Privacy Policy

Last updated August 12, 2026

Who we are

Setupp is a meeting scheduling product operated by Setupp ("Setupp", "we", "us"). It lets a team publish booking pages, put a qualification form in front of the calendar, rate each inbound request, and write the resulting meeting to the hosts' calendars.

This policy explains what we collect, why, who else sees it, and how to get it deleted. It applies to usesetupp.com, the Setupp application, and the embeddable booking widget. Questions go to support@usesetupp.com.

Information we collect

Account data. When you create a workspace we store your email address, your name if you provide one, your workspace name, and your plan. We store an authentication identifier from your sign-in provider. We never store your password.

Configuration you write. Event types, availability rules, intake questions, qualification rules, decline messages, and the scoring profile that describes your ideal customer. This is content you author.

Booking data. When someone books with you we store the name, email address, and any intake answers they submit, plus the meeting time, duration, hosts, time zone, and the Setupp Score produced for that booking.

Declined attempts are not stored. If a submission fails your qualification rules, the request is refused before any record is written. We do not keep the answers, the email address, or a count. Nothing about that person enters our database.

Operational data. Server logs containing IP address, user agent, request path, and timestamp, kept for security and abuse prevention. Delivery status for transactional email we send on your behalf.

Google user data and Limited Use

Setupp's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, and without exception: we use Google user data only to provide and improve the scheduling features you explicitly connected your calendar for. We do not sell Google user data. We do not transfer it for advertising, market research, or credit-scoring purposes. We do not use it to develop, improve, or train generalized artificial intelligence or machine learning models. No human at Setupp reads your Google user data, except with your explicit consent for a support request you raised, where necessary for security purposes such as investigating abuse, or to comply with applicable law.

Google user data is never sent to our AI provider. The Setupp Score is computed from the intake answers a booker types into your form. Calendar events, attendee lists, and event titles are not included in that request and never leave our infrastructure for that purpose.

The exact Google scopes we request, and why

Connecting a Google Calendar is optional and is never required to use Setupp. When you choose to connect one, we request only these scopes:

https://www.googleapis.com/auth/calendar.readonly — to read the busy periods on your calendar so the booking page can hide times you are not free. We read event start and end times to compute availability. We do not copy your event titles, descriptions, attendees, or attachments into our database.

https://www.googleapis.com/auth/calendar.events — to create the meeting on your calendar when a booking is confirmed, attach a Google Meet conferencing link to it, and update or cancel that event when the meeting is rescheduled or cancelled. We only create and modify events that Setupp itself created.

https://www.googleapis.com/auth/userinfo.email — to know which Google account is connected, so the dashboard can show you which calendar a host is using and so a second host cannot silently overwrite the first one's connection.

We store the OAuth refresh and access tokens Google issues, because without them we cannot check availability or write the event. They are stored server-side, are never exposed to the browser, and are deleted when you disconnect the calendar.

How we use what we collect

To render your booking page and compute available times. To evaluate a submission against the qualification rules you wrote. To produce the Setupp Score and its reasoning. To create the calendar event and send confirmation, reschedule, cancellation, and reminder emails. To show you your own bookings in your dashboard. To keep the service running, diagnose faults, and prevent abuse. To bill you for your plan.

We do not build advertising profiles, and we do not sell personal information to anyone, for any purpose.

The Setupp Score and automated processing

Every submission that passes your qualification rules is rated from 0.0 to 10.0 against the scoring profile you wrote, with written reasoning and per-criterion signals. The inputs are the intake answers the person submitted and the criteria you configured.

Where a large language model is used to produce that rating, the intake answers and your criteria are sent to Anthropic as our processor. Anthropic does not train models on data submitted through its commercial API. If that path is unavailable, a deterministic rules-based engine produces the score instead, and the score card records which method ran.

The Score is operator-facing. The person booking never sees their score or its reasoning. The Score does not by itself decide whether a meeting happens — the qualification rules you wrote do that, and you remain free to accept or cancel any booking.

Who else processes your data

We use a small number of infrastructure providers, each handling data only to deliver the service:

Supabase — hosts our Postgres database and authentication. Our application host — serves the website and API. Resend — delivers transactional email such as booking confirmations. Anthropic — generates the Setupp Score from intake answers, as described above. Google — calendar availability and event creation, only for calendars you connected.

We may also disclose information where we are legally required to, or where it is necessary to investigate suspected abuse of the service. If Setupp is acquired, data may transfer to the acquirer under this same policy, and we will say so before it happens.

Retention and deletion

Bookings and their scores are kept for as long as your workspace is active, because they are your record of who you met and why. Server logs are kept for up to 30 days. Declined submissions are never written, so there is nothing to retain.

You can delete an individual booking from your dashboard. You can delete your entire workspace, which removes your event types, bookings, intake answers, scores, and stored calendar tokens. Email support@usesetupp.com to request deletion or a copy of your data and we will act on it within 30 days.

Revoking calendar access

Disconnecting a calendar in your Setupp dashboard revokes the token with Google and deletes it from our database. You can also revoke Setupp's access at any time, independently of us, at myaccount.google.com/permissions. Once revoked we can no longer read availability or create events, and existing events already on your calendar remain yours.

Cookies and browser storage

Setupp sets one cookie today. It is named setupp_gcal_state, it holds a single random value, and it exists so the redirect back from Google can be matched to the request that started it. Without it, someone could trick you into attaching a calendar you did not intend to attach. It is httpOnly and SameSite=Lax, it expires within minutes, and it is discarded as soon as the connection completes.

That is the entire list. There is no analytics cookie, no advertising cookie, and no third-party tracking cookie anywhere in Setupp. We do not use browser local storage. The embedded booking widget mounts into your own page and sets nothing of its own.

A strictly necessary session cookie keeps you signed in to your workspace once you have an account. We will update this page before introducing any cookie beyond that, and we will not add one that tracks you.

Security

Traffic to Setupp is served over HTTPS. Google OAuth tokens and our service credentials are held server-side and are never included in any response sent to a browser. Database access is governed by row-level security policies so a workspace can only read its own rows. Qualification rules are evaluated on the server and are never shipped to the booker's browser.

No system is perfectly secure. If we become aware of a breach affecting your data we will notify you without undue delay and describe what happened and what we did about it.

Your rights

Depending on where you live you may have the right to access, correct, export, or delete your personal information, to object to or restrict processing, and to complain to a supervisory authority. We honour these requests regardless of jurisdiction. Write to support@usesetupp.com.

If someone booked a meeting with you and wants their data removed, they can contact us and we will route the request to the workspace that holds it, and act on it directly where we are the controller.

Setupp is operated from India and our infrastructure providers operate globally, so your information may be processed outside your country.

Children

Setupp is a business product and is not directed to children under 16. We do not knowingly collect their information. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top of this page. For changes that materially affect how we handle your data, or any change to the scopes we request, we will email workspace owners before the change takes effect.

Contact: support@usesetupp.com