1. Who we are
Sloto is a product of Caresoft Systems Private Limited, a company incorporated in India with its registered office at Registered office address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107, CIN:U72900MH2022PTC387875.
For questions about this Policy or about how your data is handled, write to [email protected]. Contact details for our Grievance Officer and Data Protection Officer are in Section 17.
2. Our role: Hosts vs Invitees
2.1 When you are a Host
If you sign up for a Sloto account, connect your calendar and publish booking links, we act as the data fiduciary / controller of your account data. We decide what account information is needed to run the Services, and this Policy governs that processing directly.
2.2 When you are an Invitee
If you booked a meeting using someone's Sloto link, the Host decides what to ask you, why they are scheduling with you, and what they do with your information afterwards. In respect of that booking data the Host is the data fiduciary / controller and Sloto acts as a data processor handling it under the Host's instructions.
This means: if you want your booking data corrected or erased, or you want to know why you were contacted, you should approach the Host first. We will help the Host respond, and we will act on your request ourselves where the law requires us to. Our contact details are in Section 17 either way.
2.3 When you are a website visitor
For people who simply browse our marketing pages, submit an enquiry form or subscribe to updates, we are the controller of that data.
3. Information we collect
3.1 Information you give us (Hosts)
- Account and profile data — name, work email address, password (stored only as a salted hash), profile photo, job title, organisation name, time zone, preferred language, phone number where you choose to add one.
- Scheduling configuration — your event types, durations, buffers, notice periods, daily limits, availability rules, booking-page slug, custom questions you ask Invitees, confirmation and reminder text you write, routing and redirect rules.
- Team and workspace data — team name, member list, roles and permissions, shared availability and round-robin/pooled-availability settings.
- Billing data — plan, billing name, billing address, GSTIN or tax ID, invoices and payment status. Card and bank details are collected and stored by our payment gateway, not by Sloto. We receive only a token, the last four digits, the card network and expiry.
- Support and communications — messages, tickets, attachments, call or chat records with our support team, and your responses to surveys.
3.2 Information Invitees provide
- Name, email address, and any other field the Host has configured on the booking form (for example phone number, company, meeting agenda, reason for the meeting, file uploads).
- The date, time, time zone, duration and event type selected, plus any reschedule or cancellation you make and the reason you give.
- Guest email addresses you add to the invitation.
- Payment details, where the Host has enabled paid bookings — again processed by the payment gateway, not stored by us.
Hosts: you are responsible for the questions you put on your booking form. Do not collect health information, financial account numbers, government identifiers, biometric data or other sensitive categories through Sloto booking forms unless you have a lawful basis, have given the Invitee proper notice, and have a written agreement with us covering it.
3.3 Information we collect automatically
- Device and connection data — IP address, browser type and version, operating system, device type, screen size, referring URL, language and time-zone settings.
- Usage data — pages and booking pages viewed, features used, links clicked, timestamps, session duration, error and crash logs, API call metadata.
- Cookies and similar technologies — see Section 13.
- Email engagement — whether a confirmation or reminder email was delivered, opened or clicked, used for deliverability and troubleshooting.
3.4 Information from third parties
- Your connected calendar, email and conferencing providers (Section 4).
- Single sign-on providers, if you sign in with Google, Microsoft or a SAML identity provider — we receive your name, email address and a unique identifier.
- Payment gateway — transaction status, refund status, chargeback notices.
- CRM and workflow tools you connect through our integrations or API, limited to what that integration requires.
- Publicly available business information and enrichment data used for our own marketing, where permitted by law.
4. Calendar, email and video-conferencing integrations
4.1 What we access
When you connect a calendar account (for example Google Calendar or Microsoft Outlook/365), you grant Sloto access through OAuth. We never ask for or store your calendar password. Depending on the scopes you approve, we access:
- Free/busy information — the start and end times of existing entries on the calendars you select, so that we do not offer a slot you are not free for.
