Last updated: July 25, 2026
1. Information We Collect
ShootCal operates under a privacy-first model. The App only accesses data that is strictly necessary to perform its core functions.
A. Data Accessed via Google OAuth (With Your Explicit Permission)
Google Account Information: Your email address, used solely to authenticate and identify your connection with Google Calendar.Google Calendar Events: The App reads and writes events to your selected Google Calendars. This includes event titles, dates, times, locations, color labels, recurrence rules, and attendee email addresses.Attendee RSVP Status: When a client accepts, declines, or modifies a calendar invitation, their status flows back through the Google Calendar API and is displayed inside the App.Google Contacts (Optional): If you enable the “Sync with Google Contacts” feature, the App reads and writes contacts within a single, isolated contact group label it creates, named ShootCal Clients. It does not add to or modify contacts outside of this label.Google “Other contacts” (Optional, read-only): If you separately opt in to “Find client emails” during the Client Scan (see Section 4), the App reads — on a strictly read-only basis — your Google “Other contacts” (the names and email addresses Google automatically saves from people you have emailed) solely to suggest an email address for a scanned client name. You review and confirm every suggestion, and nothing in your contacts is created or changed.Google Tasks (Optional): If you use the to-do and follow-up features, the App reads and writes tasks within a single dedicated Google Tasks list it creates, named ShootCal. This lets your follow-up to-dos appear alongside your photography schedule and stay in sync across your devices and the web. The App does not read or modify tasks outside of this list.Google Drive (Optional, app-created files only): If you choose to save a signed contract to Google Drive, the App writes a copy of that contract into a dedicated ShootCal Contracts folder using the drive.file scope, which limits access to only the files the App itself creates. The App cannot read, modify, or even see any of your other Drive files.B. Data Stored Locally on Your Device & Private iCloud
Location Metadata: A city name and geographic coordinates used strictly for computing local golden hour, sunrise, and sunset times.Application Preferences: Your custom session types, default calendar selection, deposit-label prefixes, custom notification offsets, and UI preferences.On-Device Event Cache: A localized encrypted cache of your recent Google Calendar events to ensure instant UI rendering and offline browsing.Client List: Your clients live in your own Google Contacts (the “ShootCal Clients” label described above), not on ShootCal’s servers and not in iCloud. The app reads them live from Google and keeps only a brief in-memory copy while it is open.C. Invoice & Payment Data (Optional Web Feature)
If you use ShootCal’s invoicing feature, the following records are stored in ShootCal’s server database so you and your client can view the invoice and so the payment and refund history remains auditable:
Invoice settings: Your one-time setup acknowledgement, usual sales-tax label and rate, whether tax should be applied by default, your Stripe connection status, and the manual payment methods and instructions you configure.Invoice records: The client name and optional email address, invoice number and status, issue and final-balance dates, USD line items and amounts, tax selection and calculation, an optional deposit amount within the full invoice total, memo, the payment instructions captured when the invoice is issued, and an optional exact Google Calendar event identifier used only to update that booking’s paid/not-paid deposit flag. No invoice or deposit dollar amount is copied into Calendar.Payment history: Stripe checkout, payment, and refund identifiers, statuses, amounts, and ledger results; client reports that a manual payment was sent; your confirmation or rejection of those reports; payments you record yourself; and partial or full refunds and reversals. These records can include the amount, method, date, optional reference, and notes you enter.Payment-report abuse prevention: When someone submits a client payment report, ShootCal stores a full SHA-256 hash derived from a server secret and the connection IP address. The raw IP is not stored with the report. This one-way value is used only to limit repeated submissions to that invoice.Protected client access: Issued invoices use a high-entropy access secret. ShootCal stores a one-way hash for validation and an encrypted copy needed to let you copy the link again; the raw secret is not stored in normal request or access logs.Card payments are processed by Stripe through the photographer’s connected Stripe account. ShootCal stores the identifiers, status, amount, and ledger result needed to show and reconcile the payment or refund, but it does not receive or store the client’s full card number or bank credentials. Manual-payment instructions, references, and notes are free-text fields, so you must not enter card or bank credentials, passwords, access codes, or other secrets in them. A client’s “payment sent” report is only a notice to you; it does not change the balance or enter the cash-received report until you confirm that the money arrived.
The hashed invoice-claim address is distinct from the existing contract e-signature audit trail: when a client signs a contract, ShootCal may retain that signer’s raw IP address and browser details as signature corroboration. A scheduled data-minimization cleanup erases those details roughly three years after the session date.
