Effective August 12, 2026
When you create a Cordy account, we collect your name, email address, organization name, and password. If you subscribe to a paid plan, our payment processor (Stripe) collects billing details on our behalf — we do not store credit card numbers directly.
We also collect usage data such as pages visited, features used, and browser or device information through standard server logs. This helps us understand how Cordy is used and where we can improve.
When someone books an appointment through a Cordy booking page, we collect the name, email address, phone number (where provided), time zone, and any answers to questions the organization has added to its own booking form. We collect this information on behalf of the organization being booked with, and we process it only to arrange and manage that appointment. If the booking link contained campaign tracking parameters (for example utm_source), we store those alongside the appointment so the organization can understand where its bookings come from.
If a member of your team connects a calendar or video-conferencing account, we receive an access credential for that account and the email address it belongs to. Section 5 explains this in detail.
We use your information to operate the Cordy platform, including authenticating your identity, processing bookings, sending transactional emails (confirmations, scheduling links, team invitations), and providing customer support.
We may use aggregated, anonymized usage data to analyze trends and improve our product. We do not use your personal data for advertising.
Cordy schedules appointments against real calendars. To do that, a team member may connect their own Microsoft or Google account, and (where offered) their own Zoom account. Connecting is always initiated by the individual account holder, who grants access through that provider’s own consent screen. Nothing is connected automatically, and an organization administrator cannot connect an account on someone else’s behalf.
What we access. From a connected calendar we read free/busy information — the times that account is already occupied — so that clients are only offered times the person is genuinely available. We do not read the titles, descriptions, attendees, locations, or contents of existing calendar entries. We also create, update, and delete the calendar events for appointments booked through Cordy, and only those events; we do not modify or delete anything else on the calendar.
What we store. We store an access credential and refresh credential for the connected account, the email address of that account, and, for each appointment Cordy creates, the provider’s event identifier and the video meeting join link. Credentials are stored server-side only, are never sent to a browser, and are not readable by other users of your organization or by other organizations. Busy times are read live at the moment availability is calculated and are held only briefly in memory; we do not build a copy of anyone’s calendar.
Google user data. Cordy’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it except as needed to provide the scheduling features described here or where required by law, and we do not allow humans to read it except with the account holder’s explicit permission for support purposes, for security investigations, or where required by law.
Disconnecting. A connected account can be disconnected at any time from within Cordy, by the individual or by an administrator, which deletes the stored credentials immediately. Access can also be revoked directly with the provider — for Google, at myaccount.google.com/permissions. Revoking access stops all future calendar reads and event creation; calendar events Cordy has already created remain on the calendar unless they are deleted there.
Your data is stored on infrastructure provided by Supabase, which runs on Amazon Web Services (AWS). Data is encrypted in transit (TLS) and at rest. We use row-level security policies to ensure users can only access data belonging to their organization.
While no system is perfectly secure, we take reasonable administrative, technical, and physical measures to protect your information from unauthorized access, loss, or misuse.
Cordy uses session cookies to keep you logged in and maintain your preferences. These cookies are essential to the operation of the service and are not used for tracking or advertising purposes.
We do not use third-party advertising cookies or tracking pixels.
We use a limited number of third-party services to operate Cordy:
Supabase — authentication and database hosting. Stripe — payment processing for subscriptions. Resend — transactional email delivery (booking confirmations, scheduling links, team invitations).
Where a team member has connected an account, we also communicate with: Microsoft (Graph API) — calendar availability and meeting creation for connected Microsoft accounts. Google (Google Calendar API) — calendar availability and meeting creation for connected Google accounts. Zoom — video meeting creation for connected Zoom accounts. These connections exist only for accounts that have been explicitly connected, and each provider receives only what is needed to read availability and manage the meetings Cordy creates.
These providers process data on our behalf and are contractually obligated to protect your information. We do not sell or share your data with any other third parties.
We do not sell, rent, or trade your personal information. We share data only with the third-party processors listed above, and only to the extent necessary to provide the service.
An organization may choose to authorize one of its own systems — for example a marketing or CRM tool it operates — to read that organization’s appointment data through Cordy’s API, using an access token the organization controls and can revoke at any time. Access granted this way is limited to that organization’s own appointments and never exposes data belonging to another organization.
We may disclose information if required by law, such as in response to a valid subpoena or court order.
You have the right to access, correct, or delete your personal data at any time. You can update your profile information directly in Cordy’s settings, or contact us to request a full data export or account deletion.
If you delete your account, we will remove your personal data within 90 days, except where we are required to retain it for legal or compliance purposes.
We retain your data for as long as your account is active. If you cancel your subscription or close your account, we retain your data for up to 90 days to allow for reactivation, after which it is permanently deleted.
Aggregated, anonymized data that cannot identify you may be retained indefinitely for analytical purposes.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice within the Cordy application. Your continued use of Cordy after a change constitutes acceptance of the updated policy.
Questions about this policy? Contact us at hello@cordyco.com