- Event read/write — to create, update, reschedule and cancel the events booked through Sloto, add the Invitee as an attendee, and attach a conferencing link.
- Basic profile — your name, email address and calendar list, so you can pick which calendars to check and which to write to.
We read event titles, descriptions and attendee lists only where a feature you have enabled requires it (for example, showing you the details of a conflicting event, or two-way sync). Where free/busy alone is sufficient, we request and use only free/busy.
4.2 Limited Use disclosure (Google)
Sloto's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, Google user data obtained through these APIs is used only to provide and improve the user-facing scheduling features you have enabled; is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition; is not used for advertising, ad targeting or ad personalisation; and is not used to train generalised artificial intelligence or machine-learning models. No human at Sloto reads your Google user data except with your explicit consent for a specific support request, where necessary for security purposes or to comply with law, or where the data has been aggregated and anonymised.
4.3 Video conferencing
If you connect Google Meet, Microsoft Teams, Zoom or a similar provider, we generate a meeting link for each booking and include it in the calendar event and confirmation emails. Sloto does not join, record, transcribe or store the contents of your meetings. What happens on the call is governed by that provider's own privacy policy.
4.4 Disconnecting
You can disconnect any integration at any time from Settings → Integrations, or revoke access directly with the provider (for Google, at myaccount.google.com/permissions). On disconnection we stop accessing that account and delete the stored OAuth tokens and cached availability data within 30 days. Events already written to your calendar remain there; you control them.
5. How we use personal data
- Create and administer accounts, teams and workspaces, and authenticate you.
- Compute availability, render booking pages, and confirm, reschedule or cancel bookings.
- Write and update calendar events and generate conferencing links.
- Send transactional messages — booking confirmations, reminders, reschedule and cancellation notices, follow-ups configured by the Host, verification and password-reset emails, and service notices.
- Process subscription payments, issue invoices, and handle refunds, taxes and dunning.
- Provide customer support and investigate the issues you report to us.
- Maintain and improve the Services — monitoring performance, debugging, capacity planning, and product analytics on aggregated or pseudonymised data.
- Protect the Services — detecting and preventing fraud, spam bookings, scraping, credential stuffing, abuse of booking pages, and other security incidents; enforcing our Terms.
- Comply with legal, tax, accounting and regulatory obligations and respond to lawful requests.
- Send marketing about Sloto to Hosts and enquirers, subject to Section 12.4 and applicable law. We do not send our own marketing to Invitees.
We do not sell personal data. We do not use Invitee booking data for our own advertising, and we do not use customer content to train generalised AI models.
6. Legal bases and lawful grounds
Where the EU/UK GDPR applies, we rely on the following:
| Purpose |
Legal basis |
| Providing the Services under our Terms; account creation; processing a booking you requested |
Performance of a contract |
| Calendar access and integrations |
Consent given at the OAuth screen, and performance of a contract |
| Security, fraud prevention, service improvement, aggregated analytics, direct B2B marketing |
Legitimate interests, balanced against your rights |
| Billing records, tax and statutory retention |
Legal obligation |
| Non-essential cookies, marketing emails where consent is required |
Consent |
Where India's Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of your consent, or for the "certain legitimate uses" the Act permits — including where you have voluntarily provided data for a specified purpose, and for compliance with law. Our notice at the point of collection sets out the purpose and the rights available to you.
7. How we share personal data
- Between Host and Invitee. A booking is inherently shared. The Host receives everything the Invitee submits on the booking form. The Invitee receives the Host's name, the event details and the meeting link. Both parties receive calendar invitations naming the other.
- Within a team or organisation. If a Host's account belongs to a team or an organisation-managed workspace, workspace administrators can access that Host's Sloto account data, event types and booking records, and can manage or delete the account.
- Service providers. See Section 8.
- Integrations you enable. If you connect a CRM, payment tool, automation platform or webhook endpoint, we send the data that integration is configured to receive. Once it reaches them, their privacy policy governs it.