2. Google API Services User Data Policy & Limited Use Disclosure
ShootCal’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Our practices strictly comply with these core privacy conditions:
Core Product Functionality: We request read and write access to your Google Calendar (calendar.events and calendar.readonly) and permission to send emails on your behalf (gmail.send) strictly to provide user-facing scheduling and studio features. gmail.send is used for messages such as booking confirmations, reminders, contract notices, and an invoice email that you explicitly choose to send. We do not have, and do not request, access to read, modify, or delete existing emails in your inbox.Contact Access: We access Google Contacts (contacts) solely to keep your client list synchronized in both directions inside the dedicated ShootCal Clients label. With your separate, explicit opt-in for the Client Scan, we also read your Google “Other contacts” (contacts.other.readonly) on a strictly read-only basis, solely to suggest an email address for a scanned client name (see Section 4); you confirm each suggestion before it is saved. We do not otherwise access or modify your contacts.Isolated Task Syncing: We access Google Tasks (tasks) solely to create, display, complete, and remove your follow-up to-dos inside a single dedicated Google Tasks list named ShootCal. We never access or modify tasks in your other lists.App-Created Drive Files Only: We use Google Drive (drive.file) only if you opt to save a signed contract to your Drive, writing a copy into a dedicated ShootCal Contracts folder. The drive.file scope restricts us to files the App itself creates; we cannot access any of your other Drive content.No Advertising or Marketing: Google user data obtained via ShootCal is never used, transferred, or sold to third parties for serving advertisements, personalized marketing, retargeting, or interest-based profiling.No Profiling or Advertising Data Sharing: Google user data obtained via our app is never transmitted to external servers or third-party systems for data logging, advertising, or algorithmic profiling. Data is sent to our own server (api.shootcal.com) only as needed for user-facing features you choose to use, including the Web Calendar feed, optional AI Client Scan described in Section 4, contract e-signing and Drive archive service, online booking, and invoicing described in Section 1C, and even then it is never sold or used for ads.No Human Review: We do not allow human review of your Google user data. A human may only access your data if we have obtained your explicit, affirmative consent to view specific elements for technical troubleshooting or support requests.Strict Transfer Safeguards: We only transfer your Google user data to others if it is explicitly necessary to provide or improve user-facing features visible inside the app’s interface (such as transferring availability metadata to api.shootcal.com for your optional Web Calendar publishing feature).3. How We Use Your Information
Calendar Operations: Used exclusively to display, create, modify, and delete photography session events on your behalf.Invoices & Payment Records: Used to create and share the invoices you direct ShootCal to issue, offer Stripe card payments and your configured manual methods, let the client report a manual payment, record card payments and refunds, let you confirm or reverse money received, and prepare your reports and exports.Location Processing: Location queries entered into the App’s configuration are processed directly through Apple MapKit on-device. No location search queries or tracking details are transmitted to the developer.Preferences Syncing: A subset of your app configurations (sunrise/sunset location, deposit prefixes, session types) is synced across your own personal devices using Apple iCloud Key-Value Storage. Notification preferences and calendar selection stay isolated on a per-device level.4. Text Parsing: On-Device Quick Add & Optional AI Client Scan
On-device Quick Add. The native apps include an optional natural language event parser (e.g., typing “Smith wedding next Saturday at 3pm” to pre-fill your scheduling form).
On iPhone, iPad, and Mac this processing occurs entirely on-device using local, native platform text-processing built into the operating system.The text you type, your calendar metadata, and your client details are never transmitted to the developer, to Google, or to any remote third-party for this on-device feature.This data is processed transiently in local memory and is never logged or stored externally.Optional AI Client Scan. ShootCal offers a separate, opt-in “Scan for Clients” feature that reads your calendar event titles to suggest client names for your client list.
