifying appointment invites, rescheduling appointments, and cancelling appointment invites.
SageDesk does not use connected calendar access for unrelated advertising purposes. Calendar-connected data is used to deliver the receptionist and front-desk workflow the customer has asked SageDesk to perform.
How SageDesk uses information more generally
- To operate the website and respond to inbound inquiries.
- To provide, maintain, secure, and support the SageDesk service.
- To create structured scheduling outcomes such as bookings, confirmations, and handoffs.
- To investigate misuse, prevent fraud, and meet legal obligations.
How information may be shared
SageDesk may share information with infrastructure, analytics, communications, or integration providers only where needed to run the service; with a customer’s authorized staff and connected systems; or when required by law, regulation, or a valid legal process.
How SageDesk protects sensitive data
SageDesk treats Google user data — including OAuth tokens and calendar event details — as sensitive and applies the following technical and organizational controls:
- Encryption in transit: all traffic between SageDesk, Google APIs, browsers, and internal services is encrypted using TLS/HTTPS. Database and cache connections require TLS (PostgreSQL with enforced SSL and TLS-only Redis).
- Encryption at rest: sensitive customer fields (such as names, emails, and notes) are encrypted at the application layer with AES-256-GCM before they reach the database, on top of managed storage-level encryption. OAuth access and refresh tokens are stored as encrypted secrets and are never written to logs.
- Secrets management: credentials, encryption keys, and OAuth tokens are held in a managed secrets store (AWS Systems Manager Parameter Store / Secrets Manager as encrypted SecureStrings), not in source code or plaintext configuration.
- Tenant isolation and least privilege: each business's data is logically isolated using database row-level security and tenant-scoped access controls, so calendar access granted by one business is never used for another. Access to Google data is limited to the user-initiated booking workflows the business has authorized.
- Scope minimization: SageDesk requests only the narrowest Google Calendar scopes needed to create, update, reschedule, and cancel appointments, read availability, and let the business choose which calendar to connect. SageDesk does not request broad delete/share calendar permissions.
- Operational safeguards: access to production systems is restricted, authenticated, and monitored, and security and integration events are logged for auditing and abuse prevention.
Limited use of Google user data
SageDesk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data accessed through Google APIs is used only to provide and improve the user-facing scheduling and appointment features requested by the connecting business. SageDesk does not use Google user data for advertising, does not sell it, does not transfer it to third parties except as needed to provide the service or as required by law, and does not allow humans to read it except where the business gives explicit consent, where required for security or to comply with law, or where the data has been aggregated and anonymized.
Retention and deletion
SageDesk keeps information for as long as needed to provide the service, meet contractual or legal obligations, resolve disputes, and maintain reasonable business records. When a business disconnects a Google Calendar integration or revokes access, SageDesk stops accessing that account and deletes or de-identifies the associated tokens and calendar-derived data within a reasonable period, except where retention is required by law. Businesses can request access, correction, or deletion of their data by contacting hello@sagedesk.in.
Your choices
Customers can choose whether to connect calendar integrations and can revoke that access through the relevant provider or by contacting SageDesk. To ask about access, correction, deletion, or policy questions, email hello@sagedesk.in.
Policy updates
SageDesk may update this Privacy Policy from time to time. Material updates will be reflected on this page with a revised effective date.
For a plain-English summary: if you connect a calendar, SageDesk uses that permission to help schedule appointments and manage invites — not as a backstage pass for unrelated nonsense.