- Legal and safety. Where required by applicable law, court order, or a valid request from a public authority; or where necessary to establish, exercise or defend legal claims, or to protect the rights, property or safety of Sloto, our users or the public. Where legally permitted, we will notify the affected customer before disclosing.
- Corporate transactions. In connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to the acquirer honouring commitments no less protective than this Policy. We will notify you of any resulting change in control of your data.
- With your direction. Any other sharing you ask us to do.
8. Sub-processors and service providers
We use vetted third parties to run the Services. Each is bound by a written agreement restricting them to processing on our instructions, with confidentiality and security obligations. Current categories:
| Category |
Purpose |
Typical location |
| Cloud hosting and storage |
Application servers, database, backups |
[India / region] |
| Transactional email |
Confirmations, reminders, system notices |
[region] |
| SMS / WhatsApp messaging |
Reminders where enabled by the Host |
[region] |
| Payment gateway |
Subscription and paid-booking payments |
India |
| Product and web analytics |
Usage measurement, error monitoring |
[region] |
| Support desk |
Ticketing and customer communication |
[region] |
9. International transfers
Sloto is operated from India and serves users in multiple countries. Personal data may therefore be transferred to, stored in, and accessed from India and other countries whose data-protection laws differ from those where you live.
Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organisational measures such as encryption in transit and at rest and strict access control. A copy of the relevant transfer mechanism is available on request from [email protected].
10. Data retention
| Data |
Retention |
| Host account and configuration |
For the life of the account, then deleted or anonymised within 90 days of account closure |
| Booking records and Invitee form responses |
Per the Host's configured retention setting; by default for the life of the Host's account, subject to the Host's deletion requests |
| OAuth tokens and cached calendar availability |
Deleted within 30 days of disconnection or account closure |
| Invoices, tax and accounting records |
As required by Indian tax law — currently up to 8 years |
| Server, security and audit logs |
Typically 90–180 days, longer where an investigation is open |
| Support tickets |
24 months from closure |
| Marketing contacts |
Until you unsubscribe, plus a suppression record kept indefinitely so we do not contact you again |
| Encrypted backups |
Rolling 35 days; deleted records disappear as backups age out |
We may retain data longer where necessary to comply with a legal obligation, resolve a dispute, or enforce our agreements. Aggregated and anonymised statistics that can no longer identify anyone may be kept indefinitely.
11. Security
We maintain technical and organisational measures appropriate to the risk, including: TLS encryption in transit; encryption at rest for databases and backups; passwords stored using a modern one-way hashing algorithm; OAuth tokens stored encrypted; role-based access control and least-privilege administration; multi-factor authentication for internal systems; network segmentation and firewalling; logging and monitoring; regular patching, vulnerability scanning and periodic penetration testing; secure development practices and code review; background-verified staff bound by confidentiality; and a documented incident-response plan.
No system is completely secure. If we become aware of a personal data breach affecting you, we will notify the affected users and the competent authorities within the timelines the applicable law requires — including without undue delay and, where feasible, within 72 hours under the GDPR, and in the manner and time prescribed under India's DPDP Act and CERT-In directions.
You are responsible for keeping your password confidential, enabling two-factor authentication, and controlling who you share your booking links and workspace access with.
12. Your rights and choices
12.1 Rights
Subject to the law that applies to you, you may have the right to:
- Access the personal data we hold about you and obtain a summary of processing.
- Correct inaccurate or incomplete data, and complete or update it.
- Erase your data where it is no longer needed or where consent is withdrawn.
- Withdraw consent at any time, without affecting processing already carried out.
- Receive a copy of your data in a portable, machine-readable format.
- Object to, or ask us to restrict, certain processing — including direct marketing.
- Nominate another person to exercise your rights in the event of death or incapacity (DPDP Act).
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Sloto does not carry out such decision-making.
- Complain to a supervisory authority or to the Data Protection Board of India.