When you choose to run a scan, the event titles within the date range you select are sent to our server at api.shootcal.com and then to Anthropic (the Claude AI provider) for the sole purpose of extracting suggested client names. Only the titles and the date range are sent for this purpose, not attendees, notes, or other event details.If you additionally enable “Find client emails,” ShootCal reads your Google “Other contacts” (names and email addresses Google auto-saved from people you have emailed) to match an email to a scanned name. You review and confirm every suggestion before anything is saved.This data is used only to return suggestions to you. It is not used to train AI models, and it is never sold or used for advertising. The web version of Quick Add also uses this same server-side AI rather than the on-device parser.5. Third-Party Services & Data Sharing
With whom we share, transfer, or disclose your Google user data. ShootCal does not sell your data, and does not share your Google user data with any third party for advertising, marketing, or profiling. We share, transfer, or disclose Google user data only in the limited cases below, and only to provide a feature you have chosen to use:
Google (the source APIs): Your data is read from and written to your own Google Account through the Google APIs listed below. Subject to the Google Privacy Policy.Our own backend server (api.shootcal.com): Only for user-facing features you enable — including the Web Calendar availability feed, online booking, contracts, the invoicing and manual-payment records described in Section 1C, the AI Client Scan relay (Section 4), and saving a signed-contract copy to your Google Drive. This runs on our own dedicated server infrastructure and the data is not shared onward, except that the AI Client Scan relay forwards only event titles to Anthropic as described in Section 4.Anthropic, PBC (Claude AI): Only if you run the optional AI Client Scan or web Quick Add — your event titles and the date range you select are processed to suggest client names (Section 4). Anthropic does not use this data to train its models. Subject to the Anthropic Privacy Policy.No other recipients: We do not disclose your Google user data to any other third party, and we never sell it.The App interacts with the following official APIs to provide its native features:
Google Calendar API & Google Sign-In: Authenticates your identity and processes your calendar data. Subject to the Google Privacy Policy.Google Drive API (drive.file): If you save a signed contract to Drive, ShootCal creates and updates only the contract documents it places in a “ShootCal Contracts” folder. The drive.file scope means the App can only see and manage files it created; it has no access to your other Drive files. Subject to the Google Privacy Policy.Apple MapKit (MKLocalSearchCompleter): Provides on-device location auto-complete for event coordinates. Subject to the Apple Privacy Policy.Apple iCloud Infrastructure: Syncs your app preferences (such as session types and your sun location) between your personal Apple devices. It does not store your client list, which lives in your Google Contacts. Subject to the Apple Privacy Policy.Google Tasks API: Reads and writes your follow-up to-dos within the dedicated ShootCal Tasks list. Subject to the Google Privacy Policy.Anthropic (Claude AI): If and only if you run the optional AI Client Scan (or web Quick Add), your event titles are processed by Anthropic via api.shootcal.com to suggest client names. Anthropic does not use API data to train its models. Subject to the Anthropic Privacy Policy.6. Data Storage, Security & Backend Limitations
ShootCal Web Services: Apart from the official Google and Apple endpoints and the opt-in AI Client Scan described in Section 4, the App transmits data to our own server only as needed for user-facing features you enable, including online booking, contracts, invoicing, and the optional Web Calendar. The public availability feed contains only privacy-stripped timing information and never contains your contacts, email tokens, or client personal details. An issued invoice’s content, selected manual payment instructions, and available Stripe payment buttons are visible only through its protected client link.No Developer Telemetry: The developer does not collect, track, or monitor your personal data, calendar entries, or analytics. There are no third-party software development kits (SDKs), background trackers, ads, or telemetry engines in the App.Website Analytics (Marketing Site Only): Our public marketing website at shootcal.com uses Google Analytics to understand aggregate visitor traffic, such as page views and where visitors come from. This is standard, anonymous website analytics. It is entirely separate from the App, applies only to the marketing pages, and never has any access to your in-app data, your Google Calendar, your contacts, or your clients. It is not present in the iPhone, iPad, Mac, or Watch apps.Cryptographic Security: All API communications are strictly encrypted using HTTPS / TLS protocols. OAuth tokens are managed securely via Google’s native iOS/macOS Sign-In SDK and stored directly in your local device’s hardware-encrypted System Keychain.7. Data Retention & Deletion
Your Google Calendar remains the source of truth for your schedule. Optional web features also require ShootCal to retain the records you create, including booking requests, contracts, invoices, payment reports, confirmed payments, and reversals, on our server while your account remains active. Those records are used only to provide the Service and are not sold or used for advertising. Calendar, device, and server-side data are handled as follows:
Google Cloud Infrastructure: Persists in accordance with your personal Google Account data retention policies. Deleting an event in the App moves it to your Google Calendar trash, where it remains recoverable for 30 days.Local Device Storage: Your local cache and active login states are instantly wiped from the system keychain and disk space if you tap “Sign Out” within the App, or if you uninstall the App.Apple iCloud Storage: Synced configurations persist within your secure private iCloud allocation for as long as your Apple Account remains active and the App is installed on at least one associated device.ShootCal Server: Account-scoped web records remain in ShootCal’s database until the related record or account is deleted where the Service permits, or until you ask support to delete your account. Voids and payment reversals intentionally preserve the original invoice and ledger history instead of silently rewriting financial records. Drafts may be deleted, and a void invoice may be permanently deleted only when it has no payment, refund, client-report, Stripe, booking, or uncertain-delivery history. You may request account and data deletion at support@shootcal.com.8. Your Rights
You can review, modify, or completely terminate ShootCal’s permissions at any time. To revoke access instantly, navigate to your Google Account Security settings and remove access for ShootCal. You can also purge local states by signing out of your profile inside the application settings.
9. Children’s Privacy
The App is not intended for use by individuals under the age of 13. The developer does not knowingly collect or request personal information from children.
10. Contact Information
If you have any questions or require legal or technical clarifications regarding this policy or how data is processed, please contact:
Developer: Ryan SmithEmail: support@shootcal.comMailing Address: 151 Empyrean Cir, Myrtle Beach, SC 29588Business Phone: 843-352-8640