Subprocessors
Last updated: August 10, 2026
Sync My Cal is run by Ops Automators. 8vendors sit behind it, and this is all of them. If procurement wants the contractual version of this page, it's section 6 of the Data Processing Addendum.
Vercel
United StatesHosting, serverless functions, scheduled jobs, and cookieless page analytics
Everything the app serves passes through it: account email, request logs, IP address. Vercel's own analytics counts page views and sets no cookie.
Neon
United StatesManaged Postgres, the only place we keep data at rest
Your account, encrypted calendar tokens, calendar names, sync rules, the id-to-id map between an event and its copy, and the sync log. No event titles, notes, or attendees.
Google Calendar API and Google sign-in
The calendars you connect, on your authorization. Google already holds this data: it's their calendar. Also Google Analytics 4, but only if you accept analytics cookies.
Microsoft
Microsoft's global infrastructureOnly if you connect an Outlook accountOutlook and Microsoft 365 calendars over Microsoft Graph
The same shape of access as Google, on the same authorization.
Stripe
United States, with global processingOnly once you upgrade from the trialSubscriptions, invoices, and card payments
Your email, a customer id, and your subscription state. Card numbers go to Stripe directly and never reach us.
Resend
United StatesTransactional email
Your email address and the message body: reconnect alerts, trial notices, password resets, the weekly sync digest.
Sentry
United StatesWhen error reporting is switched onServer error reports, so a failure gets fixed instead of sitting in a log
The error message and stack, where in the code it happened, and an opaque account id. We attach no tokens, no email addresses, and nothing from an event.
Cronitor
United StatesWhen job telemetry is switched onTelemetry for the background sync and email jobs
How long a run took, how many calendars it touched, and the error text if it failed. No calendar data.
What isn't on this list
Slack and custom webhooks, if you switch them on. Those send a short sync summary to a URL you chose, so the destination is yours and we can't vouch for it. No advertising networks, no data brokers, no AI vendors: your calendar data has never been used to train a model and never will be, and we don't sell it.
When this changes
Adding a vendor means editing this page, so the date at the top is the honest answer to “is this current?”. Want to hear about it first? Email privacy@syncmycal.app and we'll tell you before a new subprocessor goes live, which gives you time to object under section 6 of the DPA.
More on how the data is protected: Security & privacy · Privacy Policy