12.2 How to exercise them
Hosts can access, edit, export and delete most data directly in Settings → Account and Settings → Data & privacy. For anything else, write to [email protected] from your registered email address. We respond within 30 days, or sooner where the law requires. We may ask for information to verify your identity and may decline requests that are manifestly unfounded, excessive or that would infringe another person's rights — and we will explain why.
12.3 Invitees
If you booked through a Host's page, please raise access, correction and deletion requests with that Host — their identity and contact details are on the booking page and in your confirmation email. If you cannot reach them, or where the law places the obligation on us directly, contact us and we will assist.
12.4 Marketing and notifications
You can opt out of marketing email using the unsubscribe link in any such message or from your account settings. You cannot opt out of transactional messages (booking confirmations, reminders, billing and security notices) while you hold an account or an active booking, because they are part of the Service itself.
13. Cookies and similar technologies
We use cookies and similar technologies for four purposes:
| Type |
Why |
Can you refuse? |
| Strictly necessary |
Session management, sign-in, CSRF protection, load balancing, abuse prevention |
No — the Services will not work without them |
| Functional |
Remembering time zone, language and interface preferences |
Yes |
| Analytics |
Understanding aggregate usage and improving the product |
Yes |
| Marketing |
Measuring campaign performance on our marketing site only — never on booking pages |
Yes |
Where required, we ask for consent through our cookie banner before setting non-essential cookies, and you can change your choices at any time via Cookie settings. You can also block or delete cookies in your browser, though some features may then stop working. We honour Global Privacy Control signals where legally required. We do not currently respond to browser "Do Not Track" signals, as no common standard exists.
14. Children's data
The Services are intended for business use by adults. We do not knowingly collect personal data from children under 18 (or the age of digital consent in your jurisdiction, where lower). Consistent with India's DPDP Act, we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us personal data, contact us at [email protected] and we will delete it promptly.
15. Third-party sites and services
Booking pages, confirmation emails and integrations may link to sites we do not control — including Hosts' own websites, conferencing providers, payment gateways and calendar providers. We are not responsible for their content or privacy practices. Review their policies before providing data to them.
16. Changes to this Policy
We may update this Policy to reflect changes in our Services, technology or the law. The "Last updated" date at the top will change. For material changes we will give notice by email to account holders or by a prominent in-product notice at least 15 days before the change takes effect, unless immediate change is required by law. Continuing to use the Services after the effective date means you accept the updated Policy.
General privacy queries
Email: [email protected]
Post: Caresoft Systems Private Limited
Registered office address:311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
Grievance Officer (as required under the Information Technology Act, 2000 and rules made thereunder, and the DPDP Act, 2023)
Name: Rajeev Pillai
Designation: Grievance Officer
Email: [email protected]
Address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107
We acknowledge grievances within 24 hours and aim to resolve them within 15 days of receipt.
Annex A — Additional notice for the EEA, UK and Switzerland
The controller for Host account data is Caresoft Systems Private Limited at the address above. For Invitee booking data the Host is the controller and we act as processor. Business customers may request our Data Processing Addendum, which incorporates the Standard Contractual Clauses, by writing to [email protected].
Where we rely on legitimate interests, you may object at any time on grounds relating to your particular situation; we will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is needed for legal claims. You always have an unconditional right to object to direct marketing.
Annex B — Additional notice for California residents
In the past 12 months we have collected the categories of personal information described in Section 3 — identifiers, commercial information, internet or network activity, geolocation inferred from IP address, professional information, and the contents of communications you send us — for the business purposes in Section 5, from the sources in Section 3, and disclosed them to the categories of recipients in Sections 7 and 8.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA. We do not knowingly sell or share the personal information of consumers under 16.
California residents may request to know, delete, or correct their personal information, and may not be discriminated against for exercising these rights. Submit a request to [email protected]. An authorised agent may submit on your behalf with written permission and proof of